3 ms·
Thank you for your follow up. 1. Glad we're in agreement! 2. We agree it is not GDPR compliant to transmit IP address data to the US. This is why we salt and
by shll 3y ago
Thank you for your follow up.
1. Glad we're in agreement!
2. We agree it is not GDPR compliant to transmit IP address data to the US. This is why we salt and hash all PII data so no IP address data is sent to the US. Please see our data policy.
https://beamanalytics.io/data https://beamanalytics.io/data
3. Thank you for your suggestion. We have already consulted privacy professionals and have been assured no DPO is required.
Thank you for this conversation about GDPR. We appreciate your interest in Beam's work.
- tyingq 3y ago>salt and hash all PII data Can you share more detail on this? On this page[1], I see this: hash(pepper(salt(ip address + user agent data))) = anonymized hashed data Both the ipv4 space and typical user agent possibilities are pretty small, so it feels like you could easily de-anonymize it when you want to. That is, assuming the "salt" and "pepper" are stored somewhere. I assume you do store them, otherwise it's not helpful to identify repeat visits. [1] https://beamanalytics.io/data https://beamanalytics.io/data