Who processes your data
The controller for this website and the management of COREADS services is the company identified below. Contact it with questions about this notice or to exercise your rights, using the subject “COREADS Privacy”.
VAT number: Contact us about privacyWho this notice covers
This notice describes the processing of data about visitors, business contacts, Advertiser and Publisher users and, for the advertising activities described, visitors to websites integrating COREADS. It covers the public website, account areas and related services. Publisher websites, ad destinations and payment services have their own notices: consult them when interacting with those parties. Their respective privacy roles depend on the activities and applicable agreements; this page does not replace the notice of the website you visit.
Data collected and its sources
Data you provide: name, email, contact details, company, credentials, address and tax details; registered websites, advertising content, support requests, documents and payment information needed for the service. Financial operations also involve amounts, balances, transaction references, invoices and Publisher payout details.
Technical and usage data: IP address, date and time, requested pages or resources, browser, device, operating system, language, referring page and security logs. Ad delivery may involve ad, campaign and placement identifiers, impressions, clicks, conversions and approximate location derived from the IP address. Sources include your browser, our systems and integrations activated by Advertisers and Publishers, including pixels and conversion notifications.
Why we use data
The legal basis depends on the specific purpose under Article 6 GDPR. Consent is not a blanket condition for accessing our services.
| Purpose | Legal basis |
|---|---|
| Create and manage accounts, campaigns, advertising spaces, support and pre-contract requests. | Contract or pre-contract steps (Art. 6(1)(b)). For business representatives: legitimate interest in managing the relationship (Art. 6(1)(f)). |
| Manage invoices, tax and accounting obligations, collections and payouts. | Contract and legal obligations (Art. 6(1)(b) and (c)). |
| Protect the service, prevent abuse and invalid traffic, investigate anomalies and defend rights. | Legitimate interest in security and reliable delivery, balanced against individuals’ rights (Art. 6(1)(f)). |
| Optional website measurement and non-essential advertising tracking, when enabled. | Consent where required (Art. 6(1)(a) and cookie rules). Refusing does not prevent browsing the website. |
Which data is required
Data required for registration, security, invoicing and payments is needed to provide those functions or comply with the law. Without it we may be unable to open an account, process a payment or respond to a request. Additional information is optional. Do not include passwords, full card details, health information or other sensitive data in contact messages, assistant messages or creatives.
Advertising and campaign measurement
COREADS manages ad delivery and related events for reporting, attribution, spend control and fraud prevention. Integrations may receive data from Publisher and Advertiser websites, such as a click or conversion linked to a campaign. Selection may depend on context, approximate location, device and criteria set by the advertiser. Where retargeting is used, the CoreAds_rt identifier can link visits and ads for 30 days. Non-essential tracking requires the consent prescribed by applicable rules; on third-party websites, use their privacy controls. Choices on this website do not change choices on other websites.
Who may receive data
Data may be processed by authorised personnel and providers of hosting and infrastructure, maintenance, email, security, support and advertising tools, within their assigned activities. Providers acting on our behalf are processors; banks, payment providers, advisers and authorities may act as independent controllers according to their functions. Integrations and external services, including Google Analytics, Google reCAPTCHA and graphical resources loaded from external services, may receive technical data such as IP and browser information when used. Ad content and Publisher websites are intended for publication; do not include personal data you do not intend to make public.
Processing outside the EEA
International providers may process or access data from countries outside the European Economic Area, even where primary hosting is in Europe. For such transfers, the GDPR requires an adequacy decision or appropriate safeguards, such as standard contractual clauses and, where needed, supplementary measures. Contact us for information on the recipients and safeguards applicable to your data and to request a copy. For third-party services, also consult their own notices.
How long we keep data
Retention depends on the purpose and applicable obligations. Account and service data is kept during the relationship and afterwards to the extent needed to settle pending activities, meet obligations and handle disputes. Invoices and accounting records are subject to statutory periods, ordinarily ten years. Contact and support requests are retained to handle the request and related checks. Retention of logs and advertising events takes account of security, reporting, attribution and traffic verification needs. Data needed for a dispute may be kept until it is resolved. Closing an account does not immediately erase documents subject to mandatory retention. You can ask for the criteria and periods applicable to a specific set of data.
Security, assistance and automation
We use HTTPS connections, access controls and technical measures to limit unauthorised access and abuse. The website assistant processes your message and page context to provide service guidance. Creative generation and optimisation features, if used, may send content and campaign data to providers configured for that feature. Delivery and optimisation rules may select ads or change campaign parameters according to service settings. You can request an explanation of a result or a review by support. Services are intended for adult professional users; do not submit children’s data.
Your rights and how to exercise them
Under the conditions of Articles 15–22 GDPR you can obtain access and a copy, correction, erasure, restriction of processing and portability of data you provided where processed automatically on the basis of consent or contract. You may object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time. You may withdraw consent without affecting the lawfulness of prior processing. Where applicable, you can request human intervention and contest solely automated decisions with legal or similarly significant effects.
Write to the contact on this page or use the contact form, stating your request and account email if applicable. We may ask only for information needed to verify your identity. We respond without undue delay and normally within one month; extensions of up to two further months where permitted are explained within the first month. Requests are normally free. You may complain to the Italian data protection authority or the authority in the EU country where you live, work or consider an infringement occurred, and seek a judicial remedy.
Italian data protection authorityUpdates and references
This notice may be updated following changes to our services or the law. The date above identifies the published version. Material changes will be communicated through service channels where necessary. You can retain a copy using your browser’s print function.