Working notice ยท requires privacy/legal review before launch

Pilot privacy notice

This notice describes the current implementation pilot. It is not a final production privacy policy and must be reviewed against the actual deployment, vendors, locations, retention jobs, and customer agreements before public launch.

Data processed

The application processes account information and an uploaded original .eml. It extracts campaign subject, sender, timestamps, anchor labels, deduplicated HTTP links and remote images, UTM information, and bounded check results.

Raw email body and attachments

Raw email body content and attachment bytes are parsed transiently and are not stored in Campaign Recheck domain tables. Uploaded data still exists in process memory and temporary request handling while the request is being processed.

URLs and reports

Full original and final URLs are encrypted at rest. Display URLs and redirect evidence redact non-UTM query values and opaque or sensitive path segments. No redaction heuristic can replace appropriate authorization and data minimization.

Network checks

Eligible public destinations receive a bounded HTTP request with a Campaign Recheck user agent. Protected links are not opened. Sentry HTTP instrumentation and trace propagation are disabled for these crawler requests.

Retention

Configured 7/30/90/365-day report periods are product targets. A production retention/deletion job, backups policy, vendor inventory, and deletion verification must be completed before those periods are offered contractually.

Contact

Privacy questions about the pilot can be sent to vmarcetic@bytecode.hr.