Resources

Compliance Resource

Data Protection Impact Assessment (DPIA)

Public overview of processing, safeguards and integration-specific risks. Updated September 12, 2026.

1. Processing overview

A publisher backend requests an ad for a consumer AI product moment, such as a chat response, media-generation job or visible agent step. The request includes placement, operational and policy inputs such as topic, language, device or surface information, country and consent flags. Raw prompts are optional. Where prompt-assisted classification is enabled with the required permission, wavebird processes that context to produce a reduced matching signal.

The partner ad request excludes raw prompt text, conversation history and end-user account records. Permitted semantic context is reduced before that request is assembled; technical and regulatory fields are checked separately. Retention and erasure must be assessed for the classification path actually used.

After a filled decision, the renderer displays the creative and emits delivery events. Server-side checks determine whether those events support an eligible impression and settlement. The browser does not establish billability by itself. Operational evidence and billing records have their own processing purposes and can still contain personal data.

2. Necessity and proportionality

The publisher must establish the legal basis for each processing purpose under Article 6 GDPR. A commercial interest in financing an app does not by itself authorize every use of data. Semantic targeting requires the relevant explicit consent. The publisher controls the end-user relationship; wavebird acts as processor where it handles data on the publisher's documented instructions.

Data minimization supports this assessment: the ad request can use permitted derived context, regulatory flags and technical metadata without disclosing raw prompts. The publisher must assess necessity and proportionality for its audience, feature, data categories and actual configuration.

3. Data categories processed

  • Broad contextual topic, where permitted
  • Language, device or surface information and broad country information
  • Consent and regulatory flags supplied through the integration
  • Operational request, session and placement identifiers
  • Optional prompt context for classification, excluded from partner ad requests

Coarse or derived data can still be personal data when linked to a person or identifiable session. Data minimization reduces exposure; it does not automatically make every field anonymous.

4. Categories of data subjects

End users of the publisher's consumer AI application.

5. Recipients of data

  • wavebird infrastructure
  • Advertising partners, according to the roles documented for the integration

SSP recipients receive only the reduced outbound auction payload. They do not receive raw prompts from wavebird.

6. Retention

  • Prompt text: transient classification processing, with deletion after reduction
  • Client identifiers in the retention schedule: a 7-day target
  • Personal fields in API request logs: a 30-day anonymization or removal target
  • Request-level API and impression records: a 395-day policy target, subject to documented exceptions
  • Settlement and accounting records: the statutory period for the specific record type
  • Consent evidence: retained for its documented purpose and applicable obligations

These are policy targets, not a claim that every deployed cleanup job has been verified. Operational cleanup rules, backups and legal holds must be assessed for the relevant data flow. The privacy policy describes the schedule and exceptions.

7. Technical and organizational measures

  • TLS encryption for data in transit
  • HTTPS enforcement for SSP endpoints
  • Transient prompt handling and configured vault erasure where that runtime path is used
  • HMAC-signed beacon proofs
  • Merkle-tree log integrity
  • Firewall pre-egress sanitization

8. Risk assessment

Risk: prompt text exposure

Mitigation: exclude raw prompts from partner requests, validate outbound fields and verify the classification path's erasure behavior.

Risk: tracking user across sessions

Mitigation: limit identifiers to their stated purpose, gate optional measurement on consent and apply the relevant retention schedule. Necessary security identifiers have a separate purpose.

Risk: PII in prompts

Mitigation: raw prompts are optional and excluded from partner requests; classification and policy checks restrict permitted use. These checks do not establish perfect detection of every personal detail.

9. Residual risk

Residual risk depends on the integration, the data processed and the controls operating in that environment. Separating the ad path and reducing context address prompt-disclosure risks. Configuration mistakes, identifiers, retention and partner data flows still require assessment; this overview is not a blanket low-risk finding for every publisher.

10. Review schedule

This DPIA is reviewed annually or when material system changes occur, including changes to prompt handling, outbound SSP fields, or new subprocessors that affect the privacy posture.