Legal

Privacy policy

1. Who is responsible

Name the controller, its registered address, and a contact point for privacy questions. If you have appointed a data protection officer or an EU/UK representative, name them here too.

2. What is collected

Work from a genuine inventory. Typically it covers:

3. Why, and on what lawful basis

Each purpose needs its own stated basis — contract, legitimate interests, consent or legal obligation. Where you rely on legitimate interests, record the balancing test that justifies it.

4. How long it is kept

Give real retention periods per category, not “as long as necessary”. Note what is deleted when a subscription ends and what is retained for accounting or fraud purposes.

5. Who it is shared with

List the categories of recipient — payment processor, hosting and CDN providers, email and messaging platforms, analytics. Note that WhatsApp support means correspondence passes through Meta’s infrastructure, which is a disclosure customers should see.

6. International transfers

If personal data leaves the UK or EEA, state where it goes and the safeguard relied on — adequacy decision, standard contractual clauses or the UK addendum.

7. Your rights

State how a request is made and your response deadline.

8. Security

Describe the measures you genuinely operate: encryption in transit, access control, breach procedures. Do not list controls you have not implemented — a claim here is one you have to stand behind.

9. Cookies

Covered separately on the cookies page.

10. Changes

How updates are notified, and the effective date of this version.