Public website privacy approach

Use the minimum data needed for a clear purpose.

This page describes the principles for the ciliot public website and prospective contact journey. It is not a jurisdiction-specific privacy notice or a substitute for legal review. A production contact route, analytics service, or new data use requires an approved privacy notice and documented controls before release.

Current public preview

Static content, no hidden lead capture.

The current website package is static. Its pilot form is a visual preview only and does not send or persist submitted information. This status must change only alongside an approved, consent-aware production form design.

Public information

Page content, navigation, and deployment telemetry required to deliver a secure static service should be documented with owner, purpose, retention, and access controls.

Prospective contact data

When enabled, collect only the contact details and high-level business context needed to respond to a request. Do not ask for credentials, sensitive operational data, or customer records.

Service data

Customer connected-asset data is governed by the tenant service, contract, data classification, retention, location, and access model—not by this public marketing page.

Principles for any production route

Make data use understandable before it becomes invisible.

A public website or product interaction must make its data boundary visible and proportionate to the purpose it serves.

  • Purpose limitationDocument why a data item is needed before collection and do not reuse it for an incompatible purpose.
  • Data minimisationPrefer high-level business context in an enquiry; never ask a prospective customer to place secrets or sensitive records in a public form.
  • Visible choicesProvide the notices, consent choices, retention, contact, and opt-out path required for the applicable jurisdiction and deployment.
  • Secure deliveryUse reviewed HTTPS-only delivery and avoid embedding client-side credentials, privileged tokens, or sensitive analytics keys.

A change-control reminder

Before enabling a new data flow, ask:

  • What information will be collected, generated, or inferred, and is any of it personal or sensitive business data?
  • Who needs access, where will it be processed or stored, and how long will it be retained?
  • Which notice, consent, security, contract, residency, and deletion controls must be in place before launch?
  • Who approves the flow and how will its evidence, risks, changes, and customer requests be managed?

Connected-asset data

Telemetry can still be personal data in the right context.

A sensor value may become personal data when it is connected to a named contact, support action, vehicle route, location, future occupancy sensing, or another identifiable individual. That context needs appropriate assessment before use.

Important: Camera, audio, precise-person location, and biometric capabilities require privacy impact assessment and governance before enablement. They are not implied by the initial cold-chain service.