In summary
- Who we are: Blindspot (the TPS Engage group); your controller is the Romania entity (EEA) or the Delaware entity (everyone else).
- What we collect: account, billing, campaign, technical/usage, and limited location data, set out category-by-category in Section 4.
- Why: to provide, secure, bill, and improve the Platform, and to meet legal obligations, with the legal basis for each purpose in Section 4.
- Sharing: with our processors, suppliers, and authorities as needed. We do not sell your personal data; we use analytics and advertising tools on our site (with your consent), and you can opt out anytime via our cookie banner.
- Your choices: you can access, correct, delete, port, and object; manage cookies via Cookiebot; and opt out of marketing at any time (Sections 12–14).
- How long: only as long as needed; see the retention column in Section 4 and Section 10.
- Contact: dpo@seeblindspot.com.
Who We Are and How to Contact Us
"Blindspot" (trading name of the TPS Engage group) means TPS Engage Inc. (British Virgin Islands), TPS Engage LLC (Delaware, USA), and SC FREEDOM MASK SRL (Romania), and their affiliates. The entity responsible for your personal data (the "controller") depends on context (see Section 3).
- General privacy questions: hello@seeblindspot.com
- Data protection contact / privacy requests: dpo@seeblindspot.com
- Manage your choices: see Your Privacy Choices for opt-outs and rights requests
- Postal (EU): SC FREEDOM MASK SRL, Aleea Privighetorilor 85, Suite 68, Sector 1, Bucharest, Romania
- Postal (US/global): TPS Engage LLC, c/o Radu Bogdan Savonea, 55 Water Street, Soho Works, Brooklyn, NY 11201, USA
- EU establishment: SC FREEDOM MASK SRL (Romania) is our establishment in the European Union for GDPR purposes; a separate EU (Article 27) representative is therefore not required for EEA processing.
- UK representative: To the extent the UK GDPR requires us to designate a UK representative for UK-facing processing, we will appoint one and publish their contact details here. In the meantime, UK individuals may contact us at dpo@seeblindspot.com.
Offices: New York · Dubai · Seoul · Bucharest.
Who This Policy Covers
This Policy applies to:
- Website visitors, people who visit seeblindspot.com and its subdomains;
- Customers and their personnel, the businesses and individuals who register for and use the Blindspot platform (the "Platform"), and their authorized users; and
- Prospects and contacts, people who contact us, request a demo, or receive our marketing.
It does not apply to the personal data we process on behalf of a customer as a processor (that is governed by our DPA and the customer's own privacy notices, see Section 3), nor to third-party sites or services we link to.
Our Roles: Controller and Processor
Because Blindspot operates a platform, our role under data-protection law changes with the activity:
- We act as a controller for: our website and marketing; account registration and administration; billing and fraud/sanctions screening; our own analytics and service improvement; and our business contacts. This Policy describes that processing.
- We act as a processor (or service provider) when we process personal data on a customer's behalf to deliver the Platform (for example, data a customer uploads or instructs us to use for targeting or attribution). That processing is governed by the DPA between us and the customer; the customer is the controller and its own privacy notice applies to the individuals concerned.
- Audience and measurement data used in out-of-home planning and attribution is generally sourced from suppliers and third-party data providers who are responsible for their own lawful basis; where we handle such data we do so as described in Section 6 and, where applicable, under the DPA.
The Data We Process, Category by Category
The table below is our core data map. For each category it shows what we collect, where it comes from, why we use it, our legal basis (for EEA/UK individuals), who receives it, and how long we keep it. Not all categories apply to every person. Section 6 explains legal bases further; Section 8 describes recipients; Section 10 explains retention.
| Category | Examples | Source | Purpose | Legal basis (EEA/UK) | Recipient categories | Retention |
|---|---|---|---|---|---|---|
| Identity & contact | Name, business name, job title, email, phone, country, postal/billing address | From you/your admin | Account creation, communication, contracting, support | Contract; legitimate interests | Hosting (DoiT/AWS), CRM (Pipedrive), support, email | Account term + 12 months |
| Account & login | Username, hashed password, roles, settings, authorized users | From you/your admin | Authentication, access control, security | Contract; legitimate interests (security) | Hosting, security vendors | Account term + 12 months |
| Verification (KYC) | Identity/business-registration details, beneficial ownership, sanctions/PEP screening results | From you; screening providers | Identity verification, sanctions/AML and fraud prevention | Legal obligation; legitimate interests | Identity/sanctions-screening providers | As required by AML/sanctions law |
| Billing & payment | Billing details, transaction history, wallet/Credit balances, invoices, tax IDs (no full card numbers) | From you; Stripe; banks | Billing, payments, refunds, fraud prevention, bookkeeping | Contract; legal obligation (tax) | Stripe, Rho, Mercury, Banca Transilvania; finance systems | ~7 years (tax/accounting) |
| Campaign & transaction | Campaigns, creative metadata, Targets, bids, budgets, Deal IDs, Proof of Play, reports | From you; suppliers; measurement partners | Deliver, verify, and report on campaigns | Contract; legitimate interests | Suppliers/SSPs; measurement/attribution partners | Term + record-keeping (~7 years for billing-linked records) |
| Technical & usage | IP address, device/browser type, OS, identifiers, referring/exit URLs, clickstream, logs, timestamps, error data | Automatically (cookies/SDKs/logs) | Operate, secure, debug, and analyze the Platform/site | Legitimate interests; consent where required (cookies) | Hosting; analytics and session-analytics (Google Analytics, PostHog, LogRocket); consent tool (Cookiebot) | Logs/cookie data as stated in the Cookie Policy |
| Location | Approximate location from IP; precise location only where you enable it | Automatically; from you (if enabled) | Show nearby Screens; analytics; delivery | Legitimate interests; consent for precise location | Hosting; IP-geolocation; suppliers | Same as usage data |
| Audience & attribution | Aggregated/estimated audience and mobility data and attribution signals (generally not used to identify you) | Suppliers; data providers (Narrative, Accretive, Mastercard) | Plan campaigns; verify delivery; measure effectiveness | Legitimate interests; processor under DPA where on a customer's behalf | Measurement/attribution partners | As needed for measurement, then aggregated/de-identified |
| Communications | Support tickets, emails, chat, call notes, surveys, feedback | From you | Provide support; resolve disputes; improve | Contract; legitimate interests | Support/CRM tools | At least 24 months after case closure (longer if a dispute is active) |
| Marketing | Subscription status, engagement, preferences | From you | Send and personalize our own marketing | Consent where required; otherwise legitimate interests | CRM/email tools | Until you unsubscribe, then suppression-list only |
We do not seek special-category/sensitive data (health, race, religion, political opinions, etc.) and ask that you not provide it. Limited "sensitive personal information" under US state law (such as precise geolocation or log-in credentials) is used only to provide the service and not to infer characteristics about you. We do not sell your personal data. Our advertising- and analytics-related processing is the cookies and tools described in Sections 7 and 8 and the Cookie Policy, which run with consent where required and can be turned off via our cookie banner.
How We Collect It
- From you, when you visit the site, request a demo, register, transact, contact us, or subscribe.
- Automatically, through cookies and similar technologies, server logs, and product usage (see Cookie Policy).
- From third parties, our payment processor, identity/sanctions-screening providers, suppliers and measurement/attribution partners, analytics providers, IP-geolocation services, and, where you sign in via a third party, that provider. Where an agency or administrator manages your account, they may provide and access your account information.
Why We Use It, and Our Legal Bases (Gdpr/uk GDPR)
| Purpose | Legal basis (EEA/UK) |
|---|---|
| Provide, operate, and secure the Platform and website; authenticate users | Performance of a contract; legitimate interests (security, service operation) |
| Process payments, funding, refunds, and chargebacks; maintain financial records | Performance of a contract; legal obligation (tax/accounting) |
| Verify identity and screen for sanctions/fraud (KYC/AML) | Legal obligation; legitimate interests (fraud and sanctions prevention) |
| Deliver, verify, and report on campaigns (including Proof of Play) | Performance of a contract; legitimate interests |
| Provide support and respond to requests, complaints, and disputes | Performance of a contract; legitimate interests |
| Improve and develop products, including aggregated analytics | Legitimate interests (improving our services) |
| Send service/transactional messages | Performance of a contract; legitimate interests |
| Send marketing (where permitted) and personalize it | Consent where required; otherwise legitimate interests, subject to opt-out |
| Comply with law and enforce our terms; establish/defend legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we balance them against your rights. Where we rely on consent (e.g., certain cookies or marketing), you may withdraw it at any time without affecting prior processing. If you are in a region whose law requires a different basis, we apply the basis required there.
Cookies and Similar Technologies
We and our partners use cookies, web beacons/pixels, SDKs, and local storage to operate the site, remember preferences, measure usage, and (with consent where required) deliver and measure our own marketing. We manage these through our consent tool, Cookiebot, which lets you accept, reject, or manage non-essential cookies. Full details, categories, and controls are in our Cookie Policy.
Audience, Location, and Measurement Data (DOOH)
Programmatic digital-out-of-home advertising uses audience and location data to decide where and when to show ads on physical Screens and to estimate their effect. This section explains that processing specifically, because it is central to our service and is the kind of data individuals most want to understand.
What this data is. To plan, target, and measure campaigns, we and our measurement partners may process device identifiers and mobile advertising identifiers (MAIDs), approximate or precise device location signals, aggregated mobility and footfall patterns, demographic estimates associated with device identifiers, and points-of-interest data. This data is typically obtained from measurement and location partners (including Narrative, Accretive, and Mastercard) and from Suppliers, not collected by us directly from your device through our Platform.
How we use it. We use this data to estimate audiences near Screens, help advertisers choose Screens and dayparts, and measure outcomes, for example, whether devices exposed to a campaign were more likely to visit a location, and to produce aggregated attribution and footfall reports. We do not use it to identify you by name, and the Platform does not require, and we do not seek, data that directly identifies an individual (such as name or email) for audience targeting or measurement.
Our commitments.
- We rely on our partners' representations that the underlying data was collected with the notices and consents required by law (including, for precise location, the individual's permission).
- We work with aggregated, de-identified, or pseudonymized audience and location data wherever possible, and we do not attempt to re-identify de-identified data.
- We do not sell this data, and we do not provide raw device-level location histories to advertisers; advertiser reporting is aggregated.
- Targeting must never be used to single out or discriminate against individuals or protected groups, or to target sensitive locations in a manner prohibited by law or our Advertising Policy.
Your choices. You can limit this processing at the source: reset or disable your device's advertising identifier and location permissions in your device settings, and use industry opt-outs such as the Digital Advertising Alliance (youradchoices.com / optout.aboutads.info), the Network Advertising Initiative (optout.networkadvertising.org), and, in Europe, youronlinechoices.eu. You may also contact us at dpo@seeblindspot.com or see Your Privacy Choices for help exercising your rights.
International Data Transfers
We operate globally and may transfer personal data to countries other than your own, including the United States, the EU/EEA (including Romania), and the United Kingdom, as well as the locations of our subprocessors listed in the DPA (principally the EU and the United States). Where we transfer personal data out of the EEA, UK, or Switzerland to a country without an adequacy decision, we use appropriate safeguards, principally the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK transfers), together with any additional measures required. You may request a copy of the relevant safeguards at dpo@seeblindspot.com.
How Long We Keep It
We keep personal data only as long as necessary for the purposes in this Policy, then delete or anonymize it. Indicative periods:
| Data | Indicative retention |
|---|---|
| Account data | Duration of the account, then up to 12 months after closure (subject to legal holds) |
| Billing, tax, and transaction records (incl. Proof of Play) | As required by tax/accounting law, typically 7 years |
| KYC/sanctions records | As required by applicable AML/sanctions law |
| Support and dispute records | At least 24 months after closure, longer where a dispute or legal hold applies |
| Marketing data | Until you unsubscribe or object, then suppression-list retention only |
| Website/usage logs and cookie data | As stated in the Cookie Policy |
Where exact periods are not fixed by law, we set them by reference to the amount, nature, and sensitivity of the data, the risk of harm, the purposes, and applicable legal requirements. You may ask us about retention for a specific category at dpo@seeblindspot.com. Where we anonymize data, we may use it indefinitely.
How We Protect It
We maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the data we process, including access controls, encryption of data in transit (and at rest where appropriate), logging and monitoring, vulnerability management, secure development practices, vendor oversight, and incident response. We restrict access to personnel who need it and who are bound by confidentiality. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please protect your credentials and log out after use. We will notify you and/or regulators of a personal-data breach where required by law.
Your Privacy Rights (EEA, UK, and Similar)
Subject to applicable law, you may:
- Access a copy of your personal data;
- Rectify inaccurate or incomplete data;
- Erase data in certain circumstances;
- Restrict or object to certain processing (including direct marketing, which you can stop at any time);
- Port data you provided to us, in a structured, machine-readable format, in certain cases;
- Withdraw consent where we rely on it; and
- Lodge a complaint with your data-protection authority (in Romania, the ANSPDCP; you may also contact your local authority). We ask that you contact us first so we can help.
To exercise rights, email dpo@seeblindspot.com. We may verify your identity. We will respond within the timeframes required by law (generally one month under the GDPR, extendable for complex requests). Exercising your rights is free unless a request is manifestly unfounded or excessive.
US State Privacy Rights (California and Others)
If you are a resident of California or another US state with a comprehensive privacy law (e.g., Virginia, Colorado, Connecticut, Texas, and others), you may have the rights below, subject to that law. Note that some of these laws have exemptions for business-to-business and employee contact data, which may apply to much of our customer processing.
- Notice at collection. The categories of personal information we collect, and the purposes, are described in Sections 4 and 6.
- Right to know/access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
- Right to delete personal information, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing" of personal information and of certain targeted advertising. We do not sell your personal information. Our use of advertising and analytics cookies on our website (see Section 8) may be considered “sharing” for cross-context behavioral advertising under some state laws; you can opt out at any time through our cookie banner ("Reject all" / "Cookie settings") and we honor the Global Privacy Control signal for this purpose.
- Right to limit the use of sensitive personal information; we use it only as needed to provide the service.
- Right to non-discrimination for exercising your rights, and, where applicable, to appeal a decision on your request.
To exercise these rights, email dpo@seeblindspot.com or use Your Privacy Choices (see that page for all available controls). You may use an authorized agent (with proof of authorization). We will verify your request and respond within the timeframe your state law requires, generally within 45 days, extendable once where permitted. If we decline a request, you may appeal by replying to our decision; we will respond to appeals within the statutory period (generally 45–60 days depending on the state). California's "Shine the Light" law: we do not disclose personal information to third parties for their own direct marketing without your consent. State-specific notes: Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and similar laws give rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising, sale, and certain profiling, and to appeal; Colorado and Connecticut require honoring a recognized universal opt-out (we honor Global Privacy Control); Nevada residents may opt out of certain sales of covered information.
Marketing Choices
You can opt out of marketing at any time using the unsubscribe link in our emails or by emailing hello@seeblindspot.com; it may take a few days to take effect. You cannot opt out of transactional/service messages (e.g., billing or security notices) while you hold an account. On our marketing website we use business website-visitor identification and sales-intelligence tools (Leadfeeder and Apollo) to understand which businesses engage with us and to support our own sales and marketing, subject to consent where required; you can opt out via our cookie banner. We do not sell your personal data, and we do not share it for unrelated third parties' own marketing.
Automated Decision-making and AI
Our Platform includes automated and AI-assisted tools (such as the planning assistant "Blinky") and automated auction/pacing logic. These support your decisions and our operations but do not make decisions producing legal or similarly significant effects about individuals by solely automated means. Content-approval, pricing, and enforcement decisions involve meaningful human review, and you can ask us to explain or reconsider such a decision through the appeal route in the Support & Disputes Policy. If our use of solely automated decision-making ever changes, we will provide the information and safeguards the law requires.
Children
The website and Platform are intended for adults and for business use. They are not directed to children, and we do not knowingly collect personal data from anyone under 18 (or under 13 for purposes of the US Children's Online Privacy Protection Act). If you believe a child has provided us personal data, contact dpo@seeblindspot.com and we will delete it.
Third-party Sites and Destinations
Our site and ads may link to third-party sites and destinations we do not control. This Policy does not cover them; review their privacy policies. Advertisers are responsible for the privacy practices of any destination (including QR-code destinations) their content directs viewers to.
Changes to This Policy
We may update this Policy. We will post the updated version with a new "Last Updated" date and, for material changes, provide prominent notice (and, for account holders, email notice) reasonably in advance. We will keep prior versions available on request. Please review periodically.
How to Contact Us or Complain
Privacy questions and requests: dpo@seeblindspot.com · General: hello@seeblindspot.com · Post: Aleea Privighetorilor 85, Suite 68, Sector 1, Bucharest, Romania. You may also contact your data-protection or consumer-protection authority. We cooperate with regulators to resolve complaints we cannot resolve with you directly.
Version History
| Version | Date | Summary |
|---|---|---|
| 2.5 | 14 June 2026 | Current published version. Prior internal counsel-review drafts are superseded. |