Protected Media Ltd., having its principal office and place of business at 3 Shaham St., Petach Tikva, Israel, together with its affiliates and subsidiaries from time to time, (collectively, “Protected”, “our”, “we”, or “us”) takes privacy seriously. This Privacy Policy explains how we collect and process data from:
- Visitors to the corporate website located at protected.media and subdomains thereof, our dashboard available at ui.protected.media, and the B2B services available on the foregoing by our customers (collectively, the “Protected Websites”); and
- Our advertising verification products and services. Such advertising technology products and services include advertisement verification, brand safety, IVT detection and supply intelligence across various thirty-party owned and operated digital media (the “Ad Verification Services”).
Please read the following carefully to understand our practices regarding your information and how we will treat it. By accessing or using the Protected Websites or Ad Verification Services, you agree to us processing your information in accordance with this Privacy Policy. In this Privacy Policy, the terms “personal information” or “personal data” are defined as any information that is linked or reasonably linkable to an identified or identifiable natural person, or that otherwise constitutes “personal information,” “personal data,” “personally identifiable information,” or similarly defined data or information under applicable law.
The Protected Websites may link to, and the Ad Verification Services may appear on, third party websites and online media properties. Protected does not control and is not responsible for the privacy practices of third parties, and this Privacy Policy does not cover collection or use of information by third parties on such third party websites and media properties. Visitors to or users of such third party websites or other media properties should consult the privacy policies of such third parties to learn about such third parties’ privacy practices.
With respect to data governed by: (i) the EU’s General Data Protection Regulation 2016/679 (“GDPR”), (ii) the GDPR as transposed into UK national law by operation of section 3 of the United Kingdom’s (“UK”) European Union (Withdrawal) Act 2018 (the “UK GDPR”); or (iii) the Swiss Federal Act on Data Protection 1992 (“Swiss DPA”), some of the data processed by Protected includes “personal data”, as further described below under the Section entitled “Additional Information for Residents of the European Union, UK and Switzerland”.
This Privacy Policy does not cover Protected’s collection, use or disclosure of information relating to employees or candidates for employment with Protected (collectively, “HR Data”), as Protected provides a separate privacy policy to such individuals governing HR Data.
Table of contents
1. Protected Website Visitors and Enterprise Customers
1.1. Data we collect from Protected Website visitors and prospects
1.2. Data we collect from Customers of our Ad Verification Services
1.3. How we use data collected from the Protected Websites and from Customers
1.4. Disclosure of data about Protected Website Visitors and Customers to third parties
1.5. Cookies and other tracking technologies on the Protected Websites
2. Protected’s Ad Verification Services Utilized on Third Party Media Properties
2.2. Data collected from End Users for the Ad Verification Services
2.3. Usage of data collected or received by the Ad Verification Services
2.4. Tracking technologies used by the Ad Verification Services
2.5. Disclosure of data from the Ad Verification Services to third parties
5. Data and Information Security
7. Additional Information for Residents of the European Union, UK and Switzerland
1. Protected Website Visitors and Enterprise Customers
1.1. Data we collect from Protected Website visitors and prospects
We collect the following categories of personal information during your visits to the Protected Websites (“Website Data”):
- information you directly provide to us through the Protected Websites, including via our contact form or live chat function, such as first name, last name, title, company name and region;
- any phone number used to call our customer service number;
- information about your activity on the Protected Websites, such as mouse scrolls and clicks, keystrokes entered, clickstream behavior, pages and files viewed or visited, the duration of such visits, and the search terms you employ within the Protected Websites;
- Information about the devices and software you use to access the Protected Websites, such as browser information, operating system information, device identifier, IP address, general geographic location, date, and time of visit, whether you are a new or a return visitor, device type, mobile carrier (if applicable), connection type and identifiers assigned to your browser or device, such as the advertising identifiers assigned by platform providers, and other such information as may be delivered or shared by the applicable browser or access software or device;
- In addition, we may collect business contact information for business development purposes, in order to assess and pursue potential business opportunities, including from offline sources. For instance, we may collect business contact information about existing and prospective Customers when we attend conferences, trade shows, webinars and other events. We may receive information from third party sources, from publicly available information, and from general business networking efforts. This information may include your business contact information, including name, title, company name, business address, email address, telephone number, and the Ad Verification Services that may be of interest to you.
1.2. Data we collect from Customers of our Ad Verification Services
If you are with an advertiser, agency, publisher or other entity that is a customer of our Ad Verification Services (a “Customer”), we may collect the following categories of personal information about your use of our Ad Verification Services (“Account Data”):
- Your business contact information, including name, title, company name, business address, email address, telephone number and login credentials;
- Website Data, as defined above;
- Your training profile, including details of courses you've attended and courses that you're due to complete;
- Information that you provide by filling in forms on the Protected Websites or in our support channels;
- Information you provide when you contact us (for example, if you contact us in writing, we keep a record of that correspondence, and if you call our support or customer service team, we may retain a recording of the phone call for a limited period for training purposes);
- Details associated with your use of our products and services, including the specific Ad Verification Services you have ordered from us, billing information and account usage information;
- Information about the Customer’s interaction with an email the Customer received from us, including, for example whether the Customer clicked on a link or opened the email.
- We may contact you to participate in surveys, beta-testing, and other information-gathering activities. If you decide to participate, you may be asked to provide certain information with your consent.
1.3. How we use data collected from the Protected Websites and from Customers
We use Website Data and Account Data in the following ways:
- To conduct processing which is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract;
- To carry out obligations arising from contracts entered into between you and us;
- For authentication purposes in order to ensure we are communicating with, or allowing access by, the correct individual;
- To respond promptly and effectively to your support requests and other queries;
- To help us keep the information that we hold about you up-to-date;
- To administer your account with us, and to carry out and verify financial transactions in relation to payments you make in connection with our products and services;
- To provide you with information, products, or services that you request from us and notify you of any changes to these;
- To request feedback regarding products you have purchased or licensed from us;
- For compliance and audit purposes, such as meeting our reporting obligations in our various jurisdictions;
- To collect debts, prevent fraud, infringement, identity theft and any other service misuse, comply with our legal obligations and take action in any legal dispute and proceeding;
- To monitor, improve and optimize the Protected Websites, services and products, including understanding your needs and interests. and to personalize your experience with the Protected Websites, our products and services and our communications;
- For other purposes as requested by you, or for other purposes that are clearly disclosed to you at the time you provide the information or with your consent;
- For marketing and advertising our products and services:
- We may use personal information to provide you or enable third parties to provide you with content and advertisements related to our own products and services, and to target such content and advertisements to be more relevant to you. We may also use, and permit third parties to use, cookies and other tracking technologies (such as web beacons and pixels) with the aim of collecting certain information to analyze behavior and customize the content and advertising displayed to you related to our own products and services. If you would like to opt out of the use of your personal information for marketing purposes, please review the section entitled “Cookies and Other Tracking Technologies on the Protected Website” below to exercise your choices.
1.4. Disclosure of data about Protected Website Visitors and Customers to third parties
Website Data and Account Data may be disclosed as follows:
- To the applicable Customer, in order to provide information, invoices, analytics and reports to the Customer;
- To the Customer’s selected third party destinations, in accordance with the Customer’s or its agent’s instructions, requests or approvals;
- To affiliated and subsidiary companies that we control, or that are under common control with us;
- To third party service providers we engage to perform functions and services on our behalf, such as cloud services for storing and processing Customer information, to the extent necessary to enable such third party service providers to perform the required functions and services, and only pursuant to obligations on such third party service providers that are consistent with this Privacy Policy. In all cases in which Protected transfers any personal information to its subprocessor, it does so pursuant to a data protection agreement governing such transfers. Where personal data is transferred outside of the EU or UK, appropriate safeguards are used, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
- Protected reserves the right to disclose information if it believes, in good faith, that such disclosure is required to comply with legal or regulatory requirements, or to protect others’ rights or prevent harm, including in response to lawful requests by public authorities, or to meet national security or law enforcement requirements.
- Personal information we have collected may be disclosed to third parties if we sell or buy any business or assets, in which case such personal information may be disclosed to the prospective seller or buyer of such business or assets. Such transfers will be subject to contractual data protection provisions.
- Protected may share Aggregated usage statistics regarding Customers of the Ad Verification Services and Protected Website visitors with the public or businesses with whom Protected works. Protected may also use such Aggregated information to help Protected improve the design and delivery of its products and services and increase its effectiveness for all users.
1.5. Cookies and other tracking technologies on the Protected Websites
Like many companies, we use cookies, pixels, web beacons, and other tracking technologies to collect information about your browsing activities and your interactions with the Protected Websites, and to serve targeted ads for our own products and services. There are a number of ways to opt out of having your online activity and device data collected through these methods, which we summarize below:
- Opting out of cookie use in our ”Manage Consent” tool. You can use the “Manage Consent” tool found in the bottom right hand corner of the Protected Website, to allow or disable non-essential cookies.
- Blocking cookies in your browser. Most browsers let you remove or reject cookies, including cookies used for targeted advertising. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit www.allaboutcookies.org.
- Using privacy plug-ins or browsers. You can block our websites from setting cookies used for targeted advertising by using a browser with privacy features, like Brave, or installing browser plugins like Privacy Badger, Ghostery or uBlock Origin, and configuring them to block third-party cookies/trackers.
- In addition, if you are a resident of California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, Oregon or Texas, you may also opt-out of targeted advertising via cookies on the Protected Websites by using the Global Privacy Control. You can visit the Global Privacy Control official site at https://globalprivacycontrol.org/ to learn how to configure your device to send such signals. We will honor and process the opt-out preference signal accordingly. Please note that your opt-out choice will only apply through the current browser or device you are using and only so long as that browser’s cookies are not erased. You will need to submit a separate opt-out of targeted advertising request on each device and browser to completely opt-out using this method. Please note that you may still receive generalized ads after opting out.
- Google Analytics
- Protected uses Google Analytics, a service provided by Google, to help analyze how users use the Protected Websites. Google Analytics uses “cookies”, which are text files placed on a user’s computer or device, to track the user’s activity (including information such as the user’s flow, location by country, language, browser and OS, ISP, and devices) on the Protected Websites. We use this service with a view to analyze usage across devices and offer improvements for all users. To learn more about Google Analytics, please click here. To opt out of this feature by installing the Google Analytics Opt-out Browser Add-on, please click here.
- Pendo
- Protected uses Pendo.io to better understand how our Customers are using our platform and tools, in order to assist our product and product design team(s) when making updates to our platform. Through the use of a javascript pixel on our dashboard, Pendo may collect a limited amount of behavioral information from customers accessing the dashboard, and in addition we may share a limited amount of data with Pendo in order to tie the information together. The information Protected shares with Pendo includes, name, user ID, email address, and country. To learn more about Pendo, please click here. To view Pendo’s privacy policy and learn more about your choices, please click here.
Please note that because some of these vendors’ opt-out mechanisms may be specific to the device, app or browser on which they are exercised, you may need to opt out separately on every device, app or browser that you use. We will endeavor to honor any browser-specific opt-out preference signals communicated to the Protected Websites.
1.6. Newsletters
if you subscribed to any of our email newsletters, you can change your subscription status at any time. To unsubscribe, please follow the instructions on the bottom of each newsletter, or by writing to us here. Please note that if you are a Customer, this will not unsubscribe you from required account-related communications relevant to your account.
2. Protected’s Ad Verification Services Utilized on Third Party Media Properties
2.1. Introduction
The Ad Verification Services include a suite of advertising technology products and services such as advertisement verification, brand safety, IVT detection and supply intelligence. The Ad Verification Services are used across various third party linear and digital televisions, channels, platforms, websites, applications (including mobile apps), devices and social media platforms (collectively, “Media Properties”). Visitors to Media Properties are referred to herein as “End Users”.
2.2. Data Collected from End Users for the Ad Verification Services
When an End User browses or uses Media Properties that activates the Ad Verification Services, Protected may collect data about such End User’s interaction with the advertisements on those Media Properties, and about the Media Properties on which such Ad Verification Services are utilized. Such information may include, to the extent relevant to the specific subset of the Ad Verification Services that is ordered by the Customer:
- Advertising campaign attributes – The identifier of the advertiser that delivers an advertisement, its campaign and placement identifiers, and the identifiers of the Media Property selling the inventory to the advertiser or any intermediary advertising platform.
- Web content attributes – The web address (URL) of the page/frame where the advertisement is being delivered, and the address of any referring pages/frames.
- Digital environment attributes – The type of connected device the advertisement is being delivered to: e.g. mobile, desktop, the browser type and version used to render the page where the ad appears and the operating system.
- Viewability attributes – The location of the advertisement on the page, the size of the advertisement, the size of the screen, the size of the viewport, the tab focus status, the browser focus status, duration the advertisement was in the viewable part of the webpage and the scroll position of the webpage.
- Exposure and engagement attributes – impressions, clicks, mouse movement and engagement with the advertisement, date and time of interaction.
- IP address, device identifiers and/or user agent string, or derivatives of these values, and mobile identifiers such as IDFAs, cookie IDs.
- General geographical location (e.g. country).
- Such additional data as is instructed or requested by the Customer (as controller) to be collected and processed by Protected (as processor) in order to enable the Ad Verification Services, as determined by the Customer in its discretion. For instance, a Customer may instruct Protected to process Personal Data of such Customer’s End Users or individuals who create accounts and content within the Customer’s environments.
Protected contracts with its Customers as a processor and service provider as defined under applicable data protection laws. As a result, we require our Customers to inform End Users separately about the Customer’s own processing of the End User’s personal information and to provide the End User with the necessary disclosures and privacy choices required under applicable data protection laws.
2.3. Usage of data collected or received by the Ad Verification Services
The data collected and/or received by Protected for the Ad Verification Services may be used as follows:
- in order to provide information, analytics and reports to our Customers;
- to help Customers or their selected third party vendors decide when and whether to serve advertisements to End Users;
- to establish connections between a user’s or household’s devices for the Ad Verification Services;
- for advertising-related viewability, security, debugging and brand safety purposes, and to detect or report on fraudulent advertising activity;
- in an Aggregated manner to administer, improve, market and enhance the Ad Verification Services and perform benchmarking and analysis; and
- as otherwise requested or instructed by the applicable Customer.
We do not engage in the following:
- No Reidentification, Targeting or Profiling. Protected does not (i) combine, analyze or enrich the personal information or personal data of End Users with additional information for the purpose of identifying End Users. As it relates to Protected’s Ad Verification Services, Protected limits any information it collects to information that does not allow the identification of an individual without additional information (e.g. any IP addresses or other identifiers we collect are not combined with any other data that would enable Protected to identify the individual to whom it relates); (ii) track End Users or their online activities across apps and websites over time; or (iii) create profiles or audience groups to target individuals. To the extent we provide a Customer with the data we have collected on behalf of a specific Customer, the Customer may elect to use such data for a variety of purposes, including the uses described in this paragraph. The Customer’s use of such data is governed by their own privacy policy(ies).
2.4. Tracking technologies used by the Ad Verification Services
The Ad Verification Services may utilize one or more of the following technologies to deliver the Ad Verification Services, if and to the extent the applicable Customer has configured the Ad Verification Services to use such technologies:
- “Web beacons” (also known as “tracking pixels”), which are electronic images that help perform a variety of functions, including counting visits and understanding usage;
- Software development kits (“SDKs”), which are tools that help application developers to enable advertising in applications;
- “Macros”, which are dynamic placeholders in ad tags and URLs that are automatically replaced with information when an ad is served;
- “Server to Server Connections”, which are a connection enabling two or more servers to communicate directly with each other to synchronize data.
2.5. Disclosure of data from the Ad Verification Services to third parties
The data collected and/or received by Protected for the Ad Verification Services may be disclosed as follows:
- To the applicable Customer, in order to provide information, analytics and reports to the Customer;
- To the Customer’s selected third party destinations, in accordance with the Customer’s or its agent’s instructions, requests or approvals;
- To affiliated and subsidiary companies that we control, or that are under common control with us;
- To third party service providers we engage to perform functions and services on our behalf, such as cloud services for storing and processing information, to the extent necessary to enable such third party service providers to perform such functions and services, and only pursuant to obligations on such third party service providers that are consistent with this Privacy Policy. In all cases in which Protected transfers any personal information to its subprocessor, it does so pursuant to a data protection agreement governing such transfers. Where personal data is transferred outside of the EU or UK, appropriate safeguards are used, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
- Protected reserves the right to disclose information if it believes, in good faith, that such disclosure is required to comply with legal or regulatory requirements, or to protect others’ rights or prevent harm, including in response to lawful requests by public authorities, or to meet national security or law enforcement requirements.
- Personal information we have collected may be disclosed to third parties if we sell or buy any business or assets, in which case such personal information may be disclosed to the prospective seller or buyer of such business or assets. Such transfers will be subject to contractual data protection provisions.
- Protected may share Aggregated usage statistics regarding the Ad Verification Services with the public or businesses with whom Protected works. Protected may also use such Aggregated information to improve the design and delivery of its products and services and increase its effectiveness for all users.
3. Industry Frameworks
Protected participates in the IAB Europe Transparency & Consent Framework (TCF) and complies with its Specifications and Policies. Protected’s identification number within the framework is 762. Protected use legitimate interest as our basis for collecting data for the following purposes: (i) Ensure security, prevent and detect fraud, and fix errors (Special Purpose 1); (ii) Deliver and present advertising and content (Special Purpose 2); (iii) Save and communicate privacy choices (Special Purpose 3); (iv) Measure ad performance (Purpose 7); (v) Develop and improve services (Purpose 10).
4. Data Retention
Any personal data or personal information processed by Protected from End Users will be Deidentified by Protected within fourteen (14) days. Other information may be retained by Protected for 12 months, or longer as needed to fulfil legitimate business purposes to the extent permitted by applicable laws and Protected’s agreements with its Customers.
Information that is anonymized De-Identified or Aggregated may be stored for as long as necessary to fulfill legitimate business needs or as required by law. For purposes of this Section, (i) “Deidentified” information means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer provided that the entity that possesses the information: (1) Takes reasonable measures to ensure that the information cannot be associated with a consumer or household; (2) Publicly commits to maintain and use the information in deidentified form and not to attempt to reidentify the information, except that the entity may attempt to reidentify the information solely for the purpose of determining whether its deidentification processes satisfy the requirements of this definition; (3) Contractually obligates any recipients of the information to comply with all provisions of this subdivision; and (ii) “Aggregated” information means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device.
5. Data and Information Security
Protected is committed to safeguarding the security and integrity of the data it collects. We implement robust and industry standard measures to protect the data in our possession against unauthorized alteration, destruction, access, or misuse. We maintain stringent controls over all collected data, retaining it in firewalled and secured databases. Access to these systems is strictly controlled and monitored, with limited access rights, authentication, strong password requirements and least access privilege principles. Please note that where you are provided with (or choose) login credentials that enable you to access the Protected Websites or Ad Verification Services, you are obligated to maintain their confidentiality. Please be aware that while we employ sophisticated defenses, no method of Internet transmission or electronic storage is entirely infallible. Protected cannot guarantee the absolute security of information you transmit to us, and such transmission is undertaken at your own discretion.
6. Children’s Privacy
The Protected Websites are not directed at minors. In the event that Protected learns that it has collected personal data or personal information from a minor on the Protected Websites without consent from a parent or a guardian, Protected will delete that personal data or personal information. If you believe that Protected might have any information from or about a minor, on the Protected Websites please contact Protected at the email address set forth below, so that Protected can confirm and take appropriate steps to remove such account and delete the information.
7. Additional Information for Residents of the European Union, UK and Switzerland
When administering the Protected Websites, Protected acts as a data controller/business. When providing the Ad Verification Services to its Customers, Protected is a data processor with respect to personal data collected by Protected on behalf of, or provided to Protected by, brands, agencies, publishers and other Customers; as such it is the responsibility of such brand, agency, publisher or other Customer to secure the lawful basis for such processing.
The following lawful bases may be used by Protected to collect and process personal data:
- Legitimate business interests. We may use your personal data for legitimate interests of: (i) Protected’s Customers desire to avoid ad-related fraud and to present geographically accurate and compliant information to End Users, (ii) End Users receiving fraud-free and geographically accurate and compliant information, and (iii) the general public in the continued availability of a free internet.
- Performance of contract. We collect and use personal data where needed to fulfill a contract with our Customer, who engages us to perform Ad Verification Services related to advertisements.
- User Consent. Where required under applicable laws and regulations, we may collect and use personal data described in this Privacy Policy subject to your consent. Notably and where required by applicable laws and regulations, we will rely on a Customer’s consent for any electronic marketing and personalization of message content to that Customer. . You may withdraw your consent at any time using the opt-out and preference management mechanisms provided within the message or by contacting us as described in this Privacy Policy. Withdrawing consent will not affect the lawfulness of consent-based processing before consent was withdrawn.
If you are an individual with respect to whose personal data the General Data Protection Regulation (“GDPR”) applies (a “data subject”), and where we are a controller of your personal data under GDPR with respect to data collected from the Protected Website, you have the following rights under GDPR and local laws, including, as applicable:
- The right to be informed about processing activities and applicable rights
- The right to access personal data being processed
- The right to rectify personal data when outdated or incorrect
- The right to erasure (and to be publicly forgotten)
- The right to object to processing with respect to processing activities based on consent
- The right to restrict processing when processing is deemed to be unlawful
- The right to data portability between proprietary systems in a common format
- The rights related to automated decision making, including decisions based on profiling activities.
If you are an individual with respect to whose personal data the GDPR applies, and where we are a controller of your personal data under GDPR with respect to data collected from the Protected Websites, you may, or may have your authorized representative, contact Protected and its Data Protection Officer here in order to exercise your rights. Data subjects also have the right to lodge a complaint with a supervisory or data protection authority in their jurisdiction in the place of their habitual residence. If the supervisory authority fails to deal with a complaint, the data subject may have the right to an effective judicial remedy.
Please note that we may have to undertake a process to identify a data subject exercising their rights. There may be exemptions to the rights for specific legal reasons which, if applicable, we will set out for you in our response to your request. We may keep details of data subject requests exercised for our own compliance and audit requirements.
Where personal data is provided by a data subject acting in their capacity of an employee or personnel of a Customer of Protected, such data subject’s rights will have to be effected through that Customer in its capacity as the data subject’s employer.
The information that we collect from you and about you may be transferred to and stored in a country other than your country of residence, such as the USA and the UK, which may not offer the same level of protection of personal data as your country of residence. However, we will take contractual and/or other measures as required by GDPR Chapter V and other applicable laws, to ensure your personal data is protected; this also includes Standard Contractual Clauses approved by the EU Commission and the UK International Data Transfer Addendum. Your personal data may also be transferred to countries that have been recognized by the EU as having adequate data protection, such as Israel and Canada.
Our EU representative may be contacted as follows: info@myedpo.com
Or by mail:
MyEDPO
Attn: Protected Media EU Representative
Unit 3d North Point House, North Point Business Park
New Mallow Road
Cork, Ireland T23 AT2P
Our Data Protection Officer may be contacted as follows: info@myedpo.com
Or by mail:
MyEDPO Israel Ltd.
Unit 3, 12 Hamaapilim
Jerusalem, Israel 9358801
8. Additional Privacy Information for Customers and Protected Website Visitors who are Residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and Other U.S. States in Which an Applicable State Privacy Law is in Effect.
8.1. Introduction
In this section, we provide information for Customers and Protected Website visitors who are residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states in which an applicable State Privacy Law is in effect as may be required under applicable privacy laws of such states from time to time (“State Privacy Laws”). For instance, the California Consumer Privacy Act (“CCPA”), as amended by the California Consumer Privacy Rights Act (“CPRA”), and the Virginia Consumer Data Protection Act (“VCDPA”), require that we provide our Customers and Protected Website visitors who are residents of such states certain specific information about how we handle their personal information.
Under State Privacy Laws, subject to certain exceptions, “personal information” is generally any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular resident or household in the applicable state. Because certain State Privacy Laws require that we disclose specific information about how we handle personal information collected about our Customers and Protected Website visitors who are residents of such states, the scope of this section may be different than the scope of our Privacy Policy.
Please note that for Protected employee information-related requests, the Protected employee privacy policy (which is separately provided to Protected employees) applies.
8.2. Key concepts
(a) What is a “sale” of personal information under State Privacy Laws such as CCPA and VCDPA? What is a “share” of personal information under the CPRA?
A “sale” of personal information under State Privacy Laws may occur any time a business sells or makes available any personal information to a third party for monetary or other valuable consideration. Under the CPRA, “sharing” generally means disclosing, making available or communicating personal information by a business to a third party for cross-context behavioral advertising (also known as targeted advertising), whether or not for monetary or other valuable consideration, including transactions between a business and a third party for targeted advertising for the benefit of a business in which no money is exchanged. Targeted advertising to a consumer is based on the consumer’s personal information obtained from the consumer’s activity across businesses, distinctly-branded websites, applications, or services, other than the business, distinctly-branded website, application, or service with which the consumer intentionally interacts.
The use of some third party cookies placed on our Protected Websites may be considered or “sharing” of personal information under State Privacy Laws. For example, we may share information from the Protected Websites with our social media and other advertising partners, such as LinkedIn, in order to serve targeted ads for our own products and services and assess the effectiveness of such campaigns. You may opt out of such cookies as detailed in the section entitled “Cookies and Other Tracking Technologies” above.
The Ad Verification Services do not engage in “sale”, “sharing” or “targeted advertising” as defined under State Privacy Laws.
(b) What is “sensitive information” under State Privacy Laws?
“Sensitive information” is generally defined as personal information that reveals sensitive information about a consumer, such as social security, driver’s license, state identification card or passport numbers, account log-in, financial account, debit card or credit card numbers in combination with any required security or access code, password or credentials allowing access to an account, precise geolocation, data revealing racial or ethnic origin, religious beliefs, physical or mental health diagnosis, sexual orientation, or citizen or immigrant status, as well as processing of genetic or biometric data for identification, and personal data collected from a known child. Protected does not collect sensitive information as defined under applicable law.
8.3. Categories of personal information of Customers and Protected Website Visitors that we collect and disclose to others for a business purpose
The items below set out generally the categories of personal information that we collect and disclose to others for a business purpose from Customers and Protected Website visitors.
(a) Name, Contact Information, and other Identifiers: Identifiers such as a real name, alias, address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.
- Do we collect? – YES
- Do we disclose for a business purpose? – YES
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – YES (to the limited extent that use of non-essential third-party tracking technologies on the Protected Websites could be deemed a “sale” or a “share” under State Privacy Laws).
(b) Customer Records: Paper and electronic customer records containing personal information, such as name, signature, physical characteristics or description, address, telephone number, education, current employment, employment history, social security number, passport number, driver’s license or state identification card number, insurance policy number, bank account number, credit card number, debit card number, or any other financial or payment information, medical information, or health insurance information.
- Do we collect? – YES
- Do we disclose for a business purpose? – YES
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(c) Protected Classifications: Characteristics of protected classifications under California or federal law such as race, color, sex, age, religion, national origin, disability, citizenship status, and genetic information.
- Do we collect? – NO
- Do we disclose for a business purpose? – NO
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(d) Purchase History and Tendencies: Commercial information including records of personal property, products or services purchased, obtained, or considered, or other purchasing or use histories or tendencies.
- Do we collect? – YES
- Do we disclose for a business purpose? – YES
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(e) Biometric Information: Physiological, biological, or behavioral characteristics that can be used alone or in combination with each other to establish individual identity, including DNA, imagery of the iris, retina, fingerprint, faceprint, hand, palm, vein patterns, and voice recordings, keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information.
- Do we collect? – NO
- Do we disclose for a business purpose? – NO
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(f) Usage Data: Internet or other electronic network activity information, including, but not limited to, browsing history, clickstream data, search history, and information regarding a resident’s interaction with an internet website, application, or advertisement, including access logs and other activity information related to your use of any Protected Websites, applications or other online services.
- Do we collect? – YES
- Do we disclose for a business purpose? – YES
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – YES (to the limited extent that use of non-essential third-party tracking technologies on the Protected Websites could be deemed a “sale” or a “share” under State Privacy Laws).
(g) Geolocation Data: Precise geographic location information about a particular individual or device.
- Do we collect? – NO
- Do we disclose for a business purpose? – NO
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(h) Audio, Video and other Electronic Data: Audio, electronic, visual, thermal, olfactory, or similar information, such as CCTV footage, photographs, and call recordings and other audio recording (e.g., recorded meetings and webinars).
- Do we collect? – YES (for internal training purposes)
- Do we disclose for a business purpose? – YES
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(i) Professional or employment-related information: Employment history, qualifications, licensing, disciplinary record.
- Do we collect? – NO
- Do we disclose for a business purpose? – NO
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(j) Education Information: Information about education history or background that is not publicly available personally identifiable information as defined in the federal Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99).
- Do we collect? – NO
- Do we disclose for a business purpose? – NO
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
(k) Profiles and Inferences: Inferences drawn from any of the information identified above to create a profile reflecting a resident’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.
- Do we collect? – YES
- Do we disclose for a business purpose? – YES
- Do we sell? – NO
- Do we share with third parties for targeted advertising? – NO
8.4. Rights of Customers and Protected Website Visitors who are residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other U.S. states in which an applicable State Privacy Law is in effect
State Privacy Laws grant our Customers and Protected Website visitors who are residents of the above-named states the rights set forth below.
For the purposes of advertising served via our Ad Verification Services, we are a service provider and a processor to the Customer who has engaged us for such Ad Verification Services, and such Customer determines the purposes and means of processing personal information. The Ad Verification Services do not engage in “sale”, “sharing” or “targeted advertising” as defined under State Privacy Laws.
If you are an End User and wish to exercise any of your other rights with respect to your personal information (for instance, right to know, right to delete or right to appeal), please contact the relevant Customer to exercise such other rights.
(a) Right to Opt-out of Sale and/or Sharing of Personal Information. Customers and Protected Website visitors who are residents of the above-named states have the right to opt out of the “sale” of their personal information. Residents of California also have the right to opt out of the “sharing” of their personal information for targeted advertising. The use of some third party cookies placed on our Protected Website may be considered “sharing” of personal information under State Privacy Laws. For example, we may share information with our social media and other advertising partners, such as LinkedIn, in order to serve targeted ads for our own products and services and assess the effectiveness of such campaigns. You may opt out of such cookies as detailed in the section entitled “Cookies and other tracking technologies on the Protected Website” above.
In addition, if you are a resident of California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, Oregon or Texas, you may also opt-out of targeted advertising via cookies on the Protected Websites by using the Global Privacy Control. You can visit the Global Privacy Control official site at https://globalprivacycontrol.org/ to learn how to configure your device to send such signals. We will honor and process the opt-out preference signal accordingly. Please note that your opt-out choice will only apply through the current browser or device you are using and only so long as that browser’s cookies are not erased. You will need to submit a separate opt-out of targeted advertising request on each device and browser to completely opt-out using this method. Please note that you may still receive generalized ads after opting out.
(b) Right to opt out of targeted advertising or cross-context behavioral advertising. Some third party cookies on the Protected Website are used for targeted advertising purposes with respect to our own products and services. You may opt out of such cookies as detailed in the section entitled “Cookies and other tracking technologies on the Protected Website” above.
(c) Right to Limit Use and Disclosure of Sensitive Personal Information. Protected does not collect, use, or disclose sensitive information.
(d) Right to Revoke Consent. Under State Privacy Laws, Customers and Protected Website visitors who are residents of the above-named states have the right to revoke consent they previously provided to the processing of their personal information, subject to exceptions provided by applicable law.
(e) Notice at Collection. At or before the point of collection, notice must be provided to the individual of the categories of personal information collected and the purposes for which such information is used.
(f) Verifiable Requests to Delete and Requests to Know/Confirm. Subject to certain exceptions, Customers and Protected Website visitors who are residents of certain states have the right to make the following requests, at no charge:
- Request to Delete: Customers and Protected Website visitors who are residents of the above-named states have the right to request deletion of their personal information that we have collected about them and to have such personal information deleted, except where an exemption applies.
- Request to Know/Confirm: Customers and Protected Website visitors who are residents of the above-named states have the right to request and, subject to certain exemptions, receive a copy of the specific pieces of personal information that we have collected about them in the past and to have this delivered, free of charge, either (a) by mail or (b) electronically in a portable and, to the extent technically feasible, readily useable format that allows the individual to transmit this information to another entity without hindrance. Residents of the above-named states also have the right to request that we provide them certain information about how we have handled their personal information in the past, including the:
- categories of personal information collected;
- categories of sources of personal information;
- business and/or commercial purposes for collecting and selling their personal information;
- categories of third parties/with whom we have disclosed or shared their personal information;
- categories of personal information that we have disclosed or shared with a third party for a business purpose;
- categories of personal information collected; and
- categories of third parties and/or specific third parties to whom the residents’ personal information has been sold and the specific categories of personal information sold to each category of third party.
- Protected Website visitors who are Rhode Island residents have the right to know the specific third parties to whom their personal information was "sold" or “shared”. Such information is under Section 1.5 above.
(g) Right to Correct. Customers and Protected Website visitors who are residents of the above-named states have the right to request correction of their personal information that we have collected about them, except where an exemption applies.
(h) Right to Appeal. Customers and Protected Website visitors may appeal our decision with respect to a request they have submitted by contacting us here.
Some U.S. states provide you with the right to further appeal our determination to a consumer protection agency located in that state. For example:
- Colorado – Colorado Attorney General’s Office
- Connecticut – Connecticut Attorney General’s Office
- Delaware – Delaware Attorney General’s Office
- Indiana – Indiana Attorney General’s Office
- Iowa – Iowa Attorney General’s Office
- Kentucky – Kentucky Attorney General’s Office
- Maryland – Maryland Attorney General Consumer Protection Division
- Minnesota – Minnesota Attorney General's Office
- Montana - Montana Attorney General's Office
- Nebraska – Nebraska Attorney General’s Office
- New Hampshire – Data Privacy Unit of the Consumer Protection and Antitrust Bureau of the New Hampshire Attorney General’s Office
- New Jersey - Division of Consumer Affairs in the Department of Law and Public Safety of New Jersey
- Oregon - Oregon Attorney General's Office
- Rhode Island - Rhode Island Attorney General's Office
- Tennessee - Tennessee Attorney General's Office
- Texas - For denied appeals, visit the Texas Attorney General’s Office, Consumer Protection Division
- Virginia – For denied appeals, visit the Virginia Attorney General’s Office, Consumer Protection Division
(i) Right to Non-Discrimination. State Privacy Laws prohibit discrimination against their residents for exercising their rights under applicable state laws. Discrimination may exist where a business denies or provides a different level or quality of goods or services, or charges (or suggests that it will charge) different prices, rates or penalties on residents who exercise their privacy rights, unless doing so is reasonably related to the value provided to the business by the residents’ data. We do not engage in said discrimination practices.
(j) Authorized Agents. You may also authorize an agent (an "Authorized Agent") to exercise your rights on your behalf (e.g., in the form of an authorization signed by you showing the agent is authorized to act on your behalf). To do this, you must provide your Authorized Agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission from your Authorized Agent when they make a request on your behalf. Please note that we may ask you or your Authorized Agent for additional information to verify your identity and state of residency before executing your privacy request.
(k) Financial Incentives. A business may offer financial incentives for the collection, sale, or deletion of state residents’ personal information, provided the incentive is not unjust, unreasonable, coercive, or usurious, and is made available in compliance with applicable transparency, informed consent, and opt-out requirements. Residents of the above-named states have the right to be notified of any financial incentive offers and their material terms, the right to opt-out of such incentives at any time and may not be included in such incentives without their prior informed opt-in consent. We do not offer any financial incentives at this time.
(l) Exceptions to These Rights. The law provides for certain exceptions to the rights described above. We reserve the right to avail ourselves of these exceptions where applicable.
8.5. Submitting Requests
Some third party cookies on the Protected Website are used for targeted advertising purposes with respect to our own products and services. Customers and Protected Website visitors may opt out of such cookies as detailed in the section entitled “Cookies and other tracking technologies on the Protected Website” above.
Customers and Protected Website visitors may submit requests to know/confirm, requests to delete, requests to appeal and/or requests to revoke consent by contacting us here. We will respond to verifiable requests received from Customers and Protected Website visitors who are residents of the applicable states as required by law.
9. Contact Us
You may contact us and our Data Protection Officer here.
You may also write to us as follows:
Protected Media
Attn: Privacy
3 Shaham St.
Petach Tikva,
Israel
10. Changes to the Privacy Policy
Protected reserves the right to change or modify this Privacy Policy from time to time by posting the modified Privacy Policy on the Protected Websites. Your continued use of the Protected Websites or Ad Verification Services indicates your acceptance of the modified Privacy Policy.
Last updated: September 11, 2026
