TRANSPARENCY & PERSONAL DATA

Your privacy,
made clear.

What data we process, why we need it and how to exercise your rights. Information for people visiting COREADS, running campaigns or monetising their websites.

GDPR · UE 2016/679Last updated
Your rights

Who processes your data

The controller for this website and the management of COREADS services is the company identified below. Contact it with questions about this notice or to exercise your rights, using the subject “COREADS Privacy”.

VAT number: Contact us about privacy

Who this notice covers

This notice describes the processing of data about visitors, business contacts, Advertiser and Publisher users and, for the advertising activities described, visitors to websites integrating COREADS. It covers the public website, account areas and related services. Publisher websites, ad destinations and payment services have their own notices: consult them when interacting with those parties. Their respective privacy roles depend on the activities and applicable agreements; this page does not replace the notice of the website you visit.

Data collected and its sources

Data you provide: name, email, contact details, company, credentials, address and tax details; registered websites, advertising content, support requests, documents and payment information needed for the service. Financial operations also involve amounts, balances, transaction references, invoices and Publisher payout details.

Technical and usage data: IP address, date and time, requested pages or resources, browser, device, operating system, language, referring page and security logs. Ad delivery may involve ad, campaign and placement identifiers, impressions, clicks, conversions and approximate location derived from the IP address. Sources include your browser, our systems and integrations activated by Advertisers and Publishers, including pixels and conversion notifications.

Why we use data

The legal basis depends on the specific purpose under Article 6 GDPR. Consent is not a blanket condition for accessing our services.

Why we use data
PurposeLegal basis
Create and manage accounts, campaigns, advertising spaces, support and pre-contract requests.Contract or pre-contract steps (Art. 6(1)(b)). For business representatives: legitimate interest in managing the relationship (Art. 6(1)(f)).
Manage invoices, tax and accounting obligations, collections and payouts.Contract and legal obligations (Art. 6(1)(b) and (c)).
Protect the service, prevent abuse and invalid traffic, investigate anomalies and defend rights.Legitimate interest in security and reliable delivery, balanced against individuals’ rights (Art. 6(1)(f)).
Optional website measurement and non-essential advertising tracking, when enabled.Consent where required (Art. 6(1)(a) and cookie rules). Refusing does not prevent browsing the website.

Which data is required

Data required for registration, security, invoicing and payments is needed to provide those functions or comply with the law. Without it we may be unable to open an account, process a payment or respond to a request. Additional information is optional. Do not include passwords, full card details, health information or other sensitive data in contact messages, assistant messages or creatives.

Cookies and similar technologies

The website uses cookies and browser storage for authentication, security, language and preferences. The CoreAds_language cookie stores your chosen language for up to one year. Your cookie choice and its date are stored in browser local storage until cleared. Session cookies support access and requested features; clearing them may require you to log in again.

Google Analytics is activated on the public website only if you accept measurement cookies. It uses identifiers such as _ga and _ga_* to recognise visits and measure usage; cookie lifetime is set to a maximum of two years and may renew with visits. You can refuse or withdraw through “Manage cookies” by choosing “Use necessary only”. Withdrawal stops subsequent measurement on this website but does not automatically erase data already sent. Choices apply to the browser and domain used.

Advertising and campaign measurement

COREADS manages ad delivery and related events for reporting, attribution, spend control and fraud prevention. Integrations may receive data from Publisher and Advertiser websites, such as a click or conversion linked to a campaign. Selection may depend on context, approximate location, device and criteria set by the advertiser. Where retargeting is used, the CoreAds_rt identifier can link visits and ads for 30 days. Non-essential tracking requires the consent prescribed by applicable rules; on third-party websites, use their privacy controls. Choices on this website do not change choices on other websites.

Who may receive data

Data may be processed by authorised personnel and providers of hosting and infrastructure, maintenance, email, security, support and advertising tools, within their assigned activities. Providers acting on our behalf are processors; banks, payment providers, advisers and authorities may act as independent controllers according to their functions. Integrations and external services, including Google Analytics, Google reCAPTCHA and graphical resources loaded from external services, may receive technical data such as IP and browser information when used. Ad content and Publisher websites are intended for publication; do not include personal data you do not intend to make public.

Processing outside the EEA

International providers may process or access data from countries outside the European Economic Area, even where primary hosting is in Europe. For such transfers, the GDPR requires an adequacy decision or appropriate safeguards, such as standard contractual clauses and, where needed, supplementary measures. Contact us for information on the recipients and safeguards applicable to your data and to request a copy. For third-party services, also consult their own notices.

How long we keep data

Retention depends on the purpose and applicable obligations. Account and service data is kept during the relationship and afterwards to the extent needed to settle pending activities, meet obligations and handle disputes. Invoices and accounting records are subject to statutory periods, ordinarily ten years. Contact and support requests are retained to handle the request and related checks. Retention of logs and advertising events takes account of security, reporting, attribution and traffic verification needs. Data needed for a dispute may be kept until it is resolved. Closing an account does not immediately erase documents subject to mandatory retention. You can ask for the criteria and periods applicable to a specific set of data.

Security, assistance and automation

We use HTTPS connections, access controls and technical measures to limit unauthorised access and abuse. The website assistant processes your message and page context to provide service guidance. Creative generation and optimisation features, if used, may send content and campaign data to providers configured for that feature. Delivery and optimisation rules may select ads or change campaign parameters according to service settings. You can request an explanation of a result or a review by support. Services are intended for adult professional users; do not submit children’s data.

Your rights and how to exercise them

Under the conditions of Articles 15–22 GDPR you can obtain access and a copy, correction, erasure, restriction of processing and portability of data you provided where processed automatically on the basis of consent or contract. You may object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time. You may withdraw consent without affecting the lawfulness of prior processing. Where applicable, you can request human intervention and contest solely automated decisions with legal or similarly significant effects.

Write to the contact on this page or use the contact form, stating your request and account email if applicable. We may ask only for information needed to verify your identity. We respond without undue delay and normally within one month; extensions of up to two further months where permitted are explained within the first month. Requests are normally free. You may complain to the Italian data protection authority or the authority in the EU country where you live, work or consider an infringement occurred, and seek a judicial remedy.

Italian data protection authority

Updates and references

This notice may be updated following changes to our services or the law. The date above identifies the published version. Material changes will be communicated through service channels where necessary. You can retain a copy using your browser’s print function.

A question about your data?

For questions or privacy requests, contact us here.

Contact us about privacy