1. Who we are
Sovereign Global Compute ("SGC") publishes compute-market research, data and financing intelligence at sovereignglobalcompute.com. For anything in this policy, contact info@sovereignglobalcompute.com. SGC is the data fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where EU or UK law applies to a visitor, the controller under the GDPR.
2. The design principle
The public pages remain static and have no user accounts. The submission tools use a small Cloudflare Worker to validate the request, check for bots, store a lead record and send transactional email. If that service is unavailable, the Site offers an email fallback. We use cookieless reach measurement that sets nothing on your device and is limited to screened, aggregate signals. Google Analytics 4 and, if activated, Google Ads load only after the matching choice in the privacy banner; if you reject optional processing, no Google analytics or advertising code loads.
3. What we collect
Server logs. Our web host records standard logs when you visit: IP address, browser and device details, requested pages, referrer, and timestamps. We use these to operate and secure the service.
Form and correspondence data. If you submit a rate, capacity record, compute request or employer opening, or email us directly, we receive whatever you choose to include: typically your name, work email, firm and commercial details. A form submission receives a reference number and is stored in Cloudflare KV for up to 24 months. The record may include coarse country and consented campaign attribution, but we do not retain the visitor's raw IP address in the lead record.
Employer opening review. The employer-opening form is used to assess and respond to an authorised request to list a current role. It collects the contact's name and work email, employer and role facts, confirmation of authorisation, acceptance of this notice, and optional operational notes. We process it to take the steps requested by the employer representative and for legitimate fraud and quality controls. The submission passes through our Cloudflare lead store and Turnstile verifier, transactional email provider, and monitored company mailbox. The private lead is retained for up to two years and delivery records for up to 30 days unless a valid shorter legal request applies. An opening is never posted automatically, and we do not sell the contact data.
Job-alert subscriptions. If you subscribe to the weekly frontier-systems job alert, we collect only your email address, the role families you choose and a single geography preference — no name, CV or current employer. We use double opt-in: your address is held as pending until you click a confirmation link, and only a confirmed address ever receives the alert. We record the date, page and notice version of your consent as proof of opt-in, together with a coarse country derived from the request. Every alert carries a one-click unsubscribe; unsubscribing suppresses your address so it is not re-added without a fresh confirmed request, and a hard bounce or spam complaint suppresses it the same way. We process this on your consent, route it through Cloudflare (Turnstile and our lead store) and Resend, use it only for the alert you asked for, and never sell it. Sign-ups that are never confirmed are deleted automatically.
Cookieless reach measurement. When the Site's safety checks permit measurement, and without setting cookies or an identifier on your device, our first-party endpoint records aggregate page-view signals: the canonical page, the referring site's category and a screened host token, screened campaign tags, coarse country and whether the request looks automated. Cloudflare Web Analytics provides separate cookie-free visit and performance measurement. Our first-party page-view record does not include your raw IP address, raw query string or arbitrary URL, and it is not used to build a visitor profile.
Consented analytics. If you choose optional analytics, we collect information about how you use the Site, including pages viewed, buttons and filters selected, job listings viewed, and terms entered into Site search. Search terms are screened before they are sent to Google Analytics, and terms that appear to contain personal, confidential or sensitive information are withheld. We use this information to understand market interest, improve navigation and content, and evaluate commercial demand. Do not enter personal or confidential information into search.
After Analytics only or Analytics + ads consent, our first-party endpoint records bounded interaction events and Google Analytics 4 may collect canonical page views, session statistics, approximate location, browser/device details and a pseudonymous client ID stored in first-party cookies. A job-listing event may include a bounded employer/source token, role-family ID, provenance source and, for an SGC-verified listing, its opaque listing ID so we can reconcile consented outbound clicks to that listing.
The only exact text permitted in analytics is an approved Site job-search term. The browser screens the term, our Worker repeats the same screen without storing or logging it, and only an approved result may be sent to Google Analytics as a job_search event. The first-party interaction record receives only the screening result, controlled filter context and result counts; it never receives the exact term. Rejected terms are not sent to Google Analytics. Contact names, email addresses, company and other form values, application URLs, messages, notes, compute requirements and other arbitrary free text remain prohibited from every analytics destination. We do not connect Google or first-party analytics identifiers to a named form submission or correspondence record.
Consented advertising measurement. If you choose Analytics + ads and the Google property is linked to Google Ads, Google may use advertising cookies or identifiers for conversion measurement, campaign attribution, demographics/interests reporting and audience building. We do not enable this category from an Analytics-only choice.
4. Why we use it, and the legal bases
We process server logs and cookieless aggregate measurement to keep the Site secure, diagnose faults and understand how the Site is found and used (legitimate interests under GDPR; legitimate uses under the DPDP Act). This measurement sets nothing on your device and our first-party record excludes raw IP addresses. We process Google Analytics and advertising measurement on consent alone. We process form submissions and correspondence to respond, verify submitted market data or openings, arrange requested introductions and manage a business relationship (steps you requested and legitimate interests). Employer representatives also explicitly accept this notice before submitting an opening. We do not use this data for automated decisions with legal effect, and we do not sell it.
5. Submitted market data
Rates and commercial terms you submit are business information, but they arrive attached to a person: your name and work email. We separate the two. The commercial data is verified, normalised and folded into published market ranges; our default is anonymisation, and attribution to your firm appears only with written approval. Your identity and contact details are kept in correspondence records for verification and follow-up, never published. Compute requests and financing enquiries are treated as confidential business correspondence and shared with potential counterparties only with your consent.
6. What we do not do
No sale of personal data. No contact identities, work emails, employer-form values, confidential content or arbitrary free text in analytics. The narrow exception is a Site job-search term that passes both screens and is sent only to Google Analytics after optional analytics consent. Consented job events use only the bounded listing dimensions described above and are not treated as applications or unique people. No Google cookies, device identifiers or cross-site tracking before consent — measurement that runs without consent is cookie-free and aggregate. We do not attempt to identify people from aggregate reports or merge form identities with analytics identifiers. Google advertising features, if activated, operate only after Analytics + ads consent and remain subject to your Google ad settings. No collection of children's data: the Site is a professional research service and is not directed at anyone under 18.
7. Retention
Our approved Google Analytics policy is two months for detailed event data and 14 months for user data. That policy will apply once the GA4 containment and property configuration are completed and verified; this configuration remains pending. First-party interaction and aggregate consent events are retained for 180 days. Lead records are retained for up to 24 months unless a relationship, verification, legal or recordkeeping need requires longer, then deleted or anonymised. Resend retains transactional-email data for 30 days on its free plan; copies in the monitored mailbox follow the correspondence lifecycle. Job-alert subscriptions are retained while active and until you unsubscribe; unconfirmed sign-ups are deleted automatically after 14 days, and we keep a minimal suppression record of unsubscribed or bounced addresses so we can honour opt-outs. Server logs are kept only as long as reasonably required for security and operations. Anonymised market data, once folded into published ranges, may be retained indefinitely because it no longer relates to you.
8. Cookies and local storage
| Name | Purpose | Lifetime |
|---|---|---|
sgc-consent | Local-storage record of your choice: essential, analytics, or analytics plus advertising. | Until you clear browser site data |
_ga | Google Analytics pseudonymous browser identifier; set only after analytics consent. | Up to 395 days |
_ga_<container-id> | Google Analytics session state; set only after analytics consent. | Up to 395 days |
| Google advertising identifiers | Conversion measurement and audience building; set only after Analytics + ads consent and only when advertising features are activated. | According to the applicable Google Ads configuration |
| None from Cloudflare Web Analytics | Cloudflare Web Analytics is cookie-free. | Not applicable |
| None from first-party measurement | Our cookieless page-view measurement sets no cookie or identifier on your device. | Not applicable |
Use Privacy choices in any page footer to change or withdraw consent. Rejecting optional processing clears the Site's optional journey and campaign session state and reloads the page so previously loaded optional tags stop running. Withdrawal applies to future optional collection; to ask about deletion of information already collected, use the rights route below.
9. Providers and disclosures
Cloudflare hosts the Site, performs bot verification, screens search terms without retaining their exact value, stores lead and first-party interaction records, and provides aggregate Web Analytics and Analytics Engine measurement. Resend sends transactional acknowledgements and notifications and, to confirmed subscribers only, the weekly job alert. Google provides the monitored mailbox and, after the relevant consent, Google Analytics measurement; only a search term approved by the browser and Worker screens may be sent to Google Analytics. Google Ads measurement is a separate choice and is not enabled by Analytics-only consent. These providers receive the information assigned to the relevant service. We may also disclose correspondence to advisers or counterparties when needed to fulfil your request and with the confidentiality controls described above.
10. Your rights
Under the DPDP Act you may request access to your personal data, correction, erasure, and a means of grievance redressal; you may nominate a person to exercise these rights for you. Where GDPR applies, you additionally have rights to restriction, portability, and objection to processing based on legitimate interests, and you may complain to a supervisory authority. Either way, email info@sovereignglobalcompute.com with enough detail to locate the relevant correspondence or analytics period. We may ask for proportionate verification of identity. We will check the applicable first-party records and, where relevant, use the available Google Analytics deletion controls for the narrowest event, date and custom parameter range; any restricted downstream copy is handled separately. Not every aggregate record can be tied to one person. If you are dissatisfied with our response, say so and we will escalate the review; DPDP grievances not resolved by us may be taken to the Data Protection Board of India.
11. International transfers
Our hosting, email and analytics providers may process data outside your country of residence, including outside India and the EEA. Where a transfer mechanism is legally required we rely on the safeguards offered by the relevant provider, such as standard contractual clauses.
12. Changes
We will update this policy when our practices or legal obligations change. The current version, with its last-updated date, always lives at this address.