- Version
- 2.0.0
- Published
- Effective
This notice explains how personal data is processed when you visit https://admeking.com, use the Admeking cabinet, payment pages or other Services, do business with us, contact us, or see or click an ad delivered through the Services. It gives the information required by Articles 13 and 14 of the General Data Protection Regulation (GDPR). Capitalised terms have the meaning given in the Definitions at https://admeking.com/legal/definitions.
1. Who is responsible
1.1 The controller for the processing described in this notice is Adwirk GmbH, Haunstetter Straße 112, 86161 Augsburg, Germany ("we", "us"). Admeking is a brand of Adwirk GmbH, not a separate company.
1.2 You can reach us about data protection at [email protected]. Please write to this address to exercise any of the rights in section 10.
2. Whose data we process and where it comes from
2.1 This notice covers:
- visitors to our website and payment pages;
- people who act for a Customer, such as account users, contact persons, directors and staff of advertisers, publishers and supply partners;
- people who send us payments or receive payouts in their own name;
- people who see or click an ad that is delivered through the Services ("end users");
- people who have subscribed to browser notifications on a publisher's website through which we deliver push ads;
- people who report abuse to us or otherwise write to us.
2.2 We receive personal data from these sources:
- from you, when you register, use the cabinet, pay, or write to us;
- from the Customer you work for, when it gives us your contact details;
- from your browser or device, when you visit our website or cabinet, or when an ad is requested, shown or clicked;
- from publishers and supply partners, which send us ad requests that contain technical data about the device and the page on which an ad is to be shown, and privacy signals such as consent strings;
- from advertisers and their tracking providers, which send us conversion events;
- from payment networks and payment providers, about payments made to or by us;
- from reporters and authorities, when they send us reports, requests or orders.
3. What we process, why, and on which legal basis
References to "Art. 6(1)(a)" and so on are to the GDPR. "(a)" is consent, "(b)" is performance of a contract or steps before entering into one, "(c)" is a legal obligation, and "(f)" is our legitimate interests or those of a third party. Where we rely on legitimate interests, the interest is stated. Retention is described in each item and in section 7.
3.1 Visiting our website and payment pages
3.1.1 Data: IP address, browser user agent, requested page, referring page, time of the request and technical response data.
3.1.2 Purpose: to deliver the pages to you and to protect the website against attacks and overload. Our content delivery network (Cloudflare, Inc.) processes these data for us.
3.1.3 Legal basis: Art. 6(1)(f). Our interest is a secure and working website. No information is stored on or read from your device for this purpose beyond what is necessary to deliver the page.
3.1.4 Retention: 30 days.
3.2 Website analytics and session recording
3.2.1 With your consent, we use analytics tools on admeking.com. The tools, the cookies they set and how to change your choice are listed in our Cookie Notice at https://admeking.com/legal/cookies.
3.2.2 Data: online identifiers stored in cookies, pages viewed, events such as clicks, referring page, device and browser data, approximate location derived from the IP address, and time of the visit. We use Google Analytics 4 (property G-HJ2ZMCDKB9), provided by Google. We use Yandex Metrica (counter 100461377), provided by Yandex.
3.2.3 Session recording. If you consent to the separate "session recording" category, Yandex Metrica's session-recording feature records how you use our pages: mouse movements, clicks, scrolling, and the content of the pages you see, so that we can replay sessions to find usability problems. Form fields that are marked as protected are not recorded.
3.2.5 Purpose: to understand how visitors use the website and to improve it.
3.2.6 Legal basis: your consent, Art. 6(1)(a) GDPR, and for storing and reading information on your device, § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Without consent the tools do not load. You can withdraw consent at any time through "Cookie settings" in the footer of the website. Withdrawal does not affect processing that took place before it.
3.2.7 Retention: Google Analytics data are kept for 14 months in our Google Analytics property. Yandex Metrica data and session recordings are kept for as long as our Metrica counter exists (session recordings: 15 days). Your consent choice is stored for 6 months.
3.4 Your account
3.4.1 Data: the details you give at registration and in your profile, such as name, e-mail address, phone number, messenger contact and company; your role (advertiser or publisher); your password; account settings; the times of registration, e-mail confirmation and last login; and session data.
3.4.2 Purpose: to open and run your Account, authenticate you, protect the Account against unauthorised access, and send service messages such as e-mail confirmation, password reset, deposit and moderation notices.
3.4.3 Legal basis: Art. 6(1)(b) for the Account and service messages; Art. 6(1)(f) for security, our interest being to keep Accounts and the Services safe. Where you act for a Customer, the contract is with the Customer and we rely on Art. 6(1)(f), our interest being to perform that contract with the people the Customer has appointed.
3.4.4 Retention: while the Account exists, and afterwards until claims under the contract are time-barred. Data that are also accounting records or business correspondence are kept as described in 3.6 and 3.7.
3.4.5 The cabinet runs on a platform provided by a third-party software vendor, which processes Account data for us as a processor.
3.6 Payments, invoices and payouts
3.6.1 Data: billing name and address, VAT ID, invoices, Account Balance, deposits, spend, earnings, adjustments and payout details, and the payment transaction data the payment method produces (payer account or address, transaction reference, amount and time). Information specific to a payment method is given in its Payment Instructions in the cabinet.
3.6.2 Purpose: to accept deposits, charge for the Services, pay publishers, keep our accounts and meet tax and accounting duties.
3.6.3 Legal basis: Art. 6(1)(b); Art. 6(1)(c) for accounting and tax records.
3.6.4 Card and other payments are handled by Revolut, which processes payment data under its own responsibility as required by the payment schemes.
3.6.5 Retention: for the periods required by commercial and tax law. In Germany these are 10 years for books and annual accounts, 8 years for accounting vouchers such as invoices and payment records, and 6 years for business letters, each counted from the end of the calendar year in which the record was made.
3.7 Support and business correspondence
3.7.1 Data: names, contact details, the content of messages and attachments.
3.7.2 Purpose: to answer your request and manage the business relationship.
3.7.3 Legal basis: Art. 6(1)(b) where the message concerns a contract or a request to enter into one; otherwise Art. 6(1)(f), our interest being to answer people who contact us.
3.7.4 Retention: business letters for 6 years (see 3.6.5); other messages until the matter is closed and any related claims are time-barred.
3.10 Delivering ads
3.10.1 When an ad is requested, shown or clicked, we process the data listed in section 4.2. Section 4 explains how ad delivery works and who receives the data.
3.10.2 Purpose: to run auctions, select and deliver ads, limit how often the same ad is shown, count impressions and clicks for billing and reporting, and detect invalid traffic.
3.10.3 Legal basis: Art. 6(1)(f). Our interest, and that of advertisers and publishers, is to finance websites and apps through advertising, to deliver and measure ads correctly, and to prevent fraud. Where information is stored on or read from the end user's device, the publisher must obtain the consent required by § 25(1) TDDDG or equivalent law before the ad request is made (see 4.5).
3.10.4 Retention: event-level data that relate to a device are kept for 13 months and then deleted or anonymised. Aggregated statistics may be kept longer.
3.11 Push notification subscriptions
3.11.1 If you allowed a publisher's website to send you browser notifications, we may deliver advertising notifications to your browser on that publisher's behalf.
3.11.2 Data: the push subscription (an endpoint address and keys generated by your browser), subscription time, browser, operating system, language, country, the website where you subscribed, and which notifications were delivered and clicked.
3.11.3 Purpose: to deliver notifications, to count deliveries and clicks for billing and reporting, to detect invalid traffic, and to stop sending when you unsubscribe.
3.11.4 Legal basis: your consent to receive notifications, Art. 6(1)(a), given on the publisher's website and in your browser's permission prompt; for counting, billing and fraud prevention, Art. 6(1)(f). Allowing notifications is not consent to any other profiling. You can withdraw consent at any time by revoking the notification permission for the website in your browser settings.
3.11.5 Retention: until you unsubscribe or the subscription becomes invalid, and then for 30 days.
3.12 Conversions and postbacks
3.12.1 Advertisers can send us conversion events (for example, that a click led to a sign-up), usually server to server.
3.12.2 Data: click ID, time and type of conversion, value, campaign and sub-IDs, and any other fields the advertiser sends.
3.12.3 Purpose and role: we store conversions and show them to the advertiser on its instructions, as its processor. We also use them as controller to bill campaigns priced on conversions, to optimise delivery and to detect fraudulent conversions.
3.12.4 Legal basis for our own use: Art. 6(1)(b) toward the advertiser and Art. 6(1)(f), our interest being correct billing, effective delivery and fraud prevention. The advertiser is responsible for having a legal basis to send us the data.
3.12.5 Retention: as for ad delivery data (3.10.4); conversion records that support an invoice as accounting records (3.6.5).
3.13 Preventing fraud and invalid traffic
3.13.1 Data: the ad delivery and conversion data described above, signals and scores derived from them, decisions and reasons, review records, captures of ad destinations (which can incidentally show personal data), and correspondence about investigations.
3.13.2 Purpose: to detect, investigate and prevent invalid traffic, fraud and misuse; to correct billing; and to establish, exercise or defend legal claims.
3.13.3 Legal basis: Art. 6(1)(f), our interest and that of our Customers being to pay and be paid only for genuine activity and to protect the Services and users; Art. 6(1)(c) where a law requires us to act or keep records.
3.13.4 Retention: routine signals for 3 years; evidence relating to a specific investigation until it is closed and any related claims are time-barred, or longer while a legal hold applies (7.4).
3.14 Abuse reports and requests from authorities
3.14.1 Data: the reporter's name and contact details, the report and its attachments, information about the ad, Destination or Account concerned, and any order or request from an authority.
3.14.2 Purpose: to assess reports, stop unlawful or harmful ads, inform the Customer concerned where appropriate, and answer authorities.
3.14.3 Legal basis: Art. 6(1)(f), our interest being to keep unlawful and harmful content out of the Services; Art. 6(1)(c) where a law requires us to act or respond. We do not tell the Customer who made a report unless this is necessary to handle it or required by law.
3.14.4 Retention: 3 years, or longer while a legal hold applies (7.4).
3.15 Records of acceptance of our terms
3.15.1 Data: Account, the person who accepted, the contracting company, the role, the version and content fingerprints of the documents accepted, the time of acceptance and the method (for example, a checkbox in the cabinet).
3.15.2 Purpose: to prove which terms apply to an Account.
3.15.3 Legal basis: Art. 6(1)(b) and Art. 6(1)(f), our interest being to prove the content of our contracts.
3.15.4 Retention: for as long as the contract exists and afterwards until claims under it are time-barred.
3.16 API access and automated tools
3.16.1 Data: API credentials and postback keys, the time, endpoint and origin of API requests, and the changes made through them.
3.16.2 Purpose: to give Customers and the tools they authorise programmatic access, to secure that access and to trace changes.
3.16.3 Legal basis: Art. 6(1)(b) and Art. 6(1)(f), our interest being secure and traceable access. A Customer is responsible for the automated tools and AI agents it authorises; they act for the Customer.
3.16.4 Retention: 90 days.
3.17 Our own automated tools
3.17.1 We use software tools, including AI-based tools provided by Anthropic and OpenAI, to help our staff operate the Services, for example to analyse statistics, review campaigns and draft correspondence. These providers process personal data for us as processors. The tools act for us; their use does not change who is responsible for a decision.
3.18 Legal obligations and claims
3.18.1 We also process the data described above where necessary to comply with a legal obligation (Art. 6(1)(c)), and to establish, exercise or defend legal claims (Art. 6(1)(f)).
4. How ad delivery works and who receives data
4.1 The parties. When a website or app shows an ad through the Services, several independent businesses are involved: the publisher that runs the website or app; often a supply-side platform (SSP) or network that sells the publisher's ad space; us; and demand-side platforms (DSPs), other exchanges or advertisers' ad servers that bid for the ad space and supply the ad. Each of them decides for itself what it does with the data it receives and is responsible for that under its own privacy notice.
4.2 What an ad request contains. An ad request that reaches us directly or through an SSP typically contains: the IP address of the device, the browser user agent, device type, operating system and version, browser, language, country (derived from the IP address or supplied by the SSP), the domain or page URL or app identifier, the referring page, publisher, placement and sub-source identifiers, identifiers assigned by the SSP, request and auction identifiers, the time, and privacy signals (4.5). When an ad is shown or clicked, we record the event with these data and an impression or click identifier.
4.3 Who receives it. To find an ad, we pass ad requests, with the data in 4.2, to DSPs, exchanges and advertisers' platforms that may bid. Each of them receives the IP address and device data in the request, whether or not it wins. When you click an ad, your browser goes to the advertiser's Destination, and the advertiser and the tracking providers it uses receive your IP address and browser data directly; their own privacy notices apply. Advertisers receive reports from us with statistics, which can include click and sub-source identifiers.
4.5 Consent at the publisher. Publishers are responsible for informing their users and for obtaining any consent required before information is stored on or read from a device, for example through a consent management platform. Publishers and SSPs may send us privacy signals with an ad request, such as consent strings under the IAB Transparency and Consent Framework (TCF) or the Global Privacy Platform (GPP), and a flag for content directed at children. We pass these signals on, as received, with the ad requests we send to bidders.
4.6 Balancing of interests. We rely on legitimate interests for ad delivery because the data we use are technical data that ad delivery needs, we do not use them to identify you by name, retention of event-level data is limited (3.10.4), and you can object (4.7). The interests of publishers in financing their content and of advertisers in reaching an audience are served by this processing.
4.7 Your choices as an end user. You can object to our processing of ad delivery data (see 10.6), refuse or withdraw consent in the publisher's consent tool, and limit tracking in your browser or device settings. Because we do not know end users by name, we may need information from you to find the data concerned, such as your IP address and the time and place of the ad; if we cannot identify you from the data we hold, Article 11 GDPR applies.
5. Recipients
5.1 We share personal data only as described in this notice. Recipients fall into these categories:
- Infrastructure providers, acting as our processors: our content delivery network Cloudflare, Inc. and our hosting provider DataWeb Global Group B.V. (Advanced Hosting).
- Platform provider: a third-party software vendor, which operates the cabinet and ad serving software for us as our processor.
- Google, for Google Analytics on our website (3.2).
- Yandex, for Yandex Metrica on our website (3.2).
- E-mail and communication providers that carry our messages.
- Payment service providers and banks involved in deposits and payouts.
- Ad-tech partners: publishers, SSPs, DSPs, exchanges and advertisers, as described in section 4.
- Advertisers and publishers who are parties to an investigation, to the extent needed to support a billing correction or claim (3.13).
- Professional advisers, auditors and tax advisers, bound to confidentiality.
- Courts, authorities and law enforcement, where we are legally required to disclose data or where disclosure is necessary to establish, exercise or defend legal claims.
- A buyer or successor of all or part of our business, if the business is transferred, subject to this notice.
6. Transfers outside the European Economic Area
6.1 Some recipients are located, or process data, outside the European Economic Area (EEA). These include:
- Cloudflare, Inc., in the United States;
- Google, in the United States;
- Yandex, which may process Yandex Metrica data in Russia; the European Commission has not decided that Russia ensures an adequate level of data protection;
- ad-tech partners (section 4), which are located in many countries.
6.2 Where data are transferred to a country without an adequacy decision of the European Commission, we rely on the EU-U.S. Data Privacy Framework where the recipient is certified under it, and otherwise the standard contractual clauses adopted by the European Commission. You can ask for a copy or information about these safeguards at [email protected].
7. How long we keep data
7.1 We keep personal data only as long as needed for the purposes in section 3, and then delete or anonymise it. The periods or criteria for each purpose are stated there.
7.2 Where commercial or tax law requires us to keep records, we keep them for the statutory period even if you ask for deletion, and restrict their use to that purpose (see 3.6.5).
7.3 Records that prove a contract, such as acceptance records and correspondence about an Account, are kept for as long as the contract exists and afterwards until claims under it are time-barred. Under German law the regular limitation period is three years from the end of the year in which a claim arose.
7.4 Legal hold. When a specific dispute, investigation or request from an authority requires it, we keep the related data beyond the normal period until the matter is closed. We record the reason for each hold and release it when it is no longer needed.
7.5 Evidence. Evidence we keep about invalid traffic, abuse or breaches of our terms is limited to what is needed for the matter, is accessible only to the staff who handle it, and is never published on our Legal Hub.
8. Is providing data required?
8.1 To open an Account and use the Services you must provide the data requested at registration, and the billing and payout data needed for payments. Without them we cannot enter into or perform the contract. Where the law requires us to collect data, for example for invoices, we cannot provide the Services without them.
8.2 You do not have to give any consent described in this notice. Refusing has no effect on your use of the Services.
9. Automated decisions and profiling
9.1 Ad selection is automated: for each ad request our systems decide which ad, if any, to deliver. This does not have legal or similarly significant effects for end users.
9.2 To detect invalid traffic, our systems score traffic, impressions, clicks and conversions using automated signals. These signals can automatically filter traffic, exclude events from billing, pause a placement or campaign, or hold an amount while it is reviewed.
9.3 Decisions to suspend or close an Account, to withhold a payout beyond the amount affected by a specific issue, or to terminate a contract are taken by a member of our staff who reviews the signals and the circumstances. If you are affected by such a decision you can explain your position and ask for it to be reviewed by writing to [email protected].
9.4 We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. If we start to do so, we will tell you in advance in this notice.
10. Your rights
10.1 You have the right to access the personal data we hold about you and to receive a copy (Art. 15 GDPR).
10.2 You can ask us to rectify inaccurate data and to complete incomplete data (Art. 16).
10.3 You can ask us to erase your data where the conditions of Art. 17 are met, for example where the data are no longer needed or you have withdrawn consent and there is no other legal basis. Data we must keep by law are restricted instead of erased.
10.4 You can ask us to restrict processing, for example while the accuracy of data is checked (Art. 18).
10.5 You can ask to receive data you gave us, which we process by automated means on the basis of consent or a contract, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible (Art. 20).
10.6 Right to object. Where we process your data on the basis of legitimate interests (Art. 6(1)(f)), you can object at any time on grounds relating to your particular situation. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves legal claims (Art. 21(1)). Where we process your data for direct marketing, you can object at any time without giving reasons, and we will stop using your data for that purpose (Art. 21(2) and (3)).
10.7 Where processing is based on your consent, you can withdraw it at any time with effect for the future, as easily as you gave it (Art. 7(3)):
- for cookies on our website, through "Cookie settings" in the footer;
- for push notifications, by revoking the notification permission in your browser;
- for anything else, by writing to [email protected].
10.8 You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live or work or where you think an infringement occurred (Art. 77). The authority responsible for us is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach.
10.9 To exercise your rights, write to [email protected]. We may ask for information to confirm your identity. We answer within one month; where a request is complex or we receive many requests, we can extend this by two further months and will tell you why. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
11. Security
11.1 We protect personal data with technical and organisational measures appropriate to the risk, such as encrypted connections, access controls that limit access to the people who need it, and records of access to our systems. No method of transmission or storage is completely secure.
11.2 Keep your Account credentials and API keys confidential and tell us at once if you suspect that they have been compromised.
12. Children
12.1 The Services are intended for businesses and are not directed at children. Accounts may be opened only by adults acting for a business. We do not knowingly collect personal data of children through our website or cabinet. If you believe that a child has given us personal data, please contact [email protected] and we will delete it.
12.2 Publishers must tell us when their content is directed at children, and advertisers must not target children with ads for products that may not be advertised to them. Our Advertising & Traffic Policy sets out the details.
13. Other websites
13.1 Our website, our ads and our reports contain links to websites of other businesses, including advertisers' Destinations and publishers' sites. Those businesses are responsible for their own processing and privacy notices.
14. Changes to this notice
14.1 We update this notice when our processing changes or the law requires it. Each version has a version number and is kept in the Legal Hub at https://admeking.com/legal, together with earlier versions.
14.2 If a change materially affects how we process the data of Account holders, we tell them by e-mail or in the cabinet before the change takes effect.
14.3 A change to this notice does not turn your continued use of the website or the Services into consent. Where a new purpose requires your consent, we ask for it separately and do not start that processing until you give it.