Nothing non-essential runs until you choose.
Written from the code rather than from a precedent, and marked as unfinished where it is.
This is a template, pending review by counsel
AdBuyMCP is in design-partner phase and its legal documents have not yet been through a qualified solicitor. This page is a plain-English, UK-oriented starting point written from what the code actually does, and it is published in that state on purpose: our own pre-launch checklist lists the privacy policy, terms, data processing agreement and subprocessor list as templates to be reviewed before they are relied on, and presenting one of them as settled policy would be a misrepresentation on the page least able to afford one.
Read the factual descriptions here as accurate — they were written from the code, and the security page lists this same document as an open item. Read anything that reads like a legal commitment as not yet settled. If you are about to rely on it for a data protection assessment, ask us for the current position and you will get it in writing.
Who we are, and who to write to
AdBuyMCP is a product rather than a company, which matters here: the controller is the company behind it, and that company is on the public register.
Tenhaw LTD is the data controller for this website and for the AdBuyMCP product, a company registered in England and Wales, number 12735685, operating from London. Where a design partner runs campaigns on the platform, we act as their processor for the campaign data they put into it, under the agreement covering that engagement, and they remain the controller of it.
Privacy questions, data subject requests and security questionnaires all go to hello@adbuymcp.com. There is no separate privacy inbox yet, and publishing an address that nobody monitors would be worse than publishing the one that is read. You can also complain directly to the Information Commissioner’s Office at ico.org.uk, with or without raising it with us first.
One thing worth saying early, because it changes how the rest of this page should be read: registration for the ICO’s data protection fee and the data protection impact assessment for the exposure ledger are both open items rather than completed work. They are listed as such on the security page, beside the certifications we do not hold.
8 places a visit here causes data to exist
Including the ones a policy usually leaves out. Each row says what happens, when it happens, and which lawful basis it runs on. Where something is outside our control, it says that too rather than being quietly dropped from the list.
A cookieless page counter
Runs for everyonePlausible Analytics, loaded on every page. It sets no cookie, stores nothing on your device and keeps no IP address, so it cannot follow you to another site and there is no individual record of you to retain. What it keeps is aggregate: the page, the referrer, the country, the device type and the browser, plus outbound link clicks, file downloads and a small fixed vocabulary of named events — a call-to-action clicked, the booking calendar coming into view, a question asked of the on-page assistant. It runs for everyone rather than behind the consent gate because there is nothing stored on your device for the storage-and-access rule to bite on, and it is disclosed here rather than left to the exemption.
Legitimate interests: understanding which pages of our own site are useful.
Google Analytics
Only if you acceptNot loaded at all until the analytics category is granted. This is deliberately not the common pattern of loading the tag and then suppressing it with consent signals, because a suppressed tag still sends cookieless pings and not loading is both the defensible position and the simpler one to evidence. Once granted it sets its own cookies and records page views, referrer and which calls-to-action were used. Nothing in the configuration attempts to identify you or the company you work for. Decline, and the script never reaches your browser.
Consent, which you give or refuse in the panel and can change at any time.
Your consent decision
Runs for everyoneKept in your browser's local storage under the key adbuymcp_consent, not in a cookie and not on any server here. The stored record holds the category-set version, whether analytics was allowed, the timestamp of the decision, and whether it came from a browser privacy signal rather than a click. It never leaves your device. Clearing your site data removes it and you will be asked again.
Strictly necessary: it is the record of your own choice, and without it we would have to ask on every page.
The on-page assistant
Only when you use itWhat you type is sent to Anthropic's API to produce the answer, along with up to the last ten messages of that conversation, each capped at a thousand characters. It is not written to a database here, because this website has no database. Your IP address is held in memory for at most sixty seconds so the endpoint can be rate-limited, and is not logged or persisted. Do not type anything into it you would not put in an email.
Legitimate interests, and your own request: you asked it a question.
The booking calendar
Only when you use itA Cal.com embed, and none of Cal's code is requested until you scroll close to it, so on a page whose calendar you never reach nothing of theirs loads at all. What you enter to book a working session — your name, your email, whatever you write in the notes — goes to Cal.com and to us as a booking. The embed is a cross-origin frame, so what happens inside it is governed by Cal.com's own privacy terms as well as this page.
Steps taken at your request before entering a contract.
Email and enquiries
Only when you use itAnything you send to our address, kept for as long as it takes to deal with it and to keep a record of what was agreed. There is no separate privacy inbox yet; publishing an address nobody monitors would be worse than publishing the one that is read.
Legitimate interests, and steps taken at your request before entering a contract.
Fonts and page assets
Runs for everyoneServed from this origin. The three typefaces are downloaded at build time and self-hosted rather than fetched from a font network, so loading a page here does not tell a font provider that you visited. This is the kind of third-party request a privacy-conscious reader checks for, which is why it is stated rather than assumed.
Strictly necessary: the page has to render.
Web server request logs
Not ours to controlWhichever commercial platform serves these pages keeps ordinary request logs, which include IP addresses, under its own retention and for its own security and operations. Naming that provider and stating its retention precisely is one of the things this document has to do before it stops being a template, and it is listed here rather than quietly omitted.
Legitimate interests: keeping the site available and secure.
Two claims that appear in our own legal template are deliberately not repeated here. It says IP addresses are truncated and hashed on ingest, and no code in the platform does that. It also states a flat six-year retention on billing records; the honest version is that financial records are kept for as long as UK tax and company law requires, which is a question for counsel rather than for a website.
How the choice actually works
A consent banner is the one privacy control most visitors ever interact with, and most of them are built to be dismissed rather than to be used. This one is described here in the same detail it is implemented in, because the implementation is the claim.
Two categories, one of them optional
Strictly necessary, which is always on and has nothing to opt out of, and Analytics, which is off until you say otherwise. There is no third category, no advertising category and no cross-site tracking anywhere on this site.
Rejecting is exactly as easy as accepting
Accept all and Reject all are the same size, the same weight and the same prominence, side by side. Making rejection harder than acceptance is the most commonly cited dark pattern in ICO enforcement, and anyone evaluating us on data protection would be right to notice.
Nothing is loaded and then suppressed
The gated tools are not mounted at all until the category is granted. A tag that loads and then sends cookieless pings under a consent signal is a harder position to defend and a harder one to evidence.
Browser privacy signals are honoured without a prompt
Global Privacy Control and Do Not Track are treated as a rejection and the banner does not appear. GPC is not yet binding in the UK; honouring it costs nothing and refusing to would be indefensible if anyone checked. The footer link still lets you opt in deliberately afterwards.
A change to the categories re-asks everyone
The stored decision carries the category-set version, currently 3. If the categories or the processors behind them change, the version stops matching, the old record is treated as absent and you are asked again rather than being carried forward on an answer you gave to a different question.
A control that controls nothing is removed, not kept as furniture
There used to be a third category for session recording, which existed to gate one tool. That tool was removed from the site, so the toggle gated nothing, and it was deleted rather than left in place — a consent control that does nothing is a misrepresentation to the person reading it. Nothing on this site records a session today.
Your decision is stored in your own browser under the local storage key adbuymcp_consent, at category-set version 3, holding the version, whether analytics was allowed, when you decided, and whether the decision came from a browser privacy signal rather than from a click. It is never transmitted to a server. If storage is unavailable — a private window with site data blocked — the decision simply is not persisted, and the panel asks again rather than assuming a yes.
What the product would process
Everything above is about visiting this site. This is about running a campaign on the platform, which almost nobody is doing yet: 0 of the 25 connectors have executed a buy, and there is no multi-tenant hosted service, so a deployment today is one stood up for a single design partner with its own agreement behind it. The sandbox everyone can drive produces deterministic synthetic data and involves no personal data at all.
The full technical account- Campaign and plan data
- Personas, compiled targeting specifications, plans, creatives, delivery rows and statements, scoped to one advertiser workspace. A persona describes a market — intent topics, firmographics, geography, interests — rather than a person.
- Exposure and outcome events
- Ad exposures keyed on an opaque household key, a hashed mobile advertising id, a EUID or a postcode sector, plus the outcomes a customer imports or that arrive through their own analytics. The ledger that holds them never resolves a key back to a person or across key spaces.
- Hashed advertising ids, for at most 90 days
- After the window the hashed id is persistently stripped from the exposure event, and the event is re-graded to a coarser key rather than deleted, so the history survives without the identifier. It is enforced in one module, which is also the only module in the platform permitted to perform an identity join.
- Vendor credentials
- Encrypted at rest with AES-256-GCM, never logged and never returned by an API read. Deleted when the connection is removed.
- A lawful-basis manifest on every compiled plan
- Each segment's provider and the basis it relies on — consent-chained, legitimate interest, or outside UK GDPR scope, which is where cinema and DOOH delivery sit — recorded per segment rather than asserted once, with the warnings raised while compiling still attached. It is evidence a DPO can read; it is not a compliance guarantee, and the conditions it attaches are ones the advertiser still owes.
Five bases, and what each one is doing here
A policy that names its bases in a single sentence is a policy nobody can check. These are separated because they behave differently: consent can be withdrawn, legitimate interests can be objected to, and a legal obligation survives both.
- Consent
- The optional analytics category on this website, and — inside the product — device-level advertising identifiers, where the segment provider asserts a consent chain. Consent is the basis that can be withdrawn, and withdrawing it here means reopening the panel from the cookie settings link in the footer and choosing again.
- Legitimate interests
- The cookieless page counter, keeping this site available and secure, answering enquiries, and B2B marketing of our own service. Inside the product, business-to-business signals that rely on a legitimate interests assessment, which the manifest names as a condition the advertiser holds rather than as something we have completed for them.
- Contract, and steps before one
- Booking and holding a working session, corresponding about an engagement, and — for a design partner — running the platform itself.
- Legal obligation
- Records we are required to keep, principally financial ones. This page states no fixed retention figure for them, because the correct figure is a question for counsel rather than for a marketing site.
- Outside scope
- Cinema and digital out-of-home delivery involve no personal data at all — venue catchments, aggregate movement data, geographic polygons — and the compiler records that rather than leaving it to be inferred.
What is kept, for how long, and what happens at the end
The third column is the one usually missing. “Ninety days” and “ninety days, then persistently stripped and the event re-graded to a coarser key” are different commitments, and only one of them can be checked.
| What | How long | What happens then |
|---|---|---|
| Your consent decision | How longUntil you clear it | What happens thenIt lives in your browser and nowhere else. Clearing site data removes it, and a change to the category set makes it stop counting, so you are asked again. |
| Cookieless page analytics | How longAggregate only | What happens thenNo individual-level record is created, so there is nothing about you to keep or to delete. |
| Google Analytics, if you accepted it | How longGoogle's own retention | What happens thenHeld by Google under the retention setting on the property. If you declined, no record was created in the first place. |
| Assistant conversations | How longNot stored here | What happens thenThere is no database on this website. The API call is subject to Anthropic's own terms; the rate-limit record of your IP address is held in memory for at most sixty seconds and then gone. |
| Bookings and correspondence | How longAs long as it is needed | What happens thenHeld to arrange the meeting, to follow it up, and to keep a record of what was discussed and agreed. Deleted on request unless we are required to keep it. |
| Hashed advertising ids in the product | How long90 days maximum | What happens thenPersistently stripped from the exposure event, which is re-graded to a coarser key rather than deleted. |
| Campaign configuration and delivery data | How longLife of the workspace | What happens thenDeleted on request, and returned or deleted on the end of an engagement under the agreement covering it. |
| Vendor credentials | How longUntil the connection is removed | What happens thenDeleted. They are encrypted at rest for as long as they exist and are never returned by an API read. |
| Financial records | How longAs UK law requires | What happens thenKept for as long as tax and company law requires. This page states no number, because the number is a question for counsel. |
8 rights, and one email address
Under UK GDPR you have the rights below. Write to us and we will respond within one month; if a request is complex enough to need longer, we will tell you that inside the month rather than at the end of it. Exercising any of them costs nothing and changes nothing about how you are treated.
- Access
- A copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification
- Correction of anything inaccurate, and completion of anything incomplete.
- Erasure
- Deletion, where we have no overriding reason or legal obligation to keep it.
- Restriction
- A pause on processing while a dispute about accuracy or basis is resolved.
- Portability
- The data you gave us, in a structured, commonly used, machine-readable form.
- Objection
- An objection to anything we do on the basis of legitimate interests, including marketing our own service to you.
- Withdrawal of consent
- For anything relying on consent, at any time and as easily as it was given. On this site that is the cookie settings link in the footer.
- Complaint
- To the Information Commissioner's Office at ico.org.uk, whether or not you raise it with us first. We would rather you raised it with us, but that is a preference and not a condition.
Where we process campaign data for a design partner, they are the controller and the request belongs with them. Send it to us anyway if you do not know who they are, and we will route it and help them answer it.
Nothing here makes an automated decision producing a legal or similarly significant effect about an individual. The AI layer drafts and plans media; a named human authorises money, and consequential actions fail closed unless a human approved those exact bytes.
The next version of this page will be the reviewed one.
Changes are posted here. If the consent categories or the processors behind them change, the stored version number stops matching and everyone is asked again rather than being carried forward on an answer given to a different question. Until counsel has been through it, treat the descriptions as accurate and the commitments as provisional, and ask if you need the current position in writing.
What people actually ask about this
Six questions, including the one a privacy policy never answers about itself.
Do you set cookies?
Not before you choose. The page counter that runs for everyone is cookieless and stores nothing on your device. Your consent decision is kept in local storage under the key adbuymcp_consent rather than in a cookie. Google Analytics sets its own cookies, and it is not loaded at all unless you accept the analytics category, so declining means no analytics cookie is ever written.
How do I change or withdraw my consent?
The cookie settings link in the footer of every page reopens the panel. A new decision replaces the stored one immediately and the gated tools stop loading from the next page view. Clearing your browser's site data removes the record entirely, in which case you will simply be asked again. A browser sending Global Privacy Control or Do Not Track is treated as a rejection without being prompted at all.
What happens to what I type into the assistant on these pages?
It is sent to Anthropic's API to produce the answer, together with up to the last ten messages of that conversation, each capped at a thousand characters. It is not written to a database, because this website does not have one. Your IP address is held in memory for at most sixty seconds so the endpoint can be rate-limited, and is not logged. Treat it like an email rather than like a private note.
How long do you keep advertising identifiers?
At most 90 days. After the window, the hashed mobile advertising id is persistently stripped from the exposure event and the event is re-graded to a coarser key — a household key or a postcode sector — rather than being deleted, so the delivery history survives without the identifier. The rule is enforced in the one module permitted to perform identity joins, rather than being a policy applied by hand.
Are you registered with the ICO, and have you completed a DPIA?
Neither. Registration for the data protection fee and the data protection impact assessment for the exposure ledger are both open items rather than completed work, and they are published as such on the security page alongside the certifications we do not hold. If either is a condition of your assessment, that is worth establishing now rather than after a questionnaire cycle.
Is this policy final?
No, and the notice at the top of the page says so. It is a template written from what the code actually does, and it has not been through a qualified solicitor. Our own pre-launch checklist lists the privacy policy, terms, data processing agreement and subprocessor list as documents to be reviewed with counsel before they are relied on. The factual descriptions are accurate; anything reading like a legal commitment is not yet settled.
Ask for the position in writing.
If you are running a data protection assessment and need something this template cannot give you yet, say so and you will get the current position rather than a sentence from a precedent. Where the answer is that something is not done, that is what you will hear, and it is on the security page already.
45 minutes. Bring a real brief and we compile it live.