ertiq compliance summary

Privacy, storage, and employment-use guardrails

This summary describes the current Phase 1 baseline. It is a product transparency aid and not a substitute for legal advice.

Back to sign in

Browser storage used by the product

Storage item Mechanism Purpose Retention
ertiq_session HTTP-only cookie Strictly necessary authentication session for signed-in users. Expires after the configured session TTL, eight hours by default, or when the user signs out.
team-dashboard-date-range Browser local storage Remembers the last selected dashboard date range as a requested UI preference. Persists until the user clears site data or resets stored preferences for this application.
team-dashboard-selected-user-ids Browser local storage Remembers selected contributors on the dashboard as a requested UI preference. Persists until the user clears site data or resets stored preferences for this application.
team-dashboard-watchlist-user-ids Browser local storage Stores the local watchlist used to re-open frequently reviewed contributors. Persists until the user clears site data or resets stored preferences for this application.

Signed-in workspace admins can now reset stored browser preferences from the compliance assurance page. Users can also clear this site's stored data directly in browser settings.

Employment-use guardrails

  • ertiq is a decision-support tool only and must not be positioned as an automated performance evaluation system.
  • Metrics, labels, and contributor groupings are descriptive signals and must not be turned into hidden scoring categories.
  • Optional AI narrative output must not be used as the sole basis for personnel decisions, disciplinary action, or compensation decisions.
  • Customers should assess whether works council or labor consultation is required before rollout in their jurisdiction.

Current Phase 1 operating position

  • Optional LM Studio analysis is intended to remain local to customer-controlled infrastructure unless the deployment model is explicitly changed.
  • Dashboard and detail views read from PostgreSQL-backed persisted data rather than live provider queries.
  • Phase 1 relies on documented retention, DSAR, and support-access procedures, with manual fulfillment steps where product automation does not yet exist.
  • Detailed records for data inventory, lawful basis, retention, DSAR handling, and evidence ownership are maintained in repository compliance artifacts.