cocomob.

Privacy Policy

Last updated: August 1, 2026

1. Introduction and Controller Identity

Cocomob Ltd. ("Cocomob", "we", "our", or "us") is a global performance marketing company that provides managed digital advertising services, affiliate and cost-per-sale programme management, programmatic media buying, and growth consultancy to advertisers and brand partners worldwide.

This Privacy Policy explains how we collect, use, disclose, transfer, and protect personal data in connection with our website located at cocomob.com (the "Site") and in the course of delivering our services to clients. We are committed to handling personal data responsibly and in compliance with applicable data protection and privacy laws.

For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR, Cocomob Ltd. is the data controller. Our registered address and primary contact for privacy matters is:

Cocomob Ltd.
Email: hello@cocomob.com

If you have questions about this Policy or wish to exercise your privacy rights, please contact us at the address above. We aim to respond to all legitimate requests within 30 days.

2. Scope and Applicable Law

This Policy applies to personal data collected through the Site, through our marketing and business development activities, and through the operation of client campaigns where we act as a data processor or sub-processor on behalf of our advertising clients.

Depending on your location and the nature of our interaction, one or more of the following laws may apply to our processing of your personal data:

  • EU/EEA: Regulation (EU) 2016/679 (GDPR) and applicable national implementing legislation.
  • United Kingdom: The UK GDPR (retained GDPR as amended by the Data Protection Act 2018) and the Privacy and Electronic Communications Regulations 2003 (PECR).
  • California, USA: The California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA).
  • Brazil: Lei Geral de Proteção de Dados Pessoais (LGPD) — Law No. 13,709/2018.
  • Canada: The Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation.
  • Thailand: The Personal Data Protection Act B.E. 2562 (2019) (PDPA).
  • Singapore: The Personal Data Protection Act 2012 (PDPA) as amended by the Personal Data Protection (Amendment) Act 2020.
  • Other applicable data protection, privacy, and electronic communications laws in jurisdictions where we operate or where data subjects are located.

Where we act as a data processor on behalf of an advertiser client, the client's privacy policy and our Data Processing Agreement with that client govern our processing of end-user personal data. This Policy primarily addresses our activities as a data controller.

3. Information We Collect

(a) Information You Provide Directly

When you interact with our Site or contact us for business purposes, you may provide:

  • Contact details, including your full name, business email address, telephone number, and job title.
  • Company information, including business name, industry sector, website URL, and approximate advertising budget.
  • Enquiry content submitted through our contact forms, including descriptions of your marketing objectives, campaign briefs, or support requests.
  • Communications exchanged via email, phone, video conference, or in-person meetings in connection with our services.
  • Financial and billing information provided in connection with service agreements (processed through our secure payment infrastructure).

(b) Information Collected Automatically

When you visit the Site, our servers and third-party analytics tools automatically collect certain technical and behavioural information, including:

  • IP address and approximate geolocation derived therefrom.
  • Browser type, version, and language preferences.
  • Device type, operating system, and screen resolution.
  • Referral source, pages visited, time spent on each page, and exit pages.
  • Clickstream data and interactions with page elements.
  • Cookie identifiers and similar tracking technology data (see our Cookie Policy for full details).
  • Date and time of access.

(c) Information from Third Parties

In the course of managing advertising campaigns on behalf of our advertiser clients, we may receive or access personal data from third-party sources, including:

  • Advertising platforms such as Google Ads, Meta Ads (Facebook/Instagram), LinkedIn Campaign Manager, TikTok for Business, and programmatic DSPs — including impression, click, and conversion event data associated with pseudonymous identifiers.
  • Data management platforms (DMPs) and customer data platforms (CDPs) operated by or on behalf of clients, from which we receive audience segments or customer match lists.
  • Analytics providers, including Google Analytics 4 and third-party attribution tools, that supply aggregated or pseudonymised performance data.
  • Business data enrichment providers used to verify or supplement information about prospective clients (such as company size, industry classification, or decision-maker contacts) for our own sales and marketing activities.
  • Referral partners who introduce clients to Cocomob and provide basic contact information for follow-up.

Where we receive personal data from third parties in our capacity as a data processor acting on behalf of an advertiser, we process that data solely in accordance with the applicable Data Processing Agreement and our client's documented instructions.

4. Legal Basis for Processing

For personal data subject to the GDPR or UK GDPR, we rely on the following legal bases under Article 6:

  • Consent (Art. 6(1)(a)): Where you have given freely, specific, informed, and unambiguous consent — for example, when you subscribe to our newsletter, agree to non-essential cookies, or opt in to our marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Contract Performance (Art. 6(1)(b)): Where processing is necessary to perform a contract to which you or your organisation is a party, or to take pre-contractual steps at your request — for example, preparing proposals, onboarding, invoicing, and service delivery.
  • Legal Obligation (Art. 6(1)(c)): Where processing is required to comply with applicable legal obligations, including tax and accounting laws, anti-money laundering requirements, court orders, and responses to lawful demands from public authorities.
  • Legitimate Interests (Art. 6(1)(f)): Where processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include: operating and improving the Site; protecting our business from fraud and security threats; conducting direct marketing to existing business contacts and prospective clients in the B2B context; managing and improving our advertising services; and network and information security.

Where we rely on legitimate interests, you have the right to object to such processing (see Section 9 below). For special categories of personal data (as defined in GDPR Art. 9), we rely on your explicit consent or another applicable condition under Art. 9(2). We do not intentionally collect special category data through the Site.

5. How We Use Your Information

We use the personal data we collect for the following specific purposes:

  • Responding to enquiries and providing services: Processing contact form submissions, responding to questions, preparing proposals, and onboarding new clients onto our campaign management platform.
  • Campaign management and performance marketing: Setting up, optimising, and reporting on paid digital advertising campaigns across search, social, programmatic, and affiliate channels on behalf of advertiser clients.
  • Analytics and product improvement: Analysing Site usage patterns, measuring content engagement, identifying technical errors, and improving the design, functionality, and content of our Site and service offerings.
  • Marketing and business development: Sending commercial communications about our services, case studies, industry insights, and events to business contacts who have either consented or with whom we have a legitimate business relationship. You can opt out at any time (see Section 13).
  • Contractual and billing administration: Issuing invoices, processing payments, managing account records, and enforcing our service agreements.
  • Legal and compliance obligations: Maintaining records required by tax, accounting, anti-money laundering, or other applicable laws; cooperating with regulatory inquiries; and asserting or defending legal claims.
  • Security and fraud prevention: Monitoring for and investigating suspicious activity, protecting the integrity of our systems and client accounts, and preventing unauthorised access or misuse of our services.
  • Aggregated insights: Compiling anonymised or aggregated performance benchmarks, industry trend reports, and analytical outputs that do not identify any individual and that we may use or share for thought leadership purposes.

6. Sharing of Information

We do not sell personal data. We may share personal data in the following circumstances:

Service Providers

We engage trusted third-party vendors and service providers who process personal data on our behalf under contractual data processing agreements. These include: cloud hosting and infrastructure providers; CRM and marketing automation platforms; email delivery services; analytics and tracking tools; cybersecurity and fraud detection services; legal, accounting, and audit firms; and payment processors.

Advertising Platforms

In our role as a managed service provider, we access and operate within advertising platforms such as Google (including Google Ads, Display & Video 360, and Google Analytics), Meta (Facebook/Instagram), LinkedIn, TikTok, Amazon Advertising, and various programmatic DSPs and SSPs. These platforms act as independent data controllers or as data processors under their respective platform terms. We share campaign configuration data, audience lists, and conversion signals with these platforms as necessary to execute client campaigns. Their use of data is governed by their own privacy policies and terms.

Professional Advisors and Legal Requirements

We may disclose personal data to lawyers, auditors, insurers, or other professional advisors where necessary for the provision of their services to us, subject to appropriate confidentiality obligations. We may also disclose personal data when required by applicable law, regulation, legal process, or enforceable governmental request, or where necessary to protect our rights, property, or safety or those of our clients or others.

Business Transfers

In the event of a merger, acquisition, asset sale, restructuring, or other corporate transaction involving Cocomob, personal data held by us may be transferred to the acquirer or successor entity. We will ensure that any such transfer is subject to appropriate confidentiality protections and that affected individuals are notified as required by applicable law.

7. International Data Transfers

Cocomob operates globally and may transfer personal data across national borders in the course of our business operations. When we transfer personal data from the EU/EEA, the United Kingdom, or other jurisdictions with transfer restrictions to countries that do not provide an equivalent level of data protection, we implement appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission (including the 2021 module sets for controller-to-controller and controller-to-processor transfers), and the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers from the UK.
  • Adequacy decisions issued by the European Commission or the UK Secretary of State recognising that a third country provides an essentially equivalent level of data protection.
  • Transfer Impact Assessments (TIAs) conducted where required to evaluate the legal environment in the destination country and identify any supplementary technical or contractual measures needed to ensure effective protection.
  • Binding Corporate Rules (BCRs), where applicable within corporate group transfers.

You may request further information about the specific safeguards applicable to international transfers of your personal data by contacting us at hello@cocomob.com.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Our retention periods are as follows:

Data CategoryRetention PeriodBasis
Client contact and account recordsDuration of contract + 7 yearsLegal/tax obligation
Financial and billing records7 years from transaction dateTax and accounting law
Marketing contact data (newsletter/B2B)3 years from last engagement, or until opt-outLegitimate interests / consent
Website analytics data (GA4)14 months (rolling, per GA4 settings)Legitimate interests
Server and access logs90 daysSecurity / legitimate interests
Contact form enquiries (non-converted)12 monthsLegitimate interests
Campaign performance data (aggregated)5 yearsContractual / legitimate interests
Employee and contractor recordsDuration of engagement + 6 yearsLegal obligation

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised. We may retain data for longer periods if required by applicable law or for the establishment, exercise, or defence of legal claims.

9. Your Privacy Rights

Depending on your location and applicable law, you may have the following rights regarding your personal data. We honour these rights regardless of where you are located, to the extent technically and legally feasible.

RightApplicable Law(s)Description
Right of AccessGDPR, UK GDPR, CCPA, LGPD, PIPEDA, PDPARequest a copy of the personal data we hold about you, along with information about how it is used and shared.
Right to RectificationGDPR, UK GDPR, LGPD, PDPARequest correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")GDPR, UK GDPR, CCPA (deletion), LGPD, PDPARequest deletion of your personal data, subject to applicable legal retention requirements and other lawful grounds for continued processing.
Right to Data PortabilityGDPR, UK GDPR, LGPDReceive a structured, commonly used, machine-readable copy of personal data you have provided to us, and request that we transmit it to another controller where technically feasible.
Right to Restrict ProcessingGDPR, UK GDPRRequest that we limit our processing of your personal data in certain circumstances, such as while accuracy is contested or an objection is being assessed.
Right to ObjectGDPR, UK GDPR, LGPDObject at any time to processing based on legitimate interests, including profiling for direct marketing purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw ConsentGDPR, UK GDPR, LGPD, PDPA, PIPEDAWithdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing.
Right to Know / Right to Opt Out of Sale or SharingCCPA/CPRACalifornia residents may request disclosure of personal information collected, disclosed, or "shared" (for cross-context behavioural advertising), and opt out of the sale or sharing of their personal information.
Right to Non-DiscriminationCCPA/CPRAYou will not receive discriminatory treatment for exercising your CCPA rights.
Right to Correct (CPRA)CPRACalifornia residents may request correction of inaccurate personal information.
Right of Access and CorrectionPIPEDA (Canada)Individuals may request access to their personal information and challenge its accuracy.

To exercise any of these rights, please submit a request to hello@cocomob.com with the subject line "Privacy Rights Request." We will verify your identity before processing your request and aim to respond within 30 days (or such shorter period as required by applicable law). We do not charge a fee for reasonable requests. If you are dissatisfied with our response, you have the right to lodge a complaint with your applicable supervisory authority (e.g., the ICO in the UK, your EU Member State's Data Protection Authority, the CNIL in France, or equivalent).

10. Security Measures

We implement a comprehensive set of technical and organisational security measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include: TLS/SSL encryption for all data in transit; AES-256 encryption for sensitive data at rest; role-based access controls and the principle of least privilege; multi-factor authentication for all system access; regular security assessments and penetration testing; data loss prevention (DLP) controls; vendor security reviews; incident response and breach notification procedures; and staff training on data protection and information security.

No method of electronic transmission or storage is completely secure. While we take commercially reasonable precautions, we cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you and applicable supervisory authorities as required by law.

11. Children's Privacy

Our Site and services are directed exclusively at businesses and business professionals. We do not knowingly collect personal data from individuals under the age of 16 (or under 13 in jurisdictions where that is the applicable age threshold, including the United States). If we become aware that we have inadvertently collected personal data from a minor, we will promptly delete it. If you believe we have collected personal data from a child, please contact us at hello@cocomob.com.

12. Third-Party Links

Our Site may contain links to third-party websites, social media platforms, advertising platforms, and other online resources. These third parties have their own privacy policies and practices, for which we are not responsible. We encourage you to review the privacy policies of any third-party sites you visit. The inclusion of a link on our Site does not constitute an endorsement of that third party's privacy practices.

13. Marketing Communications and Opt-Out

We may send commercial email communications to business contacts who have either provided consent or with whom we have an existing business relationship and a legitimate interest basis for direct marketing. Every marketing email we send includes a clearly visible unsubscribe link. You may also opt out at any time by:

  • Clicking the "unsubscribe" link in any marketing email.
  • Emailing hello@cocomob.com with the subject line "Unsubscribe" and your email address.
  • Contacting us at the address above to update your communication preferences.

Opting out of marketing communications does not affect our ability to send you transactional or service-related communications (such as invoices, contract updates, or security notices).

14. Automated Decision-Making and Profiling

We do not make decisions about individuals that produce significant legal or similarly significant effects based solely on automated processing, without human involvement. In the course of managing advertising campaigns for clients, programmatic advertising systems operated by advertising platforms (such as Google's DV360 or Meta's Advantage+ systems) may perform automated bidding and audience optimisation based on pseudonymous identifiers. These automated processes are subject to the applicable platform's own terms and privacy policies. If you wish to understand or object to such automated processing in the context of advertising, please refer to the respective platform's privacy settings and opt-out mechanisms.

15. California-Specific Disclosures (CCPA/CPRA)

This section applies to California residents. In the preceding 12 months, Cocomob has collected, disclosed, and in limited circumstances "shared" (for cross-context behavioural advertising purposes) the following categories of personal information:

Category (CCPA)ExamplesBusiness PurposeSold?Shared (CPRA)?
IdentifiersName, email, IP address, cookie IDService delivery, analytics, securityNoLimited (ad platform pixels)
Commercial informationService agreements, billing recordsContractual obligationsNoNo
Internet/electronic network activityBrowsing history on Site, cookie dataAnalytics, personalisationNoLimited (Google Analytics, ad pixels)
Geolocation dataApproximate location from IP addressAnalytics, fraud preventionNoNo
Professional/employment informationJob title, company nameB2B service delivery, CRMNoNo
InferencesInterests and preferences inferred from usageMarketing personalisationNoNo

California residents may submit CCPA rights requests to hello@cocomob.com. We will not discriminate against you for exercising any CCPA rights. We do not have actual knowledge that we sell or share personal information of minors under 16 years of age.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the services we offer. When we make material changes, we will post the updated Policy on this page and update the "Last Updated" date at the top of the document. For significant changes, we may also provide additional notice such as an email notification to registered contacts or a banner on our Site. We encourage you to review this Policy periodically. Your continued use of the Site after changes are posted constitutes your acknowledgment of the updated Policy.

17. Contact and DPO Information

For all privacy-related enquiries, rights requests, or concerns, please contact us at:

Cocomob Ltd. — Privacy Team
Email: hello@cocomob.com

Where required by applicable law, we have designated a Data Protection Officer (DPO). You may contact our DPO directly at the email address above, marking your correspondence "For the attention of the DPO." If you are located in the EU/EEA or UK and are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at the European Data Protection Board website (edpb.europa.eu). The UK supervisory authority is the Information Commissioner's Office (ico.org.uk).