EEA and UK Privacy Notice

Last Updated: March 16th, 2026

This EEA and UK Privacy Notice (this "Notice") supplements RevOptimal's Global Privacy Policy and describes how we collect, use, and share personal data relating to individuals located in the European Economic Area (EEA) or the United Kingdom (UK), and the rights available to you under the General Data Protection Regulation (GDPR) and UK GDPR, respectively.

Enterprise customers should read this policy alongside their applicable contract and data protection addendum ("DPA") where and as signed with us.

This Notice Includes:

  • Our Role: Data Controller vs. Data Processor
  • How We Use and Disclose Your Personal Data
  • Legal Bases for Processing
  • International Data Transfers
  • Your Rights Under GDPR and UK GDPR
  • Data Retention
  • Your Right to Lodge a Complaint
  • Changes to this Notice
  • How to Contact Us

Our Role: Data Controller vs. Data Processor

Understanding our role matters because it determines your rights and how you should direct any requests.

When We Are a Data Controller

We act as a data controller when we decide the purposes and means of processing personal data — that is, when we determine why and how your data is used. This includes when we:

  • Operate our own website and collect data about visitors.
  • Build and enrich audience segments using data from our own sources and third-party providers.
  • Conduct our own analytics and measurement activities.
  • Process data for our own marketing and business development purposes.

As a controller, we are directly responsible for your data and your rights apply to us directly.

When We Are a Data Processor

We act as a data processor when we process personal data on behalf of our enterprise customers, following their instructions. This includes when we:

  • Activate audience segments on behalf of a customer's advertising campaign.
  • Process customer-provided data for measurement or attribution purposes.
  • Deliver analytics reports using data our customers supply.

As a processor, our enterprise customer is the data controller and is responsible for their use of your data. If your data has been processed in connection with one of our customers' campaigns and you wish to exercise your rights, you should contact that customer directly. Where we can identify the relevant customer and it is appropriate to do so, we will refer your request to them.

How We Use and Disclose Your Personal Data

The following table provides additional information about how we use and disclose your data, consistent with GDPR and UK GDPR disclosure requirements:

Category of Personal Information Processing Purpose Categories of Recipients Legal Basis & Processing Categories
Personal Identifiers (e.g. names, aliases, emails, phone numbers, customer numbers, mobile advertising IDs (MAIDs), IP addresses) Audience segmentation, targeted advertising delivery, analytics Our customers (advertisers), data analytics providers, digital data management platforms and service providers Processed on the basis of legitimate interests and/or consent; disclosed to recipients for marketing, reporting, and/or analytics purposes
Protected Classification Characteristics (sex/gender, marital status, military/veteran status, national origin, ancestry, age, home ownership, education level, professional details) Audience segmentation, demographic targeting, model development Our customers and data analytics providers Processed on the basis of explicit consent; disclosed to recipients for audience segmentation and demographic targeting purposes
Online Identifiers (e.g. device identifiers, cookies, beacons, pixel tags, and similar technologies) User recognition across sessions, tracking and analytics, fraud prevention Our customers, data analytics providers, digital data management platforms and service providers Processed on the basis of consent and/or legitimate interests; deidentified or aggregate statistics disclosed to recipients. See our Cookie Policy for more information.
Commercial Information (products/services purchased, obtained, or considered; purchasing or consuming histories) Behavioral targeting, consumer preference analysis, predictive modeling Our customers, data analytics providers, digital data management platforms Processed on the basis of legitimate interests and/or consent; disclosed to recipients for behavioral targeting and analytics purposes
Internet/Electronic Network Activity (browsing history, search history, interaction with websites, applications, advertisements) Behavioral analysis, interest-based advertising, service improvement Our customers, data analytics providers, advertising networks and service providers Processed on the basis of legitimate interests and/or consent; disclosed to recipients for behavioral analysis and interest-based advertising purposes
Geolocation Data (precise or approximate location) Geographic segmentation Our customers and data analytics providers Processed on the basis of legitimate interests and/or consent; disclosed to recipients in aggregate or deidentified form only for geographic segmentation purposes; precise location data is not disclosed to third parties
Inferences (profiles reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, aptitudes) Predictive audience modeling, personalized marketing, segment creation Our customers and data analytics providers Processed on the basis of legitimate interests and/or consent; disclosed to recipients as aggregate audience segments

The Company retains personal data for no longer than is necessary for the purposes described above. Personal data is generally deleted within 24 months of collection, unless a longer retention period is required or permitted by applicable law or contractual obligation.

Legal Bases for Processing

Under the GDPR and UK GDPR, we must have a valid legal basis for every processing activity. We rely on the following legal bases:

Consent

Where we collect data directly through our Site — for example, through cookies or marketing communications — we ask for your consent before processing non-essential data. You have the right to withdraw consent at any time without affecting the lawfulness of processing that occurred before withdrawal. You can manage your cookie consent through our Cookie Preference Center.

Legitimate Interests

We rely on legitimate interests as a legal basis for:

  • Audience segment creation and enrichment using data lawfully obtained from third-party sources, where we have assessed that our interests in providing accurate audience data to our customers do not override the fundamental rights and interests of data subjects.
  • Analytics and measurement to improve the accuracy and relevance of our segments and platform.
  • Security and fraud prevention to protect our platform and the individuals whose data we process.
  • Direct marketing to business contacts where we have a reasonable expectation of professional interest.

Where we rely on legitimate interests, you have the right to object to that processing at any time. See "Your Rights" below.

Legal Obligation

We process certain personal data where necessary to comply with our legal obligations, including obligations under data protection law, financial regulations, and applicable court orders.

Contract

Where you are an enterprise customer or a contact at an enterprise customer, we process your professional contact data to perform our contractual obligations to you.

International Data Transfers

RevOptimal is based in the United States and we maintain data in regional areas aligned with the location of collection and processing. When we process personal data of EEA or UK residents, this data is collected, processed and stored in Germany and the UK, respectively.

Automated Decision-Making and Profiling

Our core business involves profiling — the automated processing of personal data to evaluate, analyze, or predict characteristics about individuals, which we use to assign individuals to audience segments. We do not use fully automated decision-making that produces legal or similarly significant effects on individuals in the sense contemplated by Article 22 of the GDPR and UK GDPR. Our audience segment assignments are used by our customers for advertising targeting purposes, not to make binding decisions about access to services, employment, healthcare or credit.

Where our customers use segment data to make significant decisions about individuals, those customers are the relevant data controllers and are responsible for compliance with Article 22 of the GDPR and UK GDPR. You have the right to object to profiling activities we conduct as a controller. See "Your Rights" below.

Your Rights Under GDPR and UK GDPR

As an EEA or UK resident, you have the following rights regarding your personal data. Because most of the personal data we hold was not collected directly from you, some rights may be subject to exemptions or limitations, which we will explain when you submit a request.

Right to Be Informed

You have the right to receive clear, transparent information about how we process your personal data — which is the purpose of this Notice.

Right of Access

You have the right to request confirmation of whether we process personal data about you and, if so, to receive a copy of that data and supplementary information about how it is used.

Right to Rectification

You have the right to request correction of inaccurate personal data we hold about you.

Right to Erasure ("Right to Be Forgotten")

You have the right to request deletion of your personal data where:

  • The data is no longer necessary for the purposes for which it was collected.
  • You withdraw consent and there is no other legal basis for processing.
  • You object to processing and there are no overriding legitimate grounds.
  • The data has been unlawfully processed.
  • Erasure is required to comply with a legal obligation.
Right to Restrict Processing

You have the right to request that we restrict our processing of your personal data in certain circumstances, such as while we verify the accuracy of data you have disputed.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object at any time to processing based on legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims. You may also object at any time to processing for direct marketing purposes, including profiling related to direct marketing, and we will cease such processing immediately upon receipt of your objection.

Rights Related to Automated Decision-Making

Where we engage in automated profiling that produces legal or similarly significant effects, you have the right to request human review, contest the decision, and express your point of view. As noted above, our profiling activities do not currently produce such effects directly.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing. To withdraw cookie consent, please use our Cookie Preference Center.

How to Exercise Your Rights

To exercise any of the rights described above, please submit a request through any of the following methods:

We will respond to your request within one month of receipt. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you within the first month and explain the reason for the extension.

We do not charge a fee for requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.

Verification: We may need to verify your identity before processing your request. We will ask for the minimum information necessary to do so.

Data Retention

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, contractual, or reporting obligations. Retention periods vary depending on the nature of the data and the purpose of processing:

  • Audience segment data is retained in accordance with our agreements with enterprise customers and applicable law, typically no longer than 24 months from the date of last use or refresh.
  • Website visitor data collected through cookies and tracking technologies is retained in accordance with our Cookie and Tracking Technologies Policy.
  • Business contact data is retained for the duration of our business relationship and a reasonable period thereafter.
  • Legal and compliance records are retained for the period required by applicable law.

Your Right to Lodge a Complaint

If you have concerns about how we handle your personal data that we are unable to resolve to your satisfaction, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so that we have the opportunity to address your concerns directly before you approach a supervisory authority.

For EEA residents: Contact your national data protection authority. A full list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/board/members_en.

For UK residents: Contact the Information Commissioner's Office (ICO) at https://ico.org.uk/global/contact-us/.

Changes to This Notice

We review and update this Notice periodically to reflect changes in our practices, applicable law, and regulatory guidance. We will notify you of material changes by posting the updated Notice on our website and updating the effective date above. Where required by law, we will seek renewed consent or provide additional notice of material changes.

How to Contact Us

If you have questions about this Notice, your rights, or how we handle your personal data, please contact us at:

  • Email: privacy@revoptimal.com
  • Mail: RevOptimal, LLC, 612 Andrew Higgins Blvd, Ste 2000, New Orleans, LA 70130 USA

We have also appointed Superset as our representative in the European Union and United Kingdom for data protection matters. Superset can be contacted at:

  • Email: revoptimal.com@supersetreps.com
  • EU Mail: Superset Representatives SASUEEA, 12 Rue Pierre Fontaine, 75009 Paris, France
  • UK Mail: Superset Representatives Limited, Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom

Ready to supercharge your ROAS?