1. Operating principle
The client remains responsible for determining the purpose and lawful basis for use of first-party customer data. TFG acts only on documented instructions and does not require raw identifiable customer data for campaign activation where approved platform audience functionality can be used.
2. Client-controlled upload
The client or its authorised representative uploads or connects selected customer segments to approved advertising platforms such as Meta, Google/DV360, Microsoft Advertising or The Trade Desk. Uploads should use platform-approved hashing, pseudonymisation or direct integration. TFG must not receive raw personal data unless a separately approved processing arrangement, DPA, security review and operational need exist.
3. Platform processing
The advertising platform matches pseudonymised identifiers within its environment and provides named, non-identifiable segments for approved targeting, exclusion or modelling. The platform role must be confirmed through the relevant terms and DPA; it must not be assumed to be identical across providers or services.
4. TFG processing
Select approved audience segment names after media-plan approval.
Configure, optimise and report campaigns within approved platforms.
Use aggregated campaign and audience performance outputs.
Do not export or download underlying personal data.
Record purpose, owner and campaign approval for each first-party segment use.
5. AI-assisted analysis
Aggregated or anonymised campaign outputs may be used in an approved AI-assisted workflow only where the tool, purpose, source, retention and access have been approved. Personal data, raw audience lists, credentials and restricted client information must not be copied into unapproved tools. AI output is advisory and requires human review before client use or campaign action.
6. Access and account security
Named user accounts, least privilege and multi-factor authentication.
Client-approved access, periodic review and prompt removal when no longer required.
No credential sharing; privileged changes and critical actions logged where supported.
Third-party access governed by client instruction, platform controls and supplier terms.
7. Retention and deletion
The client controls first-party segment retention in the advertising platform. TFG retains campaign metadata and aggregated performance information according to the approved retention schedule. Staging copies of audience lists, where exceptionally authorised, must be deleted after upload and no later than 90 days unless a shorter client or contractual period applies.
8. Roles
Party
Role
Responsibilities
Client
Controller
Lawful basis, purpose, audience selection, upload/link, platform approval and revocation.
Advertising platform
Role determined by terms/DPA
Matching, platform security, delivery, retention and data-subject support as contractually defined.
TFG / Republic of Media
Processor or service provider as agreed
Act on instructions; activate named segments; optimise and report; protect access; avoid raw-data access.
AI/model provider
Processor/sub-processor only where approved
Process approved inputs under contract, security assessment, retention and training restrictions.
9. Required pre-use checks
Signed contract/DPA and confirmed party roles.
Lawful basis and transparent client notices.
Approved platform, audience purpose and suppression requirements.
Security review, account ownership and access list.
Retention/deletion route and evidence requirement.
AI use-case approval if AI-assisted analysis is proposed.