Author: azeeadmin

21 Feb 2019

JFrog acquires Shippable, adding continuous integration and delivery to its DevOps platform

JFrog, the popular DevOps startup now valued at over $1 billion after raising $165 million last October, is making a move to expand the tools and services it provides to developers on its software operations platform: it has acquired Shippable, a cloud-based continuous integration and delivery platform (CI/CD) that developers use to ship code and deliver app and microservices updates, and plans to integrate it into its Enterprise+ platform.

Terms of the deal — JFrog’s fifth acquisition — are not being disclosed, said Shlomi Ben Haim, JFrog’s co-founder and CEO, in an interview. From what I understand, though, it was in the ballpark of Shippable’s most recent valuation, which was $42.6 million back in 2014 when it raised $8 million, according to PitchBook data.  (And that was the last time it had raised money.)

Shippable employees are joining JFrog and plan to release the first integrations with Enterprise+ this coming summer, and a full integration by Q3 of this year.

Shippable, founded in 2013, made its name early on as a provider of a containerized continuous integration and delivery platform based on Docker containers, but as Kubernetes has overtaken Docker in containerized deployments, the startup had also shifted its focus beyond Docker containers.

The acquisition speaks to the consolidation that is afoot in the world of DevOps, where developers and organizations are looking for more end-to-end toolkits not just to help develop, update, and run their apps and microservices, but to provide security and more — or at least, makers of DevOps tools hope they will be, as they themselves look to grow their margins and business.

As more organizations run ever more of their opertions as apps and microservices, DevOps have risen in prominence and are offered both toolkits from standalone businesses as well as those whose infrastructure is touched and used by DevOps tools. That means a company like JFrog has an expanding pool of competitors that include not just the likes of Docker, Sonatype and GitLab, but also AWS, Google Cloud Platform and Azure and “the Red Hats of the world,” in the words of Ben Haim.

For Shippable customers, the integration will give them access to security, binary management and other enterprise development tools.

“We’re thrilled to join the JFrog family and further the vision around Liquid Software,” said Avi Cavale, founder and CEO of Shippable, in a statement. “Shippable users and customers have long enjoyed our next-generation technology, but now will have access to leading security, binary management and other high-powered enterprise tools in the end-to-end JFrog Platform. This is truly exciting, as the combined forces of JFrog and Shippable can make full DevOps automation from code to production a reality.”

On the part of JFrog, the company will be using Shippable to provide a native CI/CD tool directly within JFrog.

“Before most of our users would use Jenkins, Circle CI and other CI/CD automation tools,” Ben Haim said. “But what you are starting to see in the wider market is a gradual consolidation of CI tools into code repository.”

He emphasized that this will not mean any changes for developers who are already happy using Jenkins or other integrations: just that it will now be offering a native solution that will be offered alongside these (presumably both with easier functionality and with competitive pricing).

JFrog today has 5,000 paying customers, up from 4,500 in October, including “most of the Fortune 500,” with marquee customers including the likes of Apple and Adobe, but also banks, healthcare organizations and insurance companies — “conservative businesses,” said Ben Haim, that are also now realizing the importance of using DevOps.

21 Feb 2019

Redis Labs changes its open-source license — again

Redis Labs, fresh off its latest funding round, today announced a change to how it licenses its Redis Modules. This may not sound like a big deal, but in the world of open-source projects, licensing is currently a big issue. That’s because organizations like Redis, MongoDB, Confluent and others have recently introduced new licenses that make it harder for their competitors to take their products and sell them as rebranded services without contributing back to the community (and most of these companies point directly at AWS as the main offender here).

“Some cloud providers have repeatedly taken advantage of successful opensource projects, without significant contributions to their communities,” the Redis Labs team writes today. “They repackage software that was not developed by them into competitive, proprietary service offerings and use their business leverage to reap substantial revenues from these open source projects.”

The point of these new licenses it to put a stop to this.

This is not the first time Redis Labs has changed how it licenses its Redis Modules (and I’m stressing the “Redis Modules” part here because this is only about modules from Redis Labs and does not have any bearing on how the Redis database project itself is licensed). Back in 2018, Redis Labs changed its license from AGPL to Apache 2 modified with Commons Clause. The “Commons Clause” is the part that places commercial restrictions on top of the license.

That created quite a stir, as Redis Labs co-founder and CEO Ofer Bengal told me a few days ago when we spoke about the company’s funding.

“When we came out with this new license, there were many different views,” he acknowledged. “Some people condemned that. But after the initial noise calmed down — and especially after some other companies came out with a similar concept — the community now understands that the original concept of open source has to be fixed because it isn’t suitable anymore to the modern era where cloud companies use their monopoly power to adopt any successful open source project without contributing anything to it.”

The way the code was licensed, though, created a bit of confusion, the company now says, because some users thought they were only bound by the terms of the Apache 2 license. Some terms in the Commons Clause, too, weren’t quite clear (including the meaning of “substantial,” for example).

So today, Redis Labs is introducing the Redis Source Available License. This license, too, only applies to certain Redis Modules created by Redis Labs. Users can still get the code, modify it and integrate it into their applications — but that application can’t be a database product, caching engine, stream processing engine, search engine, indexing engine or ML/DL/AI serving engine.

By definition, an open-source license can’t have limitations. This new license does, so it’s technically not an open-source license. In practice, the company argues, it’s quite similar to other permissive open-source licenses, though, and shouldn’t really affect most developers who use the company’s modules (and these modules are RedisSearch, RedisGraph, RedisJSON, RedisML and RedisBloom).

This is surely not the last we’ve heard of this. Sooner or later, more projects will follow the same path. By then, we’ll likely see more standard licenses that address this issue so other companies won’t have to change multiple times. Ideally, though, we won’t need it because everybody will play nice — but since we’re not living in a utopia, that’s not likely to happen.

21 Feb 2019

Microsoft bringing Dynamics 365 mixed reality solutions to smartphones

Last year Microsoft introduced several mixed reality business solutions under the Dynamics 365 enterprise product umbrella. Today, the company announced it would be moving these to smartphones in the spring, starting with previews.

The company announced Remote Assist on HoloLens last year. This tool allows a technician working onsite to show a remote expert what they are seeing. The expert can then walk the less experienced employee through the repair. This is great for those companies that have equipped their workforce with HoloLens for hands-free instruction, but not every company can afford the new equipment.

Starting in the spring, Microsoft is going to help with that by introducing Remote Assist for Android phones. Just about everyone has a phone with them, and those with Android devices will be able to take advantage of Remote Assist capabilities without investing in HoloLens. The company is also updating Remote Assist to include mobile annotations, group calling, deeper integration with Dynamics 365 for Field Service along with improved accessibility features on the HoloLens app.

IPhone users shouldn’t feel left out though because the company announced a preview of Dynamics 365 Product Visualize for iPhone. This tool enables users to work with a customer to visualize what a customized product will look like as they work with them. Think about a furniture seller working with a customer in their homes to customize the color, fabrics and design in place in the room where they will place the furniture, or a car dealer offering different options such as color and wheel styles. Once a customer agrees to a configuration, the data gets saved to Dynamics 365 and shared in Microsoft Teams for greater collaboration across a group of employees working with a customer on a project.

Both of these features are part of the Dynamics 365 spring release and are going to be available in preview starting in April. They are part of a broader release that includes a variety of new artificial intelligence features such as customer service bots and a unified view of customer data across the Dynamics 365 family of products.

21 Feb 2019

Spotinst announces strategic partnership with AWS

Spotinst, the startup that helps customers automate selecting the cheapest set of resources to complete a job, announced a strategic partnership with Amazon Web Services today, joining the AWS Partner Network (APN) Global Startups program.

Under the agreement, Amazon will help with Spotinst’s go-to-market efforts, bringing their considerable financial and sales and marketing resources to the table. Spotinst CEO, Amiram Shachar says the partnership gives the company resources it could never get on its own as a startup.

“AWS is going to take the product we have developed and we’re going to do a kind of go to market together, and actually go to their customers and offer them everything that we’ve built in the past few years,” Shachar explained.

What Spotinst does is find the cheapest resources to meet the customer requirements. Cloud platforms like AWS, Microsoft Azure and Google Cloud Platform, all of which Spotinst supports, have to maintain more resources than they need at any given time. The companies offer steep discounts to customers who want to access these resources, but they come with a strict condition that the platforms can take those resources back whenever they need them.

Spotinst manages this process, finding the best resources for the job based on customer requirements, and seamlessly shifts those resources before the cloud platform takes them back, ensuring that workloads keep functioning, but giving the customer the best possible price.

These capabilities are what attracted Spotinst to AWS. “Spotinst provides additional options for our customers to combine AWS features and pricing choices, for a variety of customer workloads,” Joshua Burgin, general manager for compute services at AWS said in a statement.

Shachar says that even though the company is teaming up with AWS, it will continue to support a multi-cloud environment. He wouldn’t speculate if this was the beginning of a deeper relationship that could eventually result in acquisition, but it certainly makes sense that AWS would be testing the waters here. Neither party would confirm that, however.

Spotinst was founded in 2015 and has raised $50M to this point. Its most recent round was a $35M Series B last August.

21 Feb 2019

Spotinst announces strategic partnership with AWS

Spotinst, the startup that helps customers automate selecting the cheapest set of resources to complete a job, announced a strategic partnership with Amazon Web Services today, joining the AWS Partner Network (APN) Global Startups program.

Under the agreement, Amazon will help with Spotinst’s go-to-market efforts, bringing their considerable financial and sales and marketing resources to the table. Spotinst CEO, Amiram Shachar says the partnership gives the company resources it could never get on its own as a startup.

“AWS is going to take the product we have developed and we’re going to do a kind of go to market together, and actually go to their customers and offer them everything that we’ve built in the past few years,” Shachar explained.

What Spotinst does is find the cheapest resources to meet the customer requirements. Cloud platforms like AWS, Microsoft Azure and Google Cloud Platform, all of which Spotinst supports, have to maintain more resources than they need at any given time. The companies offer steep discounts to customers who want to access these resources, but they come with a strict condition that the platforms can take those resources back whenever they need them.

Spotinst manages this process, finding the best resources for the job based on customer requirements, and seamlessly shifts those resources before the cloud platform takes them back, ensuring that workloads keep functioning, but giving the customer the best possible price.

These capabilities are what attracted Spotinst to AWS. “Spotinst provides additional options for our customers to combine AWS features and pricing choices, for a variety of customer workloads,” Joshua Burgin, general manager for compute services at AWS said in a statement.

Shachar says that even though the company is teaming up with AWS, it will continue to support a multi-cloud environment. He wouldn’t speculate if this was the beginning of a deeper relationship that could eventually result in acquisition, but it certainly makes sense that AWS would be testing the waters here. Neither party would confirm that, however.

Spotinst was founded in 2015 and has raised $50M to this point. Its most recent round was a $35M Series B last August.

21 Feb 2019

Even the IAB warned adtech risks EU privacy rules

A privacy complaint targeting the behavioral advertising industry has a new piece of evidence that shows the Internet Advertising Bureau (IAB) shedding doubt on whether it’s possible to obtain informed consent from web users for the programmatic ad industry’s real-time bidding (RTB) system to broadcast their personal data.

The adtech industry functions by harvesting web users’ data, packaging individual identifiers and browsing data in bid requests that are systematically shared with third parties in order to solicit and scale advertiser bids for the user’s attention.

However a series of RTB complaints — filed last fall by Jim Killock, director of the Open Rights Group; Dr Johnny Ryan of private browser Brave; and Michael Veale, a data and policy researcher at University College London — allege this causes “wide-scale and systemic breaches” of European Union data protection rules.

So far complaints have been filed with data protection agencies in Ireland, the UK and Poland, though the intent is for the action to expand across the EU given that behavioral advertising isn’t region specific.

Google and the IAB set the RTB specifications used by the online ad industry and are thus the main targets here, with complainants advocating for amendments to the specification to bring the system into compliance with the bloc’s data protection regime.

We’ve covered the complaint before, including an earlier submission showing the highly sensitive inferences that can be included in bid requests. But documents obtained by the complainants via freedom of information request and newly published this week show the IAB itself warned in 2017 that the RTB system risks falling foul of the bloc’s privacy rules, and specifically the rules around consent under the EU’s General Data Protection Regulation (GDPR), which came into force last May.

The complainants have published the latest evidence on a new campaign website.

At the very least the admission looks awkward for online ad industry body.

“incompatible with consent under GDPR “

In an email sent to senior personnel at the European Commission in June 2017 by Townsend Feehan, the CEO of IAB Europe — and now being used as evidence in the complaints — she writes that she wants to expand on concerns voiced at a roundtable session about the Commission’s ePrivacy proposals that she claims could “mean the end of the online advertising business model”.

Feehan attached an 18-page document to the email in which the IAB can be seen lobbying against the Commission’s ePrivacy proposal — claiming it will have “serious negative impacts on the digital advertising industry, on European media, and ultimately on European citizens’ access to information and other online content and services”.

The IAB goes on to push for specific amendments to the proposed text of the regulation. (As we’ve written before a major lobbying effort has blow up since GDPR was agreed to try to block updating the ePrivacy rules which operate alongside, covering marketing and electronic communications and cookies and other online tracking technologies.)

As it lobbies to water down ePrivacy rules, the IAB suggests it’s “technically impossible” for informed consent to function in a real-time bidding scenario — writing the following, in a segment entitled ‘Prior information requirement will “break” programmatic trading’:

As it is technically impossible for the user to have prior information about every data controller involved in a real-time bidding (RTB) scenario, programmatic trading, the area of fastest growth in digital advertising spend, would seem, at least prima facie, to be incompatible with consent under GDPR – and, as noted above, if a future ePrivacy Regulation makes virtually all interactions with the Internet subject solely to the consent legal basis, and consent is unavailable, then there will be no legal be no basis for such processing to take place or for media to monetise their content in this way.

The notion that it’s impossible to obtain informed consent from web users for processing their personal data prior to doing so is important because the behavioral ad industry, as it currently functions, includes personal data in bid requests that it systematically broadcasts to what can be thousands of third party companies.

Indeed, the crux of the RTB complaints are that personal data should be stripped out of these requests — and only contextual information broadcast for targeting ads, exactly because the current system is systematically breaching the rights of European web users by failing to obtain their consent for personal data to be sucked out and handed over to scores of unknown entities.

In its lobbying efforts to knock the teeth out of the ePrivacy Regulation the IAB can here be seen making a similar point — when it writes that programmatic trading “would seem, at least prima facie, to be incompatible with consent under GDPR”. (Albeit, injecting some of its own qualifiers into the sentence.)

The IAB is certainly seeking to deploy pro-privacy arguments to try to dilute Europeans’ privacy rights.

Despite it’s own claimed reservations about there being no technical fix to get consent for programmatic trading under GDPR the IAB nonetheless went on to launch a technical mechanism for managing — and, it claimed — complying with GDPR consent requirements in April 2018, when it urged the industry to use its GDPR “Consent & Transparency Framework”.

But in another piece of evidence obtained by the group of individuals behind the RTB complaints — an IAB document, dated May 2018, intended for publishers making use of this framework — the IAB also acknowledges that: “Publishers recognize there is no technical way to limit the way data is used after the data is received by a vendor for decisioning/bidding on/after delivery of an ad”.

In a section on liability, the IAB document lays out other publisher concerns that each bid request assumes “indiscriminate rights for vendors” — and that “surfacing thousands of vendors with broad rights to use data without tailoring those rights may be too many vendors/permissions”.

So again, er, awkward.

Another piece of evidence now attached to the RTB complaints shows a set of sample bid requests from the IAB and Google’s documentation for users of their systems — with annotations by the complainants showing exactly how much personal data gets packaged up and systematically shared.

This can include a person’s latitude and longitude GPS coordinates; IP address; device specific identifiers; various ID codes; inferred interests (which could include highly sensitive personal data); and the current webpage they’re looking at;

“The fourteen sample bid requests further prove that very personal data are contained in bid requests,” the complainants argue.

They have also included an estimated breakdown of seven major ad exchanges’ daily bid requests — Index Exchange, OpenX, Rubicon Project, Oath/AOL*, AppNexus, Smaato, Google DoubleClick — showing they collectively broadcast “hundreds of billions of bid requests per day”, to illustrate the scale of data being systematically broadcast by the ad industry.

“This suggests that the New Economics Foundation’s estimate in December that bid requests broadcast data about the average UK internet user 164 times a day was a conservative estimate,” they add.

The IAB has responded to the new evidence by couching the complainants’ claims as “false” and “intentionally damaging to the digital advertising industry and to European digital media”.

Regarding its 2017 document, in which it wrote that it was “technically impossible” for an Internet user to have prior information about every data controller involved in a RTB “scenario”, the IAB responds that “that was true at the time, but has changed since” — pointing to its Transparency & Consent framework (TCF) as the claimed fix for that, and further claiming it “demonstrates that real-time bidding is certainly not ‘incompatible with consent under GDPR'”.

Here are the relevant paras of IAB rebuttal on that:

The TCF provides a way to provide transparency to users about how, and by whom, their personal data is processed. It also enables users to express choices. Moreover, the TCF enables vendors engaged in programmatic advertising to know ahead of time whether their own and/or their partners’ transparency and consent status allows them to lawfully process personal data for online advertising and related purposes. IAB Europe’s submission to the European Commission in April 2017 showed that the industry needed to adapt to meet higher standards for transparency and consent under the GDPR. The TCF demonstrates how complex challenges can be overcome when industry players come together. But most importantly, the TCF demonstrates that real-time bidding is certainly not “incompatible with consent under GDPR”.

The OpenRTB protocol is a tool that can be used to determine which advertisement should be served on a given web page at a given time. Data can inform that determination. Like all technology, OpenRTB must be used in a way that complies with the law. Doing so is entirely possible and greatly facilitated by the IAB Europe Transparency & Consent Framework, whose whole raison d’être is to help ensure that the collection and processing of user data is done in full compliance with EU privacy and data protection rules.

The IAB goes on to couch the complaints as stemming from a “hypothetical possibility for personal data to be processed unlawfully in the course of programmatic advertising processes”.

“This hypothetical possibility arises because neither OpenRTB nor the TCF are capable of physically preventing companies using the protocol to unlawfully process personal data. But the law does not require them to,” the IAB claims.

However the crux of the RTB complaint is that programmatic advertising’s processing of personal data is not adequately secure — and they have GDPR Article 5, paragraph 1, point f to point to; which requires that personal data be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss”.

So it will be down to data protection authorities to determine what “appropriate security of personal data” means in this context. And whether behavioral advertising is inherently hostile to data protection law (not forgetting that other forms of non-personal-data-based advertising remain available, e.g. contextual advertising).

Discussing the complaint with TechCrunch late last year, Brave’s Ryan likened the programmatic ad system to dumping truck-loads of briefcases in the middle of a busy railway station in “the full knowledge that… business partners will all scramble around and try and grab them” — arguing that such a dysfunctional and systematic breaching of people’s data is lurking at the core of the online ad industry.

The solution Ryan and the other complainants are advocating for is not pulling the plug on the online ad industry entirely — but rather an update to the RTB spec to strip out personal data so that it respects Internet users’ rights. Ads can still be targeted contextually and successfully without Internet users having to be surveilled 24/7 online, is the claim.

They also argue that this would lead to a much better situation for quality online publishers because it would make it harder for their high value audiences to be arbitraged and commodified by privacy-hostile tracking technologies which — as it stands — trail Internet users everywhere they go. Albeit they freely concede that purveyors of low quality clickbait might fair less well.

*Disclosure: TechCrunch is owned by Verizon Media Group, aka Oath/AOL . We also don’t consider ourselves to be purveyors of low quality clickbait  

21 Feb 2019

Even the IAB warned adtech risks EU privacy rules

A privacy complaint targeting the behavioral advertising industry has a new piece of evidence that shows the Internet Advertising Bureau (IAB) shedding doubt on whether it’s possible to obtain informed consent from web users for the programmatic ad industry’s real-time bidding (RTB) system to broadcast their personal data.

The adtech industry functions by harvesting web users’ data, packaging individual identifiers and browsing data in bid requests that are systematically shared with third parties in order to solicit and scale advertiser bids for the user’s attention.

However a series of RTB complaints — filed last fall by Jim Killock, director of the Open Rights Group; Dr Johnny Ryan of private browser Brave; and Michael Veale, a data and policy researcher at University College London — allege this causes “wide-scale and systemic breaches” of European Union data protection rules.

So far complaints have been filed with data protection agencies in Ireland, the UK and Poland, though the intent is for the action to expand across the EU given that behavioral advertising isn’t region specific.

Google and the IAB set the RTB specifications used by the online ad industry and are thus the main targets here, with complainants advocating for amendments to the specification to bring the system into compliance with the bloc’s data protection regime.

We’ve covered the complaint before, including an earlier submission showing the highly sensitive inferences that can be included in bid requests. But documents obtained by the complainants via freedom of information request and newly published this week show the IAB itself warned in 2017 that the RTB system risks falling foul of the bloc’s privacy rules, and specifically the rules around consent under the EU’s General Data Protection Regulation (GDPR), which came into force last May.

The complainants have published the latest evidence on a new campaign website.

At the very least the admission looks awkward for online ad industry body.

“incompatible with consent under GDPR “

In an email sent to senior personnel at the European Commission in June 2017 by Townsend Feehan, the CEO of IAB Europe — and now being used as evidence in the complaints — she writes that she wants to expand on concerns voiced at a roundtable session about the Commission’s ePrivacy proposals that she claims could “mean the end of the online advertising business model”.

Feehan attached an 18-page document to the email in which the IAB can be seen lobbying against the Commission’s ePrivacy proposal — claiming it will have “serious negative impacts on the digital advertising industry, on European media, and ultimately on European citizens’ access to information and other online content and services”.

The IAB goes on to push for specific amendments to the proposed text of the regulation. (As we’ve written before a major lobbying effort has blow up since GDPR was agreed to try to block updating the ePrivacy rules which operate alongside, covering marketing and electronic communications and cookies and other online tracking technologies.)

As it lobbies to water down ePrivacy rules, the IAB suggests it’s “technically impossible” for informed consent to function in a real-time bidding scenario — writing the following, in a segment entitled ‘Prior information requirement will “break” programmatic trading’:

As it is technically impossible for the user to have prior information about every data controller involved in a real-time bidding (RTB) scenario, programmatic trading, the area of fastest growth in digital advertising spend, would seem, at least prima facie, to be incompatible with consent under GDPR – and, as noted above, if a future ePrivacy Regulation makes virtually all interactions with the Internet subject solely to the consent legal basis, and consent is unavailable, then there will be no legal be no basis for such processing to take place or for media to monetise their content in this way.

The notion that it’s impossible to obtain informed consent from web users for processing their personal data prior to doing so is important because the behavioral ad industry, as it currently functions, includes personal data in bid requests that it systematically broadcasts to what can be thousands of third party companies.

Indeed, the crux of the RTB complaints are that personal data should be stripped out of these requests — and only contextual information broadcast for targeting ads, exactly because the current system is systematically breaching the rights of European web users by failing to obtain their consent for personal data to be sucked out and handed over to scores of unknown entities.

In its lobbying efforts to knock the teeth out of the ePrivacy Regulation the IAB can here be seen making a similar point — when it writes that programmatic trading “would seem, at least prima facie, to be incompatible with consent under GDPR”. (Albeit, injecting some of its own qualifiers into the sentence.)

The IAB is certainly seeking to deploy pro-privacy arguments to try to dilute Europeans’ privacy rights.

Despite it’s own claimed reservations about there being no technical fix to get consent for programmatic trading under GDPR the IAB nonetheless went on to launch a technical mechanism for managing — and, it claimed — complying with GDPR consent requirements in April 2018, when it urged the industry to use its GDPR “Consent & Transparency Framework”.

But in another piece of evidence obtained by the group of individuals behind the RTB complaints — an IAB document, dated May 2018, intended for publishers making use of this framework — the IAB also acknowledges that: “Publishers recognize there is no technical way to limit the way data is used after the data is received by a vendor for decisioning/bidding on/after delivery of an ad”.

In a section on liability, the IAB document lays out other publisher concerns that each bid request assumes “indiscriminate rights for vendors” — and that “surfacing thousands of vendors with broad rights to use data without tailoring those rights may be too many vendors/permissions”.

So again, er, awkward.

Another piece of evidence now attached to the RTB complaints shows a set of sample bid requests from the IAB and Google’s documentation for users of their systems — with annotations by the complainants showing exactly how much personal data gets packaged up and systematically shared.

This can include a person’s latitude and longitude GPS coordinates; IP address; device specific identifiers; various ID codes; inferred interests (which could include highly sensitive personal data); and the current webpage they’re looking at;

“The fourteen sample bid requests further prove that very personal data are contained in bid requests,” the complainants argue.

They have also included an estimated breakdown of seven major ad exchanges’ daily bid requests — Index Exchange, OpenX, Rubicon Project, Oath/AOL*, AppNexus, Smaato, Google DoubleClick — showing they collectively broadcast “hundreds of billions of bid requests per day”, to illustrate the scale of data being systematically broadcast by the ad industry.

“This suggests that the New Economics Foundation’s estimate in December that bid requests broadcast data about the average UK internet user 164 times a day was a conservative estimate,” they add.

The IAB has responded to the new evidence by couching the complainants’ claims as “false” and “intentionally damaging to the digital advertising industry and to European digital media”.

Regarding its 2017 document, in which it wrote that it was “technically impossible” for an Internet user to have prior information about every data controller involved in a RTB “scenario”, the IAB responds that “that was true at the time, but has changed since” — pointing to its Transparency & Consent framework (TCF) as the claimed fix for that, and further claiming it “demonstrates that real-time bidding is certainly not ‘incompatible with consent under GDPR'”.

Here are the relevant paras of IAB rebuttal on that:

The TCF provides a way to provide transparency to users about how, and by whom, their personal data is processed. It also enables users to express choices. Moreover, the TCF enables vendors engaged in programmatic advertising to know ahead of time whether their own and/or their partners’ transparency and consent status allows them to lawfully process personal data for online advertising and related purposes. IAB Europe’s submission to the European Commission in April 2017 showed that the industry needed to adapt to meet higher standards for transparency and consent under the GDPR. The TCF demonstrates how complex challenges can be overcome when industry players come together. But most importantly, the TCF demonstrates that real-time bidding is certainly not “incompatible with consent under GDPR”.

The OpenRTB protocol is a tool that can be used to determine which advertisement should be served on a given web page at a given time. Data can inform that determination. Like all technology, OpenRTB must be used in a way that complies with the law. Doing so is entirely possible and greatly facilitated by the IAB Europe Transparency & Consent Framework, whose whole raison d’être is to help ensure that the collection and processing of user data is done in full compliance with EU privacy and data protection rules.

The IAB goes on to couch the complaints as stemming from a “hypothetical possibility for personal data to be processed unlawfully in the course of programmatic advertising processes”.

“This hypothetical possibility arises because neither OpenRTB nor the TCF are capable of physically preventing companies using the protocol to unlawfully process personal data. But the law does not require them to,” the IAB claims.

However the crux of the RTB complaint is that programmatic advertising’s processing of personal data is not adequately secure — and they have GDPR Article 5, paragraph 1, point f to point to; which requires that personal data be “processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss”.

So it will be down to data protection authorities to determine what “appropriate security of personal data” means in this context. And whether behavioral advertising is inherently hostile to data protection law (not forgetting that other forms of non-personal-data-based advertising remain available, e.g. contextual advertising).

Discussing the complaint with TechCrunch late last year, Brave’s Ryan likened the programmatic ad system to dumping truck-loads of briefcases in the middle of a busy railway station in “the full knowledge that… business partners will all scramble around and try and grab them” — arguing that such a dysfunctional and systematic breaching of people’s data is lurking at the core of the online ad industry.

The solution Ryan and the other complainants are advocating for is not pulling the plug on the online ad industry entirely — but rather an update to the RTB spec to strip out personal data so that it respects Internet users’ rights. Ads can still be targeted contextually and successfully without Internet users having to be surveilled 24/7 online, is the claim.

They also argue that this would lead to a much better situation for quality online publishers because it would make it harder for their high value audiences to be arbitraged and commodified by privacy-hostile tracking technologies which — as it stands — trail Internet users everywhere they go. Albeit they freely concede that purveyors of low quality clickbait might fair less well.

*Disclosure: TechCrunch is owned by Verizon Media Group, aka Oath/AOL . We also don’t consider ourselves to be purveyors of low quality clickbait  

21 Feb 2019

Alibaba hits the gas on mobility as its bike sharing service adds carpooling

Carpooling is heralded to be environmentally friendly and money-saving, but in smog-stricken China, the transportation option became a source of public concerns after two female passengers got murdered during their lifts with Didi Chuxing drivers. The ride-hailing app has suspended its Hitch service to this date under government command, and its peers were also directed to step up safety measures for their own offerings.

The regulatory crackdown led to a shortage of cheap rides with strangers in China, but a newcomer is charging full speed ahead to reinvigorate the market. Hello TransTech, formerly Hellobike, will officially launch its carpooling service nationwide on February 22 after piloting the program for about a month. The move sets Hello up for a clash with market dominator Didi, which has been in hot water following the high-profile accidents last year.

Hello is relatively late to the ride-hailing game, but it’s got powerful backers who could potentially help it gain a meaningful foothold. Among its main investors is Ant Financial, the financial service company controlled by Alibaba’s billionaire founder Jack Ma and the creator behind one of China’s largest digital wallets Alipay . Besides shelling out checks, Ant also sent many users to HelloTrans Tech when the latter first started as the bike-rental company Hellobike. For instance, Alipay’s hundreds of millions of users could easily access Hellobike without having to download its standalone app.

As the Chinese internet becomes occupied and colonized by tech heavyweights, teaming up with a major player almost becomes a prerequisite for aspiring startups to crack their market. Another case in point is Tencent being a boon to Didi’s early user acquisition by letting the ride-hailing app tap its popular WeChat messenger app and payments service.

Alibaba’s transportation ambition is a two-pronged strategy. On the one hand, Hello competes with Didi Chuxing (which Alibaba is also involved as a minority stakeholder) in offering on-demand rides, a category that’s become more onerous to the operator as Chinese regulators introduce stricter safety policies. On the other hand, Alibaba applies what it’s best at — the asset-light platform play — to ride-hailing with its own mapping service AutoNavi acting as a marketplace for third-party apps including Didi and AutoNavi.

It could be a few more years before it’s clear which of Alibaba’s strategies will stick it out. Didi still takes the lead with 66 million unique devices on its app in December, according to data collected by research firm iResearch. Hello was a tenth of its size at 6.3 million.

Hellobike declined to answer questions from TechCrunch about its new carpooling service. However, it did say it will hold a press event for the new service soon. We’ll update this story with any new details that come out of it.

21 Feb 2019

Alibaba hits the gas on mobility as its bike sharing service adds carpooling

Carpooling is heralded to be environmentally friendly and money-saving, but in smog-stricken China, the transportation option became a source of public concerns after two female passengers got murdered during their lifts with Didi Chuxing drivers. The ride-hailing app has suspended its Hitch service to this date under government command, and its peers were also directed to step up safety measures for their own offerings.

The regulatory crackdown led to a shortage of cheap rides with strangers in China, but a newcomer is charging full speed ahead to reinvigorate the market. Hello TransTech, formerly Hellobike, will officially launch its carpooling service nationwide on February 22 after piloting the program for about a month. The move sets Hello up for a clash with market dominator Didi, which has been in hot water following the high-profile accidents last year.

Hello is relatively late to the ride-hailing game, but it’s got powerful backers who could potentially help it gain a meaningful foothold. Among its main investors is Ant Financial, the financial service company controlled by Alibaba’s billionaire founder Jack Ma and the creator behind one of China’s largest digital wallets Alipay . Besides shelling out checks, Ant also sent many users to HelloTrans Tech when the latter first started as the bike-rental company Hellobike. For instance, Alipay’s hundreds of millions of users could easily access Hellobike without having to download its standalone app.

As the Chinese internet becomes occupied and colonized by tech heavyweights, teaming up with a major player almost becomes a prerequisite for aspiring startups to crack their market. Another case in point is Tencent being a boon to Didi’s early user acquisition by letting the ride-hailing app tap its popular WeChat messenger app and payments service.

Alibaba’s transportation ambition is a two-pronged strategy. On the one hand, Hello competes with Didi Chuxing (which Alibaba is also involved as a minority stakeholder) in offering on-demand rides, a category that’s become more onerous to the operator as Chinese regulators introduce stricter safety policies. On the other hand, Alibaba applies what it’s best at — the asset-light platform play — to ride-hailing with its own mapping service AutoNavi acting as a marketplace for third-party apps including Didi and AutoNavi.

It could be a few more years before it’s clear which of Alibaba’s strategies will stick it out. Didi still takes the lead with 66 million unique devices on its app in December, according to data collected by research firm iResearch. Hello was a tenth of its size at 6.3 million.

Hellobike declined to answer questions from TechCrunch about its new carpooling service. However, it did say it will hold a press event for the new service soon. We’ll update this story with any new details that come out of it.

21 Feb 2019

Sunstone Technology re-brands as Heartcore to become a consumer-only European tech fund

Update: an earlier version of this story positioned the €160 million fund as newly announced, when in actual fact it was disclosed in late 2017 and consists of a combination of Heartcore Fund III (seed and series A) and Heartcore Progression Alpha (growth fund following through on Heartcore’s most successful companies).

Sunstone Technology, the tech arm of Sunstone, and an early-stage European venture capital firm with offices in Copenhagen and Berlin, is re-branding today and says that its combined €160 million tech fund will invest in consumer startups only going forward, at seed and at Series A.

The 12-year-old VC firm’s new name is “Heartcore Capital,” and, say its partners, is designed to reflect an understanding that “entrepreneurship is like a crash course in personal development”. In recognition of this, VCs need to provide empathy with founders, first and foremost, rather than simply optimise for returns.

(Admittedly, to some readers that will sound like a rather lofty goal. You can read my push back on the premise in the Q&A below with Heartcore’s Jimmy Fussing and Max Niederhofer).

Also related to the re-brand is a formal repositioning of the firm to be consumer-only focused — both B2C and B2B2C — with a remit to invest at seed and Series A stages. Heartcore’s thinking is that the consumer segment will continue to yield “massive outcomes,” and notes that less than 5 percent of consumer spend globally has moved online so far.

“We want to offer entrepreneurs a superior VC product in this category and believe that we can achieve this through the network effects that come with focus,” Heartcore’s Max Niederhofer tells me, citing the firm’s previous investments such as GetYourGuide, Natural Cycles, Boozt, Exporo, Seriously, Lillydoo, and others. “We want to invest in Europe’s new category-defining consumer brands,” he says.

Meanwhile, Heartcore says it has expanded its investment and partner team to give the VC “truly pan-European coverage” across the consumer segment. Yacine Ghalim has been promoted from principal to partner and is helping to establish a Paris office. Heartcore has also hired Levin Bunz as partner from Global Founders Capital, the $1 billion investment arm of Rocket Internet, and will be based at the VC’s Berlin office. Lastly, Signe Marie Sveinbjørnsson has been hired as a partner and will act as Chief Operating Officer and will be based at Heartcore’s Copenhagen HQ.

Below follows an email Q&A with Heartcore Managing Partner Jimmy Fussing and General Partner Max Niederhofer to find out more about the new fund, the new name ethos, and the pair’s thoughts on Brexit.

TC: Why the name change? If feels like you could be throwing away any brand recognition you already had.

JF: It felt like we were already changing a lot: a new positioning as Europe’s consumer-only VC, the “founders first” ethos. So the name change was a consequence of that. We had been operating as Sunstone Capital since 2007 together with Sunstone Life Sciences, who target a very different entrepreneur. Our founders are often younger, they don’t come from corporate R&D or academia, they tend to wear sneakers rather than lab coats.

MN: Over the last decade a lot of capital has come into the industry. The volume of potential deals has been increasing and we were naturally gravitating towards a consumer focus. There’s a lot of benefit from specialization and the new brand articulates much more clearly what we stand for.

JF: Like the founders we back, we have to take risks in order to offer something truly unique. This new name builds on our history and track. It’s deeply authentic. We like the vulnerability of the pun and that it’s just slightly outside our comfort zone. The objective of VC marketing is to be in the consideration set of the top founders – we think the Heartcore name is very memorable and the positioning as consumer-only VC in Europe is truly unique.

TC: Going forward, the fund is going to be entirely consumer-focussed (B2C and B2B2C), when many other VC firms presumably see B2B and the enterprise as safer bets and, arguably, playing to European strengths. What is the thinking behind going all in on consumer?

MN: VC is a game of power laws, where your largest companies represent much of your return. It isn’t really about risk reduction from a portfolio perspective. There are more large outcomes in consumer versus B2B – also in Europe. And Europe has a century-long history of creating outstanding consumer brands. Even online, think Booking.com, Spotify, Skype, Supercell, Minecraft… we think we can build on these strengths.

JF: Historically we’ve also just been very good at B2C. We backed folks like Boozt, GetYourGuide, Natural Cycles, Prezi very early on. The technology exists to build large consumer companies from pretty much anywhere. Founders all over Europe are rethinking every value chain from the point of view of the end customer – we believe that there is massive opportunity to build truly category-defining consumer companies in Europe.

TC: You cite a stat that says only 5 percent of commerce has moved online worldwide so far. Why do you think that is, what are the bottlenecks?

JF: To some extent, it’s the different nature of value chains of different industries. For example, media was much more readily disrupted by online because of its fragmentation, competitiveness, and zero marginal cost of end product delivery. Retail required setting up a physical delivery infrastructure, which has happened over the last decade and which is why e-commerce is still growing rapidly. Then industries like healthcare or finance have regulations and different gatekeepers that made it a bit more difficult for new entrants. But just look at where the neo-banks are today.

MN: As a person in tech you have a tendency to calibrate digital penetration using the existing platforms like social media or entertainment, and in particular with a skewed view on who the potential consumer is. There’s massive opportunity in old industries that are very physical, like real estate or transportation, and also a huge opportunity to give many more consumers access to better products and services. Think “the bottom 90%” – not just in the Western world, but everywhere.

TC: Digging deeper into your investment remit and beyond warm and fuzzy notions about tech changing people’s lives for the better, what particular consumer sectors, problems or technologies are you seeking to invest in out of this fund?

JF: We have sector-specific investment theses in areas like Direct-to-Consumer Brands, Food, Digital Health, Travel, Finance. We really want to invest anywhere that the consumer spends money. And we have business model-specific investment theses for e.g. Marketplaces or Consumer Subscriptions. And then we have a framework for how we think about problems: what’s the consumer trying to achieve, how does this do a better job, what emotional needs are satisfied in the context.

MN: There’s really two buckets of consumer investing: one is the emergence of new platforms, where consumers adopt a new technology very rapidly. And that’s probably where we’ve seen the bulk of venture returns, like Google, Facebook, and others. But there’s a second bucket where people are applying existing technologies to reinvent old industries and come up with new and better products and services. That’s incredibly promising right now and it is where we spend most of our time. We think the majority of our investments will come in that second category. But we’re certainly always looking for the first as well: what will the adoption curve of voice, VR/AR, or decentralizeded web look like for consumers.

TC: What stages and geographies will the fund invest? i.e. location and average cheque size.

JF: We’re focused on Europe, with the occasional investment in the US. We’re firmly Seed and Series A, with cheque sizes ranging from €250K to €5 million, allowing us to also participate in the large Series As.

TC: You talk about Heartcore Capital being “founders first” and having more empathy for the founder than returns alone. However, in various forms this is the pitch of almost every venture capital firm, perhaps a sign of a frothy market. What is Heartcore actually doing tangidly to put this ethos into practice?

MN: I love this question because it really demonstrates what we’re about. You ask for something “tangible” but that’s just it – venture according to us is not just a game of functional value-add, about what you do. It’s just as much about how you are and how you show up: with empathy and humility, with respect for the entrepreneurial journey, with a coaching mindset.

JF: We have a long list of foundational principles about how we interact with founders that’s totally different to what we’ve ever seen from other VCs. It all comes back to the Saint-Exupery quote on which we base our name: “It is only with the heart that one can see rightly; what’s essential is invisible to the eyes.”

TC: Let’s talk about Brexit… Are you long or short on the U.K. leaving the EU and how do you think it will affect the ecosystem in the U.K., but more importantly, right across the various hubs in Europe?

JF: The U.K. has a very strong and deep startup ecosystem, and Brexit won’t change that. Of course a hard Brexit will complicate doing business in the UK. We’ve seen other European hubs trying to exploit that. Paris, Berlin, and our home market in the Nordics feel like they’re doing very well, which is why we set up local offices and teams there.

MN: But we’re keen to keep looking at U.K.-based consumer startups and Brexit won’t stop us from doing that. London has the best track in European consumer tech and we think it will remain a key hub for us going forward.