Skip to main content

Two-layer privacy

Remove identity before analysis.

The designed data path applies one privacy control before upload and a second at intake, then retains only the operational fields authorized for the dealer workflow.

Data path

The file gets smaller before it becomes useful.

Each stage narrows the source and preserves the context needed to review what the analysis used.

  1. 01

    Dealer selects an authorized export

  2. 02

    Dealer-side cleaning removes personal information

  3. 03

    The cleaned operational file is submitted

  4. 04

    Independent intake screening checks the file

  5. 05

    Accepted operational fields enter the tenant context

  6. 06

    Analysis produces a dealer-review record

Field treatment

Operational signal without personal identity.

The exact source contract controls every accepted field. The examples below describe the intended treatment, not permission to upload an unapproved file.

Removed or rejected

  • Customer name and contact details
  • Customer address, email, phone, and SIN
  • Employee name and DMS user identity
  • Personnel codes outside a separately authorized workflow
  • VIN-derived identity fields blocked by the source contract

Retained when authorized

  • Authorized deal, stock, or repair-order identifiers
  • Operational dates and workflow states
  • Gross, reserve, product, or service measures
  • Institutional lender or vendor identifiers
  • Source, schema, and processing context needed for review

Authority rule

A detectable operational field is not automatically authorized. The dealer-approved source contract, purpose, workflow, and retention boundary still control whether MIQ may accept and use it.

Next decision

Separate the design from the deployed proof.

The security page shows which boundaries are governing commitments and which statements require current runtime evidence.