GaugeSeal
Privacy policy
Who holds what, on whose instructions, and what this site records about you — which is nothing at all.
https://api.gaugeseal.com/privacy · Revised 9 August 2026 · draft, not in force — effective date pending · security@gaugeseal.com
1. Two roles, and which one you are reading about
Almost all the personal data in GaugeSeal is not ours. It belongs to the organisation that connected its BI platform, and we hold it as their processor, on their instructions, under the data processing agreement.
For one narrow thing we are the controller: the sign-in addresses of the people who use the product, because we decide how sign-in works. Sections 2 and 3 are about that. Section 4 is for someone whose report views are here because their employer connected a platform.
2. What we hold as controller, and why
Your email address, so a sign-in link can reach you and so the weekly digest can. Single-use sign-in tokens and session records, held as digests with their expiry on the row. The name of the organisation you gave at signup. That is the list.
The legal basis is the contract with your organisation, and our legitimate interest in the service being secure and working. We send sign-in links, the digest your account exists to produce, and notices about the service. We do not send marketing, and there is no automated decision-making about you.
We keep it for the life of your membership. Removing you deletes the row, and your tokens and sessions with it. Expired tokens and sessions are swept daily.
3. Your rights
You may ask for access, rectification, erasure, restriction, portability, or to object to processing based on legitimate interest. Write to security@gaugeseal.com and you will get an answer within 30 days. You may also complain to a supervisory authority: yours, where you live or work, or the authority that supervises us.
4. If your employer connected a platform
Then your report views, or your name against a report you own, may be here. Your employer decides what is collected and for how long; we only act on their instructions, so ask them first — they can erase you from our store in one request. If you write to us instead we will tell you who to ask and let them know you asked.
What that data is, in full:
| Personal data | Whose | Why | How long | Erasure |
|---|---|---|---|---|
| Who viewed which report, and when | People in your BI platform who open a report | Usage cannot be judged without it — an anonymised count could never say five different people read this | 24 months by default, set per account | One request rewrites that person's identity across every event, leaving the events themselves intact |
| Report and workbook owners | People your BI platform records as owning an asset | The ownership rule, and the 'who do I talk to' column on the board | Life of the tracked report | The same rewrite |
| Your colleagues' sign-in addresses | The people you invite to use GaugeSeal | Magic-link sign-in, invites, and the weekly digest | Life of the membership | Removing the member deletes the row, and their sign-in tokens and sessions with it |
| Rejected deliveries, as they arrived | Anyone named in telemetry we could not accept | Malformed telemetry is kept for inspection rather than dropped, so nothing is lost silently | 6 months by default, set per account | The same rewrite reaches inside them |
Nothing else about a person is stored. Health verdicts, transitions, contracts and cursors carry no identities.
5. This website, and what it does not do
The public pages set no cookie, load no font, script or image from anyone else's servers, and run no analytics. There is no tracking pixel in the weekly email either — we would rather not know when you opened it.
Signed in, there is exactly one cookie: your session. It is host-only, HTTP-only and SameSite, and signing out deletes the record behind it rather than just the cookie.
We keep no web access log. The application records the method, path and status of a request and nothing else — no query strings, no addresses, no keys — and the proxy in front of it is configured without an access log, though its error output can name a client address in the system journal.
Where a customer installs the embed collector, their viewers' browsers post events to us directly. The snippet sets no cookie and stores nothing in the browser; each event carries a fresh random id used only to de-duplicate delivery, and whether a viewer is identified at all is the embedding page's choice.
6. Who else can reach it
Two sub-processors, and no others:
| Sub-processor | What it does | Where |
|---|---|---|
| OVHcloud | The virtual server the application runs on, its disk, and the daily backup snapshots on it. All stored data is here. | European Union |
| Scaleway | Delivers sign-in links and the weekly digest. It sees the recipient's address and the message, which names that account's own reports, owners and verdicts. | European Union — France |
Nothing is transferred outside the European Union. One region, no replication elsewhere. If that ever has to change, customers are told before it does.
7. How it is protected
Credentials are sealed before they are stored, secrets never reach a log, tenants are separated structurally, and backups are daily with a rehearsed restore. The security brief is the short version and the DPA's Annex II is the full list.
8. Changes, and who to write to
If this policy changes materially we email account members before it takes effect. Anything at all about privacy: security@gaugeseal.com, answered by a person.
Not ready to be signed
This policy describes what the system does today. It is waiting on the same professional review as the terms, so it is not in force yet, and these are unsettled:
- The authority that supervises us — follows the entity's country of establishment.
- Effective date — set when the professional review of the terms and the privacy policy is complete (7.H3).