Skip to main content

Data evoOrigin handles and compliance

This page describes which data evoOrigin handles and which settings limit it. Each installation decides its own legal basis and retention periods with its own adviser; this documentation takes no position on them.

Summary

  • All database logging ships off. Until you turn it on, evoOrigin only stores the origin in the Joomla session.
  • Data is stored in your site's database, in three tables of its own.
  • evoOrigin sends no visitor data to any external service. The licence client reports to our server the licence key, the product, the domain, the site identifier, the environment and the extension, PHP and Joomla versions, but no visitor data; see Licences and updates.
  • Detail and duration are inversely related: lots of detail for a short time, little detail for longer, and anonymous data with no limit.

The three levels

Level What is stored On by default Default period
1. Visits One row per session: date, source, medium, campaign, referer domain, landing page without query, IP (according to the mode), Joomla user id if the visitor identifies during the session, and a session hash. Click identifiers only if enabled. No 90 days
2. Lead attribution External reference (type and identifier supplied by the extension that creates the lead), first and last origin (source, medium, campaign, referer), the date of each and the number of times the lead was reported. Click identifiers only if enabled. No 24 months since the last interaction
3. Anonymous statistics Monthly counters by source, medium and campaign. No IP, no session and no user. Fed when level 1 is purged No limit

The periods for levels 1 and 2 are settings you can change (1 to 3650 days and 1 to 120 months). Level 3 has no expiry setting and no task deletes it.

When the level 1 period ends, the daily purge adds those visits to level 3 and deletes the detail. A level 2 summary is deleted when its last interaction is older than the period.

The IP

The How to store the IP setting has three modes:

Mode What is stored
Truncated (default) For IPv4, with the last octet set to zero. For IPv6, only the first 48 bits.
Salted hash An HMAC-SHA256 of the IP with a salt derived from the site secret.
Full The whole IP.

An invalid IP is not stored. The REST API and the MCP tools always return the truncated IP; the admin panel shows the IP as stored, so with the "Full" mode anyone with panel access will see it.

Click identifiers

gclid, gbraid, wbraid, msclkid and fbclid are advertising identifiers.

  • In the Joomla session they are always captured, and they last as long as that session.
  • In the database they are not stored unless you turn on Store click identifiers. They are then stored in visits and in lead attribution.
  • They have their own period (Click identifier retention (days), 90 by default). When it ends, the purge removes them from the row and leaves the rest of the row intact.

Cookies

  • evoOrigin creates no cookies of its own. The Joomla session uses the session cookie that Joomla already manages.
  • If you turn on Log only with consent, evoOrigin reads your banner's cookie (the one you name) to decide whether to log. It does not write it.
  • Version 1.1.6 includes no persistent visitor identifier.
  • Which cookies to list in your cookie policy is for each installation to decide with its adviser.

The session hash

The visit row does not store the Joomla session identifier. It stores an HMAC-SHA256 of that identifier with a salt derived from the site secret.

Who can see the data

  • Joomla users with the Manage permission on evoOrigin, in the panel and through the REST API.
  • evoMCP connections that have permission on the evoorigin component, as long as the user holds that same permission. Visits are flagged as personal data.
  • The Delete permission controls manual deletion of visits and summaries.

Permissions are set in the component options.

Joomla privacy tools

The evoOrigin privacy plugin integrates with the Joomla privacy tools:

Action What it does
Export Includes the visits linked to the user: id, IP, landing page, source, medium, campaign, referer and date.
Check whether it can be removed Always answers yes: evoOrigin has no obligation to retain the data.
Delete Deletes the visits linked to the user id.

A visit is linked to a person only if the visitor identified with their Joomla user during the session. Other visits are not associated with a user, although the full IP, if you chose that mode, could allow them to be related to a person.

Lead attribution summaries store no direct identifiers; they are linked by a reference (type and identifier) kept by the extension that created the lead. They are handled from that extension, or deleted from the evoOrigin panel or with the MCP delete tools.

Settings that limit the data

You want to… Adjust…
Store nothing in the database Leave Log visits and Store lead attribution set to No.
Store less of the IP How to store the IP set to Truncated or Salted hash.
Keep data for less time Detail retention (days) and Summary retention.
Not store advertising identifiers Store click identifiers set to No.
Log only visitors who accepted the banner Log only with consent, with your banner's cookie and value.
Let the purge run Keep the "evoOrigin: data purge" scheduled task enabled.

The panel warns you if you keep the full IP or click identifiers for more than 90 days, or if you require consent without naming the cookie.

This is not legal advice; consult your adviser.