ertiq compliance summary
Privacy, storage, and employment-use guardrails
This summary describes the current Phase 1 baseline. It is a product transparency aid and not a substitute for legal advice.
Browser storage used by the product
| Storage item | Mechanism | Purpose | Retention |
|---|---|---|---|
ertiq_session |
HTTP-only cookie | Strictly necessary authentication session for signed-in users. | Expires after the configured session TTL, eight hours by default, or when the user signs out. |
team-dashboard-date-range |
Browser local storage | Remembers the last selected dashboard date range as a requested UI preference. | Persists until the user clears site data or resets stored preferences for this application. |
team-dashboard-selected-user-ids |
Browser local storage | Remembers selected contributors on the dashboard as a requested UI preference. | Persists until the user clears site data or resets stored preferences for this application. |
team-dashboard-watchlist-user-ids |
Browser local storage | Stores the local watchlist used to re-open frequently reviewed contributors. | Persists until the user clears site data or resets stored preferences for this application. |
Signed-in workspace admins can now reset stored browser preferences from the compliance assurance page. Users can also clear this site's stored data directly in browser settings.
Employment-use guardrails
- ertiq is a decision-support tool only and must not be positioned as an automated performance evaluation system.
- Metrics, labels, and contributor groupings are descriptive signals and must not be turned into hidden scoring categories.
- Optional AI narrative output must not be used as the sole basis for personnel decisions, disciplinary action, or compensation decisions.
- Customers should assess whether works council or labor consultation is required before rollout in their jurisdiction.
Current Phase 1 operating position
- Optional LM Studio analysis is intended to remain local to customer-controlled infrastructure unless the deployment model is explicitly changed.
- Dashboard and detail views read from PostgreSQL-backed persisted data rather than live provider queries.
- Phase 1 relies on documented retention, DSAR, and support-access procedures, with manual fulfillment steps where product automation does not yet exist.
- Detailed records for data inventory, lawful basis, retention, DSAR handling, and evidence ownership are maintained in repository compliance artifacts.