Privacy Policy
Last updated 6 August 2026
On this page
- Two different things, kept apart
- Who we are
- Part A — This website
- What we collect when you visit archonph.com
- Third-party requests this website makes
- Legal basis and rights, Part A
- Part B — Our advertising services
- What this part covers
- Information we may process
- How it is collected
- How it is used
- Retention
- Sharing
- International transfers
- Security
- Children
- Avoiding targeted advertising
- Your rights
- European Economic Area and United Kingdom
- Brazil
- China
- Türkiye, California, Virginia, Colorado, Connecticut and Utah
- Making a request
- Changes
Two different things, kept apart
This policy covers two situations that people routinely confuse, so we separate them rather than blending them into one description:
Part A — this website. What happens when you visit archonph.com. The short answer is: very little. No cookies, no analytics, no advertising.
Part B — our services. What happens when Archon's advertising technology operates on a publisher's website or app. This is our business, it does involve identifiers and behavioural data, and it is where the substantive obligations sit.
Read the part that applies to you. If you arrived here because you saw an ad or wondered why a publisher shares data with us, Part B is the one you want.
Who we are
"We", "us" and "Archon" mean Archon Programmatic House FZC and its affiliates. We are a programmatic advertising house: we monetise publishers' advertising inventory and sell that inventory to brands and agencies.
Archon Programmatic House FZC is registered as vendor number 1318 on the IAB Europe Transparency & Consent Framework 2.2 Vendor List and on the IAB Canada TCF Vendor List.
We are headquartered in Istanbul, with a UAE company carrying the Gulf side. Both desks are listed, with maps, on our contact page.
For any privacy question, request or complaint, write to info@archonph.com. We answer within the periods the applicable law requires. We have not appointed a Data Protection Officer; privacy requests are handled by the team at that address.
Part A — This website
What we collect when you visit archonph.com
Server logs. Our host records standard request data: IP address, the page requested, timestamp, referring URL, user agent. This is ordinary web server operation, kept for security and troubleshooting, and it is the basis on which we detect abuse. We do not use it to build a profile of you, and we do not combine it with any other dataset.
Local storage. Two functional values that record whether you have already seen a page's opening animation, so it does not replay. They stay in your browser, are never transmitted to us, and contain no identifier. Full detail is in the Cookie Policy.
Email you send us. If you write to an address published here, we hold your message and address for as long as needed to deal with it and to keep a record of the correspondence.
What you type into a form. Two forms appear on this site: a weekly-letter subscription that asks only for a work email address, and the *Get started* intake, which asks what kind of publisher or advertiser you are and what you want from us. We use a subscription address to send the weekly letter and nothing else — we do not share or sell the list, and every issue carries a one-click unsubscribe. We use an intake submission to prepare a reply and to keep a record of the enquiry. Neither is used for advertising targeting.
That is the complete list. This website has no cookies, no analytics platform, no tag manager, and no advertising or conversion pixel. Our previous policy stated that this site used Google Analytics and Google AdSense. That is not the case on this site, and this policy corrects it.
Third-party requests this website makes
None. Every file this site loads — pages, stylesheets, images, video and typefaces — comes from archonph.com. The typefaces are self-hosted rather than loaded from Google's font service, so no request carrying your IP address reaches a third party. Your browser talks to us and to nobody else.
Legal basis and rights, Part A
Where the GDPR or UK GDPR applies, our basis for processing server logs is our legitimate interest in operating and securing the site (Article 6(1)(f)), and for correspondence, our legitimate interest in answering you. Functional local storage is used to provide the page you requested.
You have the rights set out under *Your rights* below, and you may exercise them for this website's data exactly as for any other.
Part B — Our advertising services
What this part covers
This part explains how personal data may be collected, used and disclosed through Archon's technology operating on behalf of the businesses that use our services — publishers, brands and agencies (our "clients").
In this context we act principally as a processor on our clients' instructions. For data collected through this website we act as a controller. Where the distinction matters to a right you wish to exercise, tell us the website or app where you encountered our technology and we will direct the request correctly.
Information we may process
We do not intentionally collect information revealing your real-world identity — not your name, postal address or telephone number. What we may process is:
- Behaviour on a client's property: the domain, referring URL, pages and content viewed, time and duration of the visit, and interactions with an advertisement.
- Device and connection: IP address, device make, model, operating system and version, browser type and version, language settings, screen dimensions, carrier, and mobile advertising identifiers where the platform provides them.
- Approximate location derived from the above, at the level of country, region or city.
- Consent and preference signals, including TCF consent strings and any applicable US privacy signals, passed to us by the publisher's consent management platform.
How it is collected
Through cookies and comparable industry technologies placed on our clients' properties, and through the bid requests that publishers and their technology partners transmit to us. We rely on our clients to obtain any consent the law requires before that data reaches us, and we require them contractually to do so.
How it is used
Principally to allow our clients to buy and sell advertising space: to match an advertisement to an opportunity, to cap how often it is shown, to detect fraud and invalid traffic, to measure delivery, and to report performance.
If Archon or an affiliate is involved in a merger, acquisition, financing due diligence, reorganisation, bankruptcy, receivership or sale of assets, or transitions a service to another provider, information may be transferred as part of that transaction as permitted by law.
Retention
We store information only where necessary. Traffic and inventory-quality data is typically deleted quarterly. Some data expires according to your device settings. Retention periods take account of the volume, nature and sensitivity of the data, the purposes for which it is processed, and the risk of harm from unauthorised use. Certain laws — anti-money-laundering, financial reporting, tax — and orders of a competent court may require us to retain records for longer.
Sharing
We share information with the participants necessary to complete an advertising transaction, including demand-side platforms, supply-side platforms, exchanges and measurement providers; with service providers acting on our behalf under contract; and where required by law or to protect our rights.
International transfers
Archon works with companies in many jurisdictions, so data may be processed outside your country of residence, including countries whose protection differs from your own. When we transfer personal data outside the European Economic Area, Switzerland or the United Kingdom, we apply the measures required by Articles 44–50 of the GDPR. Where a destination is not covered by a European Commission adequacy decision, we rely on Standard Contractual Clauses together with any supplementary measures the transfer requires.
Security
We apply physical, technical and administrative safeguards to protect personal data against unauthorised or unlawful processing and against loss, destruction or damage, and we test those measures regularly. No transmission or storage can be guaranteed completely secure, but we take all reasonable precautions and maintain procedures for responding to incidents.
Children
Our services are not directed at people under 18 and we do not knowingly collect their personal data. If you believe a child has provided us with personal information, contact us and we will delete it.
Avoiding targeted advertising
Different platforms, browsers and devices use different identifiers and different controls, so there is no single switch. Industry opt-outs are available through youronlinechoices.eu in Europe and optout.aboutads.info in the United States, and mobile operating systems provide their own advertising-identifier controls.
Note that deleting your cookies may also delete the record of an opt-out. We do not respond to browser "Do Not Track" signals, which have no agreed meaning, except where the law requires us to honour a specific signal — we do honour Global Privacy Control where applicable law gives it effect.
Your rights
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies you have the right to be informed; of access; to rectification; to erasure; to restriction of processing; to data portability; to object to processing carried out on the basis of legitimate interests; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before it.
You also have the right to lodge a complaint with your national supervisory authority. Exercising a right with us first is not a precondition for that.
Brazil
Under the Lei Geral de Proteção de Dados Pessoais you have the rights of confirmation of processing, access, rectification of incomplete, inaccurate or outdated data, anonymisation, blocking or deletion of unnecessary or excessive data, data portability, information about sharing, information about the consequences of refusing consent, and revocation of consent.
China
Under the Personal Information Protection Law you have the right to know, decide, refuse and limit the handling of your personal information; to access and copy it; to correct or complete it; to request an explanation of our handling rules; and to request deletion.
Türkiye, California, Virginia, Colorado, Connecticut and Utah
Archon observes the requirements of the Turkish Law on the Protection of Personal Data No. 6698 (KVKK), the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act and the Utah Consumer Privacy Act.
Depending on your state this may include the right to know what personal information is collected and how it is used and shared; to delete it; to correct it; to opt out of its sale or sharing and of targeted advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising a right.
We do not sell personal information. Nothing you give this website — an email address, a form submission, a message — is sold, rented, or passed to anyone else for their own marketing. The weekly-letter list is never shared.
The advertising data described in Part B is a different matter and is described there: it is processed on our clients' instructions and shared only with the parties needed to complete an advertising transaction. The opt-outs above apply to it.
Making a request
Write to info@archonph.com. To act on a request about data collected through our services rather than through this website, we usually need the website or app where you encountered our technology and an approximate date, because we hold no name or account by which to find you otherwise. We may need to verify a request before acting on it, and we will not use anything you provide for verification for any other purpose.
Changes
We may update this policy. The date at the top records the last revision. Where a change materially affects how we handle personal data, we will say so on this page rather than change it silently.