naughty.bid

Privacy & cookie policy

Effective 2 September 2026 · Covers naughty.bid, the exchange and served advertising

Controller: SONI NETWORK LTD (company number 598519), George Town, Grand Cayman, Cayman Islands, trading as Naughty.bid. Privacy contact: contact@naughty.bid. We process personal data under the Cayman Islands Data Protection Act (2021 Revision) and, where our advertising reaches users there, the EU and UK GDPR. An Article 27 representative for the EEA and UK is appointed and named on request.
We never treat adult browsing as a profile. We do not build interest segments from adult content consumption, do not infer sexual orientation or preference, do not sell or share personal information, and do not operate a cross-site identity graph. Ad-request data is used to select, cap and verify an ad, then aggregated.

1. Data we process

Category
Purpose & basis
Retention
Partner staff account details
Operating the exchange — contract
Account + 24 months
KYC and verification files, including performer-record attestations
AML, sanctions and content-compliance duties — legal obligation
7 years after exit
Bid-request data: IP, user agent, GEO, device, zone, page category
Ad selection, capping, fraud detection — legitimate interests / consent where required
IP 14 days; aggregates 25 months
Capping and click identifiers
Frequency caps and attribution — legitimate interests / contract
30 days / 90 days
Push subscription endpoints, received via publishers
Delivering push campaigns — consent obtained by the publisher
Until unsubscribe + 30 days
Content reports and takedown correspondence
Investigating reports, legal record — legal obligation
7 years
Payment, wallet and payout data
Settlement and accounting — contract / legal obligation
7 years

Page-category data is used only to match a buyer’s inclusion or exclusion rules for that single auction, and is never retained against an identifier.

2. How visitor data reaches us

Visitor data arrives as part of a bid request from a Supply Partner or an upstream SSP. The publisher is responsible for its own notice and, where the law requires consent, for obtaining it — including a valid TCF signal in the EEA and UK. Where no valid basis is signalled we serve only contextual, frequency-capped advertising.

3. Cookies and identifiers

On naughty.bid we set a strictly necessary session cookie, a CSRF token and a first-party analytics cookie you may decline. In delivery we use a first-party capping identifier with a 30-day lifetime and a click identifier passed to Demand Partner trackers.

We run no ID syncs with data brokers, no fingerprinting for advertising purposes, and no retargeting pools built from adult page views.

4. Recipients and transfers

  • Demand and Supply Partners — aggregate reporting by campaign and zone, not visitor identities
  • Infrastructure, CDN and DDoS providers in the EU, US and Singapore
  • Anti-fraud and device-integrity vendors, acting as processors
  • Payment processors, crypto payment providers, auditors and outside counsel
  • Law enforcement, NCMEC, the Internet Watch Foundation and courts, where legally required or where prohibited material is identified

Transfers out of the EEA and UK rely on standard contractual clauses with the UK Addendum. The Cayman Islands is not the subject of an adequacy decision; the clauses are the mechanism relied upon.

5. Special-category data

Inferences about sex life or sexual orientation are special-category data. We do not derive, store or transmit such inferences, and Demand Partners are contractually prohibited from constructing them from our reporting. Reporting is aggregated so that no individual can be singled out.

6. Automated decision-making

Bidding, floor setting, capping and fraud scoring are automated. Fraud scoring can cause an ad request to be discarded or a partner account to be suspended; suspensions are reviewed by a person on request. No automated decision produces a legal effect on an individual consumer.

7. Your rights

Subject to where you live, you may request access, correction, deletion, restriction, portability, withdrawal of consent, objection to processing based on legitimate interests, and an opt-out of targeted advertising. Write to contact@naughty.bid; we respond within 30 days.

To stop push campaigns, revoke notification permission for the site that requested it; the subscription is deleted at the next delivery attempt. Because bid-request data is not linked to a name, we may ask for the approximate time, GEO and publisher domain to locate any record.

8. Age and minors

The exchange is exclusively for adults and for verified businesses. We do not knowingly process any data relating to a person under 18. Supply Partners must operate age assurance, and inventory identified as reaching minors is disconnected immediately.

9. Security

TLS 1.3 in transit, AES-256 at rest, tokenised payment credentials, hardware-key two-factor authentication for staff, least-privilege access with quarterly review, annual third-party penetration testing, and segregated storage for verification files. Breaches are notified to affected partners and regulators within applicable deadlines, and within 72 hours where GDPR applies.

10. Changes

Material changes are announced in the dashboard and by email at least 14 days before they take effect. The effective date above reflects the current version; earlier versions are archived and available on request.