We’ve migrated our documentation to a new site, which means some URLs have changed. If you hit a broken link, submit a support ticket.
Compliance Center
English French
English French

Data Minimization and Anonymization

To meet the requirements of the GDPR regarding appropriate technical measures, as part of the processing contract (art. 28), regarding the security of the processing (art. 32), or simply for "privacy by design and default", Piano applies data minimisation and anonymisation principles to its products:

Piano Analytics

Data

Mechanism

Standard or option

How is it done?

PA property concerned

Example / Description

Terminal ID

Pseudonymisation

Standard

Hashing the original value

Visitor ID

The value GW_33!BG87-6 stored on Client side (e.g. Cookie), becomes xw_tr78opUI-451 within the Piano Analytics interfaces.

Visitor ID

Anonymisation

Standard

Aggregation of the opt-out traffic

Visitor ID

All the opt-out traffic data is aggregated under the same Visitor ID value => "opt-out"

Visitor ID

Anonymisation

Standard

Nulling the concerned value

Visitor ID

If an End-User would like to apply its right to be forgotten (deletion), we null the concerned value (e.g. xw_tr78opUI-451 become NULL).

Visitor ID

Anonymisation

Option

Masking of the property

None

The Visitor ID is no longer available within the Piano Analytics interfaces.

User ID

Pseudonymisation

Option

Random value

User ID

When Visitors logged in on a platform, the customer can assign a single identifier to recognise him across devices. It is highly recommended that the customer provide Piano Analytics with a random ID via the tag (instead of email address for instance), and keep a matching table on his side (e.g. Firstname.Lastname@company.com become 123456).

IP Address

Anonymisation

Option

IPv4 : Truncation of the last octet. For IPv6 : Truncation of the last 10 octets

None

The IP address is truncated before being used for the processing of geolocation for instance.

GPS coordinate

Anonymisation

Standard

Rounding (to 1 decimal)

None

If used, the GPS coordinate are rounded before being used for the processing of geolocation (e.g. 48.86000061 / 2.33999991 become 48.8 / 2.3).

Any information

Anonymisation

Standard

Nulling the concerned value

Concerned property

If an End-User would like to apply its right to be forgotten (deletion), we null the concerned value (e.g. 12345 or Order_101 become NULL).

Any information

Anonymisation

Option

Emptying the concerned value

Concerned property

The data controller can empty property during the processing, so no information is stored (see Privacy Flags and Data Manager)

Other minimization mechanisms

"Contains personal data" flag

Each of the user interactions you measure with Piano Analytics can be qualified using properties.

You can quickly manage hundreds of properties, some of which contain personal information that requires special attention.

To help you ensure good data governance, we provide ""Contains personal data" flag", which simply indicate which properties require particular vigilance from a Privacy point of view when they are used.

Note: these personal data indicators are essential to the proper functioning of the "Extended opt-out" consent management mode.

Data Management for Privacy

Correction and deletion of unwanted data using the Data Management interface of Piano Analytics;

Data Retention

ePrivacy Exemption

Piano Subscriptions

Data

Mechanism

How is it done?

Example / Description

IP Address

Pseudonymisation

Hashed wherever displayed within the solutions

Stored in an obfuscated form

Location / Address

Anonymisation

Audit records display geolocation information instead of the raw address

—

IP Address

Restriction of transmission

No longer transmitted to payment providers

Applies to subsequent transactions

Complete address

Retention limitation

Retained in raw logs for one month only

For security and fraud investigation

Device characteristics

Restriction of collection

Scrubbed when device consent is absent

—

Geolocation data

Restriction of collection

Removed, no lookup performed when geo consent is absent

—

Piano Audience

Data

Mechanism

How is it done?

Example / Description

Browser/Device ID

Pseudonymisation

Random value assigned, no direct link to a real identifier

—

IP Address

Restriction of storage

Transmitted but not stored on Piano servers

—

Identifier (browser/device)

Retention limitation

Expires six months after the last recorded event

Confirmed in the Piano Audience, Insight and CCE Platform Privacy Policy

Unique identifier

Retention limitation / Anonymisation

Removed after twelve months

Data retained afterward for analysis only, without the identifier

Reporting data

Anonymisation

Aggregated

See the Piano Audience privacy policy

Last updated: