Skip to content
Back to home ↗

Tekne Exchange · Platform privacy

Platform
privacy policy

This policy explains what data moves through the Tekne Exchange advertising platform when our partners buy and sell Connected TV inventory, what we keep, and the choices available to you.

Last updated: October 7, 2026.

1. Scope and controller

This Platform Privacy Policy covers the programmatic advertising exchange operated by Tekne Exchange (the “Platform”). It applies to data about devices and ad opportunities that our supply and demand partners trade through the Platform. It does not cover visits to teknexchange.com or emails you send us; those are described in our Privacy Policy.

You never interact with the Platform directly. It receives information from the app or channel you are watching, through the publisher or supply partner that monetises it, and uses that information to decide within a fraction of a second which advertiser will show you an ad. None of it includes your name, email address or any other detail that directly identifies you. It does include technical identifiers, described below, that privacy law treats as personal data.

Controller: Tekne & Creemy Group S.L.
Tax ID: B13945829
Registered office: C/ Siete Picos, 9, 28002 Madrid, Spain
Privacy contact: info@teknexchange.com

2. How the Platform works

The Platform is an exchange. Supply partners (publishers, apps and supply-side platforms) send a bid request for each ad opportunity; demand partners (advertisers, agencies and demand-side platforms) answer with a bid; the highest eligible bid wins and the partner’s own player serves the ad. Requests and responses travel server-to-server using the IAB OpenRTB protocol. Tekne Exchange does not place code, SDKs, pixels or cookies on your device and does not operate a website or app that you visit.

Tekne Exchange configures and operates the Platform on exchange infrastructure provided by a specialised vendor (see section 7), which runs the auctions and keeps the operational logs. Tekne decides which partners connect, which inventory is eligible for which buyers, price floors and quality controls.

At the date of this policy the Platform handles Connected TV (CTV) inventory only, served to devices located in the United States. CTV environments do not use browser cookies. If the Platform starts handling other formats or regions, this policy will be updated first.

Inventory todayConnected TV in the United States, traded server-to-server over OpenRTB.
On your deviceNothing. Tekne Exchange places no SDK, pixel or cookie and runs no consent banner of its own.
IdentifiersThe device advertising ID, IP address and user agent pass through to run each auction. No cookie or ID sync.
ProfilesNone. Tekne builds no audiences or segments and keeps no identifiers in its own records.

3. Data processed in the bid stream

Each bid request contains the fields below. Supply partners collect them from the device and the app; the Platform forwards them to the demand partners eligible for that opportunity.

CategoryFieldsPersonal data?
Auction and ad slotAuction and impression identifiers; video slot specification (size, duration, placement, playback method, skippability); floor price and currency; tag identifier; secure flag.No.
App and publisherApp bundle and store URL, app name and category, publisher identifier.No. Identifies the app or channel, not the viewer.
DeviceIP address; user agent; device advertising identifier (IFA) and its type; device type, make, model, operating system and version; carrier; language; connection type; limit-ad-tracking and do-not-track flags.Yes, in transit. IP address, user agent and advertising identifier are personal data.
LocationCountry, region and metropolitan area; in part of the traffic, postal code and approximate coordinates derived from the IP address, not from GPS.Yes, in transit. See section 8.
Privacy signalsCOPPA flag; GDPR flag and TCF consent string; US Privacy string; Global Privacy Platform string, where the supply partner provides them.Signals about your choices, forwarded unchanged. See section 5.
Supply chainTransaction identifier and, where provided, the chain of intermediaries that handled the request.No.

Bid responses contain the bid price, the creative (VAST markup), the advertiser domain, creative and campaign identifiers, and the URLs the Platform calls to record wins, impressions and losses.

The Platform does not receive names, email addresses, phone numbers, account identifiers or cookie identifiers. When a supply partner includes a user object in a request, Tekne Exchange removes it from every copy it keeps.

4. Why we process this data

  • Running the auction: the bid request is forwarded to eligible demand partners so they can decide whether and how much to bid. Eligibility depends on inventory and device attributes such as country, device type, app bundle and price floor, not on who you are.
  • Delivery and settlement: auction, bid and impression identifiers are used to count delivered ads, confirm prices and settle accounts with partners. Billing uses totals only.
  • Invalid-traffic detection: the IP address and device identifier of every request are scored by the Platform’s fraud-detection service to identify bots, spoofed devices and high-risk sources. Requests that fail the quality threshold are not offered to buyers.
  • Reporting: performance is reported by hour and day and broken down by partner, app, country and device type, never by individual device.
  • Troubleshooting: a small number of request and response samples are reviewed to diagnose integration problems. The samples Tekne keeps are stripped of identifiers before storage (section 6).
  • Honouring privacy choices: regulatory and consent signals are read and forwarded so that every party to the transaction can act on them.

Where the GDPR applies, we rely on our legitimate interest in operating a secure and accountable advertising exchange for auction execution, fraud prevention, measurement, settlement and troubleshooting; on the consent collected by the supply partner and transmitted to us where a request carries a TCF consent string; and on legal obligations where the law requires us to process or retain information. The bid stream is not used to make decisions that produce legal or similarly significant effects on you.

5. Privacy signals we honour

Your choices are collected by the app or device you use and travel with each request. The Platform reads them and passes them on; Tekne Exchange does not add, modify or infer any consent signal.

SignalHow the Platform treats it
GDPR flag and TCF consent stringForwarded to demand partners exactly as received, so that each buyer can apply the purposes and vendors you consented to.
US Privacy (CCPA) stringForwarded unchanged. Demand partners must honour an opt-out of sale or sharing carried in the string.
Global Privacy Platform (GPP) stringForwarded unchanged whenever the supply partner sends it, including the applicable US state sections.
COPPA flagForwarded unchanged. See section 10.
Limit ad tracking and do not trackForwarded unchanged. When limit ad tracking is on, the device should not provide an advertising identifier and demand partners must not use the request for personalised advertising.

6. What we keep, where and for how long

Platform logs. The exchange infrastructure provider keeps the complete request, response and impression logs needed to run the auctions, produce reports, settle billing and investigate fraud, including IP address, user agent, advertising identifier and location. These logs are held by the provider, acting as Tekne’s processor, in its United States data centre, are retained only for the limited period those purposes require, and are not copied to Tekne’s own systems.

Tekne’s own records. Tekne Exchange copies only sanitised samples and aggregated figures into its own cloud environment:

RecordContentPersonal dataRetention
Request and response samplesAuction and bid identifiers, app bundle, country, region and metro, device make, model and operating system, prices, creative markup.None. IP address, user agent, advertising identifier, device-ID hashes, user object, coordinates, postal code and city are removed when the sample is stored.90 days.
Supply-chain recordsPublisher and intermediary identifiers from received requests.None.90 days.
Reporting snapshotsDaily aggregates by partner, app, country and device type, and the Platform configuration.None.Kept as business records.
Technical service logsOperational logs of Tekne’s own services, without request bodies.None.30 days.
Partner account dataBusiness contact and billing details of partner companies.Professional contact details of partner staff.Duration of the relationship plus applicable limitation periods.

7. Who receives the data

RecipientRoleData
Exchange infrastructure provider (Project LimeLight)Hosts and runs the auction engine, reporting and fraud scoring as Tekne’s processor.The full bid stream, including IP address, user agent, advertising identifier and location.
Supply partnersPublishers, apps and supply-side platforms that originate each request. They collect the data from your device and are independently responsible for their own processing.Send IP address, user agent, advertising identifier, location, app details and privacy signals.
Demand partnersAdvertisers, agencies and demand-side platforms that bid on the opportunity. They are independently responsible for how they use the request.Receive the request, including IP address, user agent, advertising identifier, location and privacy signals.
Invalid-traffic detection serviceScores every request for fraud inside the Platform.IP address and device identifier.
Google CloudHosts Tekne’s sanitised samples, aggregates and operational tooling.No end-user personal data.

We do not sell data to data brokers and we do not share bid-stream data with anyone outside this list, except where required by law or to protect our legal rights. Partners are bound to use the data for the transaction and to honour the privacy signals it carries.

8. Location data

Location in a bid request is the country, region and metropolitan area of the device, derived from its IP address by the supply partner. Some requests also include a postal code and approximate coordinates; these have the precision of an IP address, not of GPS. The Platform forwards the location block to demand partners as received. Tekne’s own records keep country, region and metro only.

9. Identifiers, cookies and profiling

The Platform does not set cookies, does not run cookie or identifier synchronisation, and does not match identifiers across partners or devices. The only identifier relating to you that passes through the Platform is the advertising identifier supplied by your device, forwarded unchanged. Tekne Exchange does not build profiles, audiences or segments, does not apply frequency capping and keeps no identifiers in its own records. Our targeting rules operate on inventory and device attributes only.

10. Children

The Platform is not designed for inventory directed at children under 13, and Tekne Exchange does not knowingly process data about them. Eligible app lists are curated manually and exclude children’s content. Where a request carries a COPPA flag, it is forwarded to demand partners, who must not use it for behavioural advertising. If you believe a child-directed app is being traded through the Platform, contact us and we will investigate.

11. Your choices

Because Tekne Exchange never interacts with your device, the most effective controls are the ones built into it:

  • Connected TV platforms let you reset your advertising identifier or limit ad tracking in the privacy or advertising section of the device settings. When you limit tracking, requests from your device should no longer carry an identifier.
  • The app or service you watch may offer its own privacy settings and will usually explain how it shares data with advertising partners.
  • If you live in a US state with a privacy law, you can opt out of the sale or sharing of your data through the mechanisms offered by the app or device. The resulting signal travels with each request and is forwarded by the Platform.
  • Industry opt-out tools from the Network Advertising Initiative and the Digital Advertising Alliance cover web browsers and some television environments.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of personal data about you, to restrict or object to its processing, to withdraw consent, to opt out of the sale or sharing of your data, and not to be discriminated against for exercising these rights. Tekne Exchange keeps no identifiers in its own records, so to act on a request we need the advertising identifier of your device and, where possible, the app and approximate date involved. We will forward the request to our infrastructure provider and to the partners involved in the transaction, and answer within the period the applicable law allows.

Write to info@teknexchange.com. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.

13. Where data is processed

The auctions run in the infrastructure provider’s data centre in the eastern United States. Tekne’s sanitised samples and aggregates are stored in Google Cloud in the United States; its dashboard and partner records run in Google Cloud regions in Belgium and Spain. Tekne & Creemy Group S.L. is established in Spain. Where personal data of people in the European Economic Area or the United Kingdom is processed outside those territories, we rely on recognised safeguards such as adequacy decisions, the EU–US Data Privacy Framework or Standard Contractual Clauses.

14. Security

Tekne Exchange applies proportionate technical and organisational measures. Access to the Platform console and to Tekne’s cloud project is limited to authorised personnel with individual credentials; Tekne’s copies strip identifiers before storage; services run under least-privilege accounts; and technical logs are kept briefly. No system can guarantee absolute security. If we become aware of an incident affecting personal data we will act as the law requires.

15. Changes to this policy

We will update this policy when the Platform’s formats, regions, partners or data practices change, and will publish the current version and date on this page. Material changes will be reflected here before they take effect.