privacy

Nothing non-essential runs until you choose.

Written from the code rather than from a precedent, and marked as unfinished where it is.

This site runs one cookieless counter that stores nothing on your device, and one optional analytics category that loads nothing at all unless you accept it. There is no advertising tracking here and no cross-site identifier. Below: every place a visit to this site causes data to exist, what the AdBuyMCP platform would process for a customer, the lawful basis for each, and how long anything is kept.
cookies before you choose
None
optional categories
1
hashed ad-id retention
90 days
cross-site tracking
None
statusTemplate, pending counsel
the technical version
The security page carries the controls, the subprocessor table and the full list of certifications and registrations we do not hold.
Read the security page →
status of this document

This is a template, pending review by counsel

AdBuyMCP is in design-partner phase and its legal documents have not yet been through a qualified solicitor. This page is a plain-English, UK-oriented starting point written from what the code actually does, and it is published in that state on purpose: our own pre-launch checklist lists the privacy policy, terms, data processing agreement and subprocessor list as templates to be reviewed before they are relied on, and presenting one of them as settled policy would be a misrepresentation on the page least able to afford one.

Read the factual descriptions here as accurate — they were written from the code, and the security page lists this same document as an open item. Read anything that reads like a legal commitment as not yet settled. If you are about to rely on it for a data protection assessment, ask us for the current position and you will get it in writing.

who is responsible

Who we are, and who to write to

AdBuyMCP is a product rather than a company, which matters here: the controller is the company behind it, and that company is on the public register.

Tenhaw LTD is the data controller for this website and for the AdBuyMCP product, a company registered in England and Wales, number 12735685, operating from London. Where a design partner runs campaigns on the platform, we act as their processor for the campaign data they put into it, under the agreement covering that engagement, and they remain the controller of it.

Privacy questions, data subject requests and security questionnaires all go to hello@adbuymcp.com. There is no separate privacy inbox yet, and publishing an address that nobody monitors would be worse than publishing the one that is read. You can also complain directly to the Information Commissioner’s Office at ico.org.uk, with or without raising it with us first.

One thing worth saying early, because it changes how the rest of this page should be read: registration for the ICO’s data protection fee and the data protection impact assessment for the exposure ledger are both open items rather than completed work. They are listed as such on the security page, beside the certifications we do not hold.

this website

8 places a visit here causes data to exist

Including the ones a policy usually leaves out. Each row says what happens, when it happens, and which lawful basis it runs on. Where something is outside our control, it says that too rather than being quietly dropped from the list.

  1. A cookieless page counter

    Runs for everyone

    Plausible Analytics, loaded on every page. It sets no cookie, stores nothing on your device and keeps no IP address, so it cannot follow you to another site and there is no individual record of you to retain. What it keeps is aggregate: the page, the referrer, the country, the device type and the browser, plus outbound link clicks, file downloads and a small fixed vocabulary of named events — a call-to-action clicked, the booking calendar coming into view, a question asked of the on-page assistant. It runs for everyone rather than behind the consent gate because there is nothing stored on your device for the storage-and-access rule to bite on, and it is disclosed here rather than left to the exemption.

    Legitimate interests: understanding which pages of our own site are useful.

  2. Google Analytics

    Only if you accept

    Not loaded at all until the analytics category is granted. This is deliberately not the common pattern of loading the tag and then suppressing it with consent signals, because a suppressed tag still sends cookieless pings and not loading is both the defensible position and the simpler one to evidence. Once granted it sets its own cookies and records page views, referrer and which calls-to-action were used. Nothing in the configuration attempts to identify you or the company you work for. Decline, and the script never reaches your browser.

    Consent, which you give or refuse in the panel and can change at any time.

  3. Your consent decision

    Runs for everyone

    Kept in your browser's local storage under the key adbuymcp_consent, not in a cookie and not on any server here. The stored record holds the category-set version, whether analytics was allowed, the timestamp of the decision, and whether it came from a browser privacy signal rather than a click. It never leaves your device. Clearing your site data removes it and you will be asked again.

    Strictly necessary: it is the record of your own choice, and without it we would have to ask on every page.

  4. The on-page assistant

    Only when you use it

    What you type is sent to Anthropic's API to produce the answer, along with up to the last ten messages of that conversation, each capped at a thousand characters. It is not written to a database here, because this website has no database. Your IP address is held in memory for at most sixty seconds so the endpoint can be rate-limited, and is not logged or persisted. Do not type anything into it you would not put in an email.

    Legitimate interests, and your own request: you asked it a question.

  5. The booking calendar

    Only when you use it

    A Cal.com embed, and none of Cal's code is requested until you scroll close to it, so on a page whose calendar you never reach nothing of theirs loads at all. What you enter to book a working session — your name, your email, whatever you write in the notes — goes to Cal.com and to us as a booking. The embed is a cross-origin frame, so what happens inside it is governed by Cal.com's own privacy terms as well as this page.

    Steps taken at your request before entering a contract.

  6. Email and enquiries

    Only when you use it

    Anything you send to our address, kept for as long as it takes to deal with it and to keep a record of what was agreed. There is no separate privacy inbox yet; publishing an address nobody monitors would be worse than publishing the one that is read.

    Legitimate interests, and steps taken at your request before entering a contract.

  7. Fonts and page assets

    Runs for everyone

    Served from this origin. The three typefaces are downloaded at build time and self-hosted rather than fetched from a font network, so loading a page here does not tell a font provider that you visited. This is the kind of third-party request a privacy-conscious reader checks for, which is why it is stated rather than assumed.

    Strictly necessary: the page has to render.

  8. Web server request logs

    Not ours to control

    Whichever commercial platform serves these pages keeps ordinary request logs, which include IP addresses, under its own retention and for its own security and operations. Naming that provider and stating its retention precisely is one of the things this document has to do before it stops being a template, and it is listed here rather than quietly omitted.

    Legitimate interests: keeping the site available and secure.

Two claims that appear in our own legal template are deliberately not repeated here. It says IP addresses are truncated and hashed on ingest, and no code in the platform does that. It also states a flat six-year retention on billing records; the honest version is that financial records are kept for as long as UK tax and company law requires, which is a question for counsel rather than for a website.

the platform, not this website

What the product would process

Everything above is about visiting this site. This is about running a campaign on the platform, which almost nobody is doing yet: 0 of the 25 connectors have executed a buy, and there is no multi-tenant hosted service, so a deployment today is one stood up for a single design partner with its own agreement behind it. The sandbox everyone can drive produces deterministic synthetic data and involves no personal data at all.

The full technical account
Campaign and plan data
Personas, compiled targeting specifications, plans, creatives, delivery rows and statements, scoped to one advertiser workspace. A persona describes a market — intent topics, firmographics, geography, interests — rather than a person.
Exposure and outcome events
Ad exposures keyed on an opaque household key, a hashed mobile advertising id, a EUID or a postcode sector, plus the outcomes a customer imports or that arrive through their own analytics. The ledger that holds them never resolves a key back to a person or across key spaces.
Hashed advertising ids, for at most 90 days
After the window the hashed id is persistently stripped from the exposure event, and the event is re-graded to a coarser key rather than deleted, so the history survives without the identifier. It is enforced in one module, which is also the only module in the platform permitted to perform an identity join.
Vendor credentials
Encrypted at rest with AES-256-GCM, never logged and never returned by an API read. Deleted when the connection is removed.
A lawful-basis manifest on every compiled plan
Each segment's provider and the basis it relies on — consent-chained, legitimate interest, or outside UK GDPR scope, which is where cinema and DOOH delivery sit — recorded per segment rather than asserted once, with the warnings raised while compiling still attached. It is evidence a DPO can read; it is not a compliance guarantee, and the conditions it attaches are ones the advertiser still owes.
lawful basis

Five bases, and what each one is doing here

A policy that names its bases in a single sentence is a policy nobody can check. These are separated because they behave differently: consent can be withdrawn, legitimate interests can be objected to, and a legal obligation survives both.

Consent
The optional analytics category on this website, and — inside the product — device-level advertising identifiers, where the segment provider asserts a consent chain. Consent is the basis that can be withdrawn, and withdrawing it here means reopening the panel from the cookie settings link in the footer and choosing again.
Legitimate interests
The cookieless page counter, keeping this site available and secure, answering enquiries, and B2B marketing of our own service. Inside the product, business-to-business signals that rely on a legitimate interests assessment, which the manifest names as a condition the advertiser holds rather than as something we have completed for them.
Contract, and steps before one
Booking and holding a working session, corresponding about an engagement, and — for a design partner — running the platform itself.
Legal obligation
Records we are required to keep, principally financial ones. This page states no fixed retention figure for them, because the correct figure is a question for counsel rather than for a marketing site.
Outside scope
Cinema and digital out-of-home delivery involve no personal data at all — venue catchments, aggregate movement data, geographic polygons — and the compiler records that rather than leaving it to be inferred.
how long

What is kept, for how long, and what happens at the end

The third column is the one usually missing. “Ninety days” and “ninety days, then persistently stripped and the event re-graded to a coarser key” are different commitments, and only one of them can be checked.

Retention periods for data held by AdBuyMCP and this website.
WhatHow longWhat happens then
Your consent decisionHow longUntil you clear itWhat happens thenIt lives in your browser and nowhere else. Clearing site data removes it, and a change to the category set makes it stop counting, so you are asked again.
Cookieless page analyticsHow longAggregate onlyWhat happens thenNo individual-level record is created, so there is nothing about you to keep or to delete.
Google Analytics, if you accepted itHow longGoogle's own retentionWhat happens thenHeld by Google under the retention setting on the property. If you declined, no record was created in the first place.
Assistant conversationsHow longNot stored hereWhat happens thenThere is no database on this website. The API call is subject to Anthropic's own terms; the rate-limit record of your IP address is held in memory for at most sixty seconds and then gone.
Bookings and correspondenceHow longAs long as it is neededWhat happens thenHeld to arrange the meeting, to follow it up, and to keep a record of what was discussed and agreed. Deleted on request unless we are required to keep it.
Hashed advertising ids in the productHow long90 days maximumWhat happens thenPersistently stripped from the exposure event, which is re-graded to a coarser key rather than deleted.
Campaign configuration and delivery dataHow longLife of the workspaceWhat happens thenDeleted on request, and returned or deleted on the end of an engagement under the agreement covering it.
Vendor credentialsHow longUntil the connection is removedWhat happens thenDeleted. They are encrypted at rest for as long as they exist and are never returned by an API read.
Financial recordsHow longAs UK law requiresWhat happens thenKept for as long as tax and company law requires. This page states no number, because the number is a question for counsel.
who else sees it

Two lists, kept apart on purpose

The processors behind this website are not the same as the product's subprocessors, and merging them into one list would make it impossible to tell which commitment you were being given. So here they are separately, with the count on each.

This website
  • Plausible Analytics — the cookieless counter, for everyone.
  • Google — Google Analytics, only after you accept the analytics category.
  • Cal.com — the booking calendar, and only once you scroll to it.
  • Anthropic — the on-page assistant, and only when you ask it something.
  • A hosting provider — ordinary web-server request logs. Named precisely as part of the counsel review this page is waiting on.
The product · 4 subprocessors
  • Anthropic The AI layer: persona extraction, plan explanation, creative drafting and pre-check.
  • Clerk Authentication and organisation membership.
  • Stripe Wallet top-ups.
  • Plausible Analytics Cookieless product and website analytics.

Four, because those are the four that receive anything today. The reasoning, and what a longer list would get wrong in both directions, is on the security page.

International transfers, stated as intent

Several of the parties above are headquartered outside the UK. Where personal data leaves the UK, the intended basis is an adequacy regulation or the UK International Data Transfer Addendum alongside standard contractual clauses. That is a statement of intent rather than a settled position, because it describes agreements that counsel has not yet reviewed, and this is precisely the kind of sentence that a template must not be allowed to pass off as finished.

your rights

8 rights, and one email address

Under UK GDPR you have the rights below. Write to us and we will respond within one month; if a request is complex enough to need longer, we will tell you that inside the month rather than at the end of it. Exercising any of them costs nothing and changes nothing about how you are treated.

Access
A copy of the personal data we hold about you, and an explanation of what we do with it.
Rectification
Correction of anything inaccurate, and completion of anything incomplete.
Erasure
Deletion, where we have no overriding reason or legal obligation to keep it.
Restriction
A pause on processing while a dispute about accuracy or basis is resolved.
Portability
The data you gave us, in a structured, commonly used, machine-readable form.
Objection
An objection to anything we do on the basis of legitimate interests, including marketing our own service to you.
Withdrawal of consent
For anything relying on consent, at any time and as easily as it was given. On this site that is the cookie settings link in the footer.
Complaint
To the Information Commissioner's Office at ico.org.uk, whether or not you raise it with us first. We would rather you raised it with us, but that is a preference and not a condition.
If your data is in a customer’s campaign

Where we process campaign data for a design partner, they are the controller and the request belongs with them. Send it to us anyway if you do not know who they are, and we will route it and help them answer it.

Automated decisions

Nothing here makes an automated decision producing a legal or similarly significant effect about an individual. The AI layer drafts and plans media; a named human authorises money, and consequential actions fail closed unless a human approved those exact bytes.

when this changes

The next version of this page will be the reviewed one.

Changes are posted here. If the consent categories or the processors behind them change, the stored version number stops matching and everyone is asked again rather than being carried forward on an answer given to a different question. Until counsel has been through it, treat the descriptions as accurate and the commitments as provisional, and ask if you need the current position in writing.

What people actually ask about this

Six questions, including the one a privacy policy never answers about itself.

Do you set cookies?

Not before you choose. The page counter that runs for everyone is cookieless and stores nothing on your device. Your consent decision is kept in local storage under the key adbuymcp_consent rather than in a cookie. Google Analytics sets its own cookies, and it is not loaded at all unless you accept the analytics category, so declining means no analytics cookie is ever written.

How do I change or withdraw my consent?

The cookie settings link in the footer of every page reopens the panel. A new decision replaces the stored one immediately and the gated tools stop loading from the next page view. Clearing your browser's site data removes the record entirely, in which case you will simply be asked again. A browser sending Global Privacy Control or Do Not Track is treated as a rejection without being prompted at all.

What happens to what I type into the assistant on these pages?

It is sent to Anthropic's API to produce the answer, together with up to the last ten messages of that conversation, each capped at a thousand characters. It is not written to a database, because this website does not have one. Your IP address is held in memory for at most sixty seconds so the endpoint can be rate-limited, and is not logged. Treat it like an email rather than like a private note.

How long do you keep advertising identifiers?

At most 90 days. After the window, the hashed mobile advertising id is persistently stripped from the exposure event and the event is re-graded to a coarser key — a household key or a postcode sector — rather than being deleted, so the delivery history survives without the identifier. The rule is enforced in the one module permitted to perform identity joins, rather than being a policy applied by hand.

Are you registered with the ICO, and have you completed a DPIA?

Neither. Registration for the data protection fee and the data protection impact assessment for the exposure ledger are both open items rather than completed work, and they are published as such on the security page alongside the certifications we do not hold. If either is a condition of your assessment, that is worth establishing now rather than after a questionnaire cycle.

Is this policy final?

No, and the notice at the top of the page says so. It is a template written from what the code actually does, and it has not been through a qualified solicitor. Our own pre-launch checklist lists the privacy policy, terms, data processing agreement and subprocessor list as documents to be reviewed with counsel before they are relied on. The factual descriptions are accurate; anything reading like a legal commitment is not yet settled.

if you need more than this

Ask for the position in writing.

If you are running a data protection assessment and need something this template cannot give you yet, say so and you will get the current position rather than a sentence from a precedent. Where the answer is that something is not done, that is what you will hear, and it is on the security page already.

45 minutes. Bring a real brief and we compile it live.