Privacy

How we handle your information

We sell control over what is published about people. It would be a poor showing to be careless with the private information those same people hand us, so this notice says exactly what we hold, where it sits, and who can reach it.

Last updated 15 August 2026
Controller
Domain Farm Ltd, trading as Ascribed
Company number
13544286, registered in England and Wales
Registered office
Vantage House, Euxton Lane, Euxton, Chorley, Lancashire, PR7 6TB
Contact
privacy@ascribed.ai

1. Two kinds of information, and the difference matters

Most privacy notices describe one thing: the details you type into a form. Ours has to describe two, because the service itself is about information concerning you.

Both are personal data under UK data protection law and both are covered here. But only the first is confidential. The second is, by definition, already public, and the point of hiring us is to change what it says.

2. What we collect, why, and on what basis

WhoWhatWhyLawful basis
Anyone reading the site Nothing that identifies you. No analytics, no tracking, no advertising pixels. Our server keeps routine access logs containing IP addresses, as every web server does Keeping the site up and secure Legitimate interests
Free audit requests Your name, email address, the link you give us, what you do, any notes you add, plus your IP address, browser string and referring page To identify the right person, prepare your audit and send it to you Steps taken at your request before a contract, and your consent to reply
Dashboard accounts Your name and email address, passed to us by Google when you choose to sign in, plus the dates you created the account and last signed in. We do not store your Google profile picture and we never receive your password To let you sign in, and to show you your own audit and reports Performance of our contract, and your request to create an account
Clients The fact set your records are built from, the sources behind each fact, images you license to us, correspondence, and billing records To deliver what you bought, and to evidence that every published statement is sourced Performance of our contract, and legal obligation for accounting records
Removals work Information about you published by other people, and our correspondence with them To ask them to take it down on your behalf Performance of our contract
We do not buy lists, and we do not currently do cold outreach. If that changes, anyone contacted will get their own notice explaining where their details came from, as required when personal data is not collected from the person themselves. Nothing on this site feeds such a list. Every audit request is stamped at the point it arrives as an inbound enquiry, specifically so it can never be mixed into one.

What we never ask for

We do not want, and do not knowingly collect, information about your health, ethnicity, religion, politics, sex life, trade union membership, or criminal record. If something like that is already published about you and it is relevant to a removal request, tell us and we will handle it separately rather than in the ordinary run of work.

3. Where your data is kept

This is usually the vaguest section of a privacy notice. Here is the actual arrangement.

ThingWhere it lives
The website and your form submission A server in London, United Kingdom, hosted with IONOS. Your data does not leave the UK in the ordinary course of our work
Audit requests Written to a file on that same server, in a directory that sits above the public web folder. It is not reachable from the internet at any address
Email Mailboxes on the same UK server
Your published records Public by design. Wikidata, your own site, the profile page we build you

What is not involved

You can check most of this yourself. Open your browser's developer tools on any page here and watch the network tab. Every request goes to ascribed.ai and nowhere else.

4. Cookies

There is no cookie banner on this site because there is nothing to consent to. We set no advertising, analytics or profiling cookies of any kind.

Two cookies exist, both strictly necessary, both holding nothing but a random identifier, both marked HttpOnly and SameSite, and both gone when you close your browser.

5. Who else can see it

Your audit request is written to our server and emailed to our own mailbox on that same server. No other company is involved in that path.

Google, if you use the dashboard

Signing in is the one place another company is involved, and only because you chose it. When you sign in with Google:

If you would rather Google were not involved, you do not have to use the dashboard. Ask and we will send your report by email instead.

Everyone else

As the service grows, these will be:

WhoWhat they would getStatus
StripeYour name, email and billing details, to take payment. Card numbers go to Stripe directly and never reach usNot yet in use
PostmarkYour email address and the message, to deliver receipts and reportsNot yet in use
Our accountantInvoices and payment recordsAs required by law

We will update this page before any of them starts processing your information, not after. We do not sell your data, and we do not share it with anyone for their own marketing.

6. Publishing information about you

If you become a client, the work involves publishing information about you on purpose. That is the product. Two rules govern it.

Your profile page and any directory listing can be taken down at your request, normally the same day. Email privacy@ascribed.ai.

7. The part that cannot be undone

Contributions to Wikidata, Wikipedia and Wikimedia Commons are permanent and public. They are published under open licences, copied by other services, and preserved in a public edit history that names the account which made the change. We can ask for a record to be deleted, and often that succeeds, but we cannot promise it, we do not control those projects, and the edit history remains regardless. An image you release to Wikimedia Commons under a free licence cannot be un-released: anyone may keep using it under that licence.

This is a real and irreversible consequence, so we would rather you understood it before we start than discovered it afterwards. If you are not comfortable with permanence, say so and we will build your record entirely on surfaces you control, which is a legitimate choice.

8. How long we keep it

WhatHow longWhy
An audit request that does not become work12 months, then deleted So we can pick the conversation back up if you return
Client records and correspondence6 years after the last piece of work Tax records, and the period during which a claim could be brought
Invoices and payment records6 yearsRequired by law
The sources behind your published factsAs long as the record is live We must be able to evidence any published statement
Server access logsA short rotation, then overwritten Security and diagnostics. They are not analysed or profiled

You can ask us to delete your audit request at any point before that, and we will.

9. Sending data outside the UK

At present we do not. Your information is held on a UK server and handled by people in the UK. When Stripe and Postmark come into use, both involve transfers to the United States, made under the transfer arrangements UK law provides for. This section will be updated at that point.

Separately, and obviously, anything published about you as part of the work is available worldwide. That is the intended outcome rather than a transfer of confidential data.

10. Your rights

Under UK data protection law you can ask us to:

Two of these are buttons, not requests. If you have a dashboard account, you can download everything we hold as a file, or delete your account and its contents outright, without asking us and without waiting. We would rather give you the control than make you request it.

For anything else, email privacy@ascribed.ai. We will respond within one month. There is no charge.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office at ico.org.uk, or call 0303 123 1113. We would rather you came to us first so we can put it right, but you are not obliged to.

11. Security

The site is served only over HTTPS. Audit submissions are written above the public web root so no address can reach them. Access to the server is restricted to us and protected by keys rather than passwords. Administrative access to the hosting platform is separately credentialed.

We are a small team, which cuts both ways: fewer people can reach your data, and we do not have a dedicated security department. If you find a problem, tell us at privacy@ascribed.ai and we will act on it rather than argue about it.

12. Changes to this notice

When we change something that affects you, we update the date at the top and, if the change is significant, tell clients directly. We will not quietly widen what we do with your data and rely on you noticing.