Scope and controller
This policy applies to www.by4si.com, by4si.com, the public pages served at intelligence.by4si.com, the public contact and Daily Risk Briefing endpoints, and the public Presence Risk Index and Exposure Radar. Invite-only workspaces and future commercial deployments may require separate notices before additional processing begins.
The controller is For Safety Group Inc. (4SI), 11201 North Tatum Boulevard, Suite 300 PMB #365, Phoenix, AZ 85028, United States. Privacy contact: contact@by4si.com.
Data, purposes and sources
Website delivery and security
When a page is requested, hosting and network infrastructure may process the IP address, request time, requested path, browser and device information, referrer, approximate request location and security signals. This is necessary to deliver, secure and troubleshoot the service and to prevent abuse.
Contact and correspondence
If you contact 4SI, we process your name, email address, organization if supplied, selected topic, message, consent record, submission time and limited anti-abuse signals. The public contact endpoint turns the source IP into a short-lived, non-reversible rate-limit key; it does not store the full IP in an application database.
Daily Risk Briefing
If you request the Daily Risk Briefing, 4SI processes your email address, confirmation status, subscription time, delivery and suppression status, and limited anti-abuse signals. Subscription requires a confirmation link sent to the address supplied. Resend stores the confirmed contact and manages delivery and one-click unsubscribe status. In the EU/EEA, the legal basis is consent; you may withdraw it at any time through the unsubscribe link in each briefing.
Public-source research
The Presence Risk Index and Exposure Radar use cited public-source information under the rules described in the Public-Source Research Privacy Notice. Ordinary page filtering occurs in the browser and does not create an individual research profile.
Local privacy preference
Your browser stores 4si_privacy_preferences_v1 in local storage after you make a choice. It contains the policy version, necessary and analytics choices and the time of the choice. It stays on your device until cleared or replaced.
Optional Signal Analytics
Signal Analytics is loaded on the canonical 4SI website only after you select “Allow analytics.” It records page path and title, referring domain, campaign parameters, link or button labels, screen class, language, visit duration, maximum scroll depth and a random session identifier. It does not record form contents, passwords, keystrokes or cross-site browsing.
The analytics request necessarily exposes the source IP to the receiving service. Signal Analytics does not store the full address. It stores a daily rotating pseudonymous hash and a truncated IPv4 or IPv6 network prefix. The hosting edge may supply an approximate city and country.
For a pageview, Signal Analytics may use IPinfo Lite, public RDAP, reverse DNS and the GLEIF public API to infer network, ASN, network type and, where evidence reaches the configured confidence threshold, a probable organization, domain, headquarters country or city and Legal Entity Identifier. These signals may be incomplete or wrong. They do not establish a visitor’s identity or employment and are not used for advertising, eligibility, credit, insurance, employment or another decision producing legal or similarly significant effects.
The legal basis for optional analytics in the EU/EEA is consent. You may withdraw it at any time through “Cookie settings” in the footer. Withdrawal stops future analytics and removes the browser session identifier; it does not retroactively invalidate earlier consented processing.
Recipients and service providers
| Recipient | Purpose | Data involved |
|---|---|---|
| Vercel | Hosting, CDN, serverless functions, security and Signal Analytics application delivery | Request and security data; contact and analytics requests |
| Neon | Database for consented Signal Analytics events | Analytics event, session, pseudonymous network and inferred organization fields |
| Resend | Delivery of contact messages, the confirmed Daily Risk Briefing and authorized internal analytics summaries | Contact content, confirmed subscriber email and delivery or suppression status, and report summary content |
| IPinfo Lite | ASN and country-level network lookup | Source IP submitted for lookup |
| RDAP operators and DNS resolvers | Public network registration and reverse-DNS lookup | Source IP submitted for lookup |
| GLEIF | Optional validation of an inferred legal entity | Inferred organization name and country, not the source IP |
Authorized 4SI personnel and professional advisers may receive information where necessary. 4SI does not sell personal information, share it for cross-context behavioral advertising, use an advertising network or buy data from a consumer data broker for this website.
International transfers
4SI is located in the United States. Providers may process data in the United States and other documented service locations. Where applicable law requires a transfer mechanism, 4SI relies on an available mechanism such as an adequacy decision, the EU Standard Contractual Clauses or another legally recognized safeguard and evaluates supplementary measures as appropriate. You may request information relevant to your processing.
Retention
| Category | Normal period or criterion |
|---|---|
| Raw Signal Analytics events | Automatically deleted after 90 days, including pseudonymous IP and organization-attribution fields |
| Local consent preference | Until you clear browser storage or the preference is replaced |
| Contact correspondence | Normally up to 24 months; longer only for an active relationship, legal duty or claim |
| Daily Risk Briefing subscription | Until you unsubscribe or the service ends; suppression status may be retained as needed to honor the opt-out. An unconfirmed link expires after 48 hours. |
| Runtime rate-limit keys | Normally 10 minutes and never more than required for active abuse protection |
| Hosting and security logs | According to the provider configuration and only while necessary for delivery, security and incident handling |
| Public research records | While necessary for the sourced research record, corrections, version history and methodological accountability, subject to periodic review |
| Rights-request records | For the request lifecycle and then only as needed to demonstrate handling or establish, exercise or defend claims |
Your choices and rights
Depending on your location and the law that applies, you may request access, correction, deletion, restriction, portability or a copy; object to processing; withdraw consent; appeal a denied request; or exercise applicable opt-out or limitation rights. Every Daily Risk Briefing includes a one-click unsubscribe link. 4SI will not discriminate against you for exercising an applicable right.
Submit a request to contact@by4si.com. Identify the relevant service or record and your jurisdiction. 4SI may request proportionate verification and proof of authority for an agent. EU/EEA individuals may also complain to a competent supervisory authority.
See the EU/EEA Privacy Notice, U.S. Privacy Notice and California Privacy Notice for regional information.
Children, security and changes
The public website is directed to institutions, professionals and a general audience and is not designed to collect personal information from children. Do not submit unnecessary sensitive information through the general contact form.
4SI uses administrative and technical controls proportionate to the public service, but no internet transmission or storage system is completely secure. Material policy changes will be dated on this page and, where required, presented before affected processing begins.
A deliberate boundary
The public website does not send ordinary visitor browsing or filter activity to an AI model, does not perform biometric identification and does not use visitor analytics to make individual decisions with legal or similarly significant effects.