PRIVACY POLICY
Last updated: August 2026.
1. INFORMATION FOR THE USER
Elem Utils is a Manifest V3 Chrome browser extension that helps users work with a Signals One tenant (a "revvitycloud" web application) they already have access to. It issues requests to that tenant's REST API from the page the user is viewing, reusing the browser session the user is already signed in with. This Privacy Policy explains what data the extension handles, where that data is stored, who it is shared with and what choices the user has. The extension has no backend of its own: there is no Elem Utils server, no account, no login and no telemetry. The developer of the extension does not receive, collect or store any of the data described below.
2. CONTACT
Extension: Elem Utils Email: info@hexenta.com
3. KEY PRINCIPLES
Data minimisation: the extension only reads what is needed to build a request or to display a result, and nothing more. No collection: no personal data is sent to the extension developer or to any third-party service. Nothing is uploaded, aggregated or profiled. No selling or transfer: data is never sold, rented, shared or transferred to anyone. It is not used for advertising, for creditworthiness or lending purposes, or for training any model. Local only: everything the extension keeps lives inside the user's own browser profile, in Chrome's extension storage. Purpose limitation: data is used only to provide the feature the user explicitly triggered, and for no secondary purpose. Session scope: captured tenant payloads and credentials are held in session storage and disappear when the browser session ends. User control: the user can clear captured data at any time from the extension's popup, and can remove all stored data by uninstalling the extension.
4. DATA THE EXTENSION HANDLES
Active tab address: when the popup is opened, the extension reads the URL of the active tab in order to determine the tenant origin and to pre-fill entity identifiers into action fields. The tenant is never configurable and is always taken from the tab the user is on; only https addresses whose hostname contains "revvitycloud" are accepted. This URL is not stored beyond the current session. Tenant API responses and requests: when an action is executed, the response returned by the tenant is displayed in the popup or saved as a file on the user's computer, as requested. The extension also observes some of the tenant application's own network calls (grid, analytics and tabular-data endpoints) so their contents can be shown in the popup. The relevant request and response bodies, truncated to a fixed size limit, are held in Chrome's session storage. These payloads may contain the business data of the tenant, including temporary signed object-storage links; they are never transmitted anywhere by the extension. Form drafts and preferences: values typed into action fields are kept in session storage so the popup can be reopened without retyping them. Which action groups are visible is stored in Chrome's local storage so that this preference survives a browser restart. These contain no personal data beyond what the user types. Build-server credentials: if, and only if, the user chooses to launch a build from the configuration page, the username and API token entered there are stored in Chrome's session storage restricted to trusted extension contexts. They are never written to local or synchronised storage, never included in a URL, log or status message, and are removed when the browser session ends. Downloaded files: files produced by a download action are written through the browser's normal download mechanism to the user's device and are then entirely under the user's control.
5. LEGAL BASIS AND PERMISSIONS
Every processing operation happens because the user explicitly triggered it: opening the popup, selecting and executing an action, loading a tenant page whose data is captured, or launching a build. There is no background collection while the extension is idle. The extension requests the narrowest permissions that make this possible: "activeTab" to read the address of the tab the user is currently on, "scripting" to run its request code inside that tenant page, and "storage" to keep the session and preference data described above. Requests to the tenant are deliberately made from within the tenant page itself so that the user's existing first-party session cookies apply exactly as they do for the application; the extension never sees or copies those cookies. Access to tenant pages ("https://*.revvitycloud.net/*") is required to observe the application's own request and response bodies, which cannot be read any other way. One fixed additional host, the internal build server "https://jenkins.snb.revvitycloud.net", is used only for the optional build-launching feature and only with the credentials the user supplies for it.
6. RETENTION AND SHARING
Session storage, which holds captured payloads, form drafts and build credentials, is cleared automatically when the browser session ends, and captured payloads can also be cleared on demand from the popup. Local storage holds only the action group visibility preference and persists until the extension is uninstalled. Data is shared with no one. The only network destinations are the Signals One tenant the user is already signed in to and, for the optional build feature, the fixed internal build server. Both are systems the user already has their own access to; the extension adds no intermediary, no proxy and no analytics endpoint.
7. YOUR RIGHTS
Because the extension stores nothing outside the user's own browser, the user has direct control over all of it: captured data can be cleared from the popup, session data disappears when the browser closes, and uninstalling the extension removes everything that remains. Data held by the Signals One tenant itself, which the extension merely displays, is controlled by the organisation operating that tenant; requests to access, rectify, erase, restrict, port or object to the processing of that data, as provided by Articles 15 to 21 of Regulation (EU) 2016/679 (GDPR) and by Spanish Organic Law 3/2018 (LOPDGDD), should be addressed to that organisation. For questions about the extension itself, write to info@hexenta.com. Users in the EU/EEA also have the right to lodge a complaint with the competent supervisory authority (in Spain, www.aepd.es) if they believe processing does not comply with applicable law.
8. LEGAL INFORMATION
The requirements of this Policy complement, and do not replace, any other requirement under applicable data protection law, which prevails in every case. Use of the extension is also subject to the Chrome Web Store Developer Program Policies, including its Limited Use requirements, with which this Policy is intended to comply. This Policy is reviewed periodically and may be updated at any time. When it changes, the updated version will be published at this address and the "last updated" date above will be revised.