privacy policy
Effective Date: August 2026
Compliance Standards: GDPR (EU), CCPA/CPRA (USA) & Global Data Privacy Frameworks.
1. Global Data Protection Commitment
INSITE is committed to total digital sovereignty and strict data privacy. This Policy governs the collection, processing, and protection of enterprise client data, executive inquiry metadata, and end-user interactions within systems architected by INSITE.
2. Information We Collect & Processing Rationale
-
Executive & System Metadata: Contact details, brand specifications, and technical environment parameters collected to evaluate enterprise partnerships and configure custom systems.
-
Spatial & Interaction Telemetry: Non-biometric interaction logs generated during virtual try-on, 3D furniture preview, or client portal sessions—processed purely to maintain session stability and system optimization.
-
Transaction Logs: Technical event logs generated during automated checkout and airway bill generation—processed strictly to ensure transaction execution and auditability.
3. Zero Third-Party Monetization Policy
INSITE enforces a zero-monetization policy. We do not sell, rent, license, or trade enterprise client data, system metrics, or end-user analytics to third-party advertising brokers or data aggregators under any circumstances.
4. Data Isolation & Security Architecture
All data assets are housed within enterprise cloud environments (AWS / Google Cloud / Azure) utilizing bank-grade encryption protocols:
-
Data in Transit: Enforced TLS 1.3 / SSL encryption across all API channels and browser interactions.
-
Data at Rest: AES-256 bit encryption applied to all private databases and storage buckets.
-
Environment Isolation: Dedicated single-tenant database schemas deployed where high-level corporate confidentiality is required.
5. Cross-Border Data Transfers
As a global systems architecture partner, INSITE may process encrypted data across secure international cloud servers. All cross-border transfers adhere strictly to Standard Contractual Clauses (SCCs) and global data sovereignty guidelines to ensure end-to-end compliance.
6. International Data Subject Rights
Under global privacy directives (including GDPR and CCPA), authorized users and enterprise partners reserve the right to:
-
Request formal audits or structured exports of their stored account telemetry.
-
Request the permanent deletion (“Right to be Forgotten”) of non-essential account and administrative data.
-
Restrict or object to specific automated processing workflows.
7. Privacy Governance & DPO Contact
For privacy audits, compliance requests, or data protection verification, contact our Data Protection Office directly at Support@insite-agency.com.
