Privacy Policy
1. Summary
Skanda Robotics currently operates a single pre-launch website. It has no accounts, no contact form, no comments, no search box and no payment flow. Nothing on this site is stored on your device — no cookies, no local storage of any kind.
There is exactly one thing we ask you for, and two more that are true of visiting any website. We would rather state all three plainly than pretend otherwise:
- The email list. The home page offers an optional field where you may give us an email address to be told when we launch. Giving it is entirely voluntary, nothing on the site is withheld if you do not, and you can have it deleted at any time by writing to us. It is stored encrypted, we have never sent a message to it, and we will never sell, rent or share it — see section 4.3.
- Our hosting provider necessarily sees the technical details of your connection in order to serve the page to you — see section 4.1.
- The home page runs privacy-oriented, cookie-free analytics supplied by that same hosting provider — see section 4.2.
This policy is also written wide, so that it already covers things we expect to add later. Every section describing something we do not do yet is labelled as such and is not currently in effect.
This summary is a convenience. The sections below govern.
2. Scope
This policy covers personal data processed in connection with the website at skandarobotics.com and any subdomain or subpage of it.
It does not cover:
- Websites operated by other organisations that we may link to. See section 11 of our Terms.
- Personal data processed in an employment or contractor relationship, which is handled under a separate internal notice.
- Business-to-business correspondence conducted entirely outside this website, which is governed by the arrangements agreed with the relevant counterparty.
3. Who we are
"Skanda Robotics", "we", "us" and "our" mean [[ LEGAL ENTITY NAME ]], a company registered at [[ REGISTERED ADDRESS ]] under company number [[ COMPANY REGISTRATION NUMBER ]].
For the purposes of the GDPR we are the controller of the personal data described in this policy. For the purposes of India's Digital Personal Data Protection Act, 2023 (the DPDP Act) we are a Data Fiduciary. For the purposes of the California Consumer Privacy Act as amended (CCPA/CPRA) we are a business.
Our data protection contact is [[ DATA PROTECTION OFFICER OR GRIEVANCE OFFICER ]], reachable at [[ PRIVACY CONTACT EMAIL ]]. Where an EU or UK representative under Article 27 GDPR is required, that representative is [[ EU/UK ARTICLE 27 REPRESENTATIVE ]].
4. What we collect today
The only personal data we ask you for is an email address, and only if you choose to give it — section 4.3. Sections 4.1 and 4.2 describe what is processed anyway, as a consequence of the page being delivered over the internet, whether or not you ever type anything.
4.1 Server and hosting logs
The site is served by Vercel. Like every web host, Vercel's infrastructure receives and may log the technical details of each request in order to route it, serve it, protect the service from abuse and diagnose faults. Those details typically include:
- your IP address, or a truncated or derived form of it;
- the date and time of the request;
- the path requested and the HTTP status returned;
- your browser's user-agent string, and the referring page if your browser sends one;
- coarse network and geographic information derived from the IP address, typically no more precise than the country and region.
This is inherent to hosting a website at all — it is not a data collection decision we have made, and there is no configuration in which a web server can respond to a request without receiving it. We do not export, mine or enrich these logs, we do not join them to any other data set, and we do not use them to build a profile of you. They are held by Vercel as our processor and retained according to Vercel's own retention schedule, described in the privacy policy published at vercel.com/legal/privacy-policy.
One thing we do add to that stream ourselves, and would rather disclose than let you discover: when our subscribe endpoint refuses a request — because a rate limit was hit, an automated submission was detected, or a browser reported a security-policy violation — we write a short diagnostic line into those same hosting logs. It records a truncated network range rather than your full address: the first three groups of an IPv4 address, or the first four of an IPv6 one. We do this to tell a flood apart from a launch-day rush, and it is the basis on which the endpoint can be defended at all. The email address itself is never written to any log, at any level, in any field.
We note for completeness that our site's response headers include Referrer-Policy: no-referrer, which instructs your browser not to disclose the page you came from when it requests our assets or when you follow a link away from our site.
4.2 Analytics and performance measurement
The home page loads Vercel Web Analytics and Vercel Speed Insights. Both are first-party scripts served from our own origin; neither is a third-party tag, an advertising pixel or a tracker shared with any other website.
They are used to count page views and to measure how quickly the page renders — Core Web Vitals-style timings such as time to first byte and layout stability. The data sent is aggregate and non-identifying: the page path, the referrer category, the country, the device and browser type, and the performance timings themselves. Vercel documents both products as operating without cookies and without persistent cross-site identifiers.
The page you are reading now loads no scripts at all, including these — our legal pages are deliberately static HTML and CSS, so reading this policy is not itself measured.
If we later replace or supplement these products, this section will be updated before the change is deployed.
4.3 The launch-updates email list
The home page carries a single optional field, labelled "Subscribe for updates". If you type an email address into it and submit, we store that address so that we can tell you when the product launches. That is the entire purpose. This is the only personal data we hold ourselves.
What we store
Two things: the email address, and the date and time it was submitted. Nothing else. We do not record your IP address, your user-agent, the page you came from, or anything else about the submission alongside it. We do not ask for your name, and there is no field in which you could give us one.
How it is stored
The address is encrypted before it is written down, with AES-256-GCM, and it is stored in that form and no other. Separately, a one-way keyed fingerprint of the address is used as its identifier, so that the list can recognise a duplicate signup without holding a readable address to compare against. The keys that reverse either operation are held in our hosting platform's secret store, never in the database itself, and are not interchangeable with one another.
The practical consequence, which is why it is built this way: if the database were copied by an attacker tomorrow, what they would have is a count, a list of timestamps and a block of ciphertext — not a mailing list. Addresses are made readable in one place only, on a company machine, by a person who has to hold the decryption key, and never by the website itself while serving a request.
Consent, and taking it back
We store the address on the basis of your consent — section 7. Consent is given by submitting the field and nothing else; there is no pre-ticked box, no bundling with any other permission, and nothing on this site is withheld from you if you never use it.
You can withdraw it at any time, and withdrawal is as easy as giving it was: write to [[ PRIVACY CONTACT EMAIL ]] from the address in question, or naming it, and we will erase it. We hold a tool for exactly this and it takes effect immediately — the ciphertext is deleted outright rather than flagged, so there is nothing left to recover afterwards. We will confirm when it is done. You do not have to give a reason, and we will not ask for one.
Because we have never yet sent a message to this list, there is at present no unsubscribe link for you to click — email us and it is done. From the first message we ever send, every message will carry a working one-click unsubscribe, and we will keep a minimal record of unsubscribes for the sole purpose of not contacting you again.
What we will not do with it
- We will not sell, rent, share or licence the list, to anyone, at any price.
- We will not use it for anything other than telling you about Skanda Robotics and its launch. If we ever want to use it for a materially different purpose, we will ask you first, separately.
- We will not enrich it — we will not look your address up against any other data set, infer an employer or a location from its domain, or attach anything to it.
- We will not use it to advertise to you on other platforms. It will not be uploaded to any advertising network as a custom or lookalike audience.
4.4 What we do not collect
To be unambiguous, the site as it stands today does not:
- set any cookie of any kind, first- or third-party;
- write to
localStorage,sessionStorage, IndexedDB or any other client-side store; - collect your name, telephone number, postal address or payment details, or any email address other than one you deliberately submit under section 4.3;
- load fonts, images, scripts or stylesheets from any other domain — everything is served from our own origin, so no other company learns that you visited;
- run advertising, retargeting, session recording, heatmapping, fingerprinting or A/B testing tools;
- request access to your location, camera, microphone, clipboard or any other device sensor. Our
Permissions-Policyheader affirmatively denies these to our own page.
5. Cookies and similar technologies
This site sets no cookies. There is no cookie banner because there is nothing to consent to and nothing to reject. The analytics described in section 4.2 are documented by their supplier as cookie-free.
If that ever changes, we will, before any non-essential cookie or similar technology is set:
- publish an updated version of this policy listing each cookie, its purpose, its provider and its lifetime;
- obtain your prior opt-in consent where the law requires it, through a mechanism that makes refusing at least as easy as accepting;
- continue to set strictly necessary cookies — the narrow category needed to deliver a service you have asked for — without consent, as permitted, and identify them as such.
Nothing in this section is currently in operation.
6. Processing that is not yet active
This section describes processing we anticipate as the company launches. None of it is in effect today. Each item will only begin once the corresponding feature is actually deployed, and this policy will be updated with a new "last updated" date at that point. It is set out in advance so that the policy's scope is honest about the direction of travel rather than being quietly widened later.
6.1 Contact and enquiry forms
If we add a contact form or publish an enquiry address, we would process the identifiers and message content you choose to send — typically name, email address, organisation and the substance of your enquiry — for the purpose of answering you and keeping a record of the correspondence. We would not use an enquiry as a basis for marketing to you without separate consent.
6.2 Recruitment and careers
If we open applications, we would process the information in your application: contact details, curriculum vitae, work history, education, right-to-work or visa status where legally necessary, references, interview notes and the outcome. The purposes would be assessing your suitability, running the hiring process, and meeting employment-law record-keeping obligations.
Unsuccessful applicants' data would be retained for a defined period so that we can consider you for future openings and answer any challenge to the process, and then deleted. Special category data (for example, health information supporting an accommodation, or diversity monitoring data) would be handled separately, on an explicit-consent or employment-law basis, kept apart from the assessment record, and never used as a selection criterion.
6.3 Accounts, products and customer relationships
If we ship a product with accounts, a customer portal, a support desk or telemetry from a deployed robot, each of those would introduce its own processing — authentication credentials, entitlement records, support tickets, and operational or machine data that may or may not relate to an identifiable person. Robotic and sensor data deserves particular care because it can incidentally capture people and premises. Any such processing will be documented in a specific notice or a substantially expanded version of this policy, published before the feature ships.
6.4 Sending to the email list
The list itself is active and is described in section 4.3 — this subsection is only about the part that has not started yet.
We have not sent a single message to it. Doing so requires an email delivery provider, which we have not engaged; when we do, it becomes a processor holding a copy of the list, it will be named in section 8, and that will happen before the first message goes out rather than after. Every message will carry a working one-click unsubscribe from the first one onward. We will not use the list for advertising, and we will not sell, rent or share it.
7. Legal bases for processing
Where the GDPR or a comparable regime applies, we rely on the following bases. Only the first two are currently engaged.
- Legitimate interests — Article 6(1)(f)
- In effect now. Our interest, and yours, in the website being available, being served correctly, and being defended against attack and abuse. This is the basis for the hosting logs in section 4.1, the aggregate measurement in section 4.2, and the truncated network ranges we record when the subscribe endpoint refuses a request. We consider the impact on you minimal: the data is technical, not enriched, not used to make decisions about you, and not combined into a profile. You may object under section 11.1.
- Consent — Article 6(1)(a)
- In effect now. This is the basis for the email list in section 4.3, and the only thing it covers. Consent is given by submitting the field, freely and with no consequence for declining; it is specific to being told about our launch, and is not bundled with anything else. It can be withdrawn at any time, as easily as it was given, by writing to [[ PRIVACY CONTACT EMAIL ]] — without affecting the lawfulness of processing before withdrawal. It will also be the basis for non-essential cookies and any other optional feature we ask you to opt into, none of which exist today.
- Performance of a contract — Article 6(1)(b)
- Not yet engaged. Would apply to accounts, orders, support and the delivery of any product or service you buy from us, and to steps taken at your request before entering a contract.
- Legal obligation — Article 6(1)(c)
- Not yet engaged. Would apply to tax, accounting, employment and product-safety records we are required to keep, and to responding to a lawful and properly-scoped order from a competent authority.
- Vital interests and public task — Article 6(1)(d) and (e)
- We do not anticipate relying on either. They are listed only for completeness.
Under the DPDP Act, processing is generally grounded in consent or in a "legitimate use" defined by that statute. The mapping between the bases above and the DPDP Act's categories requires confirmation by counsel — see the notice at the top of this page.
8. Third parties and processors
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We have never done so and have no plan to.
The following organisations form our current infrastructure:
- Vercel Inc. — hosting, content delivery, analytics
- Serves every page and asset of this site, and supplies the measurement products described in section 4.2. Acts as our processor. Necessarily receives the connection metadata in section 4.1. Its privacy policy is published at vercel.com/legal/privacy-policy and its data processing terms at vercel.com/legal/dpa.
- Upstash, Inc. — database for the email list
- Holds the email list described in section 4.3, and nothing else. Acts as our processor. What it stores on our behalf is ciphertext: the encryption and fingerprinting keys live in Vercel's secret store, not in the database, so Upstash's own staff and infrastructure never hold a readable address. The database is a multi-region replicated deployment whose primary is in the Asia-Pacific region — see section 9. Its privacy policy is published at upstash.com/trust/privacy.pdf and its data processing addendum at upstash.com/trust/dpa.pdf.
- GoDaddy — domain registration
- Registrar of the skandarobotics.com domain. This is a relationship about the domain name, not about you: a registrar does not receive your browsing activity by virtue of that role. Where the domain also uses GoDaddy's nameservers, the DNS lookups that resolve our hostname pass through their infrastructure, as they would through whichever DNS provider a domain uses. Its privacy notice is published at godaddy.com/legal/agreements/privacy-policy.
- three.js — vendored, no data flow
- The home page's 3D scene uses the three.js library, which is MIT-licensed and served from our own origin rather than a CDN. No request is made to the three.js project or to any CDN, so no third party learns of your visit through it. See section 6.2 of our Terms.
We may in future engage further processors — an email provider, a customer support tool, an applicant tracking system, a payment processor. Where we do, we will put a written data processing agreement in place requiring the processor to act only on our documented instructions, to apply appropriate security, to assist us with data subject requests, and to delete or return the data at the end of the engagement. We will update this list.
Separately from processors, we may disclose personal data where we are compelled to by a valid legal process, where it is necessary to establish, exercise or defend a legal claim, or to protect the rights and safety of any person. Where we are lawfully able to notify you of such a demand, we will.
9. International transfers
Our infrastructure providers operate globally, so personal data may be processed in a country other than your own, including the United States. Two categories are involved: the connection metadata described above, and the email list, which is held in a multi-region database whose primary is in the Asia-Pacific region and which replicates between regions to serve requests quickly.
Where such a transfer involves data protected by the GDPR or UK GDPR leaving the EEA or the UK, we rely on a lawful transfer mechanism: an adequacy decision where one covers the destination, or the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), supplemented by a transfer risk assessment and by the technical measures in section 14. Both Vercel's and Upstash's data processing terms incorporate the Standard Contractual Clauses.
It is worth being concrete about what actually crosses a border in the case of the list, because it bears directly on the risk: what replicates is the encrypted form of the address. The keys that would turn it back into an address are held in a separate system, in Vercel's secret store, and are not replicated with it. A demand served on the database operator in any jurisdiction, or an interception of the traffic between regions, reaches ciphertext rather than a mailing list.
Under the DPDP Act, transfers outside India are permitted except to territories the Central Government restricts by notification. We will comply with any such notification as it is issued.
You may request details of the specific safeguards applied to any transfer using the contact details in section 16.
10. How long we keep things
The email list in section 4.3 is the only personal data we hold ourselves, and it has no CRM, no profile and no history attached to it — a stored address is an address and a submission date, nothing more.
- An address on the email list
- Kept until the earliest of three things: you withdraw consent or ask us to delete it, in which case it goes immediately; you unsubscribe from a message once we begin sending them; or 24 months pass from the date you gave it without us having launched. That last limit exists so that an address cannot sit in our database indefinitely on the strength of a consent given for an event that never happened. If we reach it, we delete the list rather than quietly holding it.
- A record that you unsubscribed
- Kept for as long as we run the list. It is the minimum needed — the address, and the fact that it opted out — and it exists for one purpose: so that we do not contact you again by re-importing you from somewhere else. Retaining it is what makes your opt-out durable. You can ask us to delete this too, understanding that it removes the suppression along with it.
- Hosting and analytics records — section 4
- Retained by Vercel under Vercel's own retention schedule, not one we set. Analytics data is aggregated rather than kept as individual event records tied to a person.
Deletion here means deletion: the stored ciphertext is removed outright rather than marked inactive, and because it is the only copy, the address is not recoverable afterwards by us or by anyone who later obtains the database. Backups, if and when we introduce them, will be covered by a stated schedule in this section before they exist.
For any category of personal data we begin holding in future, the principle is that it is kept only as long as it serves the purpose it was collected for, or as long as the law requires it to be kept, whichever is longer, and is then deleted or irreversibly anonymised. Concrete periods will be published here at that time.
11. Your rights
Your rights depend on where you live and which law applies to you.
In practice there is one question we can almost always answer immediately: whether your address is on the email list. If you never submitted it, we hold nothing about you, and a confirmation to that effect is a valid and complete response. If you did, we can tell you what we hold, give you a copy, and delete it — each of those takes us minutes, because there is exactly one record and we keep a tool for reaching it.
11.1 GDPR and UK GDPR
If you are in the EEA, the UK or Switzerland, you have the right to:
- Access
- Obtain confirmation of whether we process your personal data, a copy of it, and information about how and why it is processed.
- Rectification
- Have inaccurate personal data corrected and incomplete data completed.
- Erasure
- Have your personal data deleted where one of the statutory grounds applies — often called the "right to be forgotten".
- Restriction
- Have processing paused rather than deleted, for example while an accuracy dispute is resolved.
- Portability
- Receive personal data you gave us, where processing is based on consent or contract and is automated, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection
- Object to processing based on legitimate interests, on grounds relating to your particular situation. You may object to direct marketing at any time, absolutely and without needing to give a reason.
- Withdrawal of consent
- Withdraw any consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
- Complaint
- Lodge a complaint with a supervisory authority — normally the one in your country of residence, place of work, or where the alleged infringement occurred. You do not need to contact us first, though we would like the chance to put things right.
11.2 California — CCPA and CPRA
If you are a California resident, you have the right to:
- Know what categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third party we disclose to.
- Delete personal information we have collected from you, subject to the statutory exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information, so there is currently nothing to opt out of and no "Do Not Sell or Share My Personal Information" link is required. We honour Global Privacy Control signals as an opt-out for any future processing that would qualify.
- Limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information.
- Non-discrimination — we will never deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We operate no financial incentive programme.
An authorised agent may make a request on your behalf with proof of authorisation. We will verify requests proportionately to the sensitivity of the data involved.
11.3 India — Digital Personal Data Protection Act, 2023
The DPDP Act uses its own vocabulary. If you are a Data Principal — the individual the data relates to — and we are acting as a Data Fiduciary, you have the right to:
- Access information about the personal data we process, a summary of the processing, and the identities of other Data Fiduciaries and processors with whom it has been shared.
- Correction, completion, updating and erasure of your personal data.
- Grievance redressal — a readily available means of raising a complaint with us, which we must answer within the period prescribed by the Act and its rules, before you escalate to the Data Protection Board of India.
- Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
The Act also contemplates a Consent Manager — an entity registered with the Data Protection Board through which you may give, manage, review and withdraw consent from a single accessible point. We are not registered with, and do not operate through, any Consent Manager. Our one consent-based processing activity is the email list, where consent is given by submitting the field and withdrawn by writing to [[ PRIVACY CONTACT EMAIL ]]; we will say here if that ever changes or if a Consent Manager becomes available to you.
The DPDP Act also imposes duties on Data Principals — for example, not to raise false or frivolous grievances — and provides for penalties. The precise application of the Act and its rules to a company of our size and stage, including whether we fall to be classified as a Significant Data Fiduciary, requires confirmation by counsel and is flagged in the notice at the top of this page.
11.4 How to exercise a right
Write to [[ PRIVACY CONTACT EMAIL ]], saying which right you wish to exercise. Please give us enough information to find any records that concern you.
- We will acknowledge promptly and respond substantively within one month, or within the shorter period any applicable law requires. Where a request is genuinely complex we may extend by up to two further months and will tell you why within the first month.
- Exercising a right is free. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if we ever do.
- We may ask you to verify your identity before we act on a request, so that we do not disclose data to the wrong person. We will not use anything you send for verification for any other purpose, and we will delete it afterwards.
12. Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects concerning you, and we do not profile you. Should that change — for example, automated screening in a hiring process — we would tell you before it began, explain the logic involved and the consequences envisaged, and provide the right to obtain human intervention, to express your point of view and to contest the decision.
13. Children's privacy
This site is a corporate information page about industrial robotics. It is not directed at children and is not attractive to children in any commercial sense. The one thing it collects — an email address for launch updates — is of no plausible interest to a child, and we do no tracking, profiling or advertising of any kind, to anyone.
We do not knowingly collect personal data from a child, and we do not attempt to verify age, because doing so would mean demanding more personal data from every visitor than the list itself contains. If you believe an address on our list belongs to a child, tell us and we will delete it without requiring you to prove anything further. Age thresholds differ by jurisdiction, and we apply the highest one that applies to a given individual:
- Under the GDPR, the age of consent for information society services is between 13 and 16 depending on the member state.
- Under the US Children's Online Privacy Protection Act, the threshold is 13.
- Under India's DPDP Act, the threshold is 18. The Act requires verifiable consent from a parent or lawful guardian before processing a child's personal data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children outright. We do none of those things to any visitor.
If you believe a child has provided us with personal data, contact us at [[ PRIVACY CONTACT EMAIL ]] and we will act on it.
14. Security
We would rather describe the measures that actually exist than list generic assurances. As of the date at the top of this page, the site is protected by:
- Encryption in transit. The site is served exclusively over HTTPS with modern TLS. The
upgrade-insecure-requestsdirective rewrites any incidental insecure request. - Encryption at rest, of the one thing we store. Every address on the email list is sealed with AES-256-GCM before it is written, and is held only in that form. Its identifier in the database is a one-way keyed fingerprint rather than the address itself, so duplicate signups can be recognised without a readable address existing anywhere in storage. Three separate keys are used — one to fingerprint, one to encrypt, one to sign the anti-automation token on the form — so that compromising one does not compromise the others. None of them is held in the database; they live in our hosting platform's secret store. The website can add an address to the list but has no ability to read one back: decryption happens only on a company machine, deliberately, by a person holding the key.
- The address is never logged. No email address is written to any log, at any level, in any field, including in error reports. Logs are a second copy with a different retention period and a wider audience, and putting the list into them would quietly undo the encryption described above.
- Abuse resistance on the one write path. The subscribe endpoint is rate limited per address-range and in aggregate, requires a short-lived single-use token issued by us, and rejects submissions completed faster than a person could type. It answers identically whether an address is new or already on the list, so it cannot be used to test whether a particular person subscribed.
- HTTP Strict Transport Security. An
HSTSheader with a one-year max-age andincludeSubDomains, so that after your first visit your browser refuses to talk to us over plain HTTP at all. - A strict Content Security Policy. The policy starts from
default-src 'none'and permits scripts, styles and images only from our own origin. There is no CDN, no third-party tag manager and no remote font to be compromised. The policy ships both as an HTTP header and as a<meta>tag, so it holds even on a host that drops the header. - Clickjacking protection.
frame-ancestors 'none'together withX-Frame-Options: DENY. - Isolation and sniffing defences.
X-Content-Type-Options: nosniff, and Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy both set tosame-origin. - Referrer suppression.
Referrer-Policy: no-referrer. - Capability denial. A
Permissions-Policyheader that switches off camera, microphone, geolocation, USB, payment, display capture and motion sensors for our own page. - Minimisation as architecture. The strongest measure here remains structural: there are no accounts, no cookies and no client-side storage, and the single form on the site asks for one field. We collect an email address and a timestamp because that is what telling you about a launch requires, and we collect nothing else because nothing else is required. Data that is never collected cannot be breached, leaked or misused.
No system is perfectly secure, and we do not claim otherwise. If we ever suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where the law requires, and notify affected individuals without undue delay where the risk is high.
If you believe you have found a security vulnerability in this site, please report it to [[ PRIVACY CONTACT EMAIL ]]. We will not pursue legal action against anyone who reports a genuine issue in good faith, gives us reasonable time to fix it, and does not access or destroy data belonging to others.
15. Changes to this policy
This policy will change as the company grows — that is expected, and section 6 exists so that the direction of change is visible in advance rather than sprung on you.
When we change it, we will update the "last updated" date at the top of this page. Where a change is material — a new category of data, a new purpose, a new recipient, or a change in the legal basis we rely on — we will make that clear rather than relying on the date alone, and where the law requires your consent for the new processing we will ask for it before the change takes effect. Continuing to use the site after a purely clarifying change indicates acceptance of the updated policy.
Previous versions are available on request from [[ PRIVACY CONTACT EMAIL ]].
16. Contact
- Privacy enquiries and data subject requests
- [[ PRIVACY CONTACT EMAIL ]]
- Data protection officer / grievance officer
- [[ DATA PROTECTION OFFICER OR GRIEVANCE OFFICER ]]
- Postal address
- [[ LEGAL ENTITY NAME ]], [[ REGISTERED ADDRESS ]]
- EU / UK Article 27 representative
- [[ EU/UK ARTICLE 27 REPRESENTATIVE ]]
Questions about the website's terms of use rather than privacy are answered in our Terms and Conditions.