Legal

Privacy Policy

Last updated: 19 July 2026

This policy explains what data Emazi Media processes when you work with us, use our services or visit our websites, how we use it, and the choices you have.

1. Introduction / Who we are

Emazi Media is a digital advertising and marketing agency. We plan, run and measure paid advertising campaigns for our clients. This policy applies to our websites, to any account we provide, and to the advertising services we deliver.

The data controller is STARBREEZE LTD, a company incorporated in the Republic of Cyprus under registration number HE 474694, with its registered office at Andrea Araouzou 2, Stefano Plaza, 1st Floor, Office 101, Kato Polemidia, 4150 Limassol, Cyprus, trading as Emazi Media.

Where we determine the purposes and means of processing personal data, we act as a data controller; where we process on behalf of advertisers, we act as a processor under their instructions.

2. Data we collect

In the course of delivering and measuring advertising, we and our partners may process:

Device and technical identifiers (mobile advertising IDs, where permitted), IP address and coarse location;

Ad-interaction data — impressions, clicks, viewability and conversion signals;

Cookies and similar technologies on our web properties;

Account and contact details you provide as a partner or advertiser.

3. How we use data

We use data to serve and optimize campaigns, measure performance, verify traffic validity, operate and secure our systems, and comply with legal obligations. We do not sell personal data.

We process personal data on the following legal bases: your consent, where required (for example for non-essential cookies and marketing); the performance of a contract with you or steps taken at your request; compliance with our legal obligations; and our legitimate interests in operating, securing, measuring and improving our services and preventing fraud.

We do not collect special categories of data such as racial or ethnic origin, religious beliefs, political opinions or health data.

4. Advertising & measurement

We process technical and ad-interaction data to deliver campaigns, attribute results, verify that traffic is valid and protect against misuse. This processing is necessary to provide the services and to protect our clients’ budgets and the integrity of reporting.

5. Sharing with partners

We share data as necessary with supply-side platforms, exchanges, advertisers, and measurement partners (MMPs) to deliver and attribute campaigns. Each partner is responsible for its own processing under its own policy.

6. Cookies & tracking technologies

Our websites use strictly-necessary cookies and, with consent where required, analytics cookies. You can manage preferences through your browser settings or our consent controls.

7. Data retention

We retain personal data only as long as necessary for the purposes described, to meet legal and contractual obligations, and to resolve disputes.

Contract and client relationship data — up to five (5) years after our last interaction;

Marketing data — until you withdraw consent or after a period of inactivity;

Advertising and measurement data — for the period needed for delivery, attribution, billing and fraud investigation;

Other data — for the period required by applicable law.

After the applicable period the data is securely deleted or anonymised.

8. Your rights (GDPR / CCPA)

Depending on your location, you may have rights to access, correct, delete, or port your data, to object to or restrict processing, to withdraw consent at any time, and to opt out of certain data sharing. To exercise these rights, contact us using the details below; we respond within thirty (30) days.

You also have the right to lodge a complaint with a supervisory authority — in our case the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or the authority in your country of residence.

9. International transfers

Where data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses and equivalent mechanisms to protect it.

10. How we protect data

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls on a need-to-know basis, two-factor authentication for administrative access, regular backups, network and application monitoring, and staff confidentiality and security training.

Where we engage sub-processors such as cloud or analytics providers, we put data processing agreements in place requiring an equivalent level of protection.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of it, and will inform affected individuals without undue delay where the law requires.

11. Contact us

Questions about this policy, or requests to exercise your rights, can be sent to [email protected], or by post to STARBREEZE LTD, Andrea Araouzou 2, Stefano Plaza, 1st Floor, Office 101, Kato Polemidia, 4150 Limassol, Cyprus.