Consumer rights, operationally.
PII columns are tagged at ingest. Deletion requests propagate through Iceberg into NebulaGraph within the next continual refresh. MAID opt-out honored. Email hashes salted.
Applicable laws
The graph processes data about U.S. and Canadian individuals. Where a request, customer base, or data flow is governed by one of the following, our operations are designed to support it:
- California Consumer Privacy Act and California Privacy Rights Act (CCPA / CPRA)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Connecticut Data Privacy Act (CTDPA)
- Quebec Law 25 (Act respecting the protection of personal information in the private sector)
- Personal Information Protection and Electronic Documents Act (PIPEDA, Canada)
- EU General Data Protection Regulation, Article 14 — notice for indirectly collected data
This page describes operational controls. It is not legal advice.
PII tagging
Every column landing in Iceberg carries a sensitivity label. Labels are enforced by Lake Formation and Glue catalog policies. Joins that would expose a higher-sensitivity column to a lower-clearance role are blocked at query time.
| Label | Examples | Access |
|---|---|---|
| direct_pii | Plaintext email, phone, postal address | Privacy ops only |
| pseudonymous | HEM (hashed email), MAID, RampID, UID2 | Resolution + product roles |
| quasi_identifier | ZIP, employer, age band | Engineering + product |
| public | Registry-anchored company facts | All roles |
Deletion pipeline
Verified consumer deletion requests are processed in a dedicated pipeline:
- Request lands in a hold table. Identifier is normalized and hashed for matching.
- Tombstone rows are written to Iceberg. Iceberg row-level delete handles existing snapshots.
- The next continual refresh excludes tombstoned identifiers from the NebulaGraph load.
- Downstream exports rebuilt after the rebuild reflect the deletion.
- Audit log records the request, match scope, and effective build ID.
Standard turnaround is 7 days; statutory deadlines (45 days under CCPA, 30 days under GDPR Art. 12) are tracked per request.
MAID opt-out
We ingest the Digital Advertising Alliance (DAA) AppChoices opt-out list and the Network Advertising Initiative (NAI) opt-out list weekly. MAIDs on either list are excluded from the resolved view and from outbound exports. Apple Limit Ad Tracking and Android Reset state, where surfaced in upstream feeds, are also honored.
Hashed email handling
Plaintext emails are never persisted in the resolved graph. At ingest:
- Email is lowercased, trimmed, and Unicode-normalized
- Six hash variants are computed (md5, sha1, sha256, plus three salted variants for cross-vendor compatibility)
- Plaintext is dropped before Iceberg commit; only hashes persist
- Salt values rotate annually; legacy salts retained for back-compat lookups, segregated
Notice and lawful basis
Where thespine.tech is the controller, the lawful basis is legitimate interest (Art. 6(1)(f) GDPR) or contract (Art. 6(1)(b)) depending on the use. Where thespine.tech is a processor, lawful basis is governed by the customer's notice. Article 14 indirect-collection notices are published at thespine.tech/privacy/notice.
Submitting a request
Consumer rights requests (access, deletion, correction, portability, opt-out of sale/sharing) are accepted at /contact?intent=privacy. Verification follows the methods specified by the applicable statute.