Non-PII signal collection, one-way hashing, data processor DPA, and GDPR Article 6(1)(f) guidance
tracio.ai collects browser configuration and hardware signals only. No PII (names, emails, passwords) is ever collected. No browsing history or user content is accessed.
For fraud prevention and security use cases, legitimate interest (Article 6(1)(f)) is the appropriate legal basis. For analytics use cases, user consent may be required.
| Use Case | Legal Basis | Consent Required? |
|---|---|---|
| Fraud prevention | Legitimate interest (Art. 6(1)(f)) | No |
| Account security | Legitimate interest (Art. 6(1)(f)) | No |
| Bot detection | Legitimate interest (Art. 6(1)(f)) | No |
| Analytics | Consent (Art. 6(1)(a)) | Yes |
| Marketing | Consent (Art. 6(1)(a)) | Yes |
With our cloud platform, all visitor data stays on your infrastructure. No cross-border data transfers, no third-party data sharing.
You control data retention policies in our cloud. Default retention is 90 days. Configure via environment variable:
TRACIO_DATA_RETENTION_DAYS=90