Technical boundaries. Explicit permission. Verifiable evidence.
This page explains the INSIGHTS product, not the privacy notice for this marketing website. Controls constrain processing; they do not replace a controller’s legal assessment or evidence from the deployed system.
Looking for information about browsing this site or contacting us? Read website privacy information (draft) and cookies and choices.
Aggregate output does not mean every input is anonymous.
Request context and transient deduplication can involve personal or pseudonymous data even when the reporting output is aggregate. The operational lane avoids persistent visitor identifiers and cross-window subject lookup. The security lane can retain raw signals under a separate short limit. These differences matter when explaining the product to visitors and deciding which processing is permitted.
Controls to review
INV-001 / INV-002
Operational SDK boundaries
The operational browser SDK is prohibited from client-side storage and fingerprinting. Bundle-level checks cover storage primitives and device-interrogation APIs. This is a product SDK claim, not an inventory of this marketing site or a customer’s other scripts.
INV-003 / INV-004 / INV-005
Transient identifiers and window keys
Deduplication tokens must remain in memory and be zeroised after use. Plaintext salts are restricted to locked memory; wrapped material is permitted only for live-window recovery. Window closure must remove wrapped material, destroy the applicable wrapping-key version and record verifiable evidence.
INV-006 / INV-007 / INV-009
Tenant-scoped aggregate reports
Operational reporting is tenant-scoped, aggregate and subject to suppression and query restrictions. Windows are limited to 1, 7, 14 or 30 days, with profile-specific caps and additional approval for 30 days. Technical eligibility under a profile is not a legal assessment of a customer’s purpose.
INV-008 / INV-010
Separate security purpose
Raw security signals have separate keys and a configured seven-day retention limit. Only bot_label and confidence may cross the security interface into an otherwise permitted operational request. Raw security rows cannot be repurposed into visitor analytics or anonymous profiles.
INV-011
Evidence with an explicit scope
Audit and destruction records are hash-chained and verifiable. Verification of a signed pack is distinct from checking independent store absence, purge results and actual closure timestamps. Eventual cleanup is not proof that the original deletion deadline was met.
INV-012–INV-017
Consent and optional-feature gates
The current operational beta requires analytics consent. Separate consented calibration and recent-activity capabilities exist behind additional gates and are not active in this beta. Their presence in code does not make a partner feed, monthly model or subject-level non-consented profile available.
What to ask for before relying on a claim
- The deployed version, enabled feature gates, accepted terms and property-specific configuration.
- Recent test and token-persistence sweep results, including what was not tested.
- Window-end and actual closure times, key-destruction evidence and current purge results.
- The applicable notice, processing purpose, consent or other reviewed authorisation, and working objection or withdrawal controls.
Tests are not legal certification. A passing build is not, by itself, evidence that all historical production deletion deadlines were met. The versioned beta terms and subprocessor register retain their own scope and version; this explanation does not amend them.