generated: '2026-08-12' method: searched source: https://www.sojern.com/privacy/privacy-policy note: >- Sojern has no published machine-readable API contract, so there is nothing to derive technical conformance from (no OpenAPI, no AsyncAPI, no vocabulary). What Sojern DOES publish is an advertising-industry privacy and self-regulatory compliance posture, recorded below from the provider's own Privacy Center. Every entry is the provider's own claim, sourced to the page it is stated on; no certification was independently verified, and no technical standard is asserted. standards: - id: daa-self-regulatory-principles name: Digital Advertising Alliance (DAA) Self-Regulatory Principles conforms: true evidence: 'Privacy Policy: "Sojern is a member of the DAA, DAAC, and EDAA and adheres to these organizations'' Self-Regulatory Principles."' reference: https://www.aboutads.info/choices/ - id: daac-self-regulatory-principles name: Digital Advertising Alliance of Canada (DAAC) conforms: true evidence: 'Privacy Policy: member of the DAA, DAAC, and EDAA' reference: http://youradchoices.ca/ - id: edaa-self-regulatory-principles name: European Interactive Digital Advertising Alliance (EDAA) conforms: true evidence: 'Privacy Policy: member of the DAA, DAAC, and EDAA' reference: http://www.youronlinechoices.eu/ - id: eu-us-data-privacy-framework name: EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF) conforms: true evidence: 'Privacy Policy: "Sojern complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF"' reference: https://www.sojern.com/privacy/privacy-policy - id: truste-dispute-resolution name: TRUSTe independent dispute resolution conforms: true evidence: 'Privacy Policy directs unresolved complaints to https://feedback-form.truste.com/watchdog/request' reference: https://feedback-form.truste.com/watchdog/request - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: 'Sojern publishes a GDPR FAQ and a chart of data categories in its Privacy Center' reference: https://www.sojern.com/privacy/gdpr-faq - id: us-state-privacy name: U.S. state privacy laws (CCPA/CPRA and successors) conforms: true evidence: 'Privacy Policy links a U.S. State Privacy Notice, a Notice at Collection and a "Your Privacy Choices" opt-out' reference: https://www.sojern.com/privacy/notice-at-collection - id: soc2 name: SOC 2 conforms: false evidence: 'No SOC 2 claim found on sojern.com/security, the Privacy Center, or any trust page; trust.sojern.com and security.sojern.com do not resolve.' - id: iso27001 name: ISO/IEC 27001 conforms: false evidence: 'No ISO 27001 claim found on any public Sojern page probed.' - id: oauth2 name: OAuth 2.0 conforms: unknown evidence: 'No public API contract; the portal backend is Hasura GraphQL using JWT claims (https://hasura.io/jwt/claims present in the portal bundle) but the authorization model is not publicly documented.' - id: rfc9457-problem-details name: RFC 9457 Problem Details conforms: unknown evidence: 'No public API contract to evaluate.' transport_security: claim: 'Sojern requires data to be encrypted by HTTPS/TLS protocol when in transit to Sojern, and encrypts data at rest within its database.' source: https://www.sojern.com/legal/partner-documentation hashing: 'Partner-supplied email identifiers must be hashed; SHA256 is mandatory, MD5 and SHA1 also accepted.'