US Data Privacy Addendum
Keynes operates as a data transmission layer and campaign performance analyzer. Our service captures transaction metrics, optional product arrays, real-time site interaction signals, and privacy-compliant identity hashes (SHA-256 Hexadecimal and Base64 strings) for secure, immediate pass-through transmission to the Controller’s designated downstream Demand-Side Platforms (DSPs). For reporting purposes, Keynes ingests campaign performance logs from integrated downstream platforms and combines them with a proprietary, pseudonymous identifier (anon_id) generated on the client’s digital properties. Additionally, pseudonymous site-traffic telemetry is compiled and forwarded to an external third-party partner to support lookalike audience segment creation for campaign targeting. These data points are processed solely to aggregate programmatic campaign performance analytics, eliminate redundant data records via transaction deduplication, mitigate attribution fraud, and evaluate pipeline uptime. Keynes handles data on a transient or aggregate basis and does not independently maintain raw customer profiles, perform internal identity resolution, or own customer CRM data.
This US Data Privacy Addendum (the “DPA”) supplements and is made a part of the Agreement between Keynes Digital, Inc. (“Media Company”) and the Advertiser identified on the Media Company Insertion Order (“IO”). Media Company and Advertiser are collectively referred to as the “Parties” and each individually referred to as a “Party.” To the extent there is any conflict between this DPA and the Agreement, this DPA will control with respect to Advertiser Personal Information.
1. Definitions
Unless otherwise defined herein, all capitalized terms are as defined in the Agreement, the IO, or Applicable Laws.
- “Advertiser Personal Information” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to any natural person, household, or device, and that is collected, received, stored, processed, or otherwise used by Media Company in providing services to Advertiser under the Agreement and IO (the “Services”). The term Personal Information includes “Personal Data” and similar terms as defined under Applicable Laws.
- “Applicable Law(s)” means all applicable United States federal and state privacy and data protection laws and regulations.
- “Security Incident” means any actual or suspected unauthorized access to, misuse of, misappropriation of, disclosure of, damage to, loss of, or inability to account for any Advertiser Personal Information; or other compromise of the security, integrity, availability, or confidentiality of Advertiser Personal Information.
- “Subcontractor” means any entity or individual engaged by Media Company to assist in fulfilling Media Company’s obligations under the Agreement or this DPA.
2. Relationship of the Parties
Advertiser is a Controller / Business with respect to Advertiser Personal Information. Media Company is a Third Party with respect to Advertiser Personal Information.
3. Purpose of Processing
The purpose of Media Company’s Processing of Advertiser Personal Information is to provide certain advertising-related services as specified in the Agreement and the IO, including:
- Displaying advertising on behalf of Advertiser.
- Building advertising audiences and tracking events.
- Conducting analytics related to advertising and conversions.
- Generating aggregate data, statistics, and reports.
The nature of the Processing includes:
- Processing data collected and transmitted by pixels and other tracking technologies placed on Advertiser’s websites and other digital properties.
- Collecting and storing Personal Information.
- Analyzing Personal Information.
- Aggregating Personal Information.
Please see Exhibit 1. Data Dictionary & Technical Definitions for more details.
4. Compliance with Applicable Laws
Media Company shall comply with the Applicable Laws during the course, scope, and performance of the Agreement. Advertiser shall have the right to take reasonable and appropriate steps to confirm Media Company’s compliance with its obligations under this DPA and the Applicable Laws, which shall be satisfied by Media Company making available to Advertiser appropriate information and documents as evidence of its compliance. Media Company shall notify Advertiser if Media Company determines that it can no longer meet its obligations under this DPA or Applicable Laws, or if Media Company determines that Advertiser’s instructions for Processing Personal Information would violate Applicable Law. Upon such notice, Advertiser shall have the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information by Media Company.
5. Minimum Security Requirements
Taking into account the state of the art, implementation costs, the nature of Advertiser Personal Information, and processing risks, Media Company has implemented and will maintain appropriate technical and organizational measures intended to preserve the security, integrity, availability, confidentiality, and resilience of Advertiser Personal Information.
6. Subcontractors
Media Company acknowledges that the restrictions and obligations under the Applicable Laws, this DPA, and the Agreement apply even if Media Company uses Subcontractors in the operation of its business. When Media Company engages a Subcontractor, Media Company shall enter into a written agreement with the Subcontractor that imposes obligations on such Subcontractor that are at least as restrictive as those imposed on Media Company under this DPA.
7. Consumer Requests
When required by Applicable Law, Advertiser will inform Media Company of consumer requests that require Media Company’s compliance. Upon notice to Media Company from Advertiser, Media Company will timely carry out any deletion requests relating to Advertiser Personal Information within Media Company’s systems and records.
Advertiser represents and warrants that it has provided any legally required notices to users, obtained any legally required consents from users, and implemented any legally required opt-out mechanisms for users for any data provided by Advertiser in connection with Media Company’s services, and that it will not provide any data related to an individual who has exercised an option to opt out of targeted advertising, cross-contextual behavioral advertising, Sales of Personal Information, Sharing of Personal Information, or any other opt-out option that Advertiser has committed to honoring.
Exhibit 1. Data Dictionary & Technical Definitions
Keynes enforces strict privacy-by-design and data minimization principles throughout its architecture. Keynes acts as a secure processing bridge—passing obfuscated identifiers to downstream Demand-Side Platforms (DSPs) and aggregating performance logs for campaign measurement.
Keynes Data Fields
| Data Field | Required | Technical Description | Functional Purpose in Campaign Performance Analysis |
|---|---|---|---|
adv |
Yes | The unique account token assigned to the client. | Account Routing: Maps incoming performance events to the client’s specific ad account. |
kadv |
Yes | A secondary tracking identifier. | System Redundancy: Validates routing metrics and prevents cross-client data leakage. |
event |
Yes | The specific action type logged (e.g., “purchase”, “lal_visitor”). | Action Classification: Categorizes site interaction signals to structure performance funnel analytics. |
source |
Yes | The origin pipeline indicator (e.g., “shopify”, “web”, “server”). | Pipeline Identification: Notes whether the performance log originated from an automated platform integration, client-side script, or server API. |
order_id |
No | The unique alphanumeric transaction key generated by the e-commerce engine. | Transaction Identification: Used as a transient key to verify unique sales records against downstream DSP performance logs for purchase events. |
value |
No | The total monetary gross revenue of the order. | Performance Measurement: Quantifies transaction totals to calculate aggregate Return on Ad Spend (ROAS) within performance reporting for purchase events. |
currency |
No | The 3-letter ISO currency standard identifier (e.g., USD). | Financial Standardization: Normalizes monetary values across multi-currency retail environments for clean reporting on purchase events. |
first_order |
No | A binary flag detailing customer lifecycle history (“1” = new, “0” = returning). | Cohort Segmentation: Segments performance metrics to evaluate net-new customer acquisition trends versus returning traffic. |
em |
No | A SHA-256 Hexadecimal cryptographic hash of the customer’s email address. | Transient Downstream Token (Hex): Captured client-side or server-side and immediately passed to downstream DSPs to support cookieless attribution; not retained for internal CRM profiling. |
em_b64 |
No | A SHA-256 Base64 cryptographic hash of the customer’s email address. | Transient Downstream Token (Base64): An alternate format of the email hash, passed directly to downstream DSPs for platform-level graph matching. |
anon_id |
No | Unique, pseudonymous first-party cookie identifier (k_uid) set on the client’s digital properties. | Keynes Anonymous ID: A non-PII, proprietary cookie used by Keynes to locally group site interactions and combine them with platform performance logs. |
session_id |
No | Short-term browsing session identifier (k_sid) set on the client’s digital properties. | Sessionization Tracking: Temporarily groups sequential page interactions into an operational window for pathing analytics. |
items |
No | An array of line item objects associated with the order. Supported via server-side integration only. | Product-Level Analytics: Breaks down performance reports by SKU and product categories without processing user profiles. |
ip |
Yes | The Internet Protocol address captured automatically from the network connection. | Network Routing & Geography: Identifies network attributes to assist downstream DSPs with cross-screen mapping and provide coarse, aggregate geographical reporting. |
user_agent |
Yes | The technical signature string passed automatically by the network connection. | Device Identification: Details the operating system and browser version to optimize performance reporting by device profile. |
received_at |
Yes | The precise server-side timestamp logged automatically at the millisecond of ingestion. | Temporal Audit Trail: Establishes the exact date and time the performance log entry was processed. |
method |
Yes | The HTTP request protocol vector utilized automatically (e.g., GET or POST). | Protocol Identification: Flags the technical vector of data transmission for system performance auditing. |
Data Capture & Collection Methodologies
Keynes operates strictly as a data collection and transit layer, utilizing four implementation methods to feed its performance analysis engine:
- Method A: Automated E-Commerce Scripting (Shopify Customer Events Pixel) — Operating within Shopify’s secure client-side environment, this integration programmatically subscribes to checkout events (
checkout_completed). It extracts transaction details, reads first-party cookies, natively computes the SHA-256 email hashes, and transmits them to Keynes to be passed directly downstream to designated programmatic platforms. - Method B: Client-Side Web Pixel (Non-Shopify Browser-Side) — A lightweight browser script provided by Keynes (the “Keynes Pixel”) and deployed on the final purchase validation page. The Keynes Pixel runs an automated waterfall search to extract transaction indicators, processes the SHA-256 email hashes entirely within the local browser, and forwards the data to Keynes for downstream DSP transmission.
- Method C: Server-to-Server API (Server-Side Connection) — A direct backend integration that bypasses the browser entirely. When an order shifts to “Paid,” the client’s system cleans, cryptographically hashes, and packages the transaction metrics on their own backend, pushing an authenticated payload to Keynes to bypass browser tracking restrictions.
- Method D: Real-Time Event Listener & Interception Framework (Keynes JavaScript SDK & Bridge) — Tracks top-of-funnel site interactions by listening to baseline page views or platform initialization events. The bridge duplicates the technical operational arguments and logs a parallel request to Keynes, allowing the system to capture general site traffic metrics and map them to first-party cookie baselines (
anon_id,session_id).
Data Processing Activities & Purposes
Keynes operates as an independent performance analyzer, strictly limiting its data processing to the following analytics functions:
- A. Downstream Data Transmission & Pass-Through: Keynes captures privacy-safe cryptographic signatures (
em,em_b64) at the point of conversion and immediately routes them downstream to the client’s designated, integrated Demand-Side Platforms (DSPs) to support platform-level attribution graph matching. - B. Log Aggregation & Performance Reporting: Keynes ingests anonymous campaign delivery logs from downstream platforms and combines them with a proprietary pseudonymous identifier (
anon_id) captured on the client’s digital properties. Keynes aggregates metrics—such as multi-screen pathing and conversion visibility—into performance reports. - C. Composite Transaction Deduplication: Keynes audits incoming transaction strings, using the
order_idandreceived_attimestamp to automatically drop duplicate events, ensuring campaign performance metrics and Return on Ad Spend (ROAS) analytics are accurate. - D. Media Execution via External Audience Partners: Keynes transmits pseudonymous, aggregate site-visitor logs (
lal_visitor) to an independent, third-party audience modeling partner. This partner generates demographic lookalike segments, which Keynes subsequently purchases to target and optimize programmatic campaign delivery. - E. Pipeline Telemetry Auditing: System metadata fields (
user_agent,method,ip, andreceived_at) are automatically evaluated to monitor data ingestion health, diagnose installation faults, and maintain platform uptime.