Get in Touch and Find Out More
QPS Media LTD
Privacy Policy
Effective Date: 01 November 2025 • Last Updated: 01 June 2026
QPS Media LTD (“we”, “us”, “our”) is a UK-based programmatic advertising business. This policy explains what personal data we collect and process, what non-personal commercial data we handle, why, and your rights under UK GDPR.
We will update this policy before undertaking any new data activities. The “Last Updated” date above will always reflect the current version.
We handle two distinct categories of data:
A. Business contact information — personal data provided directly by business contacts. This is subject to UK GDPR.
B. Transaction location data — postal code and transaction metadata files used for geographic advertising. This data relates to merchant and transaction locations, not to identifiable individuals, and is not considered personal data under UK GDPR.
We collect only the business contact information you provide when communicating with us directly:
• Name and job title
• Business email address
• Business phone number
• Any other information you choose to include in emails, calls, or meeting invitations
We process your business contact information on the following legal bases under UK GDPR:
• Legitimate Interests (Article 6(1)(f)): to communicate with you about potential or existing business relationships. We have assessed that this interest is not overridden by your rights.
• Contract (Article 6(1)(b)): where processing is necessary to perform or administer a contract or service agreement with you.
• Legal Obligation (Article 6(1)(c)): where we are required to process data by law or regulation.
We use your contact information to:
• Respond to enquiries and manage business communications
• Schedule meetings and maintain business relationships
• Handle invoicing, record-keeping, and contract administration
• Comply with applicable legal and regulatory obligations
We retain business contact data for the duration of our business relationship and for up to six years afterwards, consistent with standard contractual limitation periods under English law. Data that is no longer needed is deleted on a rolling basis.
Note: The data described in this section represents merchant and transaction locations. It does not include any individual’s personal address, identity, or behavioural profile. We do not use this data to identify, track, or retarget any individual.
In connection with our programmatic advertising activities, we receive, process, and distribute CSV files containing:
• Postal codes (UK and USA) representing locations where transactions occurred
• Merchant Category Codes (MCC codes) indicating the type of merchant or transaction
• Card network indicators showing which payment network processed the transaction (for example, Visa, Mastercard, or American Express)
• Expenditure band: a categorisation of transaction value at a given merchant location as either “high” or “low” based on relative spend levels
This data is derived from payment transaction infrastructure and reflects where transactions took place — for example, the postcode of a retail location or merchant premises. It does not represent the home address or personal location of any cardholder.
Expenditure data is deliberately abstracted into two bands (high and low) rather than carried as actual transaction values. This banding approach reduces any risk that transaction values could be used, alone or in combination, to narrow activity to an individual. We do not receive or hold precise transaction amounts.
We use transaction location data for the following commercial purposes:
• Geographic targeting: uploading postal code datasets into Supply Side Platforms (SSPs) to enable location-based advertising targeting within curated programmatic deals. This targets geographic areas associated with transaction activity, not individual users.
• Data distribution: supplying transaction location CSV files to data providers and advertising businesses. We supply the data in its received format; we do not enrich, append, or combine it with other data prior to distribution.
Based on the nature of the data as we receive it, we do not consider it to constitute personal data under UK GDPR. The reasons for this assessment are:
• It relates to transaction and merchant locations, not to individuals’ residential or personal addresses.
• It does not contain any direct identifiers such as names, email addresses, device identifiers, or cardholder references.
• It is supplied to us at an aggregated geographic level by our data partners, who retain any underlying individual-level data within their own systems.
• We do not combine it with any other dataset in a way that could render any individual identifiable.
• We do not use it for retargeting, profiling, or any purpose directed at identified or identifiable natural persons.
We recognise that the question of whether geographic or transactional data constitutes personal data depends on context and combination. We apply conservative handling standards to this data regardless of its legal classification, and we keep this assessment under active review. If the nature of the data we receive changes — for example, if it became possible to use it to identify individuals — we will update this policy and apply full UK GDPR protections before continuing to process it.
We receive transaction location data from two categories of upstream commercial partners operating under formal written agreements with QPS Media:
• A card payment provider: a regulated payment infrastructure business that supplies transaction location extracts derived from card payment activity.
• Point-of-sale technology companies: businesses that operate merchant payment systems and supply transaction location data from those systems.
In each case, our agreement with the supplying partner explicitly confirms our right to use and distribute the data for the commercial advertising purposes described in this policy. We do not receive data that identifies individual cardholders or consumers. The personal data of cardholders remains with our partners and is not passed to us.
We satisfy ourselves before entering any such agreement that our partners have the appropriate basis under their own arrangements to supply data for these purposes. We maintain records of these agreements and can provide relevant details to regulators on request.
We do not sell your personal data. We share it only in these limited circumstances:
• Service providers: trusted third-party suppliers (such as email hosting or calendar software) who process data on our behalf, under written contracts that require them to protect it.
• Legal requirements: where required by law, regulation, or court order.
• Business transfers: if QPS Media is acquired or merged, contact data may transfer to the new entity under equivalent privacy protections.
Transaction location data is shared with or distributed to the following categories of recipients as part of our commercial activities:
• Supply Side Platforms (SSPs): we upload postal code datasets to SSP platforms for use in programmatic advertising targeting within curated deals. SSPs receive the data under their standard platform terms, which govern its use within the programmatic advertising ecosystem.
• Data providers and advertising businesses: we supply transaction location CSV files to third parties for use in their own advertising, planning, and analytics activities.
All recipients of transaction location data are subject to contractual terms that:
• Prohibit use of the data to identify, profile, or target individual natural persons.
• Restrict use to commercial advertising, planning, and analytics purposes consistent with the nature of the data.
• Require recipients to handle the data with appropriate security standards.
• Prohibit further onward sale except where expressly agreed with us in writing.
We supply the data without modification to its content. We are not responsible for how recipients combine this data with their own datasets, but our contractual terms require that any such combination does not result in the identification of individuals.
Some of our service providers and SSP partners may be based outside the UK. Where personal data (business contact information) is transferred internationally, we ensure appropriate safeguards are in place — such as UK Standard Contractual Clauses or reliance on UK Adequacy Regulations.
Transaction location data, which we do not consider to be personal data, may also be processed by recipients based outside the UK. Where relevant, we apply contractual protections governing its use and security.
You may request details of the safeguards in place for personal data transfers by contacting us.
We apply appropriate technical and organisational controls to protect personal data from unauthorised access, loss, or disclosure. These include access controls and secure communications. We apply equivalent security standards to transaction location data.
No system is entirely secure. Please contact us with any concerns.
Under UK GDPR you have the following rights in relation to your personal data (business contact information). We will respond to any request within one calendar month.
• Access: request a copy of the personal data we hold about you.
• Correction: ask us to correct inaccurate or incomplete data.
• Deletion: ask us to delete your data where we have no legitimate reason to keep it.
• Restriction: ask us to restrict processing in certain circumstances.
• Objection: object to processing based on legitimate interests; we will stop unless we have compelling grounds that override your interests.
• Portability: where processing is automated and based on contract, request a portable copy of your data.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.
We will update this policy before undertaking any new data activities — such as processing new categories of personal data or materially changing how we handle transaction location data. We will notify existing business contacts of any material changes by email. The “Last Updated” date at the top of this page will always reflect the most recent version.
QPS Media LTD
Email: a@qps.media
Registered Address: 85 Great Portland Street, First Floor, London, England, W1W 7LT
Company Number: 16670245
ICO Registration Number: ZC064109
Note: Our ICO registration is maintained to reflect our current data processing activities. If you have questions about the scope of our registration, please contact us directly.
© QPS Media LTD • Privacy Policy • Effective 01 November 2025