Your choice and the public record

Privacy and analytics

The information service works without non-essential tracking. Analytics stays off until you make an affirmative choice, and you can reject or withdraw without losing any page or calculator function.

Purpose-limited product analytics are available on this build and remain off until you accept them.

Change or withdraw consent

Analytics settings

Choose whether SIA Ireland may send purpose-limited product events

Technology, storage and retention

What runs in the browser

A small first-party script called measurement.js reads the consent choice and, only after acceptance, sends deliberately named events directly to PostHog's EU capture endpoint over HTTPS. The lawful basis for this analytics processing is consent. The script does not load Google Analytics, Google Tag Manager or the PostHog browser library.

Consent storage: sia_measurement_choice_v2 records accepted or rejected, the consent version and an expiry time. It is necessary to remember the choice, stays in first-party local storage for 180 days, and is replaced when the choice changes.

PostHog storage: No PostHog cookie, local-storage identifier or session-storage identifier is created. A random page identifier exists only in memory and is discarded on navigation.

Network metadata: PostHog and its network providers receive the IP address and user-agent information carried by the HTTPS request. SIA Ireland does not add those values to the event body.

Event retention: Analytics events are kept for up to 12 months under the PostHog project's current event-retention setting.

Session replay is disabled. Automatic capture, page-view tracking, person profiles, surveys and feature flags are also disabled. The implementation contains no replay recorder or replay endpoint.

Purpose-limited measurement

Analytics event record

Every event includes the common fields listed after the event-specific record. Calculator amounts, contribution values, calculated results, names, email addresses, full URLs, query strings and page text are not sent.

source_opened

Research purpose: Learn whether readers inspect the primary evidence placed beside a policy claim.

Trigger: A visitor follows an external source link in a labelled source or evidence area.

source_host
Distinguishes source organisations at domain level.
source_path
Distinguishes source documents without sending a query string or fragment.

status_explored

Research purpose: Learn which policy states readers choose to inspect from the status navigation.

Trigger: A visitor follows a confirmed, proposed, still-unknown or no-longer-current jump link.

status
Records the canonical policy state selected: confirmed, proposed, unknown or superseded.

calculator_started

Research purpose: Learn whether readers begin using the educational calculator after reaching it.

Trigger: The first calculator-field change captured after consent, or immediately before the first valid completion when no start has yet been captured on that page view.

No event-specific fields. Only the common privacy-controlled fields below are sent.

calculator_completed

Research purpose: Learn whether readers reach a valid illustrative result after starting the calculator.

Trigger: A valid calculation is completed.

No event-specific fields. Only the common privacy-controlled fields below are sent.

Fields sent with every event

distinct_id
Groups the small event sequence produced during one page view so a calculator start can be compared with a completion. It is random, kept in memory and not reused after navigation.
page_path
Shows which SIA Ireland route contained the interaction without sending the full URL, query string or fragment.
$process_person_profile
Set to false on every event so PostHog does not create a person profile.
$geoip_disable
Set to true on every event so PostHog does not enrich the request IP address into location fields.

Processor and transfers

Who receives analytics data

PostHog, Inc. acts as the analytics processor. Events are sent to the PostHog EU Cloud region in Frankfurt, Germany.

Robert Gloster, publisher and editor of SIA Ireland determines the event set and purpose and acts as the controller for this processing.

The EU Cloud stores customer event data in Germany. PostHog is a US company and its current subprocessor list includes global or US processing for some support, security and network services. PostHog's published DPA describes the EU Standard Contractual Clauses and its Data Privacy Framework commitments for relevant transfers.

Current core subprocessors include Amazon Web Services for EU Cloud storage in Germany, Wiz for security services in Germany and France, PlanetScale and Modal Labs for cloud services in Germany or the US, depending on the cloud configuration, Cloudflare for edge-network transit in global network. Check PostHog's current subprocessor list because that list can change.

Security and access: Access is limited to the publisher and any specifically authorised maintainer. PostHog documents encryption in transit and at rest, access controls and security review. The project token is a public ingestion identifier that cannot read project data; no personal API key is shipped to the browser.

Withdrawal and rights

Changing your mind

Use the settings at the top of this page at any time. Withdrawal takes effect immediately for future events. It does not undo processing that happened while consent was valid. Because the page identifier is random, short-lived and not retained in the browser, SIA Ireland may need the approximate date, time, route and action to locate an event.

For an access, deletion or other data-rights request, email privacy@siaireland.ie. Do not put personal information in a public GitHub issue.

You may also complain to Ireland's Data Protection Commission. The publisher reviewed and approved this analytics setup before enabling it on the production site.

Search measurement

Google Search Console

SIA Ireland supports Search Console for search queries, clicks, indexing and crawl information supplied to verified site owners by Google. The site publishes a sitemap and supports Google's homepage verification tag. Connecting and verifying the production property is a deployment task. This support does not add Google Analytics, a Google advertising tag or other Google visitor-side collection.

Privacy record last reviewed .