Skip to content

Website privacy & cookies

No optional analytics or advertising is configured in this website application. There is no optional tracking preference to save. Dismissing the notice only hides it until this page reloads; closing this panel does not give consent to anything.

Our source and public-response check is limited. Hosting logs, security challenges, enquiry handling and retention still need confirmation. The information pages are review-needed, not a complete approved privacy or cookie policy.

You can browse without an enquiry. The demo form explains whether it opens a mail draft or submits to a configured endpoint, and includes a clear-fields control. These website choices do not change consent on customer websites using INSIGHTS.

INSIGHTS closed operational beta

Processor Terms

Version beta-1 · Effective/offered 18 August 2026

1. Parties, written agreement and acceptance

These Closed Beta Processor Terms form an electronic written data-processing agreement between the legal entity that controls the approved customer property and whose authorised representative installs or directs installation of its property-specific INSIGHTS loader (the “Controller”), and PROVENANCE365 LIMITED, company number 17105747, registered at 9 Byford Court, Crockatt Road, Hadleigh, Suffolk, United Kingdom, IP7 6RD (the “Processor”). These terms, the Subprocessor Register version beta-1 and the exact property admission record are the data-processing portion of the parties’ beta agreement. The authenticated setup page presents both documents and explains the effect of installation before showing the tag. Installing or directing installation of a tag containing data-p365-terms="beta-1" and data-p365-subprocessors="beta-1" confirms authority to bind the Controller, accepts those exact versions and is the Controller’s documented instruction to process the approved property configuration. The effective time is the first verified loader request from the approved exact origin. No approval email or signature is required. The authorised installer must not install the tag if the Controller does not agree. Separately agreed terms providing greater protection for personal data continue to apply.

2. Processing details and instructions

Subject matter and purpose: consent-based, privacy-minimised website measurement and isolated traffic-security classification for one approved property; receipt of closed-schema requests; minimisation, classification and bounded-window deduplication; production of disclosure-protected aggregates; configuration and evidence. Duration: from the first verified request after authorised installation until offboarding completes, plus only a documented legal or backup-expiry interval. Data subjects: visitors to the approved property and customer administrators. Operational data, processed only after analytics consent: truncated IP address, coarse browser, operating-system, device, network and geography categories, server time, approved page group, referrer host, performance band and consent state. Security data, processed whether analytics is accepted, rejected or unresolved: full IP address, bounded path without query or fragment, protocol, TLS, network and closed-schema request metadata. Administrator data: name, work email, organisation/property membership, role, authentication/session and audit metadata. Special-category data and children’s data are not instructed or permitted. Authentication, checkout, child-directed and unusually sensitive page groups are excluded unless a later specific written instruction is reviewed and accepted. The Controller instructs the Processor to process only the fields, exact property and origin, purposes, retention and page groups in the authenticated admission record. A documented change is a new instruction. The Processor must not sell the data, use it for advertising, build identity or audience profiles, or combine it with another customer’s data. The Processor will notify the Controller if an instruction appears unlawful and suspend it while the parties resolve the issue, unless applicable law prohibits notice.

3. Confidentiality and security

The Processor will ensure authorised personnel are bound by confidentiality and have access only for a documented role. Measures appropriate to the risk include separate operational and security queues, services, credentials and stores; tenant-scoped authentication and database controls; storage-free browser collection and closed schemas; cryptographic window deduplication and salt destruction; seven-day security-store expiry; encryption in transit and provider encryption at rest; least-privilege secret storage and protected network boundaries; disclosure thresholds, query budgets and suppression ledgers; signed audit evidence, invariant checks, purge tests and isolated recovery procedures. A material reduction in these measures requires prior notice and may not reduce the protection required by applicable law or the Controller’s instructions.

4. Subprocessors

The Controller grants general written authorisation for suppliers in the accepted Subprocessor Register. The Processor will give at least 30 days’ notice before adding or replacing an in-scope supplier, except where an emergency security change reasonably requires shorter notice; provide a reasonable opportunity to object on data-protection grounds; impose equivalent data-protection obligations; and remain responsible for each subprocessor’s performance. If a reasonable objection cannot be resolved, either party may terminate the affected INSIGHTS processing. The Processor will suspend and offboard that processing rather than weaken the agreed privacy controls.

5. Rights, regulatory assistance and breaches

Taking account of the processing, the Processor will assist the Controller with reasonable technical and organisational measures for data-subject rights. The operational lane deliberately has no visitor identifier or visitor record, so the Processor will explain that limitation rather than claim it can locate an individual it cannot identify. Administrator records and security data follow their actual storage and retention paths. The Processor will reasonably assist with security duties, breach assessment and notification, data-protection impact assessments, prior consultation and regulator enquiries. It will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the service and provide available information about scope, affected systems and data, likely consequences, containment, remediation and a contact point. Support, incident and data-protection contact: support@hyceangroup.com.

6. Deletion, return and recovery boundary

At termination, the Processor will return held, technically exportable personal data at the Controller’s choice and securely delete personal data and copies unless law requires retention. It will identify any legally retained copy, purpose and end date. INSIGHTS does not retain visitor or session rows and cannot return a visitor list. It can return customer configuration, audit and evidence records. Offboarding disables collection and access, drains or purges queues, removes scoped database records, verifies logs and caches, destroys tenant key material and observes documented provider backup-expiry boundaries, with an audited result. The closed-beta recovery boundary includes Render PostgreSQL point-in-time recovery, an encrypted portable PostgreSQL export, a barrier-encrypted OpenBao snapshot and provider-managed ClickHouse backups. ClickHouse has no external recovery copy in this beta. The Controller accepts that disclosed managed-backup-only boundary; it is not represented as independent recovery custody or an availability commitment.

7. Audit and compliance evidence

The Processor will make information reasonably necessary to demonstrate compliance with these terms and applicable processor obligations available to the Controller, including the customer evidence pack, current architecture, invariant results, audit-chain verification, purge records and relevant restore evidence. On reasonable notice, the Controller may audit the Processor or appoint an independent auditor bound by confidentiality. Existing evidence should be used first, and audits should avoid another customer’s data and security secrets. These practical limits do not prevent a regulator-required audit or one following a material incident.

8. International transfers

The Processor will not transfer personal data outside the UK or EEA except on the Controller’s documented instruction or under applicable law and with a valid transfer mechanism and supplementary measures where required. Provider region selection is not, by itself, a legal transfer mechanism. The current technical suppliers and configured locations are disclosed in the accepted Subprocessor Register.

9. Controller obligations and beta limits

The Controller determines its lawful bases, supplies accurate instructions and visitor privacy information, and maintains an effective consent manager through which a visitor can grant, refuse and withdraw analytics consent. A separate INSIGHTS objection page, preference cookie or consent interface is not required. The Controller selects only approved origins and page groups and does not use outputs to identify or single out a person. It must name authorised administrators and promptly request suspension when an instruction, property or account is no longer valid. The beta has no SLA. Support, incident response, availability and recovery are best endeavours, without reducing statutory or data-protection duties. The beta excludes consented calibration, modelled reach, partner feeds, addressable segments and visitor exports. Neither party may describe an unavailable feature or suppressed value as measured data. Each admission is bounded by the exact HTTPS origin, profile, privacy window, disclosure threshold, dimension cap and page-group policy displayed in its authenticated record. The Controller’s live privacy notice and consent-manager behaviour must pass verification before the Processor activates collection. Rejected or unresolved analytics consent must reach only the isolated security process.

10. Governing law and contact

These terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction. Support, incidents, rights requests and data protection: support@hyceangroup.com Registered address: PROVENANCE365 LIMITED, 9 Byford Court, Crockatt Road, Hadleigh, Suffolk, United Kingdom, IP7 6RD