1. Two kinds of information, and the difference matters
Most privacy notices describe one thing: the details you type into a form. Ours has to describe two, because the service itself is about information concerning you.
- What you give us privately. Your email address, your notes, your billing details. This is ordinary confidential information and we treat it that way. It is never published.
- What is already published about you. Your public record: articles, registers, profiles, search results. Researching this is the service. Some of it we help you publish, correct or remove.
Both are personal data under UK data protection law and both are covered here. But only the first is confidential. The second is, by definition, already public, and the point of hiring us is to change what it says.
2. What we collect, why, and on what basis
| Who | What | Why | Lawful basis |
|---|---|---|---|
| Anyone reading the site | Nothing that identifies you. No analytics, no tracking, no advertising pixels. Our server keeps routine access logs containing IP addresses, as every web server does | Keeping the site up and secure | Legitimate interests |
| Free audit requests | Your name, email address, the link you give us, what you do, any notes you add, plus your IP address, browser string and referring page | To identify the right person, prepare your audit and send it to you | Steps taken at your request before a contract, and your consent to reply |
| Dashboard accounts | Your name and email address, passed to us by Google when you choose to sign in, plus the dates you created the account and last signed in. We do not store your Google profile picture and we never receive your password | To let you sign in, and to show you your own audit and reports | Performance of our contract, and your request to create an account |
| Clients | The fact set your records are built from, the sources behind each fact, images you license to us, correspondence, and billing records | To deliver what you bought, and to evidence that every published statement is sourced | Performance of our contract, and legal obligation for accounting records |
| Removals work | Information about you published by other people, and our correspondence with them | To ask them to take it down on your behalf | Performance of our contract |
What we never ask for
We do not want, and do not knowingly collect, information about your health, ethnicity, religion, politics, sex life, trade union membership, or criminal record. If something like that is already published about you and it is relevant to a removal request, tell us and we will handle it separately rather than in the ordinary run of work.
3. Where your data is kept
This is usually the vaguest section of a privacy notice. Here is the actual arrangement.
| Thing | Where it lives |
|---|---|
| The website and your form submission | A server in London, United Kingdom, hosted with IONOS. Your data does not leave the UK in the ordinary course of our work |
| Audit requests | Written to a file on that same server, in a directory that sits above the public web folder. It is not reachable from the internet at any address |
| Mailboxes on the same UK server | |
| Your published records | Public by design. Wikidata, your own site, the profile page we build you |
What is not involved
- No third party form processor. The audit form posts to our own server. It does not pass through Typeform, HubSpot, Google Forms or anything similar, so no other company receives a copy of what you typed.
- No analytics. There is no Google Analytics, no Tag Manager, no Meta pixel, no session recording and no heatmapping on any page of this site.
- No font or script loaded from elsewhere. Our typefaces are embedded in the page itself rather than fetched from Google Fonts, so loading a page here does not tell a third party that you visited.
- No advertising network receives anything about you from this site.
4. Cookies
There is no cookie banner on this site because there is nothing to consent to. We set no advertising, analytics or profiling cookies of any kind.
Two cookies exist, both strictly necessary, both holding nothing but a random identifier, both marked HttpOnly and SameSite, and both gone when you close your browser.
- PHPSESSID, set only if you submit the audit form and something needs correcting, so the page can show you what to fix without losing everything you typed. If you only read the page and never submit anything, it is never set.
- ascribed_portal, set only when you sign in to the dashboard, so we know it is still you between pages. If you never sign in, it is never set.
5. Who else can see it
Your audit request is written to our server and emailed to our own mailbox on that same server. No other company is involved in that path.
Google, if you use the dashboard
Signing in is the one place another company is involved, and only because you chose it. When you sign in with Google:
- Google confirms your identity to us and passes your name and email address. That is all we ask for and all we receive.
- Your Google password never reaches us. You type it on Google's own page and we never see it. We hold no password of our own, so there is nothing here to steal or reset.
- Google will know that you signed in to Ascribed, in the same way it knows about any site you use it for. Their handling of that is covered by Google's own privacy policy.
- The dashboard does not load your Google profile picture, so simply viewing a page does not cause your browser to contact Google at all. We show your initials instead.
If you would rather Google were not involved, you do not have to use the dashboard. Ask and we will send your report by email instead.
Everyone else
As the service grows, these will be:
| Who | What they would get | Status |
|---|---|---|
| Stripe | Your name, email and billing details, to take payment. Card numbers go to Stripe directly and never reach us | Not yet in use |
| Postmark | Your email address and the message, to deliver receipts and reports | Not yet in use |
| Our accountant | Invoices and payment records | As required by law |
We will update this page before any of them starts processing your information, not after. We do not sell your data, and we do not share it with anyone for their own marketing.
6. Publishing information about you
If you become a client, the work involves publishing information about you on purpose. That is the product. Two rules govern it.
- Everything we publish traces to a source. We do not invent, embellish or estimate a fact about you. If it cannot be sourced to something already published, or to something you have given us and can stand behind, it does not go in.
- You approve it before it goes live. Records, articles and profile pages are shown to you first.
Your profile page and any directory listing can be taken down at your request, normally the same day. Email privacy@ascribed.ai.
7. The part that cannot be undone
This is a real and irreversible consequence, so we would rather you understood it before we start than discovered it afterwards. If you are not comfortable with permanence, say so and we will build your record entirely on surfaces you control, which is a legitimate choice.
8. How long we keep it
| What | How long | Why |
|---|---|---|
| An audit request that does not become work | 12 months, then deleted | So we can pick the conversation back up if you return |
| Client records and correspondence | 6 years after the last piece of work | Tax records, and the period during which a claim could be brought |
| Invoices and payment records | 6 years | Required by law |
| The sources behind your published facts | As long as the record is live | We must be able to evidence any published statement |
| Server access logs | A short rotation, then overwritten | Security and diagnostics. They are not analysed or profiled |
You can ask us to delete your audit request at any point before that, and we will.
9. Sending data outside the UK
At present we do not. Your information is held on a UK server and handled by people in the UK. When Stripe and Postmark come into use, both involve transfers to the United States, made under the transfer arrangements UK law provides for. This section will be updated at that point.
Separately, and obviously, anything published about you as part of the work is available worldwide. That is the intended outcome rather than a transfer of confidential data.
10. Your rights
Under UK data protection law you can ask us to:
- give you a copy of what we hold about you
- correct anything inaccurate
- delete it, where we do not need to keep it for a legal reason
- restrict or object to how we use it
- provide it in a portable form
- withdraw consent, where consent is what we relied on
For anything else, email privacy@ascribed.ai. We will respond within one month. There is no charge.
If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office at ico.org.uk, or call 0303 123 1113. We would rather you came to us first so we can put it right, but you are not obliged to.
11. Security
The site is served only over HTTPS. Audit submissions are written above the public web root so no address can reach them. Access to the server is restricted to us and protected by keys rather than passwords. Administrative access to the hosting platform is separately credentialed.
We are a small team, which cuts both ways: fewer people can reach your data, and we do not have a dedicated security department. If you find a problem, tell us at privacy@ascribed.ai and we will act on it rather than argue about it.
12. Changes to this notice
When we change something that affects you, we update the date at the top and, if the change is significant, tell clients directly. We will not quietly widen what we do with your data and rely on you noticing.