Legitimate Interest Claim

SofiaPulse Robots Inc. ·

1. Purpose of this page

This page sets out the legitimate interests SofiaPulse Robots Inc. (“SofiaPulse”) relies on under Article 6(1)(f) of the General Data Protection Regulation (GDPR), the assessment SofiaPulse has carried out to justify that reliance, and the right to object.

It is published so that users, publishers, advertisers, and supervisory authorities can see precisely what SofiaPulse processes, why, and on what basis. It sits alongside the SofiaPulse Privacy Policy and processor list.

2. Summary of SofiaPulse’s position

SofiaPulse operates no tracking infrastructure. It holds no identifier for any user and sets nothing on any device. It retains a record of each delivery and interaction event for reporting, containing no identifier and no personal data, as described in section 5.

This is a matter of system design rather than of retention policy. There is no identifier graph to disclose, no profile to delete, and nothing in SofiaPulse’s systems that can be attributed to a person. SofiaPulse’s position is not that its retention of personal data is proportionate to purpose, but that it holds no personal data about the people to whom its advertisements are shown.

SofiaPulse does not operate systems that track users, and does not operate systems whose sole function would be to record that fact. The absence of retention is itself the safeguard.

SofiaPulse states this as a description of what its systems do. It does not follow, and SofiaPulse does not assert, that Article 5(3) of the ePrivacy Directive is inapplicable to it. SofiaPulse acts on the objection and preference signals it receives, as set out in section 10, and does not rely on the absence of device storage as a reason not to.

The sections that follow set out the application of this position to each purpose relied upon, and its effect on the exercise of data subject rights.

3. Who SofiaPulse is

SofiaPulse Robots Inc. is a company incorporated in Quebec, Canada, operating advertising delivery, dynamic creative optimisation, and campaign measurement infrastructure on behalf of advertisers and their agencies.

ControllerSofiaPulse Robots Inc.
Registered address415 Rue des Récollets, Suite 101, Montréal, QC H2Y 1W3, Canada
Privacy contact[email protected]
Person in charge of the protection of personal informationYousef Younes, Chief Executive Officer
Representative in the European Union (Article 27 GDPR)Cloudkasten GmbH, Seestraße 20 G, 50374 Erftstadt, Germany — [email protected]

SofiaPulse acts as a controller in respect of the processing described on this page, and relies on it where it is established as a vendor for legitimate interest in the record transmitted with an ad request.

Where it is not so established, SofiaPulse does not rely on this claim at all. It acts as a processor, on the documented instructions of the advertiser or agency whose campaign is being delivered and under the legal basis that party has established, and that party’s own notice governs. This page describes only the first of those two positions.

4. Purposes claimed under legitimate interest

In connection with advertising, SofiaPulse relies on legitimate interest for the following processing activities, and for nothing else. The right-hand column gives the corresponding purpose in the IAB Europe Transparency and Consent Framework, so that the claim made here can be read against the signal SofiaPulse receives.

ActivityBasisFramework purpose
Selecting advertising using limited dataLegitimate interestPurpose 2
Measuring advertising performance in aggregateLegitimate interestPurpose 7
Ensuring security, preventing and detecting fraud, and fixing errorsLegitimate interestSpecial Purpose 1
Delivering and presenting advertising to the deviceLegitimate interestSpecial Purpose 2

SofiaPulse does not carry out any other processing of personal data in connection with advertising. In particular it does not create personalised advertising or content profiles, does not select advertising or content on the basis of a profile, does not process precise geolocation data, does not scan device characteristics for identification, does not measure content performance, does not conduct audience research combining data from different sources, and does not develop or improve products or services using personal data. SofiaPulse makes no claim under Purposes 3 to 6, for which legitimate interest is in any event not an available basis under the framework.

Delivery to the device is the technically unavoidable precondition of serving any advertisement at all. The security and fraud work is not performed on a request as it is handled: it is applied afterwards to the records SofiaPulse has written, as described in section 6. Both arise only in respect of advertisements SofiaPulse serves. Advertising selection and performance measurement are subject to the right to object described in section 9; where an objection is recorded, SofiaPulse serves nothing.

5. What data SofiaPulse processes

SofiaPulse’s processing is deliberately narrow. For each ad request SofiaPulse receives:

SofiaPulse does not:

Treatment of IP addresses

An IP address is necessarily received in order for any content to be returned to a device. On receipt SofiaPulse derives a geographic area — country, region and city. Nothing finer is derived: no postal code, no coordinates and no accuracy radius, notwithstanding that the licensed database returns such values in the same lookup, and no device-based location signal of any kind. The IP address is used in memory for that derivation and for the technical routing of the response, and is then discarded. It is not written to SofiaPulse’s persistent storage, not present in SofiaPulse’s application logs, and not available for any later processing.

The derivation happens at two points. It is performed at the edge when the advertisement is selected and when the creative assets and data forming part of it are returned, on the infrastructure handling the request — for a request originating in the EEA, at an EEA edge location — and again in the Montréal region when a delivery or interaction event is recorded, so that aggregate reporting can be broken down by market. In both cases it is performed by SofiaPulse’s own software against a licensed geolocation database held locally on the infrastructure named in the SofiaPulse processor list. The database is licensed reference data, not a service: its supplier receives no personal data and is not a processor, and so does not appear on that list. The address is used in memory and discarded at each point and is not carried between them. No IP address is sent to any third-party geolocation service, and the database supplier receives no personal data.

As with any internet service, SofiaPulse’s infrastructure providers necessarily see IP addresses in order to route traffic and process them in their own operational and security logs under their agreements with SofiaPulse. Those logs are not used for advertising purposes and are not joined to any SofiaPulse dataset.

The resulting value names a city. It is not a precise location, not a household, and not sufficient to identify an individual. It does not amount to precise geolocation data within the meaning of Special Feature 1 of the Framework, which SofiaPulse does not declare and does not process.

SofiaPulse recognises that an IP address is personal data under GDPR notwithstanding that it is not retained, and this assessment is made on that basis.

Treatment of the page address

SofiaPulse does not receive the full address of the page. It receives the sanitised address supplied by the party serving the creative, in practice the demand-side platform, from which the query string is expected to have been removed before transmission. SofiaPulse uses that value as received; it has no other route to the page address and does not attempt to obtain a fuller one.

SofiaPulse states this precisely because the distinction matters. Query strings are written by publishers and routinely carry search terms, account numbers and identifiers never intended for downstream recipients. Their removal upstream is the reason SofiaPulse does not encounter such information, and SofiaPulse does not represent that removal as something it performs itself.

From the address SofiaPulse uses only the domain, and only as a dimension of the aggregate delivery and performance counts described under Purpose 7, so that an advertiser can see how a campaign performed across the publishers it ran on. It plays no part in selecting the advertisement, which is selected on geographic area alone, and it is not retained against any individual request.

What is retained

SofiaPulse writes a record of each delivery and interaction event. The record holds the campaign, creative and format, the publisher domain, the geographic area (country, region and city), the device type, brand, model and browser derived from the user-agent string, and the type of event. It holds no identifier for any person, no IP address and no user-agent string, and SofiaPulse holds nothing elsewhere against which such a record could be resolved to a person.

Each record carries the identifier of the client on whose behalf the advertisement was served — the advertiser or agency, not any person. The records are segregated by client at the level of the record itself. They are not pooled, not combined across clients, and not used to build anything that serves SofiaPulse independently of the client whose campaign produced them; and every record relating to a client’s campaigns can be located and deleted on that client’s instruction.

These records are retained so that aggregate views of a client’s own campaigns can be recompiled as that client asks different questions of them, and for as long as that remains useful to the client or until the client instructs otherwise. SofiaPulse retains them on the basis that they contain no personal data: nothing in a record identifies an individual, and SofiaPulse has no identifier, no device state and no other dataset by which one could be identified from it.

Treatment of the user-agent string

The user-agent string is parsed at the moment of the request into device type, device brand and model, and browser. Those values serve one purpose: they are dimensions of the aggregate performance counts described under Purpose 7, so that an advertiser can see how a campaign performed across devices and browsers. They play no part in selecting the advertisement.

The string is used in memory for that parsing and is not retained, and SofiaPulse does not retain it alongside any other request attribute. What survives is a count against a combination of dimensions, from which no individual request can be recovered.

Device storage disclosure

SofiaPulse publishes a machine-readable disclosure of its device storage and of the domains it operates, at:

https://privacy.sofiapulse.com/vendor-device-storage-disclosure.json

Its storage list is empty. This is not an omission. It is a complete statement that SofiaPulse accesses no client-side storage of any kind: no cookies, no localStorage, no sessionStorage, no IndexedDB, no shared storage, no Protected Audience API participation, and no mobile SDK.

SofiaPulse additionally disables cache validators, including entity tags, on its ad, tag, and event endpoints, so that no value is written to or returned from a browser cache in a form capable of re-identifying a device. SofiaPulse’s tags execute no script that queries device properties such as screen dimensions, installed fonts, canvas output, or timezone.

6. SofiaPulse’s legitimate interests

Selecting advertising using limited data. SofiaPulse has a legitimate interest in selecting advertising that is relevant to the broad market in which it is served. Geographic relevance is a baseline requirement of lawful and useful advertising: it prevents the delivery of offers unavailable in the user’s country, ensures language appropriateness, and allows compliance with jurisdiction-specific advertising rules — including, in regulated categories such as pharmaceutical advertising, restrictions that vary materially between markets.

Measuring advertising performance. SofiaPulse has a legitimate interest in measuring, in aggregate, whether the advertising it delivers was in fact delivered and how it performed. Advertisers are contractually and commercially entitled to verified delivery counts; publishers are entitled to be paid accurately for inventory served; and aggregate measurement is a condition of detecting misdelivery and of billing integrity across the supply chain.

Security, fraud prevention, and error correction. SofiaPulse has a legitimate interest in ensuring that advertisers are not billed for invalid, duplicate or fraudulent impressions and that publishers are not credited for them. This interest is shared with advertisers, publishers, and users, all of whom are harmed by undetected fraud.

SofiaPulse states plainly how this is done, because the ordinary implication of the phrase would be wrong. SofiaPulse does not evaluate a request for fraud as it is handled: nothing is scored, blocked or refused in real time on that basis, and an invalid request is served and recorded like any other. The work is applied afterwards to the delivery and interaction records described in section 5 — when those records are aggregated, records judged duplicative or fraudulent are excluded from the counts supplied to advertisers and publishers.

Two consequences follow, and both favour the data subject. No additional data is collected for this purpose and no additional record is written for it: the input is the same set of records SofiaPulse already writes for measurement, so this interest adds nothing to what is processed. And because no request is scored or refused as it is handled, no individual is subjected to a real-time assessment of any kind. Network-level protection against automated and abusive traffic is operated by SofiaPulse’s infrastructure providers, as by any hosting provider, and independently of SofiaPulse.

Delivery and presentation. SofiaPulse has a legitimate interest in transmitting the requested creative to the device and rendering it correctly at the appropriate size and format. This is the irreducible technical operation without which no advertising, and no ad-funded content, can be provided at all.

These interests are also, in part, the interests of the advertisers and publishers SofiaPulse serves, and of users who access ad-funded content without payment.

7. Necessity

For each purpose SofiaPulse has considered whether the outcome could be achieved by less intrusive means.

An IP address cannot be avoided: it is a precondition of any network response and is received before any processing decision is possible. The question is therefore not whether to receive it but what to do with it.

Having received it, SofiaPulse derives a geographic value and discards the input. That value extends to city. SofiaPulse has considered whether it could stop at country or region and has concluded that it could not: a substantial part of the advertising it delivers is bought for a local catchment — a retailer, a dealership, a venue, a service with a physical trading area — and cannot be selected at all on a national value, and an advertiser who buys a city campaign is entitled to see whether it was in fact delivered in the cities paid for. A city is also the level at which the market-appropriateness and local-advertising-rules considerations described in section 6 actually operate in the markets where those rules are set below national level.

SofiaPulse derives nothing finer than a city. It derives no postal code, no coordinates and no accuracy radius, notwithstanding that the licensed database returns such values in the same lookup and they are discarded unread. It does not use device-based location signals, and no code path in its systems reads them. The derived value is not precise geolocation data within the meaning of Special Feature 1 of the Framework: SofiaPulse does not declare that Special Feature and does not process such data.

For measurement, aggregate counting of delivery events is sufficient for the stated purpose. Measurement techniques that would require a persistent identifier — frequency capping, cross-site deduplication, view-through attribution, unique reach — are more intrusive, and SofiaPulse does not perform them. SofiaPulse considers that no less intrusive alternative exists that would achieve these purposes, and that it has adopted the least intrusive form of each.

8. Balancing

SofiaPulse has weighed its interests against the interests, rights, and freedoms of users.

Impact on the individual. The processing produces no persistent record of any individual. Because no identifier is assigned and nothing retained can be attributed to a person, the processing cannot be used to recognise a user on a later occasion, to build a profile, to infer characteristics, or to differentiate treatment between individuals. Any given ad request is, after delivery, indistinguishable in SofiaPulse’s systems from any other request sharing the same city, publisher domain, device and browser. SofiaPulse states that at the level at which it is true rather than at country level: the record is narrower than a national one. What it does not become is linkable — no identifier is written, so two records sharing every one of those values cannot be established to concern the same person, the same household or the same device, and SofiaPulse holds no other dataset by which they could be.

Reasonable expectations. A user accessing an ad-funded page or application can reasonably expect that the content will be transmitted to their device, that it will be appropriate to the area they are in — including advertising for businesses that trade in their city — and that the parties involved will count what was delivered. SofiaPulse’s processing does not extend beyond what is required for those expectations to be met. It does not involve the tracking, profiling, or cross-context data combination that has been the principal subject of regulatory concern in relation to legitimate interest in the advertising sector.

Sensitive data and vulnerable groups. SofiaPulse does not process special category data under Article 9, and does not infer or target on the basis of health, political opinion, religion, sexual orientation, or any other special category. Where creative relates to a regulated category such as pharmaceuticals, the creative itself is delivered contextually; SofiaPulse does not infer any health characteristic of any user. SofiaPulse does not knowingly direct processing at children and does not process data for the purpose of advertising to children.

Safeguards. The safeguards are structural rather than procedural: the data that would be required to cause the relevant harms is never retained, so it cannot be re-purposed, breached, requested by a third party, or accumulated over time. To these SofiaPulse adds the consent and preference handling described in section 10, so that a user’s expressed objection takes effect notwithstanding that SofiaPulse holds nothing about them.

International transfer

Ad delivery takes place on globally distributed edge infrastructure, and a request originating in the EEA is served from EEA infrastructure. The geographic derivations carried out when the advertisement is selected and when its creative assets are returned therefore ordinarily also take place within the EEA. The derivation carried out when a delivery or interaction event is recorded is performed in the Montréal region of SofiaPulse’s cloud provider’s infrastructure.

Two situations must be distinguished.

The transmission of an ad request by a user’s device in the EEA or the UK to SofiaPulse is not a transfer within the meaning of Chapter V. The data is made available by the data subject’s own device, and there is no exporter. This follows the European Data Protection Board’s guidance on the interplay between Article 3 and Chapter V. The processing remains fully subject to the GDPR by virtue of Article 3(2).

The disclosure by SofiaPulse of personal data to a service provider established outside the EEA or the UK is a transfer, and SofiaPulse is the exporter. Each such transfer is made under an Article 45 adequacy decision where the provider holds a current EU–US Data Privacy Framework certification, or otherwise under the Standard Contractual Clauses in Implementing Decision (EU) 2021/914 with the UK International Data Transfer Addendum, supported by a transfer impact assessment. The mechanism relied on for each provider is stated in the processor list, and is determined by the provider’s legal entity rather than by the location of its infrastructure. A Canadian processing region does not place a United States entity under Canadian law, and the adequacy decision for Canada is not relied on for any such provider.

The data transferred in the course of ad serving is an IP address that is discarded on receipt and retained in no jurisdiction.

Conclusion. SofiaPulse considers that its interests are not overridden by the interests or fundamental rights and freedoms of users, and that legitimate interest is an appropriate basis for the purposes listed in section 4.

9. The right to object

Data subjects have the right under Article 21(1) GDPR to object at any time to processing carried out on the basis of legitimate interest. Where processing is for direct marketing purposes, Article 21(2) gives an unqualified right to object, and SofiaPulse does not weigh that objection against its own interests: an objection recorded against advertising selection or performance measurement is given effect without further assessment.

Through a preference signal. Where the publisher or application in use operates a consent or preference management tool that passes an objection to SofiaPulse in the ad request, that objection is honoured in full: SofiaPulse serves no advertisement at all. Nothing is selected, no geographic area is derived from the IP address, and no record is written.

SofiaPulse does not fall back to delivering the advertisement on an advertiser’s instruction in that case. An objection is directed at SofiaPulse, and SofiaPulse treats it as decisive for its own participation, whatever it has been instructed to do. That is a stronger effect than an objection to a single legal basis would strictly require, and it is deliberate: a person who has been shown SofiaPulse’s entry and declined it should not then encounter its advertisement delivered under another party’s basis.

This is distinct from the case where SofiaPulse was never disclosed at all, described in section 10, where nobody was asked and nothing was declined.

An objection therefore removes SofiaPulse from the request entirely, not merely from one legal basis for it.

An objection is directed at processing that would otherwise recur, rather than at data SofiaPulse holds, because SofiaPulse holds none. Its effect is that SofiaPulse relies on legitimate interest for nothing on any subsequent request.

SofiaPulse keeps no record that an objection has been made, and needs none. The preference management platform transmits the objection with each request, so it is given effect on every occasion without SofiaPulse storing an identifier for the person who made it. An opt-out held in a list would require retaining data about a data subject for the sole reason that they asked SofiaPulse to stop.

Directly. An objection may also be sent to SofiaPulse at [email protected]. SofiaPulse will respond. The scope of that response is limited: SofiaPulse holds no identifier, and nothing it retains can be attributed to a person, so there is no past processing to locate, restrict, or halt. In substance the objection has already been given effect by the absence of retention. The preference signal described above is the mechanism by which future processing is affected.

10. Objection and preference signals

SofiaPulse relies on legitimate interest under Article 6(1)(f) for everything it declares in connection with advertising, and does not itself ask any user for consent. Whether the ePrivacy rules on terminal equipment additionally require consent for an ad call is not a question SofiaPulse seeks to settle in its own favour: it stores nothing on and reads nothing from the device, and where a publisher’s consent management platform applies a consent model rather than a legitimate interest one, the record it transmits reflects that.

SofiaPulse acts on that record either way. It does not need the point resolved, because it proceeds only where the record establishes it, and serves nothing where it does not.

The publisher’s consent management platform records the user’s choices and transmits them to SofiaPulse with the ad request, in the standard IAB Europe Transparency and Consent Framework parameters. SofiaPulse reads whether it is established as a vendor for legitimate interest, for the purposes it declares, before any processing described in section 5 takes place.

Where SofiaPulse is established as a vendor for legitimate interest in that record, it processes on its own basis as a controller, as described in section 5, and the advertisement is served and counted.

Where it is not established, SofiaPulse distinguishes two situations, and treats them differently.

Where an objection has been recorded. SofiaPulse was disclosed to the user and the user declined it. SofiaPulse serves no advertisement: nothing is selected, no geographic area is derived, and no record is written. It does not deliver on any other basis, and an instruction from an advertiser does not displace a person’s objection to SofiaPulse.

Where there is no record of SofiaPulse at all — the publisher has not disclosed SofiaPulse, or no valid record was transmitted. Nobody was asked about SofiaPulse and nothing was declined. SofiaPulse does not process on its own basis and applies none of the purposes it declares as a controller. It acts solely on the documented instructions of the advertiser or agency whose campaign is being delivered, as that party’s processor and under the legal basis that party has established. The advertisement is delivered, because delivering it is what SofiaPulse has been instructed to do.

SofiaPulse does not treat the absence of a record as permission to process for its own purposes, and records against each event which of these positions applied.

Where an advertiser’s tracking URL is delivered within a creative, the consent parameters in it are relayed unchanged.

SofiaPulse keeps no record of any user’s choices and no identifier against which one could be stored. The behaviour described here is enforced in code, which SofiaPulse will make available for inspection by a partner or a supervisory authority on request, under appropriate confidentiality terms.

11. Other rights

Data subjects have rights of access, rectification, erasure, restriction, and portability under Articles 15 to 20 GDPR. The same constraint governs all of them.

Article 11 GDPR provides that where a controller does not require identification of the data subject for its purposes, it is not obliged to retain, acquire, or process additional data solely in order to identify a data subject for the purpose of responding to a rights request. That provision describes SofiaPulse’s position. Identification of individuals is not necessary for geographic ad selection or aggregate delivery measurement, and is not performed. SofiaPulse does not collect identifying data, assign identifiers, or maintain lookup infrastructure for the purpose of responding to subject access requests, as doing so would require establishing the identification capability the remainder of this document records the absence of.

In accordance with Article 11(2), SofiaPulse informs any individual making such a request that it is not in a position to identify them, and invites them to provide additional information that would enable identification. In respect of the processing described here there is no such information, because nothing SofiaPulse holds is capable of being linked to a person.

SofiaPulse is therefore able to state completely what is done with data of the kind generated by a device, as set out in this document, but is unable to provide information specific to an individual, as no such information exists in SofiaPulse’s systems.

Data subjects have the right to lodge a complaint with their national supervisory authority.

12. Review and changes

SofiaPulse reviews this assessment at least annually, and on any change to its processing, and will keep it consistent with any disclosures it makes to industry frameworks or advertising partners. The most recent review was 3 September 2026.

DateChange
3 September 2026First publication.