Legal

Privacy policy

eNsight records where your field teams go and what they find. That's sensitive, so this page sets out exactly what we collect, what we do with it, and what you can ask us to do about it — in plain language rather than in clauses.

Last updated 2 August 2026

Who this covers

eNsight is software sold to brand activation agencies and their clients. Two different groups of people appear in it, and they are treated differently.

If you are an agency using eNsight, you decide what campaigns run, which outlets are visited and which of your staff have accounts. In data protection terms you are the controller of that information, and we process it on your instructions.

If you are a field agent, supervisor or manager with an eNsight account, the organization that invited you decides what is collected about your work. This policy explains what we hold and what you can ask for, but requests about how your employer uses it should go to them first.

What we collect

We collect three kinds of information, and nothing beyond what the product needs to work.

  • Account details: your name, email address, the organization you belong to and your role in it.
  • Field records: the outlets visited, the time of each visit, the location recorded at check-in, the counts entered, and photographs taken during the visit.
  • Technical information: basic device and browser details, and error reports when something breaks, so we can fix it.

Location, and being clear about it

The field app records where an agent is when they check in at an outlet, and how accurate that reading was. This is the core of what eNsight does: it is what lets an agency show a client that a visit genuinely happened where it was meant to.

We want to be direct about what that means. If you are a field agent, your employer can see where you were when you checked in. Location is captured at check-in and submission, not continuously, and the app does not track you between outlets or outside working hours.

Agencies using eNsight are responsible for telling their field teams that this happens, and for having a lawful basis to do it under local employment and data protection law.

Photographs

Proof photos are taken by agents during a visit and attached to that visit. They frequently show shelves, displays and stock, and they sometimes show people — shoppers, staff, or the agents themselves.

Photographs are only visible inside the organization that captured them, and in reports that organization chooses to share. When a report is shared externally, the client sees the photographs but not the agent names attached to them.

If you appear in a photograph and want it removed, contact the agency that took it, or write to us at the address in the final section and we will help route the request.

How we use it

We use the information above to:

  • Run the product — show campaigns, record visits, calculate figures and build reports.
  • Send transactional email and notifications: invites, alerts about flagged work, and scheduled campaign summaries.
  • Keep the service secure, diagnose faults and prevent abuse.
  • Understand which features are used, so we know what to improve.

What we don't do

We do not sell your data. We do not share it with advertisers, brokers or any third party for their own purposes. We do not use your campaign data or photographs to train machine learning models.

Where the product uses AI to answer questions about your campaign, it does so over your own records, and those records are not retained by the AI provider to train their models.

How long we keep it

Campaign records, including photographs, are kept for as long as your organization has an active account, because a campaign's value to an agency is partly historical — last year's results are what wins next year's brief.

If your organization closes its account, we delete or irreversibly anonymise its data within 90 days, except where we are required to keep something longer by law. You can request an export of everything before that happens.

Error and diagnostic logs are kept for a much shorter period and are cleared on a rolling basis.

Who else touches it

We use a small number of specialist providers to run eNsight: cloud hosting and databases, file storage for photographs, transactional email delivery, push notification delivery, and an AI provider for the assistant.

Each is bound by a data processing agreement, may only act on our instructions, and may not use your data for their own purposes. We will provide the current named list of these providers to any customer who asks — write to the address below.

Some of these providers operate outside your country. Where data moves across a border we rely on the transfer mechanisms recognised by the applicable law, such as standard contractual clauses.

Your rights

Depending on where you are, you may have the right to ask for a copy of your data, to have it corrected, to have it deleted, to object to certain processing, or to have it sent to another provider.

If you hold an eNsight account through an employer, we will usually pass your request to them, since it is their data and they decide the outcome. We will tell you when we do that.

You also have the right to complain to your data protection regulator. In Nigeria that is the Nigeria Data Protection Commission.

Security

Data is encrypted in transit and at rest. Access inside eNsight is limited to what an account's role requires, and that boundary is enforced by the system rather than by which screen a person opens.

No system is perfectly secure, and we would rather say so than imply otherwise. If you believe you have found a security problem, please write to security@ensightapp.com and we will confirm receipt and keep you updated.

Changes and contact

If we change this policy in a way that materially affects you, we will tell account holders by email before it takes effect, and update the date at the top of this page.

For anything about this policy, or to make a request about your data, write to privacy@ensightapp.com.