← back to home

Bluematic Privacy Policy

Effective date: 30 September 2026
Controller/service provider: Bluematic, operated by Blue Robot (Pty) Ltd
Contact: kyle.oosthuizen@bluerobot.com
Website: https://bluematic.co.za

This policy explains how Bluematic processes information when it provides creative hosting, third-party ad serving, measurement, dynamic-data delivery and related publisher or advertiser services. It is written for the Bluematic website, Studio, delivery domains, preview harnesses, SDKs, tags, pixels and APIs.

1. Our role

Bluematic normally acts as a service provider or processor for advertisers, agencies, publishers and platform partners. The customer that instructs a campaign determines the campaign purpose, audience and destinations and remains responsible for its own notices, consent and lawful instructions. Bluematic acts as an independent controller for account administration, security, billing records, support and legal compliance.

2. Information we process

Account and business information

We process names, work email addresses, organization, role, support communications, campaign configuration, approvals, audit records and account security information supplied by customer operators.

Campaign and creative information

We process uploaded ZIPs, images, video, PDFs and catalogue-derived product data; creative manifests; approved destinations; release identifiers; placement and flight settings; template and brand-kit data; and publisher or platform identifiers supplied by the customer. We do not use customer creative or catalogue data to create cross-customer advertising audiences.

Delivery and measurement information

When a Bluematic tag, SDK, creative, event endpoint or 1×1 tracking pixel is requested, we may process the request time, IP address, user-agent and other standard server-security data, an event ID, creative-instance ID, placement, release, environment, event name, referrer where supplied by the browser, and bounded event properties. We use this information to deliver the approved creative, prevent abuse, diagnose errors, deduplicate retries, measure campaign events and produce aggregate reports.

Bluematic identifiers are pseudonymous technical identifiers. Bluematic does not intentionally collect names, email addresses, telephone numbers, account passwords, government identifiers, full payment-card data, raw consent strings or free-form user input through an ad. We do not intentionally collect precise location, microphone, camera, contacts or device storage access from an ad.

IP addresses and user-agent data may appear in short-lived security or infrastructure logs. Where practical, reports use truncated, hashed or otherwise minimized values. We do not combine ad identifiers with a person's name, email address or telephone number to create an advertising segment.

Dynamic data

Campaigns may receive approved weather, sport-score, catalogue, pricing or customer-database data through a scheduled connector or authenticated push endpoint. Bluematic stores a bounded cached snapshot and uses it to render the approved creative. The customer is responsible for the lawful collection and accuracy of data sent to Bluematic. Bluematic does not fetch an external API for every impression when a cached snapshot is configured.

3. Cookies, pixels and similar technologies

Bluematic may use HTTPS requests, cache headers, local application storage, web beacons and a 1×1 image pixel for delivery, aggregate measurement, conversion or troubleshooting. A pixel request does not by itself identify a person. Bluematic does not set, modify or delete cookies on Google-owned or operated domains.

Customer or publisher code may have its own cookies or consent technology. Bluematic does not control those technologies and they remain subject to the publisher's notice and policy.

Where a campaign or route requires consent, the customer and publisher must provide an appropriate consent signal. If consent is missing, denied or malformed, Bluematic suppresses optional measurement and continues only the delivery functions permitted for that route.

4. Purposes and legal basis

We process information to:

  • authenticate operators and enforce organization roles;
  • validate, preview, approve, publish, pause and roll back immutable creative releases;
  • deliver ads, resolve approved click destinations and prevent malicious traffic;
  • receive, deduplicate and aggregate delivery, render, interaction, exit, completion, fallback and error events;
  • operate scheduled connectors and authenticated push feeds;
  • secure systems, investigate abuse, maintain audit trails and restore service;
  • provide support, invoices, service notices and legal compliance; and
  • improve reliability using aggregated, de-identified operational information.

Depending on the jurisdiction and relationship, the legal basis may be contract, legitimate interests, consent, or compliance with a legal obligation. The customer remains responsible for selecting the appropriate lawful basis for its campaign and obtaining any required consent.

5. Advertising restrictions

Bluematic does not create or sell behavioral audiences from Google inventory. We do not use PII to create segments, target sensitive categories, or knowingly target children under 13. We do not use packet sniffing or inspect unrelated traffic. We do not sell, rent or make impression-level data available for resale or syndication.

Campaigns may include only reviewed, approved tracking elements and destinations. Fourth-party calls are disabled unless the relevant platform has expressly approved the vendor and route. Google, DV360, CM360, Eskimi or another platform's report is the report of record for that platform; Bluematic operational counts are separate and are not represented as audited impressions, unique people, viewability, CTR or billable delivery.

6. Sharing

We share information only as needed to provide the requested service with:

  • the customer, agency, publisher and platform receiving the campaign or report;
  • infrastructure providers such as Vercel and Supabase acting under contract;
  • security, support, professional and legal advisers bound by confidentiality; and
  • authorities where required by law or to protect rights, safety and service integrity.

We do not share personal information with data brokers or unrelated advertisers. Customer creative, catalogue records and dynamic snapshots remain tenant-scoped.

7. International transfers and security

Bluematic may process information in countries where our infrastructure or service providers operate. We use contractual, technical and organizational safeguards appropriate to the transfer and applicable law.

Controls include private quarantine and approved storage, immutable published artifacts, tenant and role checks, encrypted credentials, signed upload and feed requests, restrictive creative isolation, content-security policies, bounded event properties, replay protection, access logging, rate limits and least-privilege service access. No security measure guarantees absolute security.

8. Retention

Unless a customer contract or law requires a different period, our provisional schedule is:

  • raw measurement events: 30 days;
  • operational and security logs: 7 days;
  • aggregate campaign reports: 13 months;
  • audit history: 12 months; and
  • published creative and campaign records: for the customer relationship and required legal or reconciliation periods.

Backups may retain encrypted copies for a limited additional period before rotation. We delete or anonymize information when the applicable period ends, subject to legal holds and dispute resolution.

9. Your choices and rights

You may opt out of optional Bluematic measurement by using the Bluematic measurement opt-out link on this page. Opting out suppresses optional event and pixel measurement; it does not necessarily stop an ad from being delivered by a publisher or platform. Browser privacy controls, Global Privacy Control and publisher consent controls may also apply.

Subject to applicable law, individuals may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing is based on consent. Requests should be sent to kyle.oosthuizen@bluerobot.com with enough information for us to locate the request. We may need to verify identity and may refer a request to the customer that controls the campaign data.

South African residents may have rights under POPIA and may complain to the Information Regulator. UK, EEA and other residents may contact their local supervisory authority. We do not make solely automated decisions that produce legal or similarly significant effects about individuals.

10. Children

Bluematic services are not directed to children under 13. We do not knowingly create or support child-directed or sensitive audience segments. Customers must not send children's personal information to Bluematic.

11. Changes and contact

We may update this policy when our services, law or certification requirements change. We will post the revised version with a new effective date. Questions, rights requests and security reports should be sent to kyle.oosthuizen@bluerobot.com.

Last updated: 30 September 2026