SECURITY / DATA

Your events stay in your project. We keep the totals.

Measurement substrate is the client BigQuery export. Pulsar stores aggregated model outputs, tenant context, and the audit log. A DPA is part of the pilot SOW.

IAM we ask for

RoleScopeWhy
BigQuery Data ViewerGA4 export dataset onlyRead events and sessions. Nothing else in the project.
BigQuery Job UserThe same projectRun the journey SQL. We cap bytes scanned per run.
Analytics ViewerOptional, GA4 propertyAdmin / Data API QA: key events, ads links, schema drift.

Prefer a service account in your project. We will not take Owner, never store key JSON in git, and isolate credentials per tenant in a secrets manager.

What leaves your GCP

  • Channel shares, credited conversions, intervals.
  • Run metadata: lookback, conversion definition, bytes billed.
  • Anomaly flags and the approved PDF.

What does not

  • user_pseudo_id paths, hit-level events, PII.
  • Your Ads account. We do not bid.
  • GTM container writes. Tag Health is read-only.

Subprocessors

  • Amazon Web ServicesJob runners, secrets, object storage
  • Google CloudYour BigQuery — in your project
  • Neon / RDS PostgresTenants, runs, aggregated results
  • ResendReport delivery
  • Anthropic / GoogleDraft commentary only. Cannot change shares.