← All news

Regional privacy: what changes when you cross a border

The claim, in one sentence

Seldeo behaves the same in every jurisdiction where you have strong data-protection law, and where a jurisdiction has weaker law we still hold ourselves to the stronger baseline. The practical effect: if you turn off ad personalisation in the United States, your account is treated the same way an EU account of a user who never consented would be.

The rest of this post is the specific version of that claim.

The four regimes we design for

There are four regulatory pillars that shape the way we build Seldeo:

  • GDPR (EU) + UK GDPR (UK). Strongest data-protection regime globally. Everything from lawful basis for processing to explicit consent for personalised advertising to specific cross-border transfer disclosures is defined here.
  • CCPA / CPRA (California). The largest US state-level regime, and the one whose "Do Not Sell / Share" signal is the closest US analogue to European consent.
  • LGPD (Brazil). GDPR-like, with its own data subject rights registration process and its own DPO requirement.
  • Apple's App Tracking Transparency (ATT). Not a law but a platform rule that applies to every iOS app. ATT gates any cross-app tracking behind an explicit user prompt.

Everywhere else, there is either no privacy regime at all or a regime that is close enough to one of the four above that we apply the closest match.

What the app does differently by region

European Economic Area, United Kingdom, and Switzerland.

  • The Google User Messaging Platform consent form appears on first launch. Nothing that requires consent (personalised ads, non-essential analytics, cross-app tracking) fires until the form resolves.
  • Advertising defaults to non-personalised. Personalisation only enables if the user consents through the UMP form.
  • We surface an explicit "manage your consent" screen in the privacy settings so the user can re-open the UMP form at any time.
  • Cross-border data transfers to the United States rely on the EU-US Data Privacy Framework where the receiver is DPF-certified, and on Standard Contractual Clauses where the receiver is not.

United States.

  • Personalised ads default to on for users who are 18 or older.
  • The "Do Not Sell or Share My Personal Information" (California) and equivalent state-law rights (Colorado, Connecticut, Virginia, Utah, Texas, and so on as they come online) are reachable one tap deep from the privacy settings.
  • Global Privacy Control signals sent by the operating system are honoured.

Brazil.

  • LGPD data subject rights are honoured at rights@seldeo.com, which routes to our DPO of record.
  • Personalised advertising is opt-out for adults, opt-in for under-18 accounts.

Elsewhere.

  • We apply the closest match. In practice this means most of Asia and Latin America is treated as CCPA-equivalent (opt-out personalisation, DSAR rights on request), and jurisdictions we assess as having a strong local privacy authority (Japan, South Korea) are treated GDPR-equivalent.

Under-18 accounts, everywhere.

  • Personalised advertising is off. Ad Manager requests carry tfua=1 (tag for users under the age of consent).
  • COPPA-tagged inventory is used for accounts we know or reasonably suspect are under 13. Ad Manager requests carry tfcd=1 (tag for child-directed treatment).

What travelling does

Regional behaviour is scoped by the account's home region, not the current device location, with two exceptions:

  1. UMP re-prompt. If your device geo suddenly resolves to an EU country and the last UMP verdict on the account was from a non-EU jurisdiction, we re-run the UMP form on next launch. Consent is the sort of thing that should be affirmed each time the user is under a jurisdiction that requires it.
  2. In-app ads compliance. The ad request path always applies the most restrictive of {device geo, account home region, account age}. If your account is set to United States but your device is in Germany, ads on that device fire with EU restrictions in effect.

The account home region is what you selected at sign-up (or your device default). You can change it at Settings → Region and language. Doing so triggers a re-prompt of any consent-affecting UI so nothing important is silently inherited from your old region.

What we do the same everywhere

Regardless of region:

  • Direct messages are end-to-end encrypted.
  • Media on your account is stored encrypted at rest.
  • Access to a live production database by our engineers requires a scoped, short-lived credential with an after-the-fact audit log.
  • We do not sell personal information to data brokers. Not in California, not in Brazil, not in a jurisdiction where we legally could.
  • We honour deletion requests within thirty days regardless of the requesting user's residency.
  • We publish the same Transparency Report numbers globally.

Data subject requests

If you want to exercise a right that your local law provides — access, correction, deletion, portability, objection — rights@seldeo.com is the single address for all of them. We do not require you to route requests through a jurisdiction-specific form; the mailbox lands with a data-subject-rights specialist who applies the appropriate legal treatment.

Please include:

  • Your account handle or the email address on file.
  • A one-sentence description of what you want to happen.
  • Where you consider yourself resident, for jurisdictional purposes.

We aim to acknowledge within 72 hours and resolve within 30 days.

Cross-border transfers

Where your data leaves the region where your account is registered:

  • EEA / UK / CH → US. EU-US DPF where the US receiver is DPF-certified. SCCs where not. Onward transfers within the US are covered by the same instruments.
  • Brazil → US. LGPD standard contract terms plus SCC fallback.
  • Anywhere → Google's infrastructure. Governed by our Google Cloud data-processing addendum, which itself relies on the EU-US DPF and SCCs as applicable. Our infrastructure region for user data is us-central1.

We publish the concrete list of subprocessors and their roles in our Privacy Policy under the "Sharing" section.

What we still owe you

  • A visible consent-state timeline. So you can see every time your consent state has changed, from where, and what that change did.
  • A configurable data-residency option. So an EEA user who prefers their data at rest to stay in an EEA region has a way to say so.
  • Machine-readable rights requests. So automated privacy-management tools can trigger a Seldeo DSAR without the human email round-trip.

Regional privacy is not a checkbox. It is the design axis that constrains every advertising, tracking, and consent decision on Seldeo. If we've made a jurisdictional choice that seems wrong to you, policy@seldeo.com is the right address, and we do read that mailbox.