Privacy Policy

This policy explains how Hyperse Group Ltd. ("WhichClick") processes personal data. It is written to satisfy the UK GDPR, the Data Protection Act 2018, the EU GDPR, the ePrivacy Directive / PECR and, where applicable, the CCPA/CPRA and other US state privacy laws. It is not a substitute for the notice an advertiser must give its own users.

1. Our roles

  • Processor for measurement data (clicks, installs, in-app events, identifiers, IP-derived signals) collected through tracking domains, smart links, SDKs and APIs on the instructions of our business customers (the advertisers). The advertiser is the controller. Requests about that data should be addressed to the advertiser; we will assist them under our Data Processing Addendum.
  • Controller for account, billing, support, security, website and marketing data and for the aggregated fraud-intelligence data described in section 5.

2. What we process when an ad is clicked or an app is opened

  • Advertising identifiers supplied by the ad platform (e.g. gclid, gbraid, wbraid, fbclid, ttclid), campaign, ad group, creative, keyword, match type, network, device class and location identifiers, and the destination URL carried in the visible transparency parameter.
  • Technical data: user agent, Accept-Language, referrer, request timing, TLS metadata, coarse geolocation (country, region, city, timezone) derived from the IP address, and the IP address itself for the limited purposes and periods below.
  • A WhichClick click identifier appended to the destination URL and, for Android, to the Play Store install referrer.
  • From the SDK: a SHA-256 hash of the vendor/app-set identifier, platform, OS and app version, install time, in-app events chosen by the advertiser and their values. Advertising identifiers (IDFA/GAID) are transmitted only where the advertiser has obtained consent and explicitly passes them, and only to forward conversions to the ad platform; they are not stored by us.
  • From the optional landing-page beacon: dwell time, scroll depth, interaction count, screen size, timezone, language and a non-persistent browser fingerprint hash tied to the click identifier.

IP addresses. For valid traffic we store only a salted, daily-rotating hash of the IP (or the /64 prefix for IPv6). The unhashed IP is stored only for traffic classified as suspicious or invalid, for the retention period set by the advertiser (default 90 days), solely to exclude it from advertising, to document invalid activity to the ad platform and to protect our and our customers' systems. We also maintain a pool of IP ranges (network blocks, not individuals) classified as hosting, VPN, proxy, Tor or crawler ranges from public sources.

3. Purposes and legal bases

  • Providing measurement and attribution to the advertiser — performance of a contract with the controller / the controller's lawful basis.
  • Detecting, preventing and evidencing invalid traffic, fraud and abuse — our and our customers' legitimate interests (Recital 47 UK/EU GDPR) and, where applicable, legal obligation.
  • Securing the Services, rate limiting, incident response — legitimate interests.
  • Account administration, billing, support and legal compliance — contract and legal obligation.
  • Marketing to business contacts — legitimate interests, with an opt-out in every message; consent where required.

4. Cookies and similar technologies

The redirect endpoints set no cookies and execute no scripts. The dashboard uses strictly necessary session cookies. Advertisers who install our web snippet may cause first-party storage of the click identifier on their own domain; that storage is under the advertiser's control and notice. See the Cookie & Tracking Notice.

5. Aggregated fraud intelligence

We derive de-identified, aggregated signals (for example, that a network range emits invalid traffic) across customers to protect all customers. These signals do not identify individuals and are retained indefinitely.

6. Sharing

We share personal data only with: sub-processors listed in the DPA (hosting, database, CDN/edge, email, error monitoring, IP intelligence providers); advertising platforms when the advertiser instructs us to forward conversions or exclusions; professional advisers, insurers and auditors; authorities and courts where required by law; and a successor in a merger, acquisition or reorganisation. We do not sell personal data and do not use measurement data for our own advertising.

7. International transfers

Data is hosted in the United Kingdom, European Union and/or United States. Transfers out of the UK/EEA are protected by the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses and supplementary measures, or an adequacy decision.

8. Retention

  • Click-level measurement data: per the advertiser's plan (30 days to 13 months), then deleted or aggregated.
  • Raw IP of flagged traffic: advertiser-configured, default 90 days.
  • Install and event data: for the life of the advertiser's account plus 30 days.
  • Account, billing and audit records: 7 years for tax and legal purposes.

9. Your rights

Depending on your location you may have rights to access, rectify, erase, restrict, port and object to processing, to withdraw consent and to complain to a supervisory authority (in the UK, the Information Commissioner's Office). For measurement data please contact the advertiser whose ad you clicked; for data we control, contact [email protected]. We may require verification and may refuse manifestly unfounded or excessive requests. We do not discriminate against anyone exercising their rights.

10. Security

TLS in transit, encryption at rest, hashed identifiers, role-based access, audit logging, least-privilege infrastructure and vendor due diligence. No system is perfectly secure; we notify controllers of personal-data breaches without undue delay as required by the DPA.

11. Children

The Services are not directed at children and advertisers must not use them in services directed at children under 13 (or the applicable age of digital consent).

12. Changes and contact

We may update this policy; the effective date and version appear in the sidebar. Contact: [email protected] · Data Protection contact: [email protected] · Hyperse Group Ltd., 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.