Working notice ยท requires privacy/legal review before launch
Pilot privacy notice
This notice describes the current implementation pilot. It is not a final production privacy policy and must be reviewed against the actual deployment, vendors, locations, retention jobs, and customer agreements before public launch.
Data processed
The application processes account information and an uploaded original .eml. It extracts campaign subject, sender, timestamps, anchor labels, deduplicated HTTP links and remote images, UTM information, and bounded check results.
Raw email body and attachments
Raw email body content and attachment bytes are parsed transiently and are not stored in Campaign Recheck domain tables. Uploaded data still exists in process memory and temporary request handling while the request is being processed.
URLs and reports
Full original and final URLs are encrypted at rest. Display URLs and redirect evidence redact non-UTM query values and opaque or sensitive path segments. No redaction heuristic can replace appropriate authorization and data minimization.
Network checks
Eligible public destinations receive a bounded HTTP request with a Campaign Recheck user agent. Protected links are not opened. Sentry HTTP instrumentation and trace propagation are disabled for these crawler requests.
Retention
Configured 7/30/90/365-day report periods are product targets. A production retention/deletion job, backups policy, vendor inventory, and deletion verification must be completed before those periods are offered contractually.
Contact
Privacy questions about the pilot can be sent to vmarcetic@bytecode.hr.