ASTRAD Privacy Policy

Please read carefully.

Last Updated: July 7, 2026

Athropos Corporation OÜ (“ASTRAD“, “we“, “us“, or “our“), a company registered in Estonia (Registration Number: 14684054, Sepapaja 6, Tallinn 15551), is committed to protecting the privacy of our business clients, website visitors, and individual consumers whose data passes through our programmatic advertising technology ecosystem.

This Privacy Policy explains how we process personal data across our operations. Because we operate both a commercial business and a programmatic infrastructure routing software platform, this policy is divided into two distinct sections to provide absolute transparency regarding our data processing tracks.

SECTION A: CORPORATE WEBSITE & USER ACCOUNT OPERATIONS

 

This section applies to data collected from corporate visitors to our website (astrad.io), business prospects, and registered account users (“Platform Users“) logging into the ASTRAD dashboard.

A.1 Data We Collect & Purpose

 

When you interact with us as a business client or user, we collect:

  • Identity & Account Data: First name, last name, job title, and corporate email address provided during account activation.
  • Billing & Financial Data: Corporate billing address, tax/VAT identification numbers, bank routing information, and transactional logs.
  • Technical Log Data: IP addresses, browser types, and system usage patterns recorded during your sessions within the secure dashboard area.

A.2 Lawful Basis for Processing (GDPR Article 6)

 

  • Performance of a Contract: Processing account credentials and billing data is strictly necessary to administer your platform account and fulfill our obligations under the Platform Terms of Service.
  • Legitimate Interests: We process corporate usage logs and technical data to maintain system stability, optimize our platform UX, and monitor for unauthorized security events.

SECTION B: PROGRAMMATIC TECHNOLOGY & ROUTING ECOSYSTEM

 

This section applies to our processing of digital telemetry and pseudonymous identifiers belonging to individual internet consumers (“End-Users“) interacting with digital media inventory across connected programmatic supply-side networks and ad exchanges.

B.1 Our Role: Data Processor (Infrastructure Intermediary)

 

Under the General Data Protection Regulation (GDPR), ASTRAD operates a proprietary programmatic advertising infrastructure and routing software platform. We do not provide services directly to consumers, nor do we maintain direct relationships with individual internet users. Our platform acts strictly as a technical intermediary (Data Processor), processing pseudonymous telemetry data on behalf of and under the explicit configuration instructions of our corporate clients (the Data Controllers).

B.2 Technical Telemetry Data Processed

 

To facilitate the automated evaluation and routing of digital advertising inventory across upstream infrastructure partners, inventory supply networks, and demand-side platform (DSP) partners, our software interfaces automatically process the following technical signals:

  • Unique Digital Identifiers: Mobile Advertising Identifiers (Apple IDFA, Google GAID), programmatic cookie tokens, and auction session IDs.
  • Network Environment Parameters: Internet Protocol (IP) addresses, device hardware types, operating system versions, and browser user-agent strings.
  • Granular Contextual Telemetry: The URL of the publisher website or the name of the mobile application where an ad is evaluated for rendering, alongside coarse geographic metrics (country, region, or city level derived from network hops).
  • Performance Metrics: Real-time event tracking logs verifying whether an ad was successfully rendered, viewed, clicked, or resulted in a conversion.

B.3 Purpose of Processing & Core Intermediary Functions

 

ASTRAD processes these technical parameters strictly for the following operational infrastructure compliance tracks:

  • Real-Time Optimization: Running extended programmatic routing algorithms to ensure high-performance budget delivery and optimal frequency management across inventory pipes.
  • Operational Security & Fraud Isolation (IVT): Actively analyzing technical telemetry to detect, isolate, and block invalid traffic (IVT), non-human bot interaction, click-fraud schemas, and malicious creative payloads.

B.4 Lawful Basis (End-User Data)

 

ASTRAD relies on the prior explicit consent collected from End-Users by the publishers and data partners operating the digital environments where ads are displayed. For fraud prevention, technical platform security, and invalid traffic (IVT) mitigation, ASTRAD processes telemetry data based on our legitimate commercial interest in safeguarding the operational integrity of our ad tech infrastructure.

SECTION C: GENERAL PRINCIPLES (APPLICABLE TO ALL DATA)

 

C.1 Sub-processors & Infrastructure Recipients

 

We share data with a restricted list of core infrastructure partners, including cloud data center operators (such as AWS or Google Cloud architecture hubs), enterprise ad-exchange pipes, and automated security verification tools. Every vendor operates under a binding Data Processing Agreement restricting their access to compliance workloads.

C.2 Cross-Border Data Transfers

 

Personal data may be routed and processed outside the European Economic Area (EEA). Where transfers occur to jurisdictions not deemed adequate by the European Commission, ASTRAD implements standard contractual safeguards (EU Standard Contractual Clauses or “SCCs”) to protect privacy infrastructure integrity.

C.3 Retention Timelines

 

  • Corporate Account Data: Maintained for the active duration of the business contract plus the statutory periods required for financial audit and corporate tax accounting under Estonian law.
  • Ad Tech Telemetry Data: Programmatic bidding logs, cookie signals, and device data are automatically anonymized or purged within ninety (90) days of receipt, unless an extended security audit or ongoing fraud investigation requires explicit isolation of historical logs.

C.4 Your Rights Under GDPR

 

Individuals inside the European Economic Area hold standard statutory rights regarding their personal data, including the right to request access, rectification, deletion, data portability, or to object to specific processing tracks.

 

Because ASTRAD operates strictly as an infrastructure routing pipeline processing pseudonymous data parameters (IP addresses, Cookie Tokens, Auction IDs), ASTRAD does not possess the technical keys, real-world data, or real-world identifiers required to link a real-world individual to automated platform logs. Consequently, ASTRAD cannot fulfill data access or erasure requests from unknown consumer users directly. Any individual seeking to exercise data protection rights must instead contact the primary publisher website or the specific advertising brand (the Data Controller) responsible for launching and serving the campaign. Requests from corporate platform clients regarding their own account dashboard logins may be directed to our internal privacy team at privacy@astrad.io.