Dorvan Srl · Flux Bidder
Last update: June 2026
This privacy policy applies to the processing of personal data that Dorvan Srl carries out through its Flux Bidder service. It also applies to the data processing relating to clients and/or third parties associated with Dorvan Srl.
This privacy policy concerns the processing of personally identifiable information (PII) in connection with the header bidding services we offer.
We work with leading exchanges and publishers in the industry, allowing us to handle large volumes of transactions reliably while maintaining the highest standards of privacy and security.
Dorvan Srl has its registered address at Via Enrico Cernuschi 4, 20129 Milano, Italy.
As Dorvan Srl is established within the European Union, it acts as data controller for the processing described in this policy under the EU General Data Protection Regulation (GDPR).
Data subjects may contact us to resolve any issue related to the processing of their personal data at the following email address: privacy@dorvan.it.
The services offered through Flux Bidder enable website owners (publishers) to connect their ad space inventory with diverse, high-quality advertising demand sources that compete in real time.
When a user visits a web page, the server loads the page content, including the ad slots where advertisements can be displayed. The publisher's website triggers the initialization of the header bidding process, and bid requests are sent simultaneously to multiple demand partners through a real-time advertising platform (Ad-Exchange).
Bid requests contain information about the ad inventory, such as ad placement, size, and other relevant details. They sometimes contain data resulting from processed personally identifiable information (PII) of the web visitor. This data is collected through cookies and local storage mechanisms and is processed to create audience segments that are sent in bid requests.
Data shared with advertisers is aggregated and anonymized. Advertisers target audience segments (e.g., "users interested in sports" or "users aged 25-34") rather than individual users. This aggregation protects user privacy while allowing for relevant ad targeting.
The real-time advertising platform verifies that PII has been collected in accordance with applicable law and is processed in compliance with data protection regulations. This data is processed and transferred in accordance with the highest standards of privacy and information security.
We collaborate with diligent partners who are registered under the IAB Transparency and Consent Framework and adhere to all required technical and legal safeguards.
When publishers operate under the GDPR or in areas with similar privacy standards, visitors' consent is required for processing and sharing PII. The real-time advertising platform verifies that valid consent, in accordance with applicable regulations, has been provided by users for sharing PII; if not, no personal information is sent to bidders. In such cases, advertising selection proceeds without personal data, sharing only the ad's contextual information. Advertisers can then bid based on this contextual information but do not receive any personal data or data inferred from processed PII.
Real-time advertising platforms, publishers, and Dorvan Srl as an agency each act as a separate data controller serving different purposes.
PII collected in this process can be classified in the following categories:
Data that by itself identifies an individual "in the real world" — such as name, address, phone number, email address, or government identifier — is NOT collected or processed in this operation.
The data described above is used to improve and tailor the web page user's advertising experience. It also provides advertisers with the information needed to make more consistent bids, securing the highest returns for publishers through real-time advertising.
The purposes of this data processing can be defined as follows:
In the case of data provided for marketing or advertising purposes, it will be deleted once consent is revoked.
We do not store data collected by our clients and processed by our partner platforms. To learn their data retention periods, please consult the privacy policies listed below.
Typically, PII is held for a maximum of 180 days.
Data is collected through the following mechanisms:
Cookies are small files of information that a web server generates and sends to a web browser. Browsers store the cookies they receive for a predetermined period, or for the length of a user's session on a website, and attach the relevant cookies to future requests made to the server. Cookies help inform websites about the user, enabling personalization of the user experience. Some cookies are also necessary for security purposes, such as authentication.
Scope and lifetime. Session cookies are temporary and deleted when the browser is closed; they store information needed only during a single browsing session. Persistent cookies remain on the device for a specified period or until deleted, storing information across multiple sessions, such as login credentials or user preferences.
Transmission. Cookies are automatically sent with every HTTP request to the server, allowing the server to recognize returning users and maintain stateful interactions. They are also accessible via JavaScript on the client side.
Types. First-party cookies are set by the website the user is currently visiting and are often used for session management, remembering preferences, and personalization. Third-party cookies are set by domains other than the one being visited, often used by advertisers and analytics services to track behavior across websites.
Security. Cookies can be marked with the HttpOnly flag, making them inaccessible to JavaScript and reducing the risk of cross-site scripting (XSS) attacks. The Secure flag ensures cookies are only sent over HTTPS connections. The SameSite attribute can be used to control when cookies are sent with cross-site requests, helping prevent cross-site request forgery (CSRF).
Local storage is a web storage mechanism that allows websites to store data on a user's device persistently and across sessions. This data remains available even after the browser is closed and reopened. It is used for purposes including user preferences and settings, session management, analytics and tracking, targeted advertising, and data caching.
We filter bids using bid response information stored through local storage. This information is identified by session with an ID that is not linked with any other information that could identify the visitor. Unlike cookies, which are sent with every HTTP request, data stored in local storage is only accessible through JavaScript in the browser and is not automatically shared with servers.
Session storage is another web storage mechanism similar to local storage, but limited to the duration of a page session. Data stored in session storage is only available while the browser tab or window is open; once it is closed, the data is deleted.
Cookies can be set up by the publisher, the Ad-Exchange, or third parties. The Ad-Exchange sets cookies to track user behavior and interactions for ad targeting, frequency capping, and analytics. These cookies build profiles based on data such as browsing behavior, device information, and geographic location, and are typically placed during the bid request process or when a user interacts with a served ad.
First-party cookies: The publisher may set first-party cookies to collect data from users visiting their site, tracking elements such as login sessions, preferences, or analytics. Some of this data may then be shared with demand-side platforms (DSPs) to enhance ad targeting.
Publishers may also integrate third-party scripts such as a header-bidding wrapper into their site, allowing third-party vendors such as Ad-Exchanges to set their own cookies. The wrapper allows various Ad-Exchanges and demand partners to participate in the auction; when these partners bid for ad impressions, they may set cookies through the process or when ads are served.
Cookie syncing: Header bidding wrappers often enable cookie syncing, allowing Ad-Exchanges and demand partners or DSPs to align their cookies to identify users across different platforms. This helps advertisers and platforms recognize users consistently and target them with relevant ads. It involves setting cookies, initiated by the demand partners through the wrapper mechanism.
The legal basis for processing personal data used by publishers and real-time advertising platforms is consent and, under some jurisdictions, legitimate interest.
For publishers operating under the GDPR, the UK GDPR, or any other regime with similar privacy standards, the legal basis is the user's consent. Publishers use a Consent Management Platform to receive and record consent provided by users. When consent has not been given in accordance with applicable regulations, PII is NOT collected or transferred to real-time advertising platforms or advertisers.
When we process and share website users' privacy choices with our partners, we rely on legitimate interest as a legal basis.
We need to process this data in order to respect users' privacy choices and to maintain documented proof that consent has been given for personal data processing. This allows us and our partners to comply with current regulations and benefits users, since their privacy choices are respected. Only the necessary data for this purpose is processed, and privacy choices are not data likely to be considered particularly private.
When users opt out or do not consent to data processing, their privacy choices are not processed or shared.
Data is transferred from publishers to real-time advertising bidding platforms and from there to advertisers. The latter receive pseudonymized and disaggregated data that they cannot relate by themselves to any individual.
Information is encrypted when transferred in order to safeguard privacy and prevent leaks. The real-time advertising platform uses pseudonymization throughout the processing to enforce privacy.
Requests from publishers for advertisers are normally served by data centers in the relevant region. Typically, information is stored on the server closest to where the ad request originated. If a request comes from within the EU, the data is normally stored on a server within the EU.
International transfers of PII are made only to countries with adequate privacy regulations and/or under the protection of standard contractual clauses. Data may also be transferred to competent authorities under applicable regulations.
Dorvan Srl works with the following real-time advertising platforms and partners as data processors. You can review their respective privacy policies via the links below:
The data subject may exercise the rights of access, rectification, and/or erasure where consent is withdrawn. Data subjects may request the restriction of the processing of their data in accordance with applicable law. We and our partners will retain only the data necessary for exercising or defending potential legal claims.
The data subject may contact Dorvan Srl to oppose any decision that may affect their rights, freedoms, or legitimate interests when it is based on an automated decision (e.g., profiling). Data subjects have the right to obtain a direct response from Dorvan Srl and may request the portability of their personal data.
These rights may be exercised by writing to privacy@dorvan.it.
If you do not receive a response from Dorvan Srl, or you consider that it does not satisfy your request, you have the right to lodge a complaint with the data protection authority of your country. In Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it).
We are registered as a vendor in the IAB Europe Transparency and Consent Framework, and we and our partners comply thoroughly with its rules. We strongly believe in providing dynamic transparency to our clients and to internet users.
We may from time to time change our practices regarding the information collected and used for our services. Changes will be reflected in this Privacy Statement. However, if we were to make material changes, those changes would not, without authorization, be applied to information collected prior to the changes.