Legal/Privacy Privacy policy

How KOTAN.ai handles personal data.

What we collect through our own website and accounts, what we process on behalf of publishers and SSPs, and the choices available to people whose data passes through the platform.

Last updated 20 August 2026

01. Who this covers

This policy applies to KOTAN.ai ("KOTAN.ai", "we", "us"), a company operating in the United States of America. It covers the KOTAN.ai website, the customer dashboard, and the APIs and services delivered through them.

It describes our practices for two very different groups, and the sections below say which one they apply to:

  • Business users. People at publishers, SSPs and other organisations who visit our website, correspond with us, or hold an account on the platform.
  • Audiences. People whose ad requests pass through inventory that a KOTAN.ai customer operates. We have no direct relationship with these people, do not know who they are, and reach their data only because a publisher or SSP sends it to us to have a decision made.

02. The two roles we play

We are the controller of data about business users: what we collect through the website, through accounts, and through our own correspondence and billing. That data is ours to explain, and this policy explains it.

We are a processor and service provider for audience data. Our customer decides what inventory to run, what data to send us, and what to do with the result. We act on that customer's documented instructions under a written agreement, we do not sell that data, and we do not use it for our own purposes or for any other customer. Where an audience member wants to exercise rights over that data, the customer is the right place to start, and we support them in answering.

03. What we collect

From business users

  • Contact and identity details you give us: name, work email, company, role, and anything you write in a form or a support conversation.
  • Account and access data: credentials, API keys, roles and entitlements, and audit records of significant actions taken in the platform.
  • Commercial data: billing and payout details, order and invoice records, and settlement history.
  • Website and product telemetry: IP address, browser and device user agent, referring page, pages viewed, session and error logs, and cookie identifiers.

From audiences, on our customers' behalf

  • Advertising and device identifiers transmitted in the ad request, together with the identifier's associated opt-out flag.
  • IP address and the coarse location derived from it, at country, region or city level. We do not derive or store precise location.
  • Technical request attributes: user agent, device and platform type, connection type, and the placement, format and dimensions of the ad slot.
  • Auction and inventory attributes: publisher, property, placement, floor, bid and clearing data, and the demand sources that participated.
  • Creative and advertiser attributes needed for separation and deduplication, including advertiser domain, category and creative identifiers.
  • Outcome signals: whether an impression was served, filled, unfilled, duplicated, blocked, viewable, or clicked.

What we do not collect. We do not seek, and instruct customers not to send, sensitive personal information — including data revealing health, precise location, race or ethnicity, religion, sexual orientation, immigration status, union membership, government identifiers, or account credentials. We do not collect biometric data and we do not build identity graphs linking people across unrelated properties. Where sensitive data reaches us anyway, we delete it.

04. How we use it

Business user data

  • Providing, securing and supporting the platform, and administering accounts.
  • Billing, settlement, collections and tax and accounting records.
  • Responding to enquiries, security reviews and contractual requests.
  • Understanding how the product is used so we can improve it, and sending service and, where permitted, marketing communications you can opt out of at any time.

Audience data

  • Building and maintaining the joined data set a customer asks for, and generating the segments and revenue forecasts they use to plan.
  • Setting and revising floor prices for the customer's inventory, and recording the reasoning behind each revision so it can be audited and reversed.
  • Enforcing competitive separation and preventing duplicate ads inside the same break.
  • Detecting and preventing invalid traffic, impression inflation, spoofing and other advertising fraud, and protecting the security and integrity of the platform.
  • Producing reporting and analytics for the customer whose inventory the data came from.
  • Producing aggregated, anonymised statistics about platform performance that do not identify any person, customer or commercial arrangement.

We do not use audience data to advertise our own services, and we do not combine one customer's data with another's.

05. Legal bases

Where data protection law requires a legal basis, we rely on:

  • Performance of a contract — providing the platform to a customer, administering accounts, and billing.
  • Legitimate interests — securing the service, preventing fraud and invalid traffic, improving the product, and running our business, where those interests are not overridden by the rights of the people involved.
  • Consent — non-essential cookies, and any processing of advertising identifiers where consent is required. Consent for audience data is collected by the publisher whose property the person is using, and transmitted to us with the request; we act on the signal we receive.
  • Legal obligation — tax, accounting, and responses to lawful requests.

06. How our models work

The platform uses machine learning to forecast revenue, build segments, price floors, and identify duplicate or competing creatives. It is worth being precise about what that does and does not involve.

Our models operate on inventory, auction, creative and performance data. They do not perform biometric identification, facial or voice recognition, emotion detection, or any analysis of a person's body or image. They do not attempt to infer health, beliefs, sexual orientation, or any other sensitive characteristic, and they are not used to make decisions that produce legal or similarly significant effects for an individual.

We do not train models on one customer's data for the benefit of another. Models we run for a customer are fitted and applied within that customer's account. Customer data is not pooled into any shared model, index or benchmark, and is not used to train models made available to third parties.

07. Cookies and identifiers

On our own website and dashboard we use strictly necessary cookies for sign-in, session integrity and security, and — with consent where required — analytics cookies that tell us how the site is used. You can refuse or clear non-essential cookies at any time; the platform will still work, though some conveniences will not persist.

We do not run advertising cookies or tracking pixels on our own website, and we do not use our website to build advertising audiences.

In the ad request path, we receive device and advertising identifiers that the publisher's environment provides. We use them to make the decision the customer asked for and to detect fraud. We do not set our own identifiers on a person's device, do not sync identifiers with third parties for our own purposes, and do not sell them.

08. Opting out of targeted advertising

We honour the consent and opt-out signals transmitted with an ad request, including the standard preference strings and consent frameworks used across the advertising supply chain, and the device-level "limit ad tracking" flag. Where a signal indicates that a person has opted out of targeted advertising or the sale or sharing of their data, we do not use their data for audience segmentation and treat the request accordingly.

Because we have no direct relationship with audiences, the most effective controls sit closer to them: the privacy settings on the device or connected television, the opt-out published by the publisher whose property they are using, and the industry opt-out tools operated by the advertising trade bodies. Our website also honours the Global Privacy Control browser signal.

We do not sell personal information, and we do not share it for cross-context behavioural advertising for our own benefit.

09. Who we share data with

  • The customer whose inventory it came from. Audience data is returned to and reported to that customer, and nobody else.
  • Demand sources in the auction path — exchanges, SSPs and DSPs — where the customer has instructed us to transact with them and only to the extent the bid request requires.
  • Infrastructure and service providers — cloud hosting, storage, monitoring, email, payment processing and support tooling — engaged as subprocessors under written agreements that limit them to our instructions, impose confidentiality and security obligations, and prohibit any use of the data for their own purposes.
  • Professional advisers, under confidentiality, where needed for audit, legal or accounting purposes.
  • Acquirers, if the business or a part of it is sold or merged, subject to this policy continuing to apply.
  • Authorities, where we are legally compelled by subpoena, court order or a valid law enforcement request. We review each request, disclose only what is required, and notify the affected customer unless we are prohibited from doing so.

A current list of subprocessors is available to customers on request, and we give notice before adding a new one.

10. International transfers

We operate from the United States of America and our infrastructure is primarily located there. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on an appropriate transfer mechanism: the Standard Contractual Clauses together with the UK Addendum, our certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where applicable, or another lawful mechanism.

We assess the destination's legal environment, apply supplementary technical measures including encryption in transit and at rest, and make our transfer documentation available to customers who need it for their own assessments.

11. How long we keep it

  • Raw ad request and impression logs containing identifiers or IP addresses: retained no longer than 180 days, then irreversibly aggregated or deleted. Shorter periods apply where a customer's agreement specifies one.
  • Aggregated and anonymised reporting data: retained indefinitely, because it no longer identifies anyone.
  • Business user account data: retained for the life of the account and for a limited period afterwards to handle disputes and wind-down.
  • Billing and tax records: retained for the period the law requires.
  • Website and security logs: retained for a short operational window, longer where an incident is under investigation.

On termination, a customer has thirty days to export their data before we securely delete it, other than what we are required to retain by law.

12. Security

We apply administrative, technical and physical safeguards proportionate to the data we hold. These include encryption in transit using TLS 1.3, encryption at rest using AES-256, role-based access control on a least-privilege basis with multi-factor authentication for administrative access, network segmentation, logging and monitoring of access to production systems, vulnerability management and patching, background-checked personnel under confidentiality obligations, and a documented incident response process.

No system is perfectly secure. Where a breach affects personal data, we notify affected customers without undue delay and support them in meeting their own notification obligations, and we notify regulators and individuals where the law requires us to.

13. Your rights

Depending on where you live, you may have the right to know what personal data we hold about you and to obtain a copy, to have it corrected, to have it deleted, to obtain it in a portable format, to opt out of targeted advertising and of the sale or sharing of personal data, to limit the use of sensitive personal information, to withdraw consent, to object to processing based on legitimate interests, and not to be discriminated against for exercising any of these.

To exercise a right over data we hold as a controller, contact us at privacy@kotan.ai. We will verify your identity before acting, respond within the time the applicable law allows, and tell you if we need longer. You may use an authorised agent where the law permits, and you may appeal a decision by replying to it; if you remain unsatisfied you may complain to your data protection authority.

If your request concerns data we process on a customer's behalf, we will forward it to that customer and assist them in responding, because they decide what happens to it.

14. Children

The platform is a business service and is not directed to children. We do not knowingly collect personal data from anyone under 13, and we do not knowingly permit our platform to be used to serve targeted advertising on the basis of personal data collected from anyone under 13.

Customers are required to identify child-directed inventory and to transmit that designation with the request, so it can be excluded from audience segmentation and treated as contextual only. If we learn that we hold personal data from a child under 13 without verifiable parental consent, we delete it promptly. A parent or guardian who believes we hold such data should contact privacy@kotan.ai.

15. Changes to this policy

We update this policy as the platform and the law change. The date at the top shows the current revision. Where a change materially affects how we handle personal data, we give notice through the platform or by email before it takes effect.

16. Contact

Privacy questions, rights requests, and data protection agreements all reach the same team at privacy@kotan.ai. General enquiries can go through the contact form.

Privacy & data protection

Reviewing us as a vendor?

Security questionnaires, data processing agreements and subprocessor detail go through the same contact. Tell us what your review process needs.