[S/1] SCORECARD — PRIVACY
Privacy Policy
Effective: 23 August 2026. The S/1 platform is operated by Salient One as a free public utility. This policy covers data handling for the Scorecard web application at s1.salientone.eu and its sub-paths.
Cookies We Use
Consent cookie (s1-cookie-consent). A first-party cookie that stores your cookie preference (“accepted” or “declined”). Set the moment you interact with the cookie banner. Expires after 1 year. Strictly necessary — without it we cannot remember your choice.
Analytics cookies (_ga, _ga_*). Google Analytics (GA4) sets a small number of first-party cookies to measure aggregate site usage. We have enabled IP anonymisation; GA4 does not log or store individual IP addresses. These cookies are only set if you click “Accept” on the cookie banner. You may decline with no loss of functionality. See Google’s Privacy Policy for details on how Google handles this data.
Session analytics cookies (Microsoft Clarity). If you consent, Microsoft Clarity records pseudonymous interaction data such as page visits, clicks, scrolling, and navigation patterns so we can identify usability problems. Clarity masks sensitive text and information entered by users. See Microsoft’s Privacy Statement for details on how Microsoft handles this data.
Session cookie (s1_session). Set only when you log into an account. An HttpOnly, Secure, SameSite Lax cookie containing an opaque session token. Expires after 30 days of inactivity. Strictly necessary for authentication — we cannot keep you signed in without it.
Other Information We Collect
Server logs. Cloudflare, our infrastructure provider, retains standard access logs (URL requested, timestamp, anonymised client IP) for a limited period for operational purposes. These logs are not shared with third parties.
User accounts. When you create an account, we store your email address, the display name you provide, and a bcrypt hash of your password (the plain-text password is never stored). We also store API keys you generate, as a SHA-256 hash; the plain-text key is shown only once at creation time. We log aggregate daily API request counts per key for rate limiting purposes, but do not log individual API request payloads or queried parameters in those aggregate counters.
Sanctions screening. Anonymous search values are processed transiently to return candidate matches and are not added to a screening decision history. Anonymous access is rate-limited using a one-way hash derived from the request IP; the raw IP is not stored in the rate-limit counter. Standard infrastructure logs may still contain request metadata, but search values are sent in a private POST body rather than the page URL. If you are signed in, your query fields, result count and top-candidate summary may be retained in your private decision history. Analytics events contain only coarse fields such as access mode, entity type and match band; names, identifiers and query values are not sent as analytics event properties. Screening inputs are masked from session analytics.
Data Sharing
Salient One does not sell or rent user data. After consent, Google and Microsoft process limited analytics data on our behalf as described above. All indicator data displayed in Scorecard is sourced from publicly available official datasets (World Bank, Transparency International, INFORM JRC, US DOL, OFAC, EU FSF, UK FCDO, UN Security Council, Swiss SECO, GDELT).
Your Rights
Under the EU General Data Protection Regulation (GDPR), you have the right to access, rectify, or erase any personal data we may hold. This includes your account data, API keys, and usage records. To request account deletion or exercise any GDPR right, contact [email protected]. We will respond within 30 days.
Salient One · Global risk-intelligence infrastructure · salientone.eu