Privacy-First by Design
Audience Base · Privacy Engineering & Responsible Advertising Technology
Privacy isn’t an add-on. It’s part of how Audience Base is designed.
Data Minimisation • Responsible AI • Secure Processing • Privacy-Conscious Advertising
Effective Date: 01 June 2026
Last Updated: 01 June 2026
- Our Philosophy
Digital advertising is changing.
Consumers expect greater privacy.
Advertisers expect better transparency.
Regulators expect greater accountability.
Browsers and operating systems are introducing stronger privacy controls.
At the same time, advertisers still need technology capable of delivering audience intelligence, relevant advertising, measurement and optimisation.
Audience Base believes these objectives can coexist.
Our approach is:
Privacy-First by Design
Privacy should not simply be added to technology after it has been developed.
Privacy considerations should influence how advertising technology is planned, designed, built and operated.
- Privacy Across the Data Lifecycle
Audience Base seeks to consider privacy throughout the complete information lifecycle:
Plan → Collect → Process → Activate → Measure → Analyse → Retain → Delete
At each stage, relevant questions include:
- What information is required?
- Why is it required?
- Can less information achieve the objective?
- Can contextual information be used?
- Can aggregated information be used?
- Can identifiers be pseudonymised?
- Who requires access?
- How should information be protected?
- How long should it remain?
- When should it be deleted?
Privacy is therefore treated as an architectural consideration rather than simply a policy document.
- Collect What Is Needed
Our data-minimisation principle is simple:
Collect what is needed. Avoid what is not.
Technical capability alone does not justify data collection.
Audience Base seeks to process information reasonably relevant to defined advertising, measurement, analytics, security and optimisation purposes.
- Context Before Identity
Where an advertising objective can be achieved by understanding content rather than identifying an individual, Audience Base supports contextual approaches.
Contextual signals may include:
- Page topic
- Keywords
- Editorial context
- Website category
- Application category
- Content classification
- General advertising environment
Relevant advertising does not always require knowing who the viewer is.
- Aggregation Before Individual Exposure
Many important advertising questions can be answered using aggregated information.
Audience Base may provide aggregated metrics including:
- Impressions
- Clicks
- CTR
- Reach
- Frequency
- Engagement
- Viewability
- Conversion
- Video interactions
- Device performance
- Geographic performance
- Contextual performance
This can provide useful intelligence without unnecessarily exposing individual-level information.
- Pseudonymous Advertising
Where individual-level signals are reasonably required, Audience Base may use pseudonymous identifiers.
Examples may include:
- Cookie IDs
- Device IDs
- Advertising IDs
- Session IDs
- Campaign IDs
- Randomised identifiers
Pseudonymisation can reduce privacy risk by separating advertising activity from directly identifying information.
Pseudonymous information remains subject to appropriate safeguards where required.
- Minimising Direct Identifiers
Audience Base seeks to minimise the use of directly identifying information within ordinary advertising workflows.
Advertising campaign measurement should not automatically require a person’s:
- Name
- Personal email
- Personal phone number
- Private credentials
Where first-party identifiers are legitimately required for authorised functionality, additional privacy and security controls may apply.
- Purpose-Limited Processing
Information should have a defined purpose.
Audience Base may process information for purposes including:
- Campaign delivery
- Audience intelligence
- Measurement
- Frequency management
- Attribution
- Reporting
- Analytics
- Fraud prevention
- Security
- Optimisation
Information should not automatically be reused for unrelated activities.
- Consent-Aware Architecture
Privacy choices may travel through modern advertising systems as technical signals.
Depending upon the environment, these signals may originate from:
- Publishers
- Advertisers
- Consent Management Platforms
- Mobile applications
- Browsers
- Operating systems
- Advertising platforms
Where technically supported and applicable, Audience Base seeks to respect relevant privacy and consent signals.
- Respecting Platform Privacy Controls
Audience Base does not view circumventing legitimate browser, mobile operating-system or consent controls as a sustainable advertising strategy.
As advertising technology evolves, our objective is to develop solutions that operate responsibly within modern privacy environments.
- First-Party Data
First-party information can help advertisers build direct customer relationships.
Where Audience Base supports first-party data activation, advertisers remain responsible for ensuring that information was:
- Lawfully collected
- Transparently collected
- Appropriate for the intended use
- Shared with appropriate authority
- Used consistently with relevant privacy choices
- Sensitive Information
Audience Base does not intentionally design standard advertising products around highly sensitive private information.
Our standard advertising services are not intended for audience creation using information such as:
- Passwords
- Authentication credentials
- Private medical records
- Biometric authentication information
- Private financial credentials
- Other highly sensitive private records
- Children’s Privacy
Children require heightened privacy protection.
Audience Base does not intentionally design standard behavioural advertising functionality for unlawful profiling or targeted advertising involving children.
Additional restrictions may apply depending upon the campaign, data, market and applicable law.
- Responsible Audience Segmentation
Audience Base may use appropriate advertising signals to create or analyse audience segments.
Signals may include:
- Context
- Broad interests
- Permitted behavioural signals
- Campaign interaction
- First-party information
- Aggregated information
- Statistical models
Audience categories may be probabilistic.
They should not automatically be interpreted as verified personal facts.
- Privacy-Conscious Measurement
Measurement is essential for understanding advertising performance.
Audience Base may measure events including:
- Impressions
- Clicks
- Engagement
- Viewability
- Conversions
- Video interactions
- Campaign interactions
Measurement should remain connected to legitimate campaign purposes.
- Privacy-Conscious Attribution
Attribution can help advertisers understand campaign outcomes.
Audience Base may support attribution through approaches involving:
- Campaign identifiers
- Conversion events
- Pseudonymous identifiers
- Aggregated information
- Statistical analysis
- Privacy-conscious modelling
Our objective is to balance useful measurement with responsible information processing.
- Frequency Management
Repeatedly showing the same advertisement can create poor consumer experiences.
Frequency controls can help reduce unnecessary repetition.
Where supported, permitted identifiers or aggregated signals may be used to manage campaign frequency.
- Secure Transmission
Information transmitted between systems should be appropriately protected.
Where applicable, Audience Base seeks to use secure encrypted communication protocols for transmitting information.
- Secure Storage
Where appropriate to the relevant data and infrastructure, stored information may be protected through encryption and other infrastructure security controls.
- Access Control
Not every person within an organisation should have unrestricted access to information.
Audience Base seeks to limit access according to:
- Role
- Responsibility
- Business requirement
- Security requirement
Access may be modified or removed when no longer required.
- Authentication
Administrative systems should use appropriate authentication controls.
Security requirements may evolve as Audience Base expands its technology and services.
- Data Isolation
Where technically appropriate, advertiser and campaign information should be logically separated.
One advertiser should not receive unrestricted access to another advertiser’s confidential information simply because both use Audience Base.
- Advertiser-Level Permissions
Audience Base may provide permissions at advertiser, account and user levels.
These controls can help determine who may:
- View campaigns
- Create campaigns
- Modify campaigns
- Access reports
- Manage integrations
- Access advertiser information
- Perform administrative actions
- API Security
Audience Base may integrate with advertising platforms through APIs.
API security considerations may include:
- Authentication
- Authorisation
- Credential protection
- Permission scope
- Secure communication
- Logging
- Access revocation
- Error handling
API credentials should not be unnecessarily exposed.
- Platform Connections
Advertisers may connect external advertising accounts and platforms to Audience Base.
Our objective is to request only the permissions reasonably necessary for supported functionality.
Connections should be revocable where supported by the relevant external platform.
- Data Retention
Information should not live indefinitely without purpose.
Retention may depend upon:
- Campaign requirements
- Reporting requirements
- Client contracts
- Security
- Legal requirements
- Technical requirements
When information is no longer reasonably necessary, it may be deleted, anonymised or aggregated.
- Deletion
Deletion is an important part of privacy engineering.
Where appropriate and technically applicable, information may be:
- Deleted
- Anonymised
- Aggregated
- Otherwise rendered no longer identifiable
Backup retention may temporarily continue according to appropriate security and operational requirements.
- Logging
Operational and security logs may help identify:
- Unauthorised access
- Security events
- Administrative actions
- Technical failures
- Suspicious behaviour
- Platform errors
Logging itself should remain proportionate to legitimate security and operational purposes.
- Monitoring
Audience Base may monitor systems for:
- Security
- Availability
- Performance
- Reliability
- Fraud prevention
- Technical troubleshooting
Monitoring should focus on legitimate operational objectives.
- AI-Assisted Advertising
Artificial intelligence is an important component of modern advertising technology.
Audience Base may use AI to support:
- Audience planning
- Media planning
- Contextual analysis
- Campaign recommendations
- Performance analysis
- Forecasting
- Optimisation
- Reporting
- Anomaly detection
Privacy principles remain relevant regardless of whether processing is performed manually or through AI.
- Better AI Does Not Require Unlimited Data
More data does not automatically mean better intelligence.
Our objective is to develop AI systems that use appropriate and relevant information rather than maximising personal-data collection.
- Responsible AI Inputs
Information should not be provided to AI systems unless the relevant party has appropriate authority to process it for the intended purpose.
Advertisers and partners remain responsible for information they provide to Audience Base.
- Human Oversight
AI should support advertising professionals rather than eliminate accountability.
Where appropriate, users may review:
- Audience recommendations
- Targeting recommendations
- Budgets
- Campaign configuration
- Creatives
- Optimisation recommendations
before material campaign decisions are implemented.
- Explainable Recommendations
Where practical, Audience Base seeks to provide useful context around AI-assisted recommendations.
Users should be able to understand the general reasoning or performance signals behind important campaign recommendations where functionality permits.
- Client Data and AI
Client and campaign information should be processed according to defined purposes.
Use of client information within AI-enabled functionality should be considered according to:
- Intended purpose
- Contractual terms
- Privacy requirements
- Security requirements
- Technology-provider requirements
- Third-Party AI Technology
Where Audience Base integrates external AI technology, relevant considerations may include:
- Information transmitted
- Processing purpose
- Provider terms
- Retention
- Security
- Privacy
- Access
- Appropriate contractual controls
- Vendor Governance
Audience Base may rely upon third-party technology providers for:
- Hosting
- Infrastructure
- Security
- Analytics
- Advertising delivery
- Measurement
- Communications
- AI services
Privacy and security considerations form part of responsible vendor management.
- Publisher Responsibility
Publishers remain responsible for their own websites, applications and relationships with users.
This may include responsibility for:
- Privacy notices
- Consent mechanisms
- Cookie implementation
- Direct data collection
- User choices
- Applicable legal requirements
Audience Base seeks to work within responsible advertising environments.
- Advertiser Responsibility
Advertisers using Audience Base remain responsible for their campaign decisions.
Responsibilities may include:
- Lawful campaign configuration
- Appropriate audience selection
- Lawful first-party data collection
- Required notices
- Required consent
- Creative compliance
- Applicable industry restrictions
Technology can support privacy but cannot replace advertiser accountability.
- Privacy Rights
Where applicable, Audience Base seeks to support appropriate processes relating to privacy rights.
Depending upon the applicable framework and processing relationship, these may include:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Consent withdrawal
- Security Incident Response
No responsible technology platform should assume security risk can be completely eliminated.
Our approach therefore includes prevention, detection and response.
Where appropriate, incident handling may follow:
Detect → Investigate → Contain → Assess → Remediate → Communicate → Learn
- Secure Development
Privacy and security considerations should be incorporated into software development.
When developing new Audience Base functionality, relevant considerations may include:
- What information is collected
- Why it is required
- Who receives access
- API permissions
- Retention
- Security
- Logging
- Privacy impact
- Privacy Review for New Features
Features involving materially new processing may require additional privacy review.
This can be particularly important for:
- New audience datasets
- New tracking technologies
- New AI capabilities
- New identity technologies
- New data partners
- New international integrations
- Sensitive processing
- Privacy by Default
Where practical, Audience Base seeks to design standard configurations so that unnecessary personal-data processing is not required simply to use platform functionality.
- Privacy Across Advertising Integrations
Audience Base may integrate with multiple advertising platforms and technology providers.
Each integration may have different:
- Data requirements
- Permissions
- Privacy signals
- Security controls
- Retention requirements
- User choices
Our objective is to evaluate privacy according to the nature of each integration rather than applying one assumption to every platform.
- Global Privacy Thinking
Audience Base is developed and operated from India while digital advertising is global.
Our privacy architecture seeks to consider principles reflected across modern privacy frameworks, including:
- India’s DPDP framework
- GDPR-aligned principles
- Platform privacy requirements
- Contractual requirements
- Advertising industry standards
- Accountability
Privacy requires people, processes and technology working together.
Our privacy approach may include:
- Governance
- Policies
- Contracts
- Security controls
- Access management
- Vendor management
- Data minimisation
- Retention management
- Incident response
- Privacy reviews
- Continuous Improvement
Privacy engineering is never finished.
Technology changes.
Advertising changes.
Regulation changes.
Consumer expectations change.
Security threats change.
Audience Base therefore seeks to continuously evaluate and improve relevant privacy and security practices.
- Transparency
Audience Base believes advertisers, agencies, partners and users should be able to understand our approach to privacy.
Our Compliance & Transparency resources may include information regarding:
- DPDP alignment
- GDPR alignment
- Privacy-first technology
- Data processing
- Privacy practices
- Cookies
- Security
- Data rights
- Technology providers
- Privacy-First by Design
For Audience Base, Privacy-First by Design means thinking about privacy before, during and after technology development.
It means asking whether data is necessary.
It means favouring context and aggregation where appropriate.
It means limiting access.
It means protecting information.
It means considering privacy when building AI.
It means reviewing technology as regulations and consumer expectations evolve.
Most importantly, it means recognising that the future of advertising should depend on better intelligence rather than simply more personal data.
- Contact
For privacy, security and data-protection enquiries:
Audience Base
Operated by Digital Shoutouts Media Pvt. Ltd.
Email: sales@digitalshoutouts.com
Gurgaon (HQ)
Unit No. 258, 2nd Floor, Tower B-1,
Spaze i-Tech Park, Sector 49, Sohna Road,
Gurgaon – 122018, Haryana, India
Mumbai Office
Ground Floor, Raheja Platinum,
Off Andheri-Kurla Road, Sag Baug,
Andheri East, Mumbai – 400059, Maharashtra, India
Bengaluru Office
HSR 6th Sector, Rajiv Gandhi Nagar,
HSR Layout, Bengaluru South – 560102, Karnataka, India
Our Privacy Principle
Collect Less. Understand Better. Protect More.
Audience Base believes privacy and advertising performance can coexist.
Our objective is to build advertising intelligence around better context, better technology, responsible AI, appropriate security and responsible data practices.
DPDP Aligned • GDPR Aligned • Privacy-First by Design
Audience Base — Responsible Advertising Intelligence for a Privacy-Conscious Digital Ecosystem.