Last Updated:
26 August 2026
This Policy explains who BMEG ME FZ LLC, headquartered in UAE, and its affiliates (collectively “BMEG ME” or “we”) are, how we collect, share, and use personal information about you in connection with our websites, advertising technology platform, products and services, business relationships, sales and marketing activities, and interactions with advertising ecosystem partners, while we operate our advertising platform services at Nexverse.ai (“Platform”), and how you can exercise your privacy rights.
This policy applies to individuals in the European Economic Area (EEA), Switzerland and United Kingdom (collectively “Covered Regions”) and supplements our general Privacy Policy. This sets out the additional information required by the EU GDPR,UK GDPR (including Data Protection Act, 2018) and applicable Swiss data protection laws. This should be read together with our above mentioned general Privacy Policy.
Our Role: Data Controller, Joint Controller and Data Processor
Depending on the nature and purpose of processing, we may act in the following roles:
Data Controller: When we collect and use your personal data for our own business purposes such as operating and improving our Platform, running auctions, preventing fraud, measuring performance, and marketing our services, we decide why and how your personal data is processed. In these situations, we act as the data controller.
Joint Controller: In some cases, we work together with online publishers and/or advertising partners to decide how certain personal data is processed. For example, we may jointly decide how identifiers are stored or accessed on your device and how your consent choices are managed. In these situations, we act as joint controllers in accordance with Article 26 of the GDPR.
Data Processor: In certain circumstances, we process personal data solely on behalf of a client and in accordance with their documented instructions. For example, when we handle a client's own audience data for them, we do not decide how or why that data is used. In these situations, we act as a data processor in accordance with Article 28 of the GDPR.
Information We Collect and How We Collect It
Information you provide to us:
Certain parts of our websites may ask you to provide personal information voluntarily. For example, we may collect your contact details when you:
Register an account
Subscribe to marketing communications
Submit inquiries
Request market reports or access to a demo
Apply for a job
Information we collect from visiting our Online Properties:
When using or interacting with our websites and marketing emails (collectively, the “Online Properties”), we may collect identifiers like your IP address, device ID, and cookie ID. This may include other electronic network activity information such as device type, domain, referring website address, browser type, language, and technical details. This information may reveal your geolocation, online activities, and information about your browser or your interactions with our Online Properties. We also collect internet or other electronic network activity information about your interactions with our Online Properties, including pages accessed, search keywords, and links clicked. If you correspond with us via email or blog postings, we may collect additional information voluntarily provided, such as email content and responses.
Information we collect from our Clients and Business Contacts:
We collect standard business-contact information from our Clients, prospective Clients, and business-contacts (“Clients”), and from our vendors or service providers who help us administer our business (“Service Providers”). The personal information we collect may include contact details (such as name, address, telephone number, or email address), contact preferences, professional information (such as job title, department, or job role), order history, and payment or invoicing information.
Information we collect from our Employees and Job Applicants:
We collect standard employment-related information for purposes such as to run payroll, to provide human resources services, to administer our business, and to fulfil our legal and reporting obligations. If you apply for a job, we will collect your resume and information related to your employment and education history. The personal information we collect from our employees and job applicants may also include contact information, professional affiliation, username and answer to a security question or password, government identification, financial information, citizenship, health data, military or veteran status, and the contents of mail, email or texts.
Information We Collect from Advertising Partners and Third Parties:
We may collect information from advertisers, agencies, publishers, connected TV providers, data providers and other advertising ecosystem partners, including information collected through their websites, applications, services or our technologies. Such information may include personal data and any other related data about advertising inventory, devices, identifiers, approximate location, content context and user interactions, as well as information used for audience targeting, campaign optimization, fraud prevention, analytics, attribution and advertising measurement.
Where advertising is delivered under the IAB Europe Transparency & Consent Framework, the transparency information presented through the publisher's consent management platform serves as the first layer of this notice and this Privacy Policy provides further details.
Legal Basis for Processing
If you are a visitor from the EEA, Switzerland or the UK, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
For individuals in Switzerland, we process personal data in accordance with the principles of the revised Swiss FADP, including lawfulness, good faith, proportionality, purpose limitation, transparency and data security. We obtain consent where the FADP requires it, including for high-risk profiling and the processing of sensitive personal data.
For individuals in the EEA or the UK, the legal bases for which we may process your personal information include:
Consent – Under Article 6(1)(a) of the GDPR, we process your personal information based on your consent for storing or reading non-essential cookies or identifiers and for creating and using profiles for personalised or targeted advertising and content. Consent may be collected through the publisher's Consent Management Platform (“CMP”), under the IAB Europe Transparency & Consent Framework (“TCF”), and can be withdrawn at any time
Contract – Under Article 6(1)(b) of the GDPR, we process your personal information when it is necessary to provide the services requested by you or your organisation. This also includes in applicable cases where you apply for a job, for identifying and recruiting eligible candidates, in order to take steps at the request of the data subject prior to entering into a contract.
Legitimate Interests– Under Article 6(1)(f) of the GDPR, we process your personal information where it is necessary for our legitimate interests or the legitimate interests of our partners, affiliates, clients, vendors, and service providers. We do this only where these interests do not override your interests and fundamental rights and freedoms. This includes:
To provide our products and services – (excluding personalised/targeted advertising and profiling, which we carry out only on the basis of your consent).
To respond to requests and inquiries.
To administer our business, including marketing, advertising, and analysis.
To prevent and detect fraud or security threats.
Ad measurement and attribution.
Billing and reporting.
Product development.
Legal Obligation – Under Article 6(1) (c) of the GDPR, in some cases, we may also have a legal obligation to collect personal information from you.
If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided under the “Contact Us” heading below.
Cookies and Similar Tracking Technology
As is true of most websites, we use cookies and similar tracking technologies to collect the information described above. Cookies are small text files that allow websites to recognize repeat visitors, facilitate a visitor’s ongoing access to and use of a website, and track usage behaviour. We may also use other standard internet technologies on our website, such as beacons, pixels, or tags, to deliver or communicate with cookies and track your use of our websites.
If you do not want information collected through the use of cookies or similar trackers, there is a simple procedure in most browsers that allows you to deny or accept cookies and trackers. You may also opt-out of certain cookies through the use of our cookie banner or the “Cookie Settings” link at the bottom of our websites. However, you should note that cookies may be necessary to provide you with certain features (e.g., customized delivery of information) available on our website.
If you are in the EEA, Switzerland or the UK, we will ask for your permission before placing or accessing any non-essential cookies or similar identifiers on your device. On websites or apps operated by publishers, this permission may be requested through the publisher's Consent Management Platform (CMP). This is done in accordance with the ePrivacy rules and Article 7 of the GDPR.
IAB Europe Transparency & Consent Framework (TCF)
We participate in the IAB Europe Transparency & Consent Framework (TCF), comply with its Specifications and Policies and are a registered vendor on the Global Vendor List.
If advertising is delivered using the IAB Europe Transparency & Consent Framework (TCF), the publisher’s Consent Management Platform (CMP) records the privacy choices you make, including whether you consent to the processing of your personal data or object to certain processing activities. These choices are shared with us and other registered vendors through the TC String, a digital signal that communicates your consent preferences and enables us and other registered advertising partners to process your personal data in accordance with those preferences. A list of the named third-party Vendors that may process your personal data within the TCF, together with a link to each Vendor's privacy policy, is accessible via the privacy/consent settings interface on the publisher website where advertising is delivered to you. You can change or withdraw your consent at any time, as easily as you gave it, by using the publisher’s CMP or the “Cookie Settings” link.
We process your personal data only when the TC String indicates that there is a valid legal basis for us to do so. If we do not receive a valid signal, we treat it as no permission to process your personal data.
How We Use Your Information
We use personal information to provide our advertising and marketing services to our Clients. These uses include: displaying advertisements; allowing Clients to place advertising space for sale; allowing Clients to search for, bid on, purchase, and place ads; tracking and reporting engagement with ads; analysing ad effectiveness; screening for fraud or other security issues; and improving the effectiveness and engagement of ads or the operation of our Platform. For example, we may use your geolocation, zip code, or Mobile ID to allow Clients to find and place ads in a certain geofenced location. We may use demographic information to allow Clients to better target their ads to a particular audience. We may also use personal information, including online or advertising identifiers, online activities, and interactions with ads, to provide feedback to our Clients on how End Users interacted with their ads.
We use personal information of our Clients and Service Providers for standard business purposes such as providing our marketing and advertising services, maintaining and updating the Platform, processing orders, facilitating invoices and payments, responding to requests, and generally administering our business.
We use personal information collected from our own websites to perform statistical analyses of visitor behaviour, measure interest in and use of various areas of our website and generally improve and optimize our website. We may also use this personal information to notify you about important changes, new services, and special opportunities, in accordance with your marketing preferences. It is not our practice to link personal information from cookies or similar technologies collected through our website to other personal information we may have about visitors to our websites, although we reserve the right to do so in certain circumstances, such as to screen for or prevent fraud and to ensure website security.
Sharing Your Information
We may share your personal information with trusted third parties, such as Service Providers, who help us provide our marketing and advertising services and maintain our Online Properties. Examples include supporting the delivery of, providing functionality on, or enhancing the security of our websites, administering surveys and research, and working with event organizers to confirm registration or according to your indicated preferences.
We may also share personal information with our Clients for the purposes set forth above, including to: search for, purchase, and place ads or advertising space; track and report engagement; and analyze and improve ad effectiveness.
We may provide personal information collected through our own websites to third parties, such as Google Analytics, in return for website analysis that we use for purposes of research and evaluation of our websites.
Additionally, Personal information may be shared with other companies within the BMEG ME group for any purposes outlined in this Policy.
Finally, in rare circumstances we may share your personal information to: comply with applicable laws and regulations; to detect, prevent or otherwise address fraud, security or technical issues; to respond to a subpoena, court order, other lawful request for information; or to otherwise protect our rights, property, or safety, or the rights, property, or safety of other persons or entities.
International Data Transfers
We are established in the United Arab Emirates (UAE) and work with service providers and group companies located in the United States and other countries. As a result, your personal information may be transferred to countries outside the EEA, Switzerland or the UK.
If we transfer your personal information to a country that is not recognized by the European Commission, Switzerland or the UK as providing an adequate level of data protection, we apply appropriate safeguards in accordance with Chapter V of the GDPR. These safeguards primarily include the European Commission's Standard Contractual Clauses (SCCs) and, for personal data transferred from the UK, the UK International Data Transfer Agreement (IDTA) or the UK Addendum. We also assess the risks associated with the transfer and implement any additional measures needed to protect your personal information.
If we transfer your personal information to a country that is not recognized by Switzerland as providing an adequate level of data protection, we use appropriate safeguards, including the European Commission's Standard Contractual Clauses as recognized and adapted for Switzerland by the Federal Data Protection and Information Commissioner (FDPIC) (the “Swiss amendments”). If we transfer your personal information from Switzerland to a US organisation that is certified under the Swiss-U.S. Data Privacy Framework, we may use the framework as a safeguard for the transfer.
You can find out about the specific safeguards that we have in place or request a copy by contacting us (as the “controller” of your data) at the contact details provided below.
How We Retain And Delete personal information
We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements). We do not retain personal information for longer than reasonably necessary to fulfill the business purposes for which it was collected, conduct audits, enforce our legal rights, prevent fraud and ensure security, or comply with our legal obligations.
Because our marketing and advertising business depends on current information, most personal information that we collect about visitors to our Online Properties has a pre-set expiration date. For example, demographic information that we receive from third-parties is deleted after 30 days. And information collected from cookies and other trackers on our website generally expires after 12 months. For advertising bid-stream and identifier data we retain personal information for no longer than 2 weeks from collection, after which it is deleted or aggregated.
Our retention periods for other types of personal information vary depending on the nature of our relationship with you, the sensitivity of the personal information, and the risks involved with any related processing. We regularly review our data retention periods and update these policies as needed.
How We Protect personal information
We use industry-standard administrative, technical, and physical security measures designed to protect and safeguard the security of the personal information that we process. Unfortunately, no transmission of data over the internet, and no system for storing data, is guaranteed to be completely secure. While we strive to protect your personal information and privacy, we cannot guarantee or warrant the security of any information disclosed or transmitted to us and cannot be responsible for the theft, destruction, or inadvertent disclosure of personal information. In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required under the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify the affected individuals without undue delay, as required under GDPR Articles 32–34.
Third Party Websites
We are not responsible for the practices employed by websites or applications (including widgets) linked to or from our website nor the information or content contained therein. Often links to other websites are provided solely as pointers to information on topics that may be useful to the users of our website. Please remember that your browsing and interaction on any other website, including websites which have a link on our website, is subject to that website’s own rules and policies.
Children’s Privacy
We do not knowingly collect any personal information from, or market to or target, individuals under the age of 18. If you are under 18, please do not submit any personal information on our website or through any communications channels, including through any of our Online Properties. We do not use our platform to create profiles of, or deliver personalised or behavioural advertising to, individuals whom we know or reasonably believe are children. We rely on publishers to identify child-directed inventory and apply appropriate age-gating where required. For such inventory, only non-personalised (contextual) advertising should be served.
Your Privacy Rights
Residents of the EEA or the UK have unique privacy rights. Residents of the EEA or the UK have the following rights under applicable data protection law:
Right of access— to obtain confirmation of whether we process your personal data and a copy of it.
Right to rectification— to correct inaccurate or incomplete personal data.
Right to erasure— to request deletion of your personal data in certain circumstances.
Right to restriction— to request that we limit our processing of your personal data.
Right to data portability— to receive your personal data in a structured, commonly used, machine-readable format.
Right to object— to object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to withdraw consent— to withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
Right to lodge a complaint— if you consider that we have processed your personal data in an adequate manner, you have the right to complain to your national supervisory authority. You have the right to object at any time to the use of your personal information for direct marketing, including any profiling related to direct marketing, in accordance with Article 21(2) of the GDPR. If you object, we will stop processing your personal information for these purposes.
If you withdraw your consent, it will not affect the lawfulness of any processing carried out before your consent was withdrawn.
We do not make decisions about you based solely on automated processing where those decisions produce legal or similarly significant effects. Where we carry out profiling for advertising purposes, we do so only on the basis of your consent, which you may withdraw at any time, in accordance with Article 22 of the GDPR, the UK GDPR and Article 21 of the revised FADP.
All of these rights are subject to certain conditions and exemptions. Although we make good faith efforts to provide individuals with access to their personal information, there may be circumstances in which we are unable to provide access, including but not limited to when it would compromise others’ privacy or other legitimate rights, when the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy, or when the information is commercially proprietary. To protect your privacy, we will take commercially reasonable steps to verify your identity before granting access to or making any changes to your personal information.
If you would like to exercise any of these rights, review or update your personal information or preferences, or have your information removed from our mailing lists, please let us know by contacting us (as the “controller” of your data) at the contact details provided below. You may also opt out of receiving marketing communications from BMEG ME by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send to you or by clicking here.
Your right to complain
Residents of the European Economic Area and the United Kingdom may also report privacy complaints directly to their local data protection authorities. See www.edpb.europa.eu for more information. UK residents may complain to the Information Commissioner’s Office (ICO) at ico.org.uk. Residents of Switzerland may complain to the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.You may also contact us to be directed to the relevant authorities for your jurisdiction.
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. To protect your privacy and security, we take reasonable steps to verify your identity before granting you access to your personal information or making corrections to your personal information.
Our EU / UK & Switzerland Representatives and Data Protection Officer
As BMEG ME FZ LLC is established outside the EEA, Switzerland and the UK, we have appointed representatives in accordance with Article 27 of the GDPR, Article 27 of the UK GDPR, and Article 14 of the revised Swiss FADP. If you have questions about your personal data or would like to request to access, update, or delete it, you may contact our representative at:
Bird & Bird GDPR Representative Services SRL
Avenue Louise 235
1050 Bruxelles
Belgium
EUrepresentative.nexverse@twobirds.com
AND
Bird & Bird GDPR Representative Services UK
12 New Fetter Lane
London
EC4A 1JP
United Kingdom
UKrepresentative.nexverse@twobirds.com
Our Data Protection Officer / privacy officer can be reached at dpo@nexverse.in
Changes to this Policy
We may update this Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons. If we make material changes to this Policy, we will notify you of any material changes by posting the revised Policy on this website, and where necessary, by any other means required by applicable law. Where such changes affect processing based on your consent, we will seek a fresh consent from you before implementing those changes. Our use of the personal information that we gather is subject to the Privacy Policy in effect at the time of use.
Contact Information
For Privacy related queries please contact dpo@nexverse.in
Contact Address — 2401 & 2402 Thuraya Tower 1, Dubai Internet City, Dubai, United Arab Emirates.