Legal

Privacy policy


The short version: this site asks for one thing, an email address, and only if you want the newsletter. There is no analytics, there are no cookies, and nothing about you is sold or shared with anyone selling anything.

  • Last reviewed: [PLACEHOLDER: date these policies were last reviewed]
  • Not yet reviewed by a solicitor

These documents were written to be accurate about how this site actually works, clause by clause, against the code that runs it. They have not been reviewed by a solicitor.

They should be, before this site takes real traffic or takes money. Treat everything below as a good-faith description of current practice rather than as finished legal advice, and if you are relying on it for anything that matters, write to me and ask.

The whole thing in one paragraph

If you read this site and do nothing, I hold no personal data about you at all. If you subscribe to the newsletter, I hold your email address and the fact that you consented, for as long as you want the newsletter, and I use it to send you the newsletter. Nothing else. You can have it back or have it deleted whenever you ask, and asking costs you one email.

Everything below is that same statement, said carefully enough to be checked.

Who is responsible for it

The data controller, the person who decides what happens to your data and is answerable for it, is [PLACEHOLDER: legal entity name of the data controller: sole trader or registered company, exactly as it should appear in a legal document], at [PLACEHOLDER: registered address of the data controller].

I am based in Islamabad, Pakistan. That matters for the transfers section below, so it is stated here rather than buried.

For anything in this policy, the contact route is [PLACEHOLDER: public contact email]. There is no separate data protection officer; the site is not large enough to require one, and I answer these myself.

What is collected

Your email address, if you subscribe to the newsletter, and the record that you consented. That is the only thing this site asks you for. The consent checkbox is unticked by default and the form will not submit without it, because a pre-ticked box is not consent under GDPR Art. 7 and the CJEU settled that point in Planet49.

A note on the current state, because it would be misleading to leave it out. As this is written the newsletter form has no backend connected. It validates your address in your browser and shows you a success message; nothing leaves your device and nothing is stored anywhere. The form says so on the page. The rest of this policy describes what happens once the newsletter is live, so that the document is already true on the day it is wired up rather than a week later.

Technical request data, which every website receives and none of which I look at. Your browser sends an IP address, a user agent string and the address of the page you asked for to whatever server answers. Here that server is Cloudflare Pages. I have no analytics product, no dashboard and no log pipeline of my own, so I do not see, store or analyse any of it.

Nothing else. No cookies are set. No analytics or advertising script runs. No fonts are loaded from a third party. No chat widget, no heatmap, no pixel, no tag manager. If you write to me by email, I obviously have that email, and I keep correspondence the way anybody keeps their inbox.

Why I am allowed to hold it

Your consent, under GDPR Art. 6(1)(a) and the UK GDPR equivalent. You gave it by ticking an unticked box next to a plainly worded sentence, and that is the only basis relied on for the newsletter.

Consent that you can withdraw is the whole point of consent. Withdrawing it is one click in the footer of any issue, or one email to me, and it does not affect anything lawfully done before you withdrew it.

I do not rely on legitimate interests to email you marketing you did not ask for, and I do not treat a business email address as a loophole for doing so.

How long it is kept

Your email address is kept for as long as you choose to stay subscribed. Unsubscribing takes you off the sending list immediately, and the underlying record is deleted within [PLACEHOLDER: the deletion window after an unsubscribe: 30 days is the usual answer].

If the newsletter stops for good, the whole list is deleted rather than kept in case it starts again. If you never confirm your subscription, the unconfirmed record is discarded after [PLACEHOLDER: how long an unconfirmed double-opt-in signup is kept before being discarded: 30 days is typical].

Email correspondence with me is kept for as long as it is useful to have the thread, and then deleted.

Who else touches it

A processor is a company that handles the data on my instructions and is not allowed to do anything else with it. There are three, and there is no fourth.

Supabase: the database the newsletter list will live in. The project region is [PLACEHOLDER: the Supabase project region for the newsletter database, so the transfer position below can be stated exactly].

[PLACEHOLDER: the email sending provider, once chosen (the service that will actually send the newsletter)]: sends the newsletter and handles the unsubscribe link. It necessarily holds your address to do that. Email providers usually offer open and click tracking; whether it is switched on here is [PLACEHOLDER: decision: is open and click tracking enabled in the email provider (say so plainly here either way)].

Cloudflare Pages: hosts and serves the site. It processes the technical request data described above in order to deliver the pages and to keep the site up under abuse.

Each of these should be under a signed data processing agreement before the newsletter goes live: [PLACEHOLDER: confirmation that a written data processing agreement is in place with each processor, with the date each was signed].

Your address is not sold, rented, swapped or shared with anyone else, and there is no advertising network involved in any part of this site.

Where the data goes

I am in Islamabad, Pakistan. Pakistan is not covered by a UK adequacy regulation or an EU adequacy decision, so if you are in the UK or the EEA, subscribing means your email address is handled outside your own jurisdiction. That is stated plainly here because it is exactly the kind of thing a policy usually hides.

Where a processor is outside the UK or the EEA, the transfer is intended to rest on the standard contractual clauses in that processor's own data processing agreement, together with the UK addendum where it applies. That is the mechanism; the confirmation that it is signed is in the section above.

If you would rather not have your address leave your jurisdiction, the correct answer is not to subscribe, and I would rather tell you that than talk you past it.

Your rights, all of them

Under the UK GDPR and the EU GDPR you have the following rights. They are listed in full rather than summarised, because the summarised version is always the one missing the inconvenient entries.

Access: you can ask what I hold about you and get a copy. Rectification: you can have anything inaccurate corrected. Erasure: you can have it deleted. Restriction: you can ask me to stop using it while something is being sorted out. Portability: you can have it in a machine-readable form, or sent to someone else. Objection: you can object to how it is being used. Withdrawal of consent: you can withdraw consent at any time, and unsubscribing is exactly that. Complaint: you can complain to a supervisory authority, and you do not have to raise it with me first.

There is no automated decision-making or profiling on this site, so the Art. 22 rights do not arise. If that ever changes this page changes with it.

Exercising any of them is free and I will answer within one month, which is the statutory deadline. I will not make you justify the request, and I will not treat it as a retention conversation.

How to exercise them, and how to complain

Write to [PLACEHOLDER: public contact email]. Put the word in the subject line if you like; it does not need to be formal, and it does not need to come from a solicitor.

If you are in the UK, the supervisory authority is the Information Commissioner's Office. If you are in the EEA, it is the data protection authority for the country you live or work in. You can go to them directly and at any point.

I would rather you told me first, because most of these are a two-minute fix and a complaint is not. But that is a preference, not a condition.

How it is kept

The site is served over HTTPS. The newsletter form posts rather than gets, specifically so an email address can never end up in a URL, in browser history, in a referrer header or in an access log; that is a deliberate choice in the code, not a default.

The list itself sits in a managed database with access restricted to me. No copy of it is kept in a spreadsheet, an inbox or a laptop folder.

If a breach ever happens that is likely to be a risk to you, I will tell the relevant supervisory authority within 72 hours and I will tell you, in plain language, what went out and what to do about it.

Children

This is a site about consulting and professional training and it is not aimed at children. I do not knowingly collect data from anyone under 16. If you believe a child has subscribed, tell me and I will delete the record.

When this policy changes

It changes when the site changes: when the newsletter backend goes live, when the email provider is chosen, or if anything is ever added that collects more than this does today. The date at the top is the date it was last reviewed, and it moves whenever the text does.

If a change materially affects how your data is used, I will say so in the newsletter rather than quietly editing this page and relying on you to notice.