Overview
This policy explains what personal data EX Info processes, why it processes it, how long it retains it, and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The site is operated from the United Kingdom and applies UK data-protection standards to all processing.
Data we collect
We collect the minimum amount of personal data required to operate the site and to respond to correspondence. This is limited to server access logs, which are retained for security and troubleshooting purposes, and to the contents of any email you choose to send us. We do not run analytics scripts that identify individual visitors, we do not run advertising tags, and we do not embed third-party content that fingerprints readers.
Server logs
Our web server records the IP address of each request, the time of the request, the URL requested, the referring URL if any, and the user agent string. These logs are used exclusively to identify malicious activity, to diagnose technical faults and to produce aggregate readership statistics. They are stored for thirty days and then deleted.
Email correspondence
If you write to us we will process your email address and the contents of your message for the purpose of responding. We store email correspondence for a maximum of two years after the last exchange, after which the message is deleted. We do not add correspondents to any marketing list. We do not have a marketing list.
Cookies
The site sets no analytics or advertising cookies. A small number of strictly-necessary session cookies may be set for basic technical purposes such as consistent page delivery. Detail on cookie usage is set out on our cookies page.
Legal basis for processing
Under Article 6 of the UK GDPR, we rely on legitimate interests for the processing of server logs (specifically, our interest in operating and securing the site) and on your consent for the processing of email correspondence (implied by your act of sending an email). Where sensitive personal data is inadvertently included in correspondence, we delete the message and do not process it further unless you explicitly ask us to.
Your rights
Under the UK GDPR you have the right to be informed about our processing, to access your data, to have inaccurate data corrected, to have your data erased in defined circumstances, to restrict processing, to object to processing, and to data portability where relevant. To exercise any of these rights, write to the address on our contact page.
Complaints and enforcement
If you believe our processing does not meet the standards required by UK data-protection law, you have the right to complain to the Information Commissioner's Office, which is the UK's independent data-protection regulator. Their address and complaint procedures are published on their website. We would appreciate the opportunity to resolve any concern directly before you escalate, but the ICO route is always available and does not require any prior contact with us.
Changes to this policy
We review this policy annually and update it as required by changes in law or in our own operations. The last-updated date at the top of this page reflects the most recent revision. Substantive changes will be summarised at the top of the page for a period of at least three months after publication.