Privacy Policy & Data Sovereignty
1. Executive Overview & Technological Scope
Signal Recovery Software Engine ("SRSE", "we", "us", or "our"), accessible at https://signalrecoverysoftwareengine.com, operates specialized enterprise server-side conversion tracking, reverse-proxy event routing, and Conversions API (CAPI) infrastructure.
Our architecture is engineered upon the fundamental principles of cryptographic data minimization, edge normalization, and zero unauthorized third-party personal data exposure. We deliver reverse-proxy infrastructure that ingests marketing attribution signals on our subscribers' first-party domains, cryptographically sanitizes sensitive match attributes, and securely relays conversion events directly to designated downstream ad network endpoints (such as Meta Conversions API, Google Ads Enhanced Conversions, and TikTok Marketing API).
This Privacy Policy delineates how personal information is collected, processed, normalized, and secured across our public web properties, administrative customer portal, and enterprise reverse-proxy edge ingestion nodes.
2. Dual Regulatory Capacity: Data Controller vs. Data Processor
Under global data protection frameworks—including the European Union General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom General Data Protection Regulation ("UK GDPR"), and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA")—SRSE operates in two distinctly separate legal capacities:
SRSE acts as a Data Controller exclusively with respect to:
- Visitors browsing our primary website (
signalrecoverysoftwareengine.com). - Direct enterprise subscribers, account registrants, and billing contacts.
- Commercial subscription transactions, invoices, and payment tokens handled via our PCI-DSS Level 1 partner, Stripe, Inc.
- Administrative technical telemetry and infrastructure security logs.
SRSE acts strictly as a Data Processor (GDPR Art. 28) and Service Provider (CCPA/CPRA § 1798.140(ag)) with respect to:
- Conversion event payloads and attribution signals ingested on behalf of our enterprise subscribers.
- Customer match parameters (emails, phone numbers, transaction values) routed via our reverse-proxy edge nodes.
- Processing performed solely under the documented instructions of the subscriber (the Data Controller/Business).
3. Categories of Personal Data & Payload Architecture
The categories of data processed by SRSE depend upon the interaction context:
| Data Category | Specific Elements | Processing Role | Retention / Lifecycle |
|---|---|---|---|
| Subscriber Account Data | Name, enterprise email, company name, billing address, IP address, payment tokens (Stripe). | Data Controller | Duration of commercial agreement + 7 years (statutory tax requirement). |
| Customer Match Parameters | Cryptographically hashed email (SHA-256), hashed phone number (E.164 SHA-256), hashed name, postal code, city. | Data Processor | Ephemeral (transient in-memory edge transit; max 72h deduplication buffer). |
| Attribution Identifiers | First-party HTTP cookie (_cg_fp_uid), click identifiers (fbclid, gclid, ttclid). |
Data Processor | 1st-party persistent storage up to 365 days; reverse proxy does not retain historical graphs. |
| Ephemeral Network Telemetry | Client IP address, User-Agent, coarse geolocation (Country/Region/City level). | Processor / Controller | IP truncated/anonymized at edge memory; never stored in plaintext database records. |
| Event Metadata | Order ID, currency, transaction value, product categories, conversion timestamp. | Data Processor | Transmitted directly to downstream ad APIs; purged post-dispatch. |
4. Cryptographic Edge Normalization & Data Minimization
SRSE implements edge-native cryptographic normalization protocols to ensure absolute data minimization before conversion signals leave the merchant's first-party boundary:
- Standardized Pre-Hashing Sanitization: Customer data attributes are sanitized according to ad platform developer standards. Emails are trimmed of leading/trailing whitespace, converted to lowercase ASCII, and stripped of unallowable characters. Telephone numbers are normalized to strict international E.164 format (e.g.,
+1234567890). - 256-Bit SHA-256 Hashing: Sanitized attributes are converted into irreversible 64-character hexadecimal SHA-256 hashes directly in edge runtime memory (Cloudflare Workers, AWS Lambda@Edge, Fastly).
- Zero Plaintext Storage: Raw, unhashed personal data is never written to non-volatile disks, database tables, or persistent logs within our reverse-proxy infrastructure.
- Transient In-Memory Buffering: Payloads are buffered in memory solely for idempotent retry dispatch and event deduplication (maximum 24 to 72 hours), after which all temporary caches are cryptographically shredded.
5. European Union & United Kingdom GDPR Compliance
For users residing in the European Economic Area (EEA), United Kingdom (UK), and Switzerland, our data processing operations strictly comply with the requirements of GDPR, UK GDPR, and the Swiss Federal Act on Data Protection (FADP):
A. Legal Bases for Processing (Article 6(1))
- Article 6(1)(b) (Contractual Necessity): Processing required to establish subscriber accounts, deliver edge reverse-proxy signal routing, provide customer billing, and fulfill technical SLA commitments.
- Article 6(1)(f) (Legitimate Interests): Processing required to detect and neutralize fraudulent conversion bursts, safeguard infrastructure against distributed denial-of-service (DDoS) attacks, and maintain edge network availability.
- Article 6(1)(a) (Consent): For direct marketing communications and non-essential web cookies. Where SRSE acts as a Data Processor, our subscribers warrant that they have secured valid, freely given, specific, and informed opt-in consent from data subjects before routing marketing attribution signals.
- Article 6(1)(c) (Legal Obligation): Retaining financial transaction and corporate accounting records in compliance with statutory fiscal requirements.
B. Data Processing Addendum (Article 28)
When acting as a Data Processor, SRSE binds itself to the enterprise Data Processing Addendum ("DPA"), incorporated by reference into our Terms of Service. Under the DPA, SRSE covenants to: (i) process personal data solely on documented instructions from the subscriber; (ii) ensure all personnel authorized to process data are bound by strict confidentiality; (iii) implement state-of-the-art technical and organizational measures (TOMs) pursuant to Article 32; (iv) notify the subscriber without undue delay (and in any event within 48 hours) upon confirming a personal data breach; and (v) delete or return all personal data upon termination of services.
C. International Data Transfers & Standard Contractual Clauses (SCCs)
Where personal data originating in the EEA, UK, or Switzerland is routed or processed outside these jurisdictions (such as in the United States), SRSE safeguards such transfers through:
- EU-U.S. Data Privacy Framework (EU-U.S. DPF): The UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF as recognized by the European Commission's adequacy decision of July 10, 2023.
- Standard Contractual Clauses (SCCs): European Commission Implementing Decision (EU) 2021/914, specifically Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor).
- Supplementary Technical Measures (Schrems II): Edge SHA-256 pre-hashing, end-to-end TLS 1.3 encryption in transit, ephemeral RAM-only routing buffers, and regional European edge ingress options preventing transatlantic transit of raw customer attributes.
D. Data Subject Rights (Articles 15–22)
Data subjects possess statutory rights to request: (i) Access to personal data; (ii) Rectification of inaccurate data; (iii) Erasure ("Right to be Forgotten"); (iv) Restriction of processing; (v) Data Portability; and (vi) Objection to processing.
Note for End Consumers: Because SRSE is an intermediary technical processor acting on behalf of subscriber merchants, end consumers seeking to exercise rights regarding purchase or conversion data should direct requests primarily to the merchant/brand with whom they transacted. If a request is received directly by SRSE, we will promptly forward it to the applicable subscriber. Direct controller requests regarding SRSE account data may be submitted to compliance@signalrecoverysoftwareengine.com.
6. California Consumer Privacy Act (CCPA / CPRA) Disclosures
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.):
A. Statutory Service Provider Certification (§ 1798.140(ag))
SRSE acts as a certified Service Provider on behalf of its enterprise business clients. SRSE expressly certifies that it:
- Does NOT Sell personal information (as defined under Cal. Civ. Code § 1798.140(ad)).
- Does NOT Share personal information for cross-context behavioral advertising (as defined under Cal. Civ. Code § 1798.140(ah)) on its own behalf.
- Does NOT retain, use, or disclose personal information for any purpose other than the business purposes specified in the commercial service agreement, including retaining, using, or disclosing personal information for a commercial purpose other than the business purposes specified.
- Does NOT retain, use, or disclose personal information outside of the direct business relationship between SRSE and the subscriber.
- Does NOT combine personal information received from, or on behalf of, the subscriber with personal information received from or on behalf of another person or entity, except as expressly permitted under CPRA regulations (§ 7050).
B. California Consumer Rights
California residents maintain the Right to Know/Access personal information collected, the Right to Delete, the Right to Correct inaccurate personal information, the Right to Opt-Out of the Sale or Sharing of personal information, the Right to Limit the Use of Sensitive Personal Information, and the Right to Non-Discrimination for exercising privacy rights.
C. Global Privacy Control (GPC) & Universal Opt-Outs
SRSE's reverse-proxy ingestion infrastructure natively inspects HTTP request headers for the Universal Opt-Out Mechanism signal known as the Global Privacy Control (Sec-GPC: 1). When detected, our edge nodes automatically execute downstream opt-out parameters, including passing Meta Limited Data Use (LDU) flags and setting Google Consent Mode parameters to denied.
7. Multi-State US Privacy Legislation
SRSE complies with all applicable US state data privacy acts—including the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Texas Data Privacy and Security Act (TDPSA), Oregon Consumer Privacy Act (OCPA), and Montana Consumer Data Privacy Act (MCDPA). In all cases, SRSE functions as a data processor adhering to statutory processing instructions and honoring opt-outs for targeted advertising and profiling.
8. Downstream Ad Platform Developer Policy Compliance
SRSE maintains strict adherence to downstream advertising platform partner and developer terms:
Meta Conversions API (CAPI) Platform Compliance
In compliance with Meta Platform Terms, Business Tools Terms, and Commercial Terms, SRSE enforces required hashing (SHA-256) on all customer information parameters before transmission. SRSE provides automated support for Meta's Limited Data Use (LDU) flag (data_processing_options: ['LDU'], data_processing_options_country: 1, data_processing_options_state: 1000), ensuring compliance when Californian or regulated state users are processed.
Google Ads API & Enhanced Conversions Policy Compliance
SRSE complies with Google Customer Data Terms and the Google EU User Consent Policy. Our reverse proxy dynamically propagates Google Consent Mode v2 parameters (ad_storage, ad_user_data, ad_personalization, analytics_storage). Unhashed PII is never transmitted to Google endpoints.
TikTok Marketing API & Events Partner Terms
In accordance with TikTok Marketing API Commercial Terms, SRSE applies SHA-256 edge hashing to user identity parameters and dynamically forwards TikTok Limited Data Use and opt-out directives.
9. Authorized Sub-processors
SRSE engages vetted, tier-1 technical sub-processors to deliver mission-critical hosting, edge compute, and billing infrastructure. All sub-processors are bound by data processing agreements meeting GDPR Article 28 standards:
10. Security Standards & Retention Lifecycle
SRSE enforces robust technical and organizational security measures meeting GDPR Article 32:
- TLS 1.3 In-Transit Encryption: All HTTP traffic passing through our reverse-proxy ingress nodes requires TLS 1.3 with modern cipher suites and Strict-Transport-Security (HSTS).
- AES-256 At-Rest Encryption: Any transient queue buffers or administrative database storage are protected with AES-256 encryption.
- Ephemeral Edge Retention: Conversion signals passing through the reverse proxy are held in volatile memory buffers for a maximum duration of 24 to 72 hours solely for event deduplication and retry delivery, after which all temporary caches are permanently erased.
- Role-Based Access Controls (RBAC): Administrative access to production proxy configurations requires hardware multi-factor authentication (MFA) and least-privilege role authorization.
11. Privacy Governance & Regulatory Contacts
For questions regarding this Privacy Policy, our Data Processing Addendum, or to submit data subject access/deletion requests, contact our designated privacy office: