Useful intelligence.
Clear boundaries.
BGraph builds clickstream and AI search intelligence around aggregated, privacy-secured behavioral signals. These principles define the public standard for product design, customer review, and market expansion.
Browsing and query data can be personal or sensitive even when direct identifiers are removed. BGraph does not treat pseudonymisation as proof of anonymity. Product claims, fields, retention, delivery, and geographic scope must match the legal basis and realistic re-identification risk.
Market patterns first
Standard outputs focus on aggregated journeys, category movement, audience cohorts, and market-level trends. We do not market the product as a way to identify people or read private conversations.
Purpose before fields
Every request starts with the buyer's question. Fields that do not support that purpose should not be included. Sensitive categories and high-risk uses require separate review or exclusion.
Jurisdiction controls
Available data may differ by country. Consent, opt-out, data broker, individual rights, retention, and cross-border requirements must be mapped before a dataset is offered in a market.
Claims follow evidence
We publish only metrics that can be supported by current data. Until coverage figures are verified, BGraph uses capability language such as global-ready, daily-ready, and flexible delivery.
One product standard.
Different legal tests.
This overview guides product wording and review. It is not a substitute for advice from counsel in the relevant market.
European Union
Online identifiers and browsing records may be personal data. Pseudonymisation is a safeguard, not the same as anonymisation. Collection from a device may also require consent under national ePrivacy rules.
Official source: European Data Protection Board ↗United States
Requirements vary by state. California treats internet browsing history as personal information and gives consumers rights over sale or sharing, including browser-based opt-out signals.
Official source: California Privacy Protection Agency ↗China
PIPL can require notice, a legal basis, separate consent for third-party or overseas transfers, and approved cross-border transfer mechanisms.
Official source: Personal Information Protection Law ↗Japan
APPI regulates personal data and third-party provision. Web browsing history may also require analysis under the rules for personal-related and anonymously processed information.
Official source: Personal Information Protection Commission ↗South Korea
PIPA requires a legal basis, transparent privacy information, individual rights, and controls for overseas transfers. Foreign businesses may fall within its scope.
Official source: Personal Information Protection Commission ↗Singapore
PDPA centers on notification, consent or another permitted basis, reasonable purposes, security, retention, individual rights, and comparable protection for overseas transfers.
Official source: Personal Data Protection Commission ↗India
The Digital Personal Data Protection Act establishes notice, consent and certain permitted-use rules, data principal rights, security duties, breach response, and controls that may apply to transfers outside India.
Official source: Digital Personal Data Protection Act ↗What customers should expect
- A documented dataset scope and intended use
- Delivery fields and geography defined in the contract
- Restrictions on re-identification and individual targeting
- Security and retention terms appropriate to the data
- Review of sensitive categories and regulated uses
- Cross-border controls where the dataset requires them