← Back to the site

Privacy Policy

This site collects almost nothing: one contact form, the server logs our host keeps, and analytics that run only if you ask for them. What follows is the complete account of it.

1. Controller

Shigo Ad Server Solutions LTD.
156 Begin Road, 6492108 Tel Aviv, Israel
Represented by: Shilo Asi, Chief Executive Officer
Israel Registrar of Companies · Company No. 517212650
Email: info@trusted-media-alliance.com

This policy covers the website trusted-media-alliance.com only. The member companies of the alliance (TRUSTX, madSense, Shigotech) operate their own websites under their own privacy policies.

2. Representative in the Union and the United Kingdom (Art. 27 GDPR)

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/15137890493

3. What we collect, and why

3.1 Contact form

When you submit the contact form we process what you type into it: your name, work email, company, the audience category you select, and your message. The form also records which call-to-action you clicked — a hidden source field holding one of six values (general, trustx, madsense, shigotech, dmexco-meeting, dmexco-rsvp) — so that the inquiry reaches the right alliance member without you having to explain where on the site you came from. We use all of this to answer your inquiry and route it. Where you used the RSVP button for our DMEXCO booth party, we also use your name, email and company to manage the guest list for that event and to contact you about it. Legal basis for that use: Art. 6(1)(b) GDPR — the invitation you asked for is the service being provided.

We do not store your IP address or your browser's user-agent. Neither is written to the submission record and neither is included in the notification email we receive. The anti-abuse check (Cloudflare Turnstile) sees your IP address and basic browser signals when the page carrying the contact form loads and again when you press submit, uses them to judge whether the submission is automated, and discards them; it is not passed on to us and not retained.

Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract, at your request) and Art. 6(1)(f) GDPR (our legitimate interest in preventing automated abuse of the form).

Is it obligatory? No. Providing your name, work email, company and audience category is neither a statutory nor a contractual requirement. It is simply what we need in order to answer you and send the inquiry to the right member — without it we cannot respond. The message field is optional.

Retention: inquiries are kept for as long as it takes to handle them, and in no case longer than 24 months in the website database. That cap is enforced, not merely intended: a scheduled job runs every day and deletes leads older than 24 months. Separately, the notification email carrying your inquiry is delivered to the alliance mailbox; that copy sits in ordinary business email and is retained by the receiving member under its own mail-retention rules rather than by the daily job. If an inquiry becomes an actual business relationship, the details you gave us pass into the records of the member company you work with, where they are held by that company as its own controller, under its own privacy policy and its own retention rules including statutory commercial and tax retention periods. From that point they are no longer held under this policy — and the copy stored here is still deleted at 24 months.

3.2 Server logs and security

Our hosting provider processes technical connection data (IP address, requested URL, timestamp, user-agent) to deliver the website and defend it against attacks. Legal basis: Art. 6(1)(f) GDPR.

3.3 Cookies and analytics (opt-in only)

This website sets no advertising cookies and runs no cross-site tracking. Two things measure it. Our hosting platform counts page views without cookies (Cloudflare Web Analytics — see §4; nothing is stored on your device, so it needs no consent). Separately, and only with your explicit consent given via the cookie banner, we use Google Analytics 4 to understand how the site is used. Google Analytics sets cookies (_ga and similar) only after you choose “Allow analytics”. Legal basis: Art. 6(1)(a) GDPR (consent).

Google's Enhanced Measurement is switched on, so if you consent GA4 records more than pageviews. It also measures how far down a page you scroll and clicks on links that lead off this site, together with the category of device, browser and operating system you are using. Google's data-retention setting for this property is 14 months; event-level data expires after that.

The banner and the record of what you chose are operated for us by Cookiebot (Usercentrics A/S) — see §4. Your choice is stored in your browser and, so that we can demonstrate it if we are ever asked to, also logged on Cookiebot's servers together with the time you made it, the version of the banner text you were shown and an anonymised key. That log contains no directly identifying information about you. We ask again after 12 months, and sooner if the terms change.

If you decline, no analytics run and no analytics cookies are set — the site works exactly the same. You can withdraw or change your choice at any time via the “Cookie settings” link in the footer; on withdrawal we stop measurement and delete the analytics cookies we can reach from your browser. Withdrawal works forwards only: data already collected before you withdraw remains with Google under its own retention settings, and we cannot recall it.

Beyond that, the only technical mechanism in use is Cloudflare Turnstile (see below), which is strictly necessary to protect the contact form from bots and requires no consent.

4. Processors and third parties

Where a transfer relies on a safeguard, a copy can be requested at info@trusted-media-alliance.com.

We do not sell personal data, and we do not share it with third parties beyond the processors and recipients listed above.

5. Your rights

Under the GDPR you can ask us to:

Where processing rests on your consent — which here means analytics, and nothing else — you may withdraw that consent at any time with effect for the future.

To exercise any of these rights, email info@trusted-media-alliance.com. We answer within one month of receiving the request. You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence or place of work.

6. Automated decision-making

There is no automated decision-making or profiling within the meaning of Art. 22 GDPR on this website. Nothing you send us is scored to reach a decision about you.

Submissions are screened automatically for signs of automated abuse — a hidden field that only a bot would fill in, how long the form took to complete, and the result of the Cloudflare Turnstile check. That screening decides only whether a submission reaches us, and produces no legal or similarly significant effect for you.

7. Changes to this policy

We will update this policy as the website or the legal situation changes. The current version is always available at trusted-media-alliance.com/privacy.