Controller and contacts
Legal identity, address, privacy route, representative and DPO where applicable.
Legal draft · Noindex
Trace does not yet have a verified operating legal entity, complete processing inventory or professional privacy-law approval. This page identifies what must be resolved before a public privacy notice can be relied on.
Do not rely on this page as a privacy notice. It does not identify a legally verified controller and does not provide a complete or approved description of processing. No live pilot should process customer case data until the applicable privacy notice, DPA, security terms and operational procedures are complete.
Publication gate
Entity placeholder: “Trace” is currently a product and brand name on this site. It must not be substituted for the controller’s verified legal identity.
Implementation inventory · Verify before use
The present codebase uses the following browser and server storage. This is a technical inventory for legal review, not a settled statement of purpose or legal basis:
/api/events, which runs without cookies for visitors who have not answered the banner and stops entirely for visitors who select necessary only;_ga-family cookies, whose final configuration and retention must be included in the operative notice;The waitlist does not persist an IP address. It uses server validation, an origin check, a honeypot, rate limiting and duplicate suppression. An optional notification webhook may run after the durable record is written, but it cannot replace first-party storage.
The current analytics schema rejects common personal fields and does not receive names, email addresses, company details, website values or the optional difficult-request narrative. That technical control is not a legal conclusion that no personal data is processed elsewhere.
The required contact permission covers assessing and responding to the next step selected in the enquiry. It is not a general marketing permission. A separate marketing choice is required only when someone asks for design-partner updates, and it defaults to off.
For launch, an unprogressed waitlist or direct-enquiry record should be reviewed and deleted no later than 12 months after receipt. If a relevant conversation or commercial relationship starts, only the information needed for that relationship should move into the applicable approved record and retention schedule.
Current implementation gap: the database does not yet enforce that deletion automatically. The operator must approve this period, document exceptions, assign an owner and implement a deletion procedure before public intake is enabled. Analytics retention also requires a separately approved period.
Visitors must not submit identity documents, data exports, credentials, live data-subject requests or other sensitive case material through a public website form. Any future live work needs a separately approved secure transfer route and contractual scope.
Required notice structure
Exact content must follow the verified processing operation. These headings are drafting prompts, not pre-approved answers.
Legal identity, address, privacy route, representative and DPO where applicable.
Website, application, commercial, support and pilot-case data described separately.
A purpose-specific analysis, including legitimate-interest detail where used.
Processors, subprocessors, other recipients, locations and transfer safeguards.
Concrete periods or criteria for leads, analytics, contracts, security logs and case data.
How rights can be exercised, identity handled and complaints made to the competent authority.
Next legal action: appoint the operating entity and legal owner, complete the actual processing register, approve and operationalise the proposed retention rule, confirm every production vendor and data route, then have EU privacy counsel approve a notice that matches the deployed service. Until then, this page remains noindex and non-operative.