Kliksight
Kliksight (Pty) Ltd · Registration 2026/622670/07 · South Africa

Privacy Policy

Effective 1 September 2026 · Version 1.9 · This page is the privacy policy referred to in Kliksight’s customer agreements.

Kliksight measures whether clicks on online advertising are genuine. We are engaged by marketing agencies and advertisers to detect invalid traffic (clicks generated by bots, click farms, or other non-genuine sources) and to help them pursue advertising credits from the platforms. This policy explains what we process, why, for how long, and what your rights are. It is written for three groups of people, and each section says who it applies to.

Everyone
1. Who we are

Kliksight (Pty) Ltd, a private company incorporated in the Republic of South Africa (registration number 2026/622670/07), with its registered address at Stanley and Dock Road, Cape Town, Western Cape, 8001, South Africa.

Our primary data protection law is the South African Protection of Personal Information Act, 2013 (POPIA). Because our customers and the visitors whose ad-clicks we measure may be anywhere, we also apply the EU and UK GDPR and the applicable US state privacy laws (including the California Consumer Privacy Act) where they reach our processing, and this policy is written to satisfy all of them.

Legal bases at a glance

Where the GDPR or UK GDPR applies (with the POPIA equivalents in brackets): tag collection and measurement rest on your consent, given through the website’s consent mechanism (Art 6(1)(a); POPIA s 11(1)(a)), and the detection processing is performed on our customers’ documented instructions in their legitimate interest in preventing advertising fraud (Art 6(1)(f), Recital 47; s 11(1)(f)). Perimeter firewall logs and website server logs rest on our legitimate interest in securing our services and infrastructure (Art 6(1)(f); s 11(1)(f)). Dashboard accounts and subscriptions rest on contract (Art 6(1)(b); s 11(1)(b)), and record-keeping on legal obligation (Art 6(1)(c); s 11(1)(c)). One-off pre-contract reconciliations (Cold Audits) rest on steps taken at your request before entering a contract (Art 6(1)(b); s 11(1)(b)) and, where the contracting party is a company, on our, the account holder’s and the requesting business’s legitimate interest in evaluating the service against real account data (Art 6(1)(f); s 11(1)(f)).

Our Information Officer is Michael De Sousa, Director, reachable at privacy@kliksight.com or at the registered address above. Our PAIA manual is published on this site at kliksight.com/paia and is also available from the Information Officer on request.

Site visitors
2. Ad-click measurement: what we collect and why

If you click an online advertisement and arrive on a website that uses Kliksight, and you have given the consent described in section 3, our measurement tag reports the arrival to our collection service, which records it as an event. We classify events as valid or invalid. We never classify you: no person and no device is ever labelled fraudulent, and we build no advertising or marketing profile of anyone. Our classifications are reconciled against the advertising platforms’ own invalid-traffic credits, and are used solely to measure traffic quality and support our customers’ claims for advertising credits (we call this the invalid-traffic purpose).

For each consented arrival event we process:

About your raw IP address. It is not stored in our measurement databases. It is accepted by our collection service and held in a transient processing queue only until the derivations above are made (up to 4 days in the ordinary queue and up to 14 days if a message lands in the error queue), after which it is discarded. Separately, like most internet services we operate a perimeter firewall, whose security logs record the IP addresses of requests to our infrastructure and are kept for 90 days.

The Kliksight tag collects nothing without consent, and it is built to fail in your favour. It fires only when the website’s consent mechanism signals that you have granted advertising-storage consent (for example, the ad_storage signal in Google’s consent framework). If consent is absent, denied, or given for analytics only, the tag does not fire and no event is collected. Our servers independently enforce the same rule: an event arriving without an affirmative consent value is rejected. If you withdraw consent, collection stops from that point.

Cookies and your device. The tag sets no cookies and reads none; our cookie policy sets out the full position. It runs as a small script delivered from a content delivery network (your browser may cache the script, as it caches any script), reads the click identifier and consent state from the page context, and transmits the event using standard browser mechanisms (sendBeacon/fetch). After consent, the tag stores one session-scoped marker in your browser’s sessionStorage (a fixed key with the value “1”, containing no identifier), solely to avoid transmitting the same event twice in one session; it is cleared when your browsing session ends. We disclose this because European law treats any storage on your device as significant, whatever the mechanism. Beyond that marker, nothing is written to your device by Kliksight, and no identifier ever is.

Site visitors
4. Automated evaluation: what our detection does and does not do

To classify events, our detection engine evaluates device-level behaviour: the speed, repetition, and location consistency of events over rolling time windows, grouped by the pseudonymised device value described in section 2. In European law terms this is a form of automated profiling, and we say so plainly. What it is not: it is not profiling for advertising, marketing, or content personalisation; it produces no decision with legal or similarly significant effects for any person (the consequences of a classification fall on advertising billing between businesses, not on you); and no natural person is classified as fraudulent. Detection determinations are retained for the periods in section 6.

Site visitors
5. Aggregate, cross-customer data

Kliksight derives aggregate invalid-traffic signals across its customer base: patterns such as the rate of invalid activity from a network or region. These are population-level statistics governed by minimum-population thresholds and suppression rules; no visitor, and no individual customer, is identifiable in them, and they are covered by the de-identification commitment in section 13.

Kliksight may also in future derive aggregate claim outcome intelligence: statistics about which categories of evidence and which claim characteristics tend to succeed when invalid-traffic credit claims are decided by advertising platforms, used to improve how we prepare future claims. This is derived from claim packages once claim preparation comes into operation, contains no personal information and identifies no visitor and no individual customer, and is kept and used only in that aggregate form under the commitment in section 13. Until claim preparation comes into operation no such data is derived, and this policy will be updated when it comes into operation.

Kliksight may in future display aggregate comparative statistics (benchmarks, such as median arrival rates) to customers. That capability comes into operation only on release; until then no such statistics are derived, and this policy will be updated when it comes into operation.

Site visitors
6. How long we keep measurement data

We state our real retention periods rather than a formula. Each class of data is deleted automatically at the end of its period, and the businesses we work for can trigger earlier deletion; section 14 explains how deletion requests are handled.

DataKept for
Raw event data (including click identifier, hashed network values, full user-agent string)90 days
Transient processing queue (includes raw IP pending derivation)Up to 4 days; up to 14 days in the error queue
Daily statistical aggregates (campaign and ad-group level)120 days
Monthly and account-level aggregates; evidence records (aggregate findings supporting invalid-traffic claims, containing no identifiers)2 years
Claim packages (event-level evidence submitted to an advertising platform, once that capability is in operation)The platform’s dispute window plus 60 days, or 60 days after the claim is finally resolved if later
Advertising-platform reporting responses (contain no personal information)Up to 730 days
Perimeter firewall logs (IP addresses of requests to our infrastructure)90 days
Infrastructure audit logs (administrative actions on our cloud estate; no visitor data)365 days

Agency users
7. Customer dashboard accounts

If you use the Kliksight dashboard as a member of one of our customers’ teams, we process your name, work e-mail address, authentication data (including multi-factor authentication enrolment), and activity records, to provide and secure the service, support you, and meet our legal obligations. We retain account data for the life of the account and as required thereafter for legal and accounting purposes. For this data Kliksight acts as the responsible party (controller); for the measurement data in sections 2–6 we act on the instructions of our customers under our data processing agreement.

Agency users
8. Google Ads data (API access)

Where the holder of a Google Ads account connects it (a customer, a prospective customer, or an advertiser for whom a one-off pre-contract reconciliation, a “Cold Audit”, has been requested), Kliksight requests read-only access to the Google Ads API under that account holder’s authorisation, given together with acceptance of the Cold Audit terms presented in the grant flow where applicable. We use that access to retrieve advertising reporting data (campaign and click reporting and invalid-activity credit adjustments) solely to reconcile our measurements against Google’s records, to support customers’ invalid-traffic claims, and, in the case of a Cold Audit, to produce the one-off reconciliation itself. We do not write to the account, and OAuth tokens are stored in a dedicated secrets manager, per connection, and are deleted on disconnection. For a Cold Audit, we read aggregate reporting and invalid-activity credit data only, not click-level records; access is disconnected and the token deleted when the audit is complete; the audit output is provided to the account holder and, where the account holder authorises it in the grant flow, to the requesting agency; and the output is retained by Kliksight for no more than 90 days unless a subscription is concluded.

Kliksight’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Agency users
9. Payments

Subscriptions are sold through Paddle, our merchant of record. When you buy, Paddle processes your payment, billing, and tax information as an independent controller under Paddle’s privacy policy. Kliksight does not receive or store your payment card details; we receive confirmation of the transaction and the billing information needed to administer your subscription.

Website visitors
10. Visitors to this website

kliksight.com currently sets no cookies of its own, as set out in our cookie policy; if that changes, for example when checkout or analytics are introduced, this section will be updated, and any consent required will be obtained, before it does. When you browse kliksight.com, our infrastructure records standard server and security logs (your IP address, the pages requested, and your browser’s user-agent) for security and operations, retained per section 6. If you e-mail us or submit a contact request, we process what you send us to respond, and retain the correspondence for as long as the enquiry and any follow-up requires.

Contact form. More specifically: if you send us an enquiry through the contact form on this site, we collect the name and e-mail address you give us, together with any details you choose to add about your agency, your clients’ verticals, the advertising platforms you use and the number of ad accounts you manage. We process this on the basis of our legitimate interest in responding to your enquiry, and use it for nothing else. We keep the submission for twelve months and then delete it automatically. It is not shared with anyone outside Kliksight and the service providers listed in section 11.

Everyone
11. Service providers

ProviderRoleNotes
Amazon Web ServicesCloud hostingAll storage and regional processing in the US (us-east-1); content-delivery edge locations worldwide for the public website; North America, Europe and Israel for the measurement tag (section 12)
DB-IPGeolocation databaseDownloaded and used locally; no IP address is ever sent to DB-IP. Attribution: IP geolocation by DB-IP, licensed under CC BY 4.0
GoogleAdvertising platform integrationRead-only Google Ads API access under customer authorisation (section 8)
PaddleMerchant of recordIndependent controller for payment data (section 9)
ZohoBusiness e-mailProcesses correspondence you send to our e-mail addresses

Everyone
12. Where data is processed

Measurement data is stored and processed in the United States (AWS region us-east-1). The content delivery network serving the tag terminates requests at the edge location nearest you (in North America, Europe or Israel) with no storage of event content at the edge. For transfers out of the EEA and UK we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, incorporated in our customer data processing agreement; transfers from South Africa are made under section 72 of POPIA on the basis of binding contractual protections. A copy of the relevant safeguards is available from the Information Officer.

Everyone
13. Our de-identification commitment

This is Kliksight’s public commitment for the purposes of the US state privacy laws, including Cal. Civ. Code § 1798.140(m): where Kliksight creates, derives, or receives de-identified or aggregate data, we maintain and use it only in de-identified form; we do not attempt to re-identify any individual from it, except controlled testing conducted solely to confirm that our de-identification works, whose results are used only to strengthen our safeguards; we take reasonable measures to ensure it cannot be associated with any individual or household; and we contractually oblige any recipient to the same standard. This commitment applies to the de-identified and aggregate data classes described in this policy as in operation; if further derived-data classes come into operation, this policy and this commitment will be updated to address them expressly before they do.

Everyone
14. Your rights

Depending on where you are, you have rights to access, correct, and delete personal information about you, to object to or restrict processing, to data portability, and to lodge a complaint with a supervisory authority. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of under the US state laws, but the rights to know, delete, and correct apply, and we do not discriminate against anyone for exercising them.

Measurement data (sections 2–6): we process it on behalf of the businesses whose advertising is being measured: they are the responsible parties (controllers). Send your request to the business responsible for the website you visited or for its advertising, or to us at privacy@kliksight.com and we will pass it to them and support their response. Deletion, once actioned, removes the relevant data from live systems promptly and from backups within 35 days, and a permanent-erasure option exists that is irreversible by design. Note that most measurement data cannot be linked back to you by us at all, which also means that for some requests we are unable to identify which events, if any, relate to you; where that is so, we will say so rather than guess.

Account, payment, and website data (sections 7–10): contact us directly at privacy@kliksight.com.

Complaints: in South Africa, the Information Regulator (inforegulator.org.za); in the EEA or UK, your national data protection authority or the ICO; in the US, your state attorney general or, in California, the California Privacy Protection Agency.

Everyone
15. Children

Kliksight’s services are business tools and are not directed at children. Our customer agreements prohibit deployment of the tag on services directed at children, and we do not knowingly process children’s personal information. If you believe we have done so, contact the Information Officer and we will delete it.

Everyone
16. Security

We protect personal information with encryption in transit and at rest, least-privilege access controls per function, with deployment via single sign-on using short-lived credentials and no static access keys, multi-factor authentication on all administrative access, per-customer tenant isolation, pseudonymisation in our processing pipeline, an allowlist that prevents personal information from entering application logs, automated integrity alarms on our processing pipeline, and internal verification exercises that test our published claims against the running system. Details are set out in our customer data processing agreement.

Everyone
17. Changes and contact

We will post any changes to this policy on this page with a new effective date and version number, and material changes will be notified to our customers. Questions, requests, and complaints: privacy@kliksight.com, or write to the Information Officer, Kliksight (Pty) Ltd, Stanley and Dock Road, Cape Town, Western Cape, 8001, South Africa. Our PAIA & POPIA manual sets out how to make a formal request for access to records.