Legitimate Interest Claim

Gonnaclick Pte. Ltd. · IAB Europe Transparency & Consent Framework
Last updated: 21 August 2026

This document sets out the legitimate interests on which Gonnaclick Pte. Ltd. (“Gonnaclick”, “we”) relies under Article 6(1)(f) GDPR, and summarises the balancing test carried out for each. It is published in support of our registration on the IAB Europe Global Vendor List and should be read together with our Privacy Policy.

1. Who we are and what we do

Gonnaclick Pte. Ltd. is a company registered in Singapore (112 Robinson Road #03-01, Robinson 112, Singapore 068902). We operate a server-side programmatic advertising system — a demand-side bidder and an ad exchange, marketed under the product brand ClickSage.

We receive OpenRTB bid requests from supply-side platforms and publishers, decide whether to bid, and measure the outcome of the advertising we buy. We operate no consumer-facing product, no browser tag and no mobile SDK. We never interact with a data subject directly; every item of personal data we process is transmitted to us by a supply partner in a bid request or by an attribution partner in a conversion postback.

2. Categories of data

The data we process is pseudonymous and limited to what an OpenRTB bid request contains:

We do not process precise geolocation, and our systems contain no field capable of storing it. We do not process names, e-mail addresses, postal addresses, telephone numbers, authentication-derived identifiers, or any special category of data within the meaning of Article 9 GDPR. Our contracts with supply partners prohibit the transmission of such data to us.

3. Purposes for which we rely on legitimate interest

TCF purposeOur interestWhy the processing is necessary
Purpose 2
Use limited data to select advertising
Selecting an advertisement that fits the ad slot, and limiting how often the same advertisement is shown to the same device. An advertising system cannot fill an ad slot without deciding which advertisement to place in it. Frequency capping additionally requires a pseudonymous counter per device, and exists to reduce — not increase — the number of advertisements a person sees.
Purpose 7
Measure advertising performance
Determining whether an advertisement was delivered, seen, clicked or led to a conversion, so that advertisers are billed correctly and publishers are paid correctly. Advertising is bought and sold on measured outcomes. Without measurement there is no basis on which to invoice, to reconcile accounts with supply partners, or to detect billing discrepancies. Attribution is deterministic, using a click identifier we issued ourselves; we do not fingerprint devices.
Purpose 9
Understand audiences through statistics
Producing aggregated reporting on delivery and performance for our advertiser and publisher customers. Reports are aggregate and are not used to make decisions about any individual. Individual-level records are not exposed to customers.
Purpose 10
Develop and improve services
Training and calibrating our bidding, pacing, budget-control and yield models on historical bidding and outcome data. Bid pricing models are trained on the outcomes of past auctions. This is a statistical exercise over aggregate historical data; the output is a pricing model, not a record about a person.
Special Purpose 1
Ensure security, prevent and detect fraud, and fix errors
Detecting invalid traffic, bot activity and misdeclared inventory; protecting the integrity of our systems and our customers' budgets. Invalid traffic detection is a direct financial protection for advertisers and is expected of any participant in the programmatic supply chain. It is also required of us contractually by our supply partners.
Special Purpose 2
Deliver and present advertising
Transmitting the winning advertisement to the device and recording that it was delivered. Technically unavoidable: an advertisement cannot be delivered without processing the request that carries it.
Special Purpose 3
Save and communicate privacy choices
Reading the privacy signals attached to a bid request, acting on them, and passing them unaltered to any downstream buyer we forward the opportunity to. A privacy choice is only effective if it travels with the request. Forwarding the TCF consent string and regulatory flags unmodified is what allows a downstream party to honour the same choice.

4. Balancing test

4.1 Necessity

For each purpose above we considered whether a less intrusive means would achieve the same result. Our conclusions:

4.2 Reasonable expectations

A person using an ad-supported app or website can reasonably expect that the advertising slot is filled by an automated auction, that the advertiser will learn whether the advertisement was delivered and clicked, and that fraudulent traffic will be filtered out. Purposes 2, 7, 9, 10 and Special Purposes 1 and 2 fall within that expectation.

We consider that profiling for personalised advertising does not. Accordingly we do not rely on legitimate interest for Purposes 3 and 4 — we rely on consent, and where consent is absent we do not bid at all.

4.3 Impact on the individual, and the safeguards that limit it

The impact is low: the data is pseudonymous, is not used to make any decision with legal or similarly significant effect, and is not used to determine access to any service, price or opportunity outside advertising. The following safeguards are enforced in our bidding system before a bid is formed, so a suppressed opportunity generates no record at all:

SignalOur behaviour
device.lmt = 1 (Limit Ad Tracking)We do not bid.
device.dnt = 1 (Do Not Track)We do not bid.
regs.coppa = 1We do not bid. We never bid on child-directed traffic.
regs.ext.gdpr = 1 with no TCF consent stringWe do not bid.
TCF consent string present but Purpose 1 not grantedWe do not bid.
TCF consent string present but undecodableWe do not bid. Every gate fails closed; an ambiguous signal is treated as an objection.
regs.ext.us_privacy with opt-out of sale assertedWe do not bid.

The device-level opt-out check is evaluated before any dependency on the regulatory object, so a request carrying a limit-ad-tracking flag but no regulatory object is still suppressed. Where an opportunity is forwarded to a downstream buyer and a device-level restriction is asserted, device identifiers and the user identifier are stripped and location is truncated before transmission.

These behaviours are covered by automated tests that run on every build, including a regression test that prevents the device opt-out check from being reordered behind the regulatory-object check.

4.4 Retention

DataRetention
Raw host logs2 hours to 2 days
Audience segment membership30 days, garbage-collected by day 60
Frequency-capping countersDaily and hourly counters, expiring with the period
Bid, impression, click and conversion records in object storageTiered lifecycle, deleted at 365 days

4.5 Conclusion

Having weighed our interests against the interests, rights and freedoms of data subjects, we consider that our legitimate interests are not overridden for Purposes 2, 7, 9 and 10 and for Special Purposes 1, 2 and 3, given the pseudonymous and limited nature of the data, the absence of precise location and cross-device linking, the short retention periods, and the fail-closed opt-out handling described above. We reached the opposite conclusion for profiling and personalised advertising, for which we require consent.

5. Your right to object

You have the right under Article 21(1) GDPR to object at any time to processing based on legitimate interest. You can exercise it in any of the following ways:

You also have the right to request erasure. We operate a data-subject erasure endpoint that removes a given identifier from audience segments and frequency-capping state. See our Privacy Policy for the full description of your rights and how to exercise them.

6. Contact

ControllerGonnaclick Pte. Ltd., 112 Robinson Road #03-01, Robinson 112, Singapore 068902
Privacy contactprivacy@gonnaclick.com — monitored by Frank Huang, Chief Operating Officer (frank@gonnaclick.com), who is the data protection contact named in our partner data processing agreements
Lead supervisory authority for complaints concerning our EEA supply partnersDer Hamburgische Beauftragte für Datenschutz und Informationsfreiheit — mailbox@datenschutz.hamburg.de

You may lodge a complaint with the supervisory authority in your country of residence or place of work.