Data governance covers who owns customer data in Insider One, who decides what happens to it, and which controls enforce those decisions. This page answers those three questions and points to the reference article behind each control.
Use it when you are completing a vendor assessment, scoping a data protection impact assessment (DPIA), assigning data stewardship inside your team, or answering a data subject request.
Data ownership: controller and processor roles
You own your customer data. Insider One holds and processes it on your behalf, under your instructions.
In the wording of the Insider One Data Processing Addendum, the customer is the data controller and Insider One is the data processor. The Insider One and General Data Protection Regulation (GDPR) article states the same split.
Decision | Data controller (you) | Data processor (Insider One) |
|---|---|---|
What personal data to collect | Chooses the attributes and events sent to the platform | Ingests and stores what you send |
Lawful basis and consent | Establishes the basis and captures consent | Records the consent value you send and honors it in campaigns |
Retention periods | Requests the periods your policy requires | Applies platform defaults and configures approved extensions |
Data owners and stewards | Assigns roles, groups, and PII access in the InOne panel | Enforces the permissions you assign |
Deletion | Decides a request is valid and triggers deletion | Deletes the profile or the personally identifiable information (PII) on request |
Responding to a data subject | Verifies identity and issues the response | Passes on any request it receives and supplies the means to fulfill it |
On the last row, the DPA is explicit. When an end user contacts Insider One directly, Insider One confirms that the request has been passed to you. Insider One does not execute the request itself.
The governance toolset
Control | What it does | Reference |
|---|---|---|
Data Governance APIs | Set consent, delete a user profile, delete a user's PII, and change messaging permission per channel | |
Data retention and TTLs | Publishes the time to live (TTL) for user profiles and each event type | |
RBAC and PII access | Assigns roles and controls separately who can open a user profile and export results | |
Panel access logs | Exports login events, failed attempts, and user management actions for audit | |
Data validation | Inspects incoming data for correctness and consistency | |
DPA and subprocessors | Sets the processing terms and names every third party engaged | |
Certifications and assessments | Collects attestations, regional DPA variants, and questionnaire responses |
How data subject requests flow
You receive and verify the request. Insider One provides the means to execute it. Insider One's Commitment to End Users' Rights is the full reference.
Request | What you use |
|---|---|
Access and portability | Export Raw User Data, and the User Data APIs for individual profiles |
Erasure | Delete User Profile for the whole record, or Delete User's PII Data to strip identifying fields |
Objection and restriction | Set Data Processing Consent for App Users, plus the unsubscribe endpoints on the Data Governance page |
Running a DPIA or vendor review
A DPIA is the controller's responsibility, so you run it. Insider One supplies the processor-side evidence, and the Insider One Trust Center is the single place to request it, including certifications, regional DPA variants, and questionnaire responses. Pair those documents with the retention periods, access settings, and audit logs linked above.
Conclusion
You are the data controller and Insider One is the data processor. Every division of work on this page follows from that split: you decide, and the platform gives you the controls and the records to carry the decision out.