GaugeSeal

Privacy policy

Who holds what, on whose instructions, and what this site records about you — which is nothing at all.

https://api.gaugeseal.com/privacy · Revised 9 August 2026 · draft, not in forceeffective date pending · security@gaugeseal.com

1. Two roles, and which one you are reading about

Almost all the personal data in GaugeSeal is not ours. It belongs to the organisation that connected its BI platform, and we hold it as their processor, on their instructions, under the data processing agreement.

For one narrow thing we are the controller: the sign-in addresses of the people who use the product, because we decide how sign-in works. Sections 2 and 3 are about that. Section 4 is for someone whose report views are here because their employer connected a platform.

2. What we hold as controller, and why

Your email address, so a sign-in link can reach you and so the weekly digest can. Single-use sign-in tokens and session records, held as digests with their expiry on the row. The name of the organisation you gave at signup. That is the list.

The legal basis is the contract with your organisation, and our legitimate interest in the service being secure and working. We send sign-in links, the digest your account exists to produce, and notices about the service. We do not send marketing, and there is no automated decision-making about you.

We keep it for the life of your membership. Removing you deletes the row, and your tokens and sessions with it. Expired tokens and sessions are swept daily.

3. Your rights

You may ask for access, rectification, erasure, restriction, portability, or to object to processing based on legitimate interest. Write to security@gaugeseal.com and you will get an answer within 30 days. You may also complain to a supervisory authority: yours, where you live or work, or the authority that supervises us.

4. If your employer connected a platform

Then your report views, or your name against a report you own, may be here. Your employer decides what is collected and for how long; we only act on their instructions, so ask them first — they can erase you from our store in one request. If you write to us instead we will tell you who to ask and let them know you asked.

What that data is, in full:

Personal dataWhoseWhyHow longErasure
Who viewed which report, and whenPeople in your BI platform who open a reportUsage cannot be judged without it — an anonymised count could never say five different people read this24 months by default, set per accountOne request rewrites that person's identity across every event, leaving the events themselves intact
Report and workbook ownersPeople your BI platform records as owning an assetThe ownership rule, and the 'who do I talk to' column on the boardLife of the tracked reportThe same rewrite
Your colleagues' sign-in addressesThe people you invite to use GaugeSealMagic-link sign-in, invites, and the weekly digestLife of the membershipRemoving the member deletes the row, and their sign-in tokens and sessions with it
Rejected deliveries, as they arrivedAnyone named in telemetry we could not acceptMalformed telemetry is kept for inspection rather than dropped, so nothing is lost silently6 months by default, set per accountThe same rewrite reaches inside them

Nothing else about a person is stored. Health verdicts, transitions, contracts and cursors carry no identities.

5. This website, and what it does not do

The public pages set no cookie, load no font, script or image from anyone else's servers, and run no analytics. There is no tracking pixel in the weekly email either — we would rather not know when you opened it.

Signed in, there is exactly one cookie: your session. It is host-only, HTTP-only and SameSite, and signing out deletes the record behind it rather than just the cookie.

We keep no web access log. The application records the method, path and status of a request and nothing else — no query strings, no addresses, no keys — and the proxy in front of it is configured without an access log, though its error output can name a client address in the system journal.

Where a customer installs the embed collector, their viewers' browsers post events to us directly. The snippet sets no cookie and stores nothing in the browser; each event carries a fresh random id used only to de-duplicate delivery, and whether a viewer is identified at all is the embedding page's choice.

6. Who else can reach it

Two sub-processors, and no others:

Sub-processorWhat it doesWhere
OVHcloudThe virtual server the application runs on, its disk, and the daily backup snapshots on it. All stored data is here.European Union
ScalewayDelivers sign-in links and the weekly digest. It sees the recipient's address and the message, which names that account's own reports, owners and verdicts.European Union — France

Nothing is transferred outside the European Union. One region, no replication elsewhere. If that ever has to change, customers are told before it does.

7. How it is protected

Credentials are sealed before they are stored, secrets never reach a log, tenants are separated structurally, and backups are daily with a rehearsed restore. The security brief is the short version and the DPA's Annex II is the full list.

8. Changes, and who to write to

If this policy changes materially we email account members before it takes effect. Anything at all about privacy: security@gaugeseal.com, answered by a person.

Not ready to be signed

This policy describes what the system does today. It is waiting on the same professional review as the terms, so it is not in force yet, and these are unsettled:

  • The authority that supervises us — follows the entity's country of establishment.
  • Effective date — set when the professional review of the terms and the privacy policy is complete (7.H3).