Controller and contact
For Safety Group Inc. (4SI), 11201 North Tatum Boulevard, Suite 300 PMB #365, Phoenix, AZ 85028, United States. Email: contact@by4si.com.
4SI has no establishment in the EU/EEA. Requests and supervisory-authority correspondence may be sent directly to the controller at the address above. This notice does not represent that every GDPR territorial-scope condition applies to every visit or processing activity.
Processing activities
Website delivery and security
IP address, request time, requested path, browser or device information, referrer, approximate request location and security signals may be processed to deliver, secure and troubleshoot the service.
Contact
Name, email, organization if supplied, selected topic, message, consent record, submission time and limited anti-abuse signals are processed to respond and protect the endpoint.
If you request the Daily Risk Briefing, 4SI processes your email address, double-opt-in confirmation, subscription time, delivery and suppression status, and limited anti-abuse signals. An unconfirmed link expires after 48 hours.
Optional analytics
After consent, Signal Analytics processes site-use events, a random session identifier, a daily pseudonymous IP hash, truncated network prefix, approximate city and country and possible network or organization attribution. The attribution may use IPinfo Lite, RDAP, reverse DNS and GLEIF and can be inaccurate. Full details are in the Privacy Policy.
Public-source research
The Presence Risk Index and Exposure Radar process cited public-source data as described in the Public-Source Research Privacy Notice.
Purposes and legal bases
- Website delivery, security and abuse prevention: legitimate interests in providing and protecting the service (Article 6(1)(f)).
- Requested correspondence: steps requested before a possible contract, performance of a relationship or legitimate interests in answering communications (Articles 6(1)(b) and 6(1)(f)).
- Daily Risk Briefing: consent after double opt-in (Article 6(1)(a)); consent may be withdrawn through the unsubscribe link in every briefing.
- Optional Signal Analytics: consent before activation (Article 6(1)(a)).
- Public-source research: legitimate interests in documenting systemic trust risks and maintaining an accountable sourced record, balanced against data nature, context, necessity and impact (Article 6(1)(f)).
- Legal and rights requests: legal obligations and establishment, exercise or defense of claims (Articles 6(1)(c) and 6(1)(f)).
Where 4SI relies on legitimate interests, safeguards include minimization, source attribution, separation of fact from inference, correction routes, human review and limits on sensitive personal data. You may request information about the relevant balancing assessment.
Recipients and international transfers
Recipient categories are Vercel for hosting, security and serverless processing; Neon for analytics database storage; Resend for contact delivery, confirmed Daily Risk Briefing contact management and briefing delivery; IPinfo Lite for ASN and country lookup; RDAP operators and DNS resolvers for network lookup; and GLEIF for optional inferred-entity validation. Authorized 4SI personnel and professional advisers may receive data when necessary.
4SI and relevant providers may process data in the United States or other documented locations. Where Chapter V GDPR requires a transfer mechanism, 4SI relies on an applicable adequacy decision, EU Standard Contractual Clauses or another recognized safeguard and considers supplementary measures. Contact 4SI for information relevant to your transfer.
Retention criteria
- raw Signal Analytics events and associated pseudonymous network and attribution fields: 90 days;
- contact correspondence: normally up to 24 months, longer only for an active relationship, legal obligation or claim;
- Daily Risk Briefing subscription: until withdrawal or service termination; suppression status may be retained as needed to honor the opt-out;
- runtime contact rate-limit keys: normally 10 minutes;
- hosting and security logs: according to provider configuration and operational necessity;
- public research records: while necessary for the sourced record, correction history and methodological accountability, subject to review;
- rights-request records: for the request lifecycle and then only as needed to demonstrate handling or protect legal rights.
Rights and complaints
Subject to applicable conditions and exceptions, you may request access, correction, deletion, restriction or portability; object to processing based on legitimate interests; and withdraw consent without affecting processing before withdrawal. 4SI does not use public-site visitor data for automated individual decisions producing legal or similarly significant effects.
Submit a request to contact@by4si.com. 4SI may request proportionate verification. You may lodge a complaint with the supervisory authority for your habitual residence, place of work or alleged infringement.