Policy review draft

Privacy should describe the system we actually operate.

This draft identifies the information and decisions that a final privacy notice must bind. It does not pretend provider, retention or jurisdiction choices have been made.

Approval status

Not approved for public reliance.

Review draft — not approved public policy.

This page is a decision-ready content draft. It must be reviewed against the real hosting, analytics, inquiry, CRM, notification, security and legal-provider bindings before public publication.

The final notice must name Intelligence Factory’s correct legal identity/contact, the selected website host, inquiry store, abuse verifier, CRM, notification provider, analytics tools and any cross-border processing that actually applies.

Information categories

What the current public design may handle.

Website requests
IP/network metadata, requested route, user agent and security diagnostics required to deliver and protect the site.
Inquiry details
Name, work email, company, optional phone and the business context a person chooses to submit.
Attribution
Only approved, bounded campaign/referrer/entry fields—not arbitrary query strings.
Documentation feedback
A guide/section key and bounded feedback; the final destination is not yet selected.

No live commerce customer data is needed to browse this explanation site. A future project may involve separate client-system data under its own approved agreements and operating controls.

Bindings required before approval

Real choices, not fake promises.

Purpose and legal basis

Counsel/owner must approve purposes and applicable legal bases for inquiries, security, analytics and communication.

Providers and locations

Insert the actual contracted providers, subprocessors and processing locations.

Retention and deletion

Approve concrete periods and deletion/backup handling for logs, inquiries, CRM records and feedback.

Rights and contact

Name the responsible entity, privacy contact and jurisdiction-appropriate request process.

Cookies and analytics

Describe only enabled tools and implement consent controls where required.

Security and incidents

State accurate controls and notification commitments from the real operating model.