1. Data Controller
The data controller responsible for personal information processed in connection with the Site is [TODO: legal entity name], registered at [TODO: registered address]. You can contact us at any time using the details set out in Section 13 of this Policy.
2. Categories of Personal Information We Process
We collect and process the following categories of personal information:
- Identifiers and contact information: name and email address you submit through the contact, submission, or newsletter forms.
- Communications content: the content of messages and submissions you send us.
- Technical and device information: IP address, browser user-agent, referring URL, pages visited, and timestamps, captured automatically in server logs.
- Cookie and tracking identifiers: identifiers stored in cookies, local storage, and similar technologies, as described in our Cookie Notice.
- Inferences and usage statistics: aggregate metrics derived from analytics, where you have consented to non-essential cookies.
We do not knowingly collect special categories of personal data (such as health, racial or ethnic origin, political opinions, religious beliefs, biometric or genetic data) or information from individuals known to be under the age of 16.
3. Purposes and Legal Bases for Processing
We process personal information for the following purposes, relying on the corresponding lawful bases under the EU General Data Protection Regulation 2016/679 ("EU GDPR") and the UK General Data Protection Regulation as incorporated by the Data Protection Act 2018 ("UK GDPR"):
- Operating and securing the Site — Article 6(1)(f) (legitimate interests in providing a working, secure publication).
- Responding to enquiries, submissions and corrections — Article 6(1)(b) (performance of a contract or steps prior to entering one) and Article 6(1)(f).
- Sending the newsletter where you have subscribed — Article 6(1)(a) (consent), withdrawable at any time.
- Analytics and audience measurement — Article 6(1)(a) (consent given through the cookie banner).
- Compliance with legal obligations — Article 6(1)(c).
- Establishing, exercising or defending legal claims — Article 6(1)(f).
4. Disclosures to Third Parties
We disclose personal information only to the following categories of recipient, all of whom act as our processors under written contracts that comply with Article 28 GDPR:
- Hosting and infrastructure providers — [TODO: hosting provider name].
- Email and transactional message providers — [TODO: email provider name].
- Analytics providers — [TODO: analytics provider name], only with your consent.
- Professional advisers (legal, accounting, audit) where reasonably required.
- Public authorities, where required by law or to defend legal rights.
We do not sell or share your personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").
5. International Transfers
Where personal information is transferred outside the European Economic Area or the United Kingdom, we rely on a transfer mechanism recognised under Article 46 GDPR — typically the European Commission's Standard Contractual Clauses and, for transfers from the United Kingdom, the UK International Data Transfer Addendum or the International Data Transfer Agreement, supplemented by appropriate technical and organisational measures. Details are available on request.
6. Retention
We retain personal information only for as long as necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. As a guideline:
- Contact and submission correspondence — [TODO: retention period].
- Newsletter subscription data — until you unsubscribe, plus a short housekeeping period.
- Server access logs — typically 30–90 days.
- Analytics aggregates (where consented) — up to 26 months.
7. Your Rights under EU and UK GDPR
Subject to applicable law, you have the right to:
- Request access to the personal information we hold about you (Article 15);
- Request rectification of inaccurate personal information (Article 16);
- Request erasure of your personal information (Article 17);
- Request restriction of processing (Article 18);
- Request portability of your personal information (Article 20);
- Object to processing carried out under legitimate interests (Article 21); and
- Withdraw any consent you previously gave at any time, without affecting the lawfulness of processing performed prior to withdrawal (Article 7(3)).
You also have the right to lodge a complaint with your local supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In Ireland this is the Data Protection Commission (dataprotection.ie).
8. Your Rights under the CCPA
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose and (if applicable) sell or share;
- Request deletion of personal information collected from you, subject to statutory exceptions;
- Request correction of inaccurate personal information;
- Opt out of any "sale" or "sharing" of personal information (we do not engage in either);
- Limit use and disclosure of sensitive personal information; and
- Be free from retaliatory or discriminatory treatment for exercising your CCPA rights.
You may exercise these rights by contacting us using the details in Section 13. We will verify your identity before responding, in accordance with applicable regulations.
9. Cookies and Similar Technologies
Detailed information about the cookies we use, the purposes for which we use them, and how you can manage your preferences is set out in our Cookie Notice. You may revoke or change your consent at any time via the "Cookie settings" link in the site footer.
10. Security
We maintain appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful processing, accidental loss, destruction, or damage. No method of transmission over the Internet or electronic storage is fully secure; we cannot guarantee absolute security.
11. Children
The Site is not directed at children under the age of 16, and we do not knowingly collect personal information from such children. If you believe a child has provided personal information to us, please contact us and we will take steps to delete the information.
12. Updates to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of this page indicates when the most recent revision was made. Material changes will be communicated where required by applicable law.
13. How to Contact Us
Questions, requests under Sections 7 or 8, or complaints about this Policy may be addressed to:
App Comrade — Privacy
Email: [email protected]
Postal: [TODO: postal address]