Privacy Policy

This privacy notice for Fonemedia Ltd (‘Company’, ‘we’, ‘us’, or ‘our’) describes how and why we might collect, store, use, and/or share (‘process’) your information when you use our services (‘Services’), such as when you:

  • View advertisements delivered by us on mobile applications and websites
  • Visit our website at https://www.fonemedia.co.uk/, or any website of ours that links to this privacy notice
  • Interact with advertisements we serve on behalf of our advertising partners
  • Use mobile applications that display our advertisements
  • Engage with us in other related ways, including any sales, marketing, or events

Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@fonemedia.co.uk.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice.  You can find full details using the table of contents below.

  • What personal information do we process? When you view or interact with advertisements we serve, we may process device identifiers, approximate location data, and information about your interactions with advertisements. The information we process depends on the mobile applications and websites you use, your device settings, and whether you have opted out of personalised advertising.
  • Do we process any sensitive personal information? We do not intentionally process sensitive personal information.  However, where you have granted precise location permissions to an app displaying our advertisements, that data may constitute sensitive personal information under certain privacy laws (including for California residents under CPRA).  See Sections 1 and 12 for details.
  • Do we receive any information from third parties? In connection with our programmatic advertising services, we may receive data from app publishers, demand-side platforms (DSPs), supply-side platforms (SSPs), data management platforms (DMPs), and attribution providers. This includes bid request data, audience segments, and conversion signals.
  • How do we process your information? We process your information to deliver and measure advertising, detect fraud, and administer our business. We process your information only when we have a valid legal basis to do so.
  • With whom do we share personal information? We share information with advertising technology partners (DSPs, SSPs, ad exchanges, DMPs), analytics providers, and infrastructure suppliers. In real-time bidding, we share limited device and contextual data with multiple partners in milliseconds as part of standard programmatic advertising operations.
  • California residents: We share personal information for cross-context behavioural advertising, which constitutes ‘sharing’ under CCPA/CPRA. You have the right to opt out. See Section 12.
  • What are your rights? Depending on your location, you may have rights including access, rectification, erasure, restriction, portability, and objection. California residents have additional rights under CCPA/CPRA.

TABLE OF CONTENTS

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on to process your personal information?
  4. When and with whom do we share your personal Information?
  5. International data transfers
  6. Do we use cookies and other tracking technologies?
  7. Automated decision-making and profiling
  8. How long do we keep your information?
  9. How do we keep your information safe?
  10. What are your privacy rights?
  11. Controls for do-not-track features and global privacy control
  12. Do California residents have specific privacy rights?
  13. Do residents of other US States have specific privacy rights?
  14. Children’s privacy
  15. Do we make updates to this notice?
  16. How can you contact us about this notice?
  17. How can you review, update, or delete the data we collect from you?

1.     WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us
We collect personal information that you voluntarily provide to us when you express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

The personal information we collect may include:

  • Names
  • Phone numbers
  • Email addresses
  • Mailing addresses
  • Contact preferences
  • Contact or authentication data

Sensitive Information.
We do not intentionally process sensitive personal information as part of our direct business operations.   Please note, however, that precise geolocation data (where collected via app permissions) may constitute sensitive personal information under applicable law, including for California residents. See Section 12 for further detail.

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Information collected through our advertising services
When advertisements are displayed to you through our Services, we and our advertising partners may automatically collect certain information to deliver relevant advertisements and measure their effectiveness.  This information is collected subject to your consent or other applicable lawful basis – see Section 3.

Device Identifiers:

  • Mobile advertising identifiers – Apple’s Identifier for Advertisers (IDFA) and Google’s Advertising ID (GAID). These are collected only where consent has been obtained or where you have not opted out via your device settings
  • Device identifiers and hardware information
  • IP address (truncated or hashed where technically feasible)

Device and technical information:

  • Device type, model, and manufacturer
  • Operating system and version
  • Screen size and resolution
  • Browser type (for mobile web advertising)
  • Language and locale settings
  • Time zone
  • Mobile network carrier

Location information:

  • Approximate (coarse) location derived from IP address – this is used by default
  • Precise location data only where you have expressly granted permission to the app displaying our advertisements.  We do not directly request location permissions.  Note: precise geolocation (within 1,852 metres) is treated as sensitive personal information under CPRA for California residents

Advertising Interaction Data:

  • Advertisements viewed, clicked, or otherwise interacted with
  • Time and date of ad impressions and interactions
  • App or website where the advertisement was displayed
  • Conversion events (such as app installations or purchases following an ad click)
  • Frequency of ad exposure

Contextual Information:

  • Category or content type of the app or website displaying the advertisement
  • Information provided by app publishers about their users (in aggregated or anonymised form)

Information received from third parties:
In the course of operating our programmatic advertising services, we may also receive data from third parties, including:

  • Bid request data from supply-side platforms (SSPs) and ad exchanges, which may include device identifiers, truncated IP addresses, location segments, audience segments, publisher app/URL, and user agent strings
  • Attribution and conversion data from measurement providers
  • Audience segment data from data management platforms (DMPs)
  • Fraud intelligence from fraud detection services

Information automatically collected
We automatically collect certain information when you visit, use, or navigate our website.  This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, and information about how and when you use our Services.

  • Log and Usage Data. Service-related, diagnostic, usage, and performance information our servers automatically collect, including IP address, device information, browser type, date/time stamps, pages viewed, and other actions taken.
  • Device Data. Information about your computer, phone, tablet, or other device, including IP address, device and application identification numbers, location, browser type, hardware model, internet service provider and/or mobile carrier, operating system, and system configuration information.
  • Location Data. We collect location data such as information about your device’s location, which can be either precise or imprecise. How much information we collect depends on the type and settings of the device you use. You can opt out by disabling your Location setting on your device; however, if you do so, certain aspects of our Services may not function as expected.

2. HOW DO WE PROCESS YOUR INFORMATION?

We process your personal information for the following purposes, each subject to a valid legal basis as described in Section 3:
  • To deliver and serve advertisements. We process your information to display advertisements on mobile applications and websites, including selecting which advertisements to show based on your approximate location, device type, and contextual information.
  • To personalise advertising (where permitted). Where you have given your consent and where permitted by applicable law, we may process your information to deliver advertisements more relevant to your interests based on inferred preferences and previous interactions.
  • To conduct real-time bidding (RTB). We participate in programmatic advertising auctions in which we share and receive limited data – including device identifiers, truncated IP addresses, location segments, audience segments, and contextual signals – with DSP, SSP, and ad exchange partners. This occurs in milliseconds as part of standard industry operations and is subject to consent where required by PECR and UK GDPR.
  • To measure and report on advertising effectiveness. We process your information to measure whether advertisements were viewed, clicked, or led to conversions, and to provide aggregated reporting to our advertising partners.
  • To detect and prevent advertising fraud. We process your information to identify and prevent fraudulent activity, including invalid clicks, bot traffic, and other forms of advertising fraud.
  • To deliver services to you. We may process your information to provide you with the requested service, including managing projects, responding to enquiries, and fulfilling contractual obligations.
  • To respond to user enquiries and offer support. We may process your information to respond to your enquiries and resolve any issues you may have.
  • To send administrative information to you. We may process your information to send details about our products and services, changes to our terms and conditions, and similar information.
  • To send you marketing and promotional communications. Where you have opted in, we may use your personal information for marketing purposes. You may opt out at any time (see Section 10).
  • To evaluate and improve our services. We may process your information to identify usage trends, determine the effectiveness of our campaigns, and improve our Services, products, and marketing.
  • To comply with our legal obligations. We may process your information to comply with our legal obligations, respond to legal requests, and exercise or defend our legal rights.

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, require us to identify the valid legal basis for each processing activity.  The table below maps our key processing activities to the legal bases we rely upon.

Processing ActivityLegal BasisNotes
Personalised advertising via device identifiers (IDFA/GAID)ConsentICO guidance confirms legitimate interest is not a valid basis for cross-site/app tracking via device identifiers without consent
Contextual advertising (no device ID tracking)Legitimate InterestServes relevant ads without tracking individuals across apps/sites
RTB bid request data sharingConsentConsent required where device identifiers are included in bid requests
Advertising fraud detectionLegitimate InterestNecessary to protect the integrity of advertising systems
Attribution and conversion measurementConsent or Legitimate InterestDepends on measurement method; server-to-server may qualify for LI
Delivering services under contractPerformance of a ContractNecessary to fulfil our obligations to advertising clients
Sending marketing communicationsConsentPECR requires consent for electronic marketing
Responding to legal requestsLegal ObligationRequired by law
Preventing harmVital InterestsWhere necessary to protect an individual

In addition to the above, the Data (Use and Access) Act 2025 recognises certain processing activities as legitimate interests by default, including safeguarding vulnerable individuals, preventing and detecting crime, and responding to emergencies.   Where we rely on these recognised legitimate interests, we are not required to conduct a full balancing test but must ensure the processing is necessary for the stated purpose.

Our role in processing your data
We act in different capacities depending on the context:

  • Data Controller: We determine the means and purposes of processing in respect of our own advertising operations and website.
  • Data Processor: Where we process data on behalf of advertising clients under a data processing agreement, they are the data controller and we act solely on their instructions.
  • Joint Controller: In the context of real-time bidding, we may act as joint controller with DSP and SSP partners where we jointly determine the purposes and means of processing. We have, or are in the process of establishing, Article 26 joint controller arrangements with our principal RTB partners.

This privacy notice does not apply to personal information we process solely as a data processor on behalf of our clients.  In those cases, please refer to the relevant client’s privacy policy.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We may share information in the following specific situations and with the following categories of third parties.

Advertising technology partners

  • Demand-Side Platforms (DSPs) – platforms that allow advertisers to buy advertising space programmatically. We share device identifiers, approximate location, and contextual data as part of bid requests where consent has been obtained.
  • Supply-Side Platforms (SSPs) – platforms that help publishers sell advertising space.
  • Ad exchanges – digital marketplaces facilitating the buying and selling of advertising inventory.
  • Data Management Platforms (DMPs) – platforms used to collect and manage audience data for advertising purposes.
  • Attribution and measurement providers – services that measure advertising effectiveness and attribute conversions.
  • Fraud detection and prevention services – to identify and prevent invalid traffic.
  • Advertisers and their agencies – to enable them to purchase advertising inventory and measure campaign effectiveness.

General service providers

  • Data Analytics Services (eg, Google Analytics)
  • Performance Monitoring Tools (eg, Google Search Console)
  • Advertising and Retargeting Platforms (eg, Google Ads, Meta/Facebook Ads)
  • Social Networks (eg, LinkedIn, Facebook, Instagram)
  • Cloud hosting and infrastructure providers

Other sharing scenarios

  • Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business.
  • Real-time bidding. When an advertising opportunity arises, we share limited data (which may include device identifiers, truncated IP address, approximate location segment, audience segment, app/website URL, and user agent) with multiple potential advertisers and their technology partners through real-time bidding processes. This sharing occurs in milliseconds.  Where such data constitutes personal data, it is shared only where consent has been obtained or another valid legal basis applies.   Under CCPA/CPRA, this sharing for cross-context behavioural advertising constitutes ‘sharing’ and California residents may opt out – see Section 12.
  • Google Maps Platform. We may share your information with certain Google Maps Platform APIs. For more information, please see Google’s Privacy Policy at https://policies.google.com/privacy.

All third-party service providers who process personal data on our behalf are subject to written contracts designed to safeguard your personal information.  They are not permitted to use personal data for any purpose other than those we specify.

CCPA Notice — Sharing for Cross-Context Behavioural Advertising

For California residents: we share personal information with advertising technology partners for cross-context behavioural advertising (targeted advertising), which constitutes ‘sharing’ under CCPA/CPRA regardless of whether monetary consideration is received.  The categories of personal information shared include: device identifiers; IP addresses; inferred interest/audience segments; and advertising interaction data. You have the right to opt out of this sharing — see Section 12.

5. INTERNATIONAL DATA TRANSFERS

Our advertising services operate globally, which means your personal information may be transferred to, stored, and processed in countries other than your own.  Many of our advertising partners, technology providers, and data centres are located outside the United Kingdom, including in the United States, the European Economic Area, and other jurisdictions.

Whenever we transfer your personal information out of the UK, we ensure an equivalent degree of protection is afforded to it by ensuring at least one of the following safeguards is in place:

  • Adequacy decisions. We transfer data to countries that have been deemed to provide an adequate level of protection by the UK Government.
  • UK Extension to the EU-US Data Privacy Framework. For transfers to the United States, we may rely on the UK Extension to the EU-US Data Privacy Framework, which permits transfers to US organisations that have self-certified under the framework.
  • International Data Transfer Agreement (IDTA) or Addendum. Where we use certain service providers, we may use the UK’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, which give personal data the same protection it has in the UK.

Please contact us if you want further information on the specific mechanism used when transferring your personal data out of the UK.

6. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

We use cookies, mobile advertising identifiers, SDKs, and other tracking technologies to deliver and measure advertisements. Certain of these technologies are subject to consent requirements under PECR (Privacy and Electronic Communications Regulations) as set out below.

Mobile advertising technologies

  • Mobile Advertising Identifiers. We use IDFA (Apple) and GAID (Google) to deliver and measure advertisements on mobile devices. Under PECR, accessing or storing information on a user’s device via these identifiers requires consent (equivalent to the cookie consent requirement).  These identifiers can be reset or limited via your device settings.   We do not use IDFA or GAID where you have opted out of ad tracking at the device level.
  • Software Development Kits (SDKs). Our advertising technology may be integrated into mobile applications through SDKs, which enable ad serving and collection of ad interaction data within those applications. The SDK operator will obtain any necessary consent in the context of the application.
  • Pixels and Web Beacons. We use pixels and web beacons to track whether advertisements have been viewed and to measure conversions.
  • Server-to-Server Tracking. We may receive information about advertising interactions and conversions through server-to-server integrations with app publishers and advertisers.

Consent Management
IAB Transparency and Consent Framework (TCF). Where applicable, our advertising operations participate in the IAB UK Transparency and Consent Framework.  Consent and legitimate interest signals are passed in TCF format within OpenRTB bid requests, enabling downstream DSP and measurement partners to apply consent consistently. Where a valid TCF consent string is not present for personalised advertising, we serve contextual advertising only.

Under PECR, as amended by the Data (Use and Access) Act 2025, consent is not required for:

  • Cookies strictly necessary for the provision of a service expressly requested by the user
  • Cookies used solely to carry out a transmission of a communication
  • Audience measurement cookies meeting specified conditions under the amended PECR

For all other cookies and equivalent tracking technologies, including those used for advertising, analytics beyond the exempted category, and personalisation, we will obtain your consent before placement.

Your choices

7. AUTOMATED DECISION-MAKING AND PROFILING

We do not currently use automated decision-making that produces legal or similarly significant effects on you without human involvement.

Profiling for marketing purposes. We may use limited profiling in connection with our marketing activities to help ensure that marketing communications are relevant to you. This may include analysing your interactions with our website and Services to understand your preferences. This profiling does not produce legal or similarly significant effects on you.

You have the right to object to profiling for direct marketing purposes at any time. Please contact us using the details in Section 16.

If we introduce any automated decision-making processes that produce legal or similarly significant effects in the future, we will update this notice and ensure appropriate safeguards are in place, including meaningful human oversight.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

We will only keep your personal information for as long as it is necessary for the purposes set out in this notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).
Category of Personal Information Retention Period Rationale
Advertising interaction data (impressions, clicks) 13 months from collection Standard industry measurement period; aligned to GA4 default and IAB guidance
Device identifiers (IDFA/GAID) for advertising 13 months from last interaction Sufficient for attribution and frequency capping
Conversion and attribution data 12 months from conversion event Covers standard attribution windows and campaign reporting cycles
Fraud detection data Up to 3 years Ongoing fraud pattern analysis and defence
Enquiry and contact data 2 years from last interaction Proportionate to typical sales/service cycles
Client and advertiser project/campaign data 7 years from campaign completion Aligned to HMRC record-keeping requirements
Aggregated and anonymised reporting data Indefinitely No longer constitutes personal data once anonymised
Website analytics data 14 months Aligned to Google Analytics 4 default retention period
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or, if deletion is not immediately possible (for example, where data is stored in backup archives), we will securely store it and isolate it from any further processing until deletion is possible.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

We have implemented appropriate technical and organisational security measures designed to protect your personal information. These include:

  • Cyber Essentials certification – an independently assessed standard covering our key technical controls
  • Encryption of personal data in transit and at rest
  • Access controls and role-based permissions limiting access to personal data to authorised personnel
  • Regular security assessments and staff training
  • Incident response procedures aligned to ICO notification requirements

Despite these safeguards, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. We cannot guarantee that unauthorised third parties will not be able to defeat our security measures. Transmission of personal information to and from our Services is at your own risk, and you should only access the Services within a secure environment.

10. WHAT ARE YOUR PRIVACY RIGHTS?

Under UK data protection laws, you have the following rights regarding your personal information:

  • Right of access: You may request a copy of the personal information we hold about you. Under the Data (Use and Access) Act 2025, your right to obtain a copy is limited to information found by a reasonable and proportionate search. We will inform you if we are unable to comply with a request in full.
  • Right to rectification: You may request that we correct information you believe is inaccurate or complete information you believe is incomplete.
  • Right to erasure: You may request that we erase your personal information, under certain conditions.
  • Right to restrict processing: You may request that we restrict the processing of your personal information, under certain conditions.
  • Right to data portability: You may request that we transfer the data we hold about you to another organisation, or directly to you, under certain conditions.
  • Right to object: You may object to our processing of your personal information, under certain conditions, including where we rely on legitimate interest.

Advertising-specific rights and choices

  • Opt out of personalised advertising by adjusting your device settings or using industry opt-out tools (see Section 6)
  • Reset your advertising identifier through your device settings to disconnect future activity from past data
  • Object to profiling for advertising purposes by contacting us

Opting out of personalised advertising does not mean you will stop seeing advertisements – you will continue to see advertisements, but they may be less relevant to your interests.

How to exercise your rights
To exercise any of your rights, please contact us using the details provided in Section 16. We will respond within 30 days of receipt of your request. Where a request is complex or we receive a high volume of requests, we may extend this period by a further two months, in which case we will inform you within the first 30 days.

Complaints. If you believe we are unlawfully processing your personal information, you have the right to complain to the Information Commissioner’s Office (ICO). Contact details: https://ico.org.uk/make-a-complaint/. ICO registration number: ZA156835.

Withdrawing consent.
Where we rely on consent as our legal basis, you may withdraw it at any time by contacting us. Withdrawal does not affect the lawfulness of processing that occurred prior to withdrawal.

Opting out of marketing communications.
You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email we send, or by contacting us. We may continue to send service-related messages that are necessary for administration of your account or our contractual relationship.

11. CONTROLS FOR DO-NOT-TRACK FEATURES AND GLOBAL PRIVACY CONTROL

Do-Not-Track (DNT)

Most web browsers include a Do-Not-Track (‘DNT’) feature that signals your preference not to have your online browsing activity monitored and collected.  No uniform technology standard for recognising and implementing DNT signals has been finalised. We do not currently respond to DNT browser signals. If a standard is adopted that we must follow in the future, we will update this notice accordingly.

Global Privacy Control (GPC)

Important for California residents
The Global Privacy Control (GPC) is a browser-level signal that communicates a user’s preference to opt out of the sale or sharing of their personal information. Under California regulations (11 CCR §7025), businesses must treat a valid GPC signal as a legally effective opt-out of the sale and sharing of personal information under CCPA/CPRA.

We honour the GPC signal for California residents. Where our website detects a GPC signal from your browser, we will treat this as a valid opt-out of sale and sharing of your personal information for cross-context behavioural advertising purposes. This applies in addition to — and is processed consistently with — any opt-out you make using the methods described in Section 12.

12. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

Yes.  If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Categories of personal information collected, shared, and sold
We are required under CCPA to disclose the categories of personal information we collect, the purposes for which they are used, and with whom they are shared. The following table sets out this information for California residents.

CategoryExamplesBusiness PurposeSold?Shared for CCBA?
IdentifiersDevice IDs (IDFA/GAID), IP addressAd delivery, fraud detection, measurementNoYes
Internet/network activityAd impressions, clicks, conversion eventsCampaign measurement, reportingNoYes
Geolocation data (coarse)IP-derived approximate locationGeo-targeted advertisingNoYes
Precise geolocation (SPI)GPS-derived location (where app permission granted)Hyper-local advertising onlyNoLimited — see below
Commercial informationConversion events (purchases, installs)Attribution reportingNoYes
Contact dataName, email, phone, address (from direct enquiries)Service delivery, marketingNoNo

Note on sensitive personal information (SPI): Precise geolocation data (within 1,852 metres) constitutes SPI under CPRA. Where we collect this data (only via app permissions granted by you), we use it solely for the purpose of delivering and measuring location-targeted advertising. We do not sell SPI. Sharing of SPI for cross-context behavioural advertising is limited and subject to your right to restrict its use as described below.

Your California privacy rights

  • Right to Know: Request information about the categories and specific pieces of personal information we collect, use, disclose, and share, and the purposes for which it is used.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: Opt out of the sale or sharing of your personal information, including sharing for cross-context behavioural advertising (CCBA). See the opt-out mechanism below.
  • Right to Limit Use of Sensitive Personal Information: Request that we limit the use and disclosure of your sensitive personal information (including precise geolocation) to purposes permitted by CPRA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

How to opt out of sale and sharing

Do Not Sell or Share My Personal Information
To opt out of the sale or sharing of your personal information for cross-context behavioural advertising, please use one of the following methods:

•  Email us at info@fonemedia.co.uk with the subject line ‘CCPA Opt-Out Request’, including your name and, where known, the device identifier or identifiers you wish to opt out for.

•  Use your device settings to opt out of ad tracking (see Section 6 for instructions for iOS and Android).

•  Use the Global Privacy Control (GPC) signal in your browser — we will treat this as a valid opt-out for web-based advertising (see Section 11).

We will process opt-out requests as promptly as possible and, in any event, within 15 business days of receipt.

Exercising your other California rights — response timeframes
To exercise your right to Know, Delete, Correct, or Limit use of SPI, please contact us at info@fonemedia.co.uk. We will:

  • Acknowledge your request within 10 business days
  • Respond substantively within 45 days of receipt of your request
  • Notify you if we require an extension of up to a further 45 days (90 days maximum total), with the reason for the extension

Submitting requests via an authorised agent. A California resident may designate an authorised agent to submit a CCPA request on their behalf. To use an authorised agent, please provide: (a) written authorisation signed by you permitting the agent to act on your behalf; or (b) a valid power of attorney. We may contact you directly to verify the request and your identity. We will not process a request from an agent who cannot demonstrate authority to act on your behalf.

Shine the Light
California Civil Code Section 1798.83 (‘Shine the Light’) permits California residents to request, once per year and free of charge, information about the categories of personal information we disclosed to third parties for their direct marketing purposes, and the identities of those third parties, in the preceding calendar year. Please submit such requests in writing to the address in Section 16.

Minors
If you are under 18 years of age, reside in California, and have a registered account with our Services, you have the right to request removal of unwanted data you publicly post on the Services. Please contact us at info@fonemedia.co.uk, including the email address associated with your account and a statement that you reside in California.

13. DO RESIDENTS OF OTHER US STATES HAVE SPECIFIC PRIVACY RIGHTS?

Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other US states with comprehensive privacy laws may have similar rights to California residents, including:

  • Right to access personal information
  • Right to delete personal information
  • Right to opt out of targeted advertising
  • Right to opt out of the sale of personal information
  • Right to non-discrimination

Please contact us to exercise these rights. We will respond in accordance with the applicable state law governing your residence.

14. CHILDREN’S PRIVACY

Our advertising services are not directed at children under the age of 13. We do not knowingly collect personal information from children. We also take steps to avoid serving personalised advertisements to children, including:

  • Not knowingly serving personalised advertisements in apps or content directed at children
  • Respecting app store age ratings and content classifications
  • Honouring ‘child-directed’ flags set by app publishers in accordance with COPPA (US) and applicable UK requirements

If we learn that we have collected personal information from a child under 13 without appropriate consent, we will delete that information promptly. If you believe we have collected information from a child, please contact us at info@fonemedia.co.uk.

15. DO WE MAKE UPDATES TO THIS NOTICE?

We may update this privacy notice from time to time. The updated version will be indicated by an updated ‘Last updated’ date and will be effective as soon as it is accessible. If we make material changes, we may notify you by prominently posting a notice or by sending you a direct notification. We encourage you to review this notice periodically.

16. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, please contact our data protection contact, James Dalton, by email at info@fonemedia.co.uk, or by post to:

Fonemedia Ltd
James Dalton
Suite 4.2
1175 Century Way
Leeds, LS15 8ZB
United Kingdom

ICO registration number: ZA156835
ICO register entry: https://ico.org.uk/ESDWebPages/Entry/ZA156835

Note on data protection roles
Fonemedia Ltd is the data controller for personal information described in this notice. James Dalton is our designated data protection contact responsible for overseeing compliance with UK data protection law. Note that the role of ‘data protection contact’ is distinct from the formal ‘Data Protection Officer’ (DPO) role under UK GDPR Article 37. Fonemedia Ltd is assessing whether a formal DPO appointment is required based on the scale and nature of its processing activities, and will update this notice if a formal DPO is appointed.

17. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it. To submit a request, please contact us at info@fonemedia.co.uk.

AMENDMENT LOG — APRIL 2026 REVISION
The following material changes were made to the December 2025 draft in this revision:

SectionChange MadeReason
SummaryCorrected statement on third-party data receipt — we do receive data from advertising tech partnersPrevious statement was factually incorrect and contradicted Section 4
SummaryCorrected SPI statement — precise geolocation may constitute SPI for CA residentsCPRA definition of SPI includes precise geolocation within 1,852m
S2Added explicit RTB processing activity with data type detailTransparency requirement under UK GDPR Article 13/14
S3Added processing activity to legal basis mapping tableICO adtech guidance — LI not valid for device ID tracking without consent
S3Added joint controller disclosure with Article 26 referenceUK GDPR Article 26 obligation in RTB context
S4Added CCPA ‘sharing for CCBA’ callout boxCPRA §1798.100 mandatory disclosure requirement
S6Added PECR/IDFA/GAID consent requirementICO confirmed mobile ad IDs are equivalent to cookies under PECR
S6Added IAB TCF reference and consent signal handlingIndustry standard consent mechanism for programmatic advertising
S8Completed all retention period placeholdersRequired for UK GDPR transparency and CPRA compliance
S9Added Cyber Essentials certification referenceTangible security commitment; differentiator for tenders
S11Added Global Privacy Control (GPC) sectionCA Regs 11 CCR §7025 — GPC must be treated as valid CCPA opt-out
S12Added personal information categories/sharing tableCCPA §1798.100(a)(2) mandatory disclosure
S12Added ‘Do Not Sell or Share’ opt-out mechanismCCPA mandatory opt-out mechanism for targeted advertising
S12Added GPC as valid opt-out mechanismCA Regs requirement
S12Addressed precise geolocation as SPI under CPRACPRA sensitive personal information definition
S12Added 45-day response timeframeCCPA §1798.145 statutory response period
S12Added authorised agent processCCPA §1798.135 requirement
S16Corrected DPO/data protection contact distinctionUK GDPR Article 37 — formal DPO appointment is a distinct designation
S16Added ICO registration number ZA156835Good practice; supports consumer verification
TOC/numberingRenumbered all sections — former 12A/12B now Sections 13/14Section numbering was duplicated in previous draft

This privacy notice was last reviewed and updated in April 2026.