Privacy Policy
Last updated: September 1, 2026 · iTekMedia.com
1. Overview
iTekMedia.com ("iTek", "we") builds programmatic advertising infrastructure. This policy covers personal data processed through itekmedia.com (the "Site") and, at a summary level, through our platform services, which are governed in detail by customer agreements and Data Processing Addenda ("DPAs").
2. Data we process
- Site inquiries: name, work email, company and message. Demo-request forms compose an email in your mail client; the Site does not store submissions.
- Account & platform data: administrator and user account details, SSO identifiers, API usage logs, and configuration of customer campaigns.
- Campaign data (as processor): pseudonymized identifiers, bidstream metadata, consent strings and aggregated performance events processed on behalf of customers.
- Site telemetry: IP address, user agent and request logs for security and abuse prevention. We run no advertising or analytics trackers on the Site.
3. Roles & responsibilities
For platform campaign data, customers are the controllers and iTek is the processor; processing purposes and safeguards are fixed in each DPA. For our own site and business contacts, iTek is the controller and applies this policy. We never sell personal data and never combine campaign data across customers to build profiles of individuals.
4. Privacy-by-design controls
- Clean-room processing: partner data matching occurs in sealed enclaves with hashed keys and differential-privacy thresholds.
- Consent enforcement: TCF/USP strings and custom consent flags are evaluated at every decisioning hop.
- Data minimization: raw PII is never stored in the bid path; identifiers are pseudonymized and rotated.
- Retention: bidstream metadata 30 days; aggregated campaign metrics per contract; account data for the life of the contract plus 90 days.
5. Legal bases (EEA/UK)
Site and business-contact processing relies on legitimate interest (responding to inquiries, securing our services) and contract performance. Campaign processing is carried out under the controller customer's legal basis, typically consent or legitimate interest, as documented in the DPA.
6. Sub-processors & transfers
We use vetted sub-processors for cloud hosting (US/EU), email and support tooling, bound by DPAs and, where applicable, EU Standard Contractual Clauses and the UK IDTA. The current sub-processor list is available from dpo@itekmedia.com.
7. Your rights
Subject to your jurisdiction (EU/EEA, UK, California/CPRA, and others), you may request access, correction, deletion, restriction, portability, or object to processing, and you will not be discriminated against for doing so. We do not "sell" or "share" personal information as defined by the CPRA. Contact dpo@itekmedia.com; we respond within 30 days. EEA/UK residents may complain to their supervisory authority.
8. Security
SOC 2 Type II audited, ISO 27001-aligned controls, TLS 1.2+ everywhere, encryption at rest, least-privilege access with SAML/SCIM, and continuous vulnerability management. Suspected incidents: security@itekmedia.com (PGP available).
9. Children & sensitive data
The Site and platform are not directed to children under 16, and our services include contractual prohibitions on processing children's data or sensitive categories except as legally required for contextual, non-identifying purposes.
10. Changes & contact
Material updates to this policy will be posted here with a new date. Data-protection contact: Data Protection Officer, iTekMedia.com, 240 W 40th St, New York, NY 10018, USA · dpo@itekmedia.com.