Privacy Policy
Last updated 25 August 2026
On this page
- Two different things, kept apart
- Who we are
- Part A — This website
- What we collect when you visit archonph.com
- Third-party requests this website makes
- Legal basis and rights, Part A
- Part B — Our advertising services
- What this part covers
- Information we may process
- How it is collected
- How it is used
- Retention
- Sharing
- International transfers
- Security
- Children
- Avoiding targeted advertising
- Part C — Business contact with publishers and advertisers
- Prospecting
- Your rights
- European Economic Area and United Kingdom
- Brazil
- China
- Türkiye, California, Virginia, Colorado, Connecticut and Utah
- Making a request
- Changes
Two different things, kept apart
This policy covers two situations that people routinely confuse, so we separate them rather than blending them into one description:
Part A — this website. What happens when you visit archonph.com. The short answer is: very little, and the measurable part only with your consent. No advertising is served here.
Part B — our services. What happens when Archon's advertising technology operates on a publisher's website or app. This is our business, it does involve identifiers and behavioural data, and it is where the substantive obligations sit.
Read the part that applies to you. If you arrived here because you saw an ad or wondered why a publisher shares data with us, Part B is the one you want.
Who we are
"We", "us" and "Archon" mean Archon Programmatic House FZC and its affiliates. We are a programmatic advertising house: we monetise publishers' advertising inventory and sell that inventory to brands and agencies.
Archon Programmatic House FZC is registered as vendor number 1318 on the IAB Europe Transparency & Consent Framework 2.2 Vendor List and on the IAB Canada TCF Vendor List.
We are headquartered in Istanbul, with a UAE company carrying the Gulf side. Both desks are listed, with maps, on our contact page.
For any privacy question, request or complaint, write to info@archonph.com. We answer within the periods the applicable law requires. We have not appointed a Data Protection Officer; privacy requests are handled by the team at that address.
Part A — This website
What we collect when you visit archonph.com
Server logs. Our host records standard request data: IP address, the page requested, timestamp, referring URL, user agent. This is ordinary web server operation, kept for security and troubleshooting, and it is the basis on which we detect abuse. We do not use it to build a profile of you, and we do not combine it with any other dataset.
Local storage. A small number of functional values: whether you have already seen a page's opening animation, so it does not replay, and — once you have answered it — your response to the consent banner. They stay in your browser and contain no identifier. Full detail is in the Cookie Policy.
Analytics and ad measurement, with consent. If you allow it, the site loads Google Analytics 4 (which pages are visited, how visitors arrive) and the conversion tags of Google Ads, Microsoft Advertising and LinkedIn (whether a visit followed one of our own ads). Visitors from Türkiye are asked under KVKK, visitors from the EEA, the United Kingdom and Switzerland under the GDPR, and visitors from Brazil, Canada, Chile, China, Colombia, Egypt, Indonesia, Israel, Nigeria, Qatar, Saudi Arabia and South Korea under their own laws, before any of this loads. Elsewhere it runs by default, a one-time notice says so, and it can be turned off through the footer's Cookie preferences link (Your Privacy Choices, for visitors from the United States). If your browser sends the Global Privacy Control signal we treat it, worldwide, as an opt-out of the advertising-measurement tags — it prevails even over an earlier acceptance. These tags measure the marketing of our own company. Nothing collected here is sold, and nothing collected here feeds the advertising systems described in Part B.
Email you send us. If you write to an address published here, we hold your message and address for as long as needed to deal with it and to keep a record of the correspondence.
What you type into a form. Two forms appear on this site: a weekly-letter subscription that asks only for a work email address, and the *Get started* intake, which asks what kind of publisher or advertiser you are and what you want from us. We use a subscription address to send the weekly letter and nothing else — we do not share or sell the list, and every issue carries a one-click unsubscribe. We use an intake submission to prepare a reply and to keep a record of the enquiry. Neither is used for advertising targeting.
That is the complete list. This website serves no advertising, uses no tag manager, and sets no cookie or measurement pixel outside the consent-governed tags described above.
Third-party requests this website makes
Before consent, none. Every file this site loads by itself — pages, stylesheets, images, video and typefaces — comes from archonph.com. The typefaces are self-hosted rather than loaded from Google's font service, so no request carrying your IP address reaches a third party. If you consent to measurement, your browser additionally talks to the providers you allowed — Google, Microsoft, LinkedIn — and to no one else. The Cookie Policy lists each one.
Legal basis and rights, Part A
Where the GDPR or UK GDPR applies, our basis for processing server logs is our legitimate interest in operating and securing the site (Article 6(1)(f)), and for correspondence, our legitimate interest in answering you. Functional local storage is used to provide the page you requested. Analytics and ad measurement run on your consent (Article 6(1)(a)); where KVKK applies, on your explicit consent under Article 5 of Law 6698. You can withdraw either at any time through the Cookie preferences link in the footer, and withdrawal does not affect processing carried out before it.
You have the rights set out under *Your rights* below, and you may exercise them for this website's data exactly as for any other.
Part B — Our advertising services
What this part covers
This part explains how personal data may be collected, used and disclosed through Archon's technology operating on behalf of the businesses that use our services — publishers, brands and agencies (our "clients").
In this context we act principally as a processor on our clients' instructions. For data collected through this website we act as a controller. Where the distinction matters to a right you wish to exercise, tell us the website or app where you encountered our technology and we will direct the request correctly.
Information we may process
We do not intentionally collect information revealing your real-world identity — not your name, postal address or telephone number. What we may process is:
- Behaviour on a client's property: the domain, referring URL, pages and content viewed, time and duration of the visit, and interactions with an advertisement.
- Device and connection: IP address, device make, model, operating system and version, browser type and version, language settings, screen dimensions, carrier, and mobile advertising identifiers where the platform provides them.
- Approximate location derived from the above, at the level of country, region or city.
- Consent and preference signals, including TCF consent strings and any applicable US privacy signals, passed to us by the publisher's consent management platform.
How it is collected
Through cookies and comparable industry technologies placed on our clients' properties, and through the bid requests that publishers and their technology partners transmit to us. We rely on our clients to obtain any consent the law requires before that data reaches us, and we require them contractually to do so.
How it is used
Principally to allow our clients to buy and sell advertising space: to match an advertisement to an opportunity, to cap how often it is shown, to detect fraud and invalid traffic, to measure delivery, and to report performance.
If Archon or an affiliate is involved in a merger, acquisition, financing due diligence, reorganisation, bankruptcy, receivership or sale of assets, or transitions a service to another provider, information may be transferred as part of that transaction as permitted by law.
Retention
We store information only where necessary. Traffic and inventory-quality data is typically deleted quarterly. Some data expires according to your device settings. Retention periods take account of the volume, nature and sensitivity of the data, the purposes for which it is processed, and the risk of harm from unauthorised use. Certain laws — anti-money-laundering, financial reporting, tax — and orders of a competent court may require us to retain records for longer.
Sharing
We share information with the participants necessary to complete an advertising transaction, including demand-side platforms, supply-side platforms, exchanges and measurement providers; with service providers acting on our behalf under contract; and where required by law or to protect our rights.
International transfers
Archon works with companies in many jurisdictions, so data may be processed outside your country of residence, including countries whose protection differs from your own. When we transfer personal data outside the European Economic Area, Switzerland or the United Kingdom, we apply the measures required by Articles 44–50 of the GDPR. Where a destination is not covered by a European Commission adequacy decision, we rely on Standard Contractual Clauses together with any supplementary measures the transfer requires.
Security
We apply physical, technical and administrative safeguards to protect personal data against unauthorised or unlawful processing and against loss, destruction or damage, and we test those measures regularly. No transmission or storage can be guaranteed completely secure, but we take all reasonable precautions and maintain procedures for responding to incidents.
Children
Our services are not directed at people under 18 and we do not knowingly collect their personal data. If you believe a child has provided us with personal information, contact us and we will delete it.
Avoiding targeted advertising
Different platforms, browsers and devices use different identifiers and different controls, so there is no single switch. Industry opt-outs are available through youronlinechoices.eu in Europe and optout.aboutads.info in the United States, and mobile operating systems provide their own advertising-identifier controls.
Note that deleting your cookies may also delete the record of an opt-out. We do not respond to browser "Do Not Track" signals, which have no agreed meaning. We do honour the Global Privacy Control signal, everywhere, not only where the law requires it: on this website a GPC signal switches the advertising-measurement tags off in a frictionless manner — no account, no verification, no pop-up — and the page footer confirms it with "Opt-out preference signal honored". Instructions for enabling GPC in a browser are at globalprivacycontrol.org. If you prefer not to use the signal, the footer's opt-out link achieves the same result manually.
Part C — Business contact with publishers and advertisers
Prospecting
This section is the notice we give, under Article 14 of the GDPR and the UK GDPR, to people whose business contact details we did not collect from them directly. If you received an email or a LinkedIn message from us about your company's advertising, this is how we came to hold your details and what you can do about it.
Who is contacting you. Archon Programmatic House FZC, described under *Who we are* above. Every message names the person sending it and their role; we do not use disguised or misleading sender identities or subject lines.
What we hold. Your name, job title, work email address, the company you work for and its website, your public LinkedIn profile URL, and notes about the correspondence itself. We also analyse your company's publicly published advertising files (ads.txt, app-ads.txt, sellers.json) and public web performance signals; those describe the company, not you.
Where it came from. One or more of: your company's own website or publisher pages; your public LinkedIn profile; company registries; and business-contact databases we license (currently Apollo.io). The first email we send you names the specific source we used for your address.
Why, and on what basis. To tell decision makers at publishers, brands and agencies about services that are relevant to the role they hold, and to answer any reply. Where the GDPR or UK GDPR applies, our legal basis is our legitimate interest in marketing our services to businesses (Article 6(1)(f)), which we have assessed and documented; it is not consent, and we do not need your consent to send a first business message to a corporate address. For electronic marketing we follow the rules of each country: in the United Kingdom we email only corporate subscribers, never sole traders or partnerships that count as individuals under PECR; in Türkiye we send commercial messages only where the İYS rules allow; in Germany we send only where a business-to-business legitimate interest is clearly present and we stop at the first objection.
Who else sees it. Our email-sequencing provider (Woodpecker), our CRM (HubSpot), the contact database named above, and Google Workspace for mail. Each acts under contract as our processor. Nobody else, and never for their own marketing. Some of these providers are in the United States; transfers are covered by Standard Contractual Clauses or the UK International Data Transfer Addendum, as described under *International transfers*.
How long. If you do not reply, we stop writing after a short sequence of at most four messages and delete your contact record within 12 months of the last one. If you reply, we keep the correspondence for as long as the business relationship or the enquiry is live, and for up to 3 years after it ends. If you object, we keep only your email address on a suppression list so that we never contact you again; that is the one record we deliberately retain.
Your rights. You may object to this processing at any time, for any reason, and we will stop immediately, no questions and no further message (Article 21). Reply "unsubscribe" or "stop" to any message, use the opt-out link in the email, or write to info@archonph.com. You also have the rights of access, rectification, erasure and restriction listed under *Your rights* below, and you can complain to your supervisory authority; in the United Kingdom that is the Information Commissioner's Office (ico.org.uk). We make no decisions about you by automated means.
Your rights
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies you have the right to be informed; of access; to rectification; to erasure; to restriction of processing; to data portability; to object to processing carried out on the basis of legitimate interests; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before it.
You also have the right to lodge a complaint with your national supervisory authority. Exercising a right with us first is not a precondition for that.
Brazil
Under the Lei Geral de Proteção de Dados Pessoais you have the rights of confirmation of processing, access, rectification of incomplete, inaccurate or outdated data, anonymisation, blocking or deletion of unnecessary or excessive data, data portability, information about sharing, information about the consequences of refusing consent, and revocation of consent.
China
Under the Personal Information Protection Law you have the right to know, decide, refuse and limit the handling of your personal information; to access and copy it; to correct or complete it; to request an explanation of our handling rules; and to request deletion.
Türkiye, California, Virginia, Colorado, Connecticut and Utah
Archon observes the requirements of the Turkish Law on the Protection of Personal Data No. 6698 (KVKK), the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act and the Utah Consumer Privacy Act.
Depending on your state this may include the right to know what personal information is collected and how it is used and shared; to delete it; to correct it; to opt out of its sale or sharing and of targeted advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising a right.
We do not sell personal information. Nothing you give this website — an email address, a form submission, a message — is sold, rented, or passed to anyone else for their own marketing. The weekly-letter list is never shared.
The advertising data described in Part B is a different matter and is described there: it is processed on our clients' instructions and shared only with the parties needed to complete an advertising transaction. The opt-outs above apply to it.
Making a request
Write to info@archonph.com. To act on a request about data collected through our services rather than through this website, we usually need the website or app where you encountered our technology and an approximate date, because we hold no name or account by which to find you otherwise. We may need to verify a request before acting on it, and we will not use anything you provide for verification for any other purpose.
Changes
We may update this policy. The date at the top records the last revision. Where a change materially affects how we handle personal data, we will say so on this page rather than change it silently.