Privacy-minimizing intake
Minimize personal information before analysis.
Where the dealer-side cleaning tool is used, it minimizes the file before upload. Every operational intake is then independently screened for detectable personal information before storage.
- 01Authorized exportDealer-approved source
- 02Dealer-side preparationLocal field minimization
Pre-transfer exclusionIdentity removed before transfer
- 03Intake screeningIndependent privacy check
- 04Field authorizationContract-approved scope
Fail-closed exitRejected before storage
- 05Lineage attachedSource and treatment recorded
- 06Operational analysisAuthorized fields only
- 07Dealer review recordContext remains inspectable
Terminal instructionAuthorized retention or deletion
Data path
Keep useful operational signal. Remove unnecessary personal information.
Each stage narrows the source while preserving the operational context needed to understand and review the analysis.
- 01
Dealer selects an authorized export
- 02
Where used, dealer-side cleaning removes unnecessary personal information
- 03
The minimized operational file is submitted
- 04
Independent intake screening checks the file
- 05
Accepted operational fields enter the tenant context
- 06
Analysis produces a dealer-review record
Field treatment
Operational signal with personal information minimized.
The dealership-approved source contract controls every accepted field. A separately authorized personnel workflow may retain dealer-assigned pseudonymous codes; the dealership keeps the code-to-name mapping.
Removed or rejected
- Customer name and contact details
- Customer address, email, phone, and SIN
- Employee name and DMS user identity
- Personnel codes outside a separately authorized workflow
- VIN-derived identity fields blocked by the source contract
Retained when authorized
- Authorized deal, stock, or repair-order identifiers
- Operational dates and workflow states
- Gross, reserve, product, or service measures
- Institutional lender or vendor identifiers
- Source, schema, and processing context needed for review
Authority rule
A detectable operational field is not automatically authorized. The dealer-approved source contract, purpose, workflow, and retention boundary still control whether MIQ may accept and use it.
Next decision
See how the data promise is supported.
The security page explains the product commitments, the evidence behind environment-specific controls, and the claims MIQ deliberately keeps bounded.