Flow Display Privacy Policy
Privacy information for measure.flowbymisgroup.com
Effective 25 September 2026 - Version 1.0
1. Scope of this policy
This Privacy Policy explains how MIS Group uses personal data through the Flow Display measurement service at measure.flowbymisgroup.com, including its one-pixel measurement endpoint. It applies to invited consumer-panel members who activate Flow Display for advertising-exposure research, including Study 30023.
This policy supplements the participation charter and the privacy policy of the panel through which you were recruited. It does not replace the policy governing your existing panel account or the separate terms for the Flow audio application.
2. Who is responsible
MIS Group, 85 rue Nationale, 59800 Lille, France, is responsible for the consumer-panel relationship and the Flow Display browser-measurement service described in this policy.
Fluzo is MIS Group's project partner for advertising-measurement research and may receive study information for that purpose. For more information about the organisations involved, their respective roles or any applicable international transfer arrangements, contact MIS Group's Data Protection Officer at dpo@misgroup.io.
3. How Flow Display works
Participation is voluntary and requires an invitation. If you consent and activate the service in a browser, Flow places a random identifier in that browser. When a tagged advertisement loads, the advertisement may call the Flow measurement pixel. The browser may then send the identifier to Flow so that the advertisement-loading event can be associated with your study participation.
The identifier and your panel reference are pseudonymous, not anonymous. MIS Group can link them to the relevant panel member in its controlled systems. The cookie does not contain your name or email address, and activating it does not give Flow access to your microphone, camera, files or messages.
Each browser and browser profile is treated separately. Browser privacy settings may block or isolate the cookie. You do not have to weaken browser protections to participate, and a technical failure is not treated as a successful activation.
4. Information we use
- Panel and participation information: your pseudonymous panel reference, panel of origin, country and participation status.
- Browser identifier: a random token stored in the activated browser and a cryptographic hash used by the server to recognise it.
- Consent records: whether consent was granted or withdrawn, the applicable purpose and policy version, the date and time, the activation source and browser information supplied during activation.
- Browser setup and testing information: a browser label, browser and operating-system family, compatibility-test identifiers, test results and relevant timestamps.
- Advertising-exposure information: campaign, creative, placement and impression identifiers when supplied by the advertising system, whether the request matched an active browser identifier, and the date and time of the request.
- Technical connection information: an IP address, user-agent information and other ordinary HTTP request details necessarily exposed to the server. Limited server logs may retain this information for security and troubleshooting.
The current configuration does not store an approximate-device identifier with exposure records. If MIS Group later enables a device-estimation feature, it would use a derived, keyed hash of technical connection information for approximate device counts; it would not replace the cookie for identifying a panel member. The notice and configuration must be reviewed before such a change is introduced.
Flow Display does not require you to click advertisements or change your normal browsing habits. The measurement endpoint is designed to record tagged advertisement loads, not the contents of the pages you visit.
5. Why we use the information
| Purpose | Main legal basis |
|---|---|
| Activate the browser identifier and associate eligible tagged-advertisement loads with study participation | Your consent |
| Run browser compatibility checks and provide setup guidance | Your consent |
| Carry out advertising-exposure research and compare results with MIS panel information and Fluzo measurement data | Your consent |
| Maintain evidence of consent and withdrawal | Legal obligations and the establishment or defence of legal claims, where applicable |
| Protect the service, investigate errors and prevent misuse using limited technical logs | MIS Group's legitimate interests in service security and integrity |
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal affects future consent-based processing and does not make earlier lawful processing unlawful.
Flow Display is a measurement service. The Flow cookie is not used by this service to decide which advertisement you receive or to build an advertising profile for targeting.
8. How long information is kept
Participation in Study 30023 is planned for 180 days from the first browser activation. The Flow cookie has a requested lifetime of up to 180 days after activation or authorised restoration.
Flow Display measurement data is retained for no longer than one year from collection and is then deleted. This period is separate from the cookie lifetime and from the retention rules governing your panel account.
Some limited records, such as evidence of consent or withdrawal, may need to be retained for a different legal purpose. If that applies to a rights request, MIS Group will explain the purpose and applicable period.
9. Your choices and rights
You can stop participation and withdraw consent at any time. In each activated browser or browser profile, open https://measure.flowbymisgroup.com/status and select "Retirer mon consentement". The status page must be opened in the same browser profile that contains the active Flow cookie.
The withdrawal control securely submits a POST request to /withdraw with the required session protection. The endpoint is not intended to be opened directly. On success, Flow revokes the browser identifier, records the withdrawal event and asks the browser to delete the flow_measure_id cookie. Future pixel requests from that browser will no longer be associated with your panel profile.
Withdrawal through the status page applies to that browser profile. Repeat it on every activated browser or contact MIS Group to request withdrawal across your participation.
If you cannot use the withdrawal control, email dpo@misgroup.io and state that your request concerns Flow Display, Study 30023. Use the email address associated with your panel account and identify your panel of origin. Do not send your password or personal activation link.
Subject to applicable law, you may request access to your personal data, correction, deletion, restriction of processing and, where applicable, data portability. You may object to processing based on legitimate interests and withdraw consent for consent-based processing. MIS Group may need to verify your identity before completing a request.
You may also complain to the data-protection authority in your country. In France, this is the CNIL at www.cnil.fr. In the United Kingdom, this is the ICO at ico.org.uk.
10. Security and responsible participation
MIS Group uses technical and organisational measures intended to protect study information against unauthorised access, loss, alteration or disclosure. The browser cookie is transmitted over HTTPS and is configured as Secure and HttpOnly. The server stores a cryptographic hash of the browser token rather than the token itself for matching purposes.
Only use your personal invitation and browsers you are authorised to use. Do not share an invitation. On a shared device, use your own browser profile so that another person's activity is not incorrectly associated with your participation.
11. Changes and contact
MIS Group may update this policy if the service, study arrangements or legal requirements change. Material changes affecting consent-based processing will be brought to participants' attention and, where required, fresh consent will be requested before the changed processing begins.
Questions and data-protection requests may be sent to MIS Group's Data Protection Officer at dpo@misgroup.io or by post to MIS Group, 85 rue Nationale, 59800 Lille, France.