The personalization tool your legal team won't block.
Most personalization tools trigger a weeks-long legal review. Busyfolder passes in 15 minutes — the DPA is 2 pages, the architecture collects zero PII, and there's no consent banner to negotiate.
The normal legal review. vs. the Busyfolder one.
With cookie-based tools
- Marketing sends tool for review.
- Legal asks: cookies? PII? consent? retention? subprocessors?
- Three weeks of back-and-forth.
- Consent banner negotiation.
- Privacy policy update required.
- Project stalls. Everyone frustrated.
With Busyfolder
- Marketing sends DPA (2 pages, pre-reviewed).
- Legal reads architecture: “Zero PII. No cookies. ZIP only. 24hr TTL.”
- Legal asks: “So no consent banner?”
- You answer: “No.”
- Legal signs. 15 minutes.
What makes the review fast
| Concern | Cookie-Based Tools | Busyfolder |
|---|---|---|
| Cookies dropped? | Yes — first-party + third-party | No cookies |
| PII collected? | Email, IP, device ID, behavior | 5-digit ZIP only |
| Consent banner required? | Yes (GDPR, CCPA, state laws) | No |
| Privacy policy update? | Yes — new data category | No |
| DPA needed? | Yes — complex, negotiated | Yes — template, 2 pages |
| Subprocessor audit? | Weeks | Pre-reviewed, listed |
| Data retention? | Months to years | 24 hours |
| Right to deletion? | Complex (profile data) | Trivial (ZIP already gone) |
DPA summary
Processing purpose
Banner selection + conversion attribution only
Data processed
5-digit ZIP (ephemeral), banner tags, impression IDs
What we DON'T process
Names, emails, IPs, device IDs, cookies, profiles, behavioral history
International
Standard Contractual Clauses (EU/UK)
- • Security: TLS 1.3, AES-256 at rest. SOC 2 Type II audit available.
- • Subprocessors: Full list at busyfolder.com/subprocessors. 30-day notice for changes.
- • Breach notification: 72 hours.
- • Data export/deletion: Fulfilled within 5 business days.
What if a regulator disagrees?
We indemnify. If any regulator determines Busyfolder processes personal data in violation of our zero-PII architecture, we cover the resulting fines and penalties (Pilot Agreement §9.1). We're that confident in the design.
Send this page to your legal team
DPA template available. No PII. No consent banner. No privacy policy update.