Privacy Policy
Controller: Traverse Limited
Website: www.darcked.com
Registered Office: RS
Jurisdiction of Establishment: RS
Privacy Contact: privacy@darcked.com
Document version: 1.0
Effective date: 03 August 2026
Date last revised: 03 August 2026
1. Introduction and Purpose of this Privacy Policy
1.1 The Company is an independent digital publisher of long-form editorial work, including literary criticism, philosophical essays, film criticism and television criticism, digital magazines, digital books and other Digital Publications, made available through the Website by way of open access, Membership, subscription and individual purchase.
1.2 This Privacy Policy explains how the Company collects, uses, discloses, transfers, retains and otherwise processes Personal Data relating to Users, Subscribers, purchasers of Digital Publications, newsletter recipients, correspondents and visitors to the Website, and sets out the rights available to those individuals.
1.3 This Privacy Policy is issued in fulfilment of the transparency obligations arising under Articles 12, 13 and 14 of Regulation (EU) 2016/679 (the “GDPR“), the equivalent provisions of the United Kingdom General Data Protection Regulation as incorporated by the European Union (Withdrawal) Act 2018 and supplemented by the Data Protection Act 2018 (the “UK GDPR“), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (the “CCPA“), and comparable data protection and privacy legislation applicable to the Company’s activities.
1.4 This Privacy Policy forms part of the Company’s contractual and legal framework and must be read together with the Terms of Service, the Subscription and Membership Terms, the Cookie Policy, the Refund Policy, the Editorial Policy, the AI Policy and the Copyright and Intellectual Property Notice. In the event of any inconsistency concerning the processing of Personal Data, this Privacy Policy prevails.
1.5 This Privacy Policy is published in English. Translations, if provided, are supplied for convenience only; the English text governs.
2. Identity of the Controller and Contact Details
2.1 Controller. The Company is the controller in respect of the processing described in this Privacy Policy, except where this Privacy Policy expressly states that a third party acts as an independent controller or as a joint controller.
2.2 Identification and contact details of the Controller:
| Item | Detail |
|---|---|
| Legal entity | Traverse Limited |
| Trading name / brand | DARCKED.COM |
| Registration number | 20767855 |
| VAT / tax identification number | 107171899 |
| Registered office | Nikole Spasica 3/1, 11000 Belgrade, RS |
| Website | www.darcked.com |
| General contact | official@darcked.com |
| Support contact | support@darcked.com |
| Privacy contact | privacy@darcked.com |
2.3 Data Protection Officer. The Company has assessed its processing activities and has determined that it is not required to designate a Data Protection Officer. Enquiries concerning data protection should be addressed to the privacy contact identified above or Traverse Limited, Email: privacy@darcked.com.
2.4 Representative in the European Union. Company is not established in the European Union and the conditions of Article 3(2) GDPR are met, the Company designates the following representative pursuant to Article 27 GDPR: Traverse Limited, Email: privacy@darcked.com.
2.5 Representative in the United Kingdom. Company is not established in the United Kingdom and the conditions of Article 3(2) UK GDPR are met, the Company designates the following representative pursuant to Article 27 UK GDPR: Traverse Limited, Email: privacy@darcked.com.
2.6 Data subjects may contact the Company, the Data Protection Officer (where designated) or the relevant representative in relation to any matter arising under this Privacy Policy or in connection with the exercise of their rights.
3. Scope of this Privacy Policy
3.1 This Privacy Policy applies to the processing of Personal Data in connection with:
(a) the Website and all pages, sections and features forming part of it;
(b) the Services, including Memberships, recurring subscriptions and one-time purchases of Digital Publications;
(c) direct digital downloads of Digital Publications, including PDF and EPUB editions;
(d) the Newsletter and other editorial communications issued by the Company;
(e) correspondence with the Company, including editorial, commercial, support, licensing and rights enquiries;
(f) the Company’s official channels on Instagram, Facebook, X, LinkedIn, YouTube and Pinterest, to the extent set out in Section 20; and
(g) any other activity in which the Company determines the purposes and means of processing.
3.2 This Privacy Policy does not apply to:
(a) the processing of Personal Data by third-party platforms, distributors, retailers or intermediaries acting as independent controllers, including Amazon.com, Inc. and its affiliates in respect of Amazon KDP editions (Section 19), the operators of the social media platforms referred to in Section 20, and payment providers to the extent described in Section 15;
(b) websites, applications or services operated by third parties and accessible from the Website by hyperlink (Section 34); or
(c) information that does not constitute Personal Data, including aggregated, anonymised or statistical information from which no individual can be identified, whether directly or indirectly.
3.3 Where a third party acts as an independent controller, that third party is responsible for its own processing and for providing its own privacy information. Users are advised to consult the privacy notices of those third parties.
4. Definitions
4.1 In this Privacy Policy, the following terms have the meanings set out below. Terms defined in the Terms of Service have the same meaning where used here, unless otherwise stated.
“Account” means the personal registered account through which a User accesses the Services.
“AI-generated Illustrations” means visual material produced with the assistance of artificial intelligence tools and reviewed and approved by a human editor prior to publication.
“Company”, “we”, “us” and “our” mean the legal entity identified in Section 2.
“Digital Publications” means digital books, digital magazines, special editions, downloadable PDF publications, EPUB publications and any other publication issued by the Company in digital form.
“Editorial Content” means articles, essays, critical essays, academic-style criticism, literary criticism, philosophical criticism, film analysis, television analysis, AI-generated Illustrations and any other editorial material published by the Company.
“Membership” means a paid or unpaid access tier granting a User rights of access to Editorial Content, Digital Publications or other Services in accordance with the Subscription and Membership Terms.
“Newsletter” means the periodic editorial communication distributed by electronic mail to recipients who have subscribed to it.
“Personal Data” means any information relating to an identified or identifiable natural person, and includes “personal information” as that term is used in the CCPA and comparable legislation.
“Processing” means any operation performed on Personal Data, whether or not by automated means.
“Processor” means a natural or legal person that processes Personal Data on behalf of and on the documented instructions of the Company, and includes a “service provider” or “contractor” as those terms are used in the CCPA.
“Services” means the services made available by the Company through the Website, including access to Editorial Content, Memberships, subscriptions, purchases and downloads of Digital Publications, and the Newsletter.
“Subscriber” means a User who holds an active subscription or Membership.
“User”, “you” and “your” mean any natural person who accesses or uses the Website or the Services, whether or not registered.
“Website” means the website identified in Section 2 and any subdomain or successor domain operated by the Company.
4.2 References to legislation include that legislation as amended, extended, consolidated or re-enacted from time to time, and any subordinate legislation made under it.
5. Principles Governing the Processing of Personal Data
5.1 The Company processes Personal Data in accordance with the following principles:
(a) Lawfulness, fairness and transparency — Personal Data is processed lawfully, fairly and in a transparent manner in relation to the data subject.
(b) Purpose limitation — Personal Data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes.
(c) Data minimisation — Personal Data is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
(d) Accuracy — Personal Data is kept accurate and, where necessary, up to date, and reasonable steps are taken to erase or rectify inaccurate data without delay.
(e) Storage limitation — Personal Data is kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which it is processed.
(f) Integrity and confidentiality — Personal Data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
(g) Accountability — The Company is responsible for, and is able to demonstrate compliance with, the foregoing principles.
5.2 The Company applies the principles of data protection by design and by default in the development and operation of the Website and the Services, in accordance with Article 25 GDPR.
5.3 The Company does not sell Personal Data, does not share Personal Data for cross-context behavioural advertising, and does not act as a data broker. The Company does not use Personal Data to train artificial intelligence or machine learning models, and does not permit its Processors to do so.
6. Categories of Personal Data Processed
6.1 The Company processes the following categories of Personal Data. Not all categories are processed in relation to every individual; the categories processed depend on the nature of the individual’s interaction with the Company.
6.2 Identity and Account Data
Name or display name; electronic mail address; username; password in hashed and salted form; Account preferences and settings; language preference; date of Account creation; Account status; and communication preferences.
6.3 Membership and Subscription Data
Membership tier; subscription period selected from the periods of one (1), three (3), six (6), nine (9) or twelve (12) months; subscription start date; renewal date; renewal status; cancellation date and cancellation record; entitlement and access records; and records of any suspension, restriction or termination of access.
6.4 Transaction and Payment Data
Records of orders and purchases of Digital Publications; order reference numbers; amounts, currency and applicable taxes; date and time of transaction; payment method type; billing name and billing address; country of residence for tax determination purposes; partial payment card identifiers (such as the last four digits and the card scheme) where transmitted to the Company by a payment provider; payment status; invoices and receipts; refund, chargeback and dispute records.
The Company does not collect, receive or store full payment card numbers, card verification values or comparable payment credentials. Such information is collected directly by the payment providers identified in Section 15 within their own secure environments.
6.5 Content Access and Usage Data
Records of Editorial Content viewed, opened or read; downloads of Digital Publications, including PDF and EPUB editions; download counts and timestamps; reading progress where such a feature is provided; saved items, bookmarks and library entries; and search queries entered on the Website.
6.6 Technical and Device Data
Internet Protocol address; approximate location derived from the Internet Protocol address at country, region or city level; browser type, version and language; operating system and platform; device type and screen characteristics; referring and exit pages; date and time of access; duration of session; clickstream data; server log data; and cookie and similar identifiers, as further described in the Cookie Policy.
6.7 Communications Data
The content of correspondence sent to or received from the Company, including support enquiries, editorial correspondence, submissions, rights and licensing enquiries, complaints, requests for the exercise of data protection rights, and any attachments; the electronic mail address, name and other contact details supplied by the correspondent; and metadata associated with such correspondence.
6.8 Newsletter and Marketing Data
Electronic mail address; name where supplied; date, time and source of subscription; consent record where consent constitutes the legal basis; language and topic preferences; delivery, bounce and unsubscribe status; and, where the newsletter provider makes such measurement available and it is permitted under applicable law, engagement measurements such as whether a message was opened and whether links within it were selected.
6.9 Social Media Data
Publicly available information associated with a User’s social media profile where the User interacts with the Company’s official channels, including username, comments, messages, mentions and reactions, together with the aggregated and pseudonymised page and channel statistics made available to the Company by the relevant platform, as described in Section 20.
6.10 Contributor, Correspondent and Rights-Holder Data
Where an individual submits editorial material, corresponds in a professional capacity, or asserts rights in respect of published material: name; professional affiliation; contact details; the content of the submission or communication; and, where a contractual relationship arises, contractual and, where legally required for payment or tax purposes, financial and fiscal identification data.
6.11 Compliance and Records Data
Records maintained to demonstrate compliance with legal obligations, including consent and consent-withdrawal records; records of requests for the exercise of data protection rights and the Company’s responses; accounting and tax records; records relating to complaints and to intellectual property notices; and records of security incidents.
7. Sources of Personal Data
7.1 The Company obtains Personal Data from the following sources:
(a) Directly from the individual, when the individual creates an Account, purchases a Digital Publication, subscribes to a Membership or to the Newsletter, corresponds with the Company, submits editorial material, or otherwise interacts with the Website or the Services;
(b) Automatically, through cookies, server logs, analytics technologies and similar means, when the individual accesses the Website, as described in Sections 6.6, 13 and 14;
(c) From payment providers, in the form of transaction confirmations, payment status, partial payment instrument identifiers, billing information and dispute records, as described in Section 15;
(d) From social media platforms, in the form of public interactions with the Company’s official channels and aggregated statistical reporting, as described in Section 20;
(e) From third-party distributors and retailers, in the form of aggregated or, where applicable, individual sales and royalty reporting relating to editions distributed through such channels, including Amazon KDP editions, as described in Section 19; and
(f) From publicly available sources, where necessary for editorial, rights-clearance, verification or legal purposes.
7.2 Where the Company obtains Personal Data other than directly from the data subject, it complies with the information obligations set out in Article 14 GDPR and Article 14 UK GDPR, subject to the exemptions provided in those Articles, including the exemption applicable where the provision of information would involve a disproportionate effort.
8. Purposes of Processing and Legal Bases
8.1 The Company processes Personal Data only where a valid legal basis exists. The table below sets out, for each processing purpose, the categories of Personal Data concerned and the legal basis relied upon under Article 6(1) GDPR and Article 6(1) UK GDPR.
| No. | Purpose of processing | Categories of Personal Data | Legal basis |
|---|---|---|---|
| 1 | Creation, authentication, administration and security of the Account | Identity and Account Data; Technical and Device Data | Performance of a contract — Art. 6(1)(b) |
| 2 | Provision of access to Editorial Content and Digital Publications in accordance with the User’s Membership or purchase | Identity and Account Data; Membership and Subscription Data; Content Access and Usage Data | Performance of a contract — Art. 6(1)(b) |
| 3 | Administration of Memberships and recurring subscriptions, including renewal, cancellation and the continuation of access until the end of the paid period | Membership and Subscription Data; Transaction and Payment Data | Performance of a contract — Art. 6(1)(b) |
| 4 | Processing of one-time purchases of Digital Publications and delivery of direct digital downloads | Identity and Account Data; Transaction and Payment Data; Content Access and Usage Data | Performance of a contract — Art. 6(1)(b) |
| 5 | Processing of payments, prevention and investigation of payment fraud, and management of chargebacks and disputes | Transaction and Payment Data; Technical and Device Data | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f); compliance with a legal obligation — Art. 6(1)(c) |
| 6 | Determination, calculation, collection and remittance of value added tax, sales tax and equivalent indirect taxes | Transaction and Payment Data; Technical and Device Data (country determination) | Compliance with a legal obligation — Art. 6(1)(c) |
| 7 | Issue of invoices and receipts and maintenance of accounting records | Identity and Account Data; Transaction and Payment Data | Compliance with a legal obligation — Art. 6(1)(c) |
| 8 | Provision of user support and response to enquiries and complaints | Identity and Account Data; Communications Data; Membership and Subscription Data | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| 9 | Service communications relating to the Account, a Membership, a subscription, a purchase, renewal notices, payment failures and material changes to the Services or to the legal framework | Identity and Account Data; Membership and Subscription Data | Performance of a contract — Art. 6(1)(b); compliance with a legal obligation — Art. 6(1)(c) |
| 10 | Distribution of the Newsletter and other editorial communications to individuals who have subscribed | Newsletter and Marketing Data | Consent — Art. 6(1)(a); or, in respect of existing customers and where permitted under applicable law, legitimate interests — Art. 6(1)(f) |
| 11 | Measurement of Newsletter delivery and engagement | Newsletter and Marketing Data | Consent — Art. 6(1)(a) |
| 12 | Operation, maintenance, performance monitoring, testing and technical improvement of the Website and the Services | Technical and Device Data; Content Access and Usage Data | Legitimate interests — Art. 6(1)(f) |
| 13 | Analytics and measurement of audience and editorial performance | Technical and Device Data; Content Access and Usage Data; cookie identifiers | Consent — Art. 6(1)(a) in respect of the storing of and access to information on the User’s device; legitimate interests — Art. 6(1)(f) in respect of subsequent analysis |
| 14 | Editorial planning and development of the publishing programme on the basis of aggregated readership information | Aggregated Content Access and Usage Data | Legitimate interests — Art. 6(1)(f) |
| 15 | Security of the Website and the Services, prevention and detection of unauthorised access, credential sharing, systematic downloading, scraping and other misuse | Technical and Device Data; Content Access and Usage Data; Membership and Subscription Data | Legitimate interests — Art. 6(1)(f); compliance with a legal obligation — Art. 6(1)(c) |
| 16 | Protection and enforcement of intellectual property rights in Editorial Content and Digital Publications, including the investigation of unauthorised reproduction or distribution | Content Access and Usage Data; Technical and Device Data; Identity and Account Data | Legitimate interests — Art. 6(1)(f) |
| 17 | Establishment, exercise or defence of legal claims, and response to complaints, intellectual property notices and regulatory enquiries | All categories, as relevant | Legitimate interests — Art. 6(1)(f); compliance with a legal obligation — Art. 6(1)(c) |
| 18 | Management of editorial submissions, contributor relationships and rights and licensing matters | Contributor, Correspondent and Rights-Holder Data; Communications Data | Performance of a contract or steps prior to entering into a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| 19 | Administration of the Company’s official social media channels, including moderation of comments and messages | Social Media Data | Legitimate interests — Art. 6(1)(f) |
| 20 | Compliance with data protection obligations, including the handling of data subject requests and the maintenance of records of processing | Compliance and Records Data | Compliance with a legal obligation — Art. 6(1)(c) |
| 21 | Corporate transactions, including any merger, acquisition, reorganisation or transfer of assets | All categories, as relevant | Legitimate interests — Art. 6(1)(f) |
8.2 Where a User declines to provide Personal Data that is necessary for the performance of a contract or for compliance with a legal obligation, the Company may be unable to create an Account, to provide a Membership or a Digital Publication, or to respond to an enquiry. The consequences of not providing Personal Data are indicated at the point of collection where they are not otherwise apparent.
8.3 Where the Company intends to process Personal Data for a purpose other than that for which it was collected, it will, prior to that further processing, assess the compatibility of the new purpose in accordance with Article 6(4) GDPR and, where required, inform the data subject and obtain consent.
9. Legitimate Interests
9.1 Where the Company relies on legitimate interests as the legal basis for processing, it has carried out an assessment balancing those interests against the interests, rights and freedoms of the data subject, taking into account the reasonable expectations of data subjects, the nature of the Personal Data concerned, the context of the processing, and the safeguards applied.
9.2 The legitimate interests pursued by the Company are:
(a) the operation, continuity, security and technical integrity of the Website and the Services;
(b) the prevention and detection of fraud, misuse, unauthorised access and infringement of the Company’s rights;
(c) the protection and enforcement of intellectual property rights subsisting in Editorial Content and Digital Publications;
(d) the maintenance and development of an independent editorial programme informed by aggregated readership information;
(e) the provision of responsive user support and the handling of complaints;
(f) the establishment, exercise and defence of legal claims; and
(g) the sound administration and lawful commercial management of the Company’s publishing business.
9.3 Data subjects have the right to object at any time, on grounds relating to their particular situation, to processing based on legitimate interests, in accordance with Section 29.8. Further information concerning the Company’s legitimate interests assessments is available on request from the privacy contact identified in Section 2.
10. Consent and Withdrawal of Consent
10.1 Where processing is based on consent, that consent is obtained by a clear affirmative act, is freely given, specific, informed and unambiguous, is recorded, and is separate from the acceptance of the Terms of Service.
10.2 Consent may be withdrawn at any time, without detriment and without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. Consent may be withdrawn by:
(a) using the unsubscribe mechanism included in every Newsletter and in every marketing communication;
(b) adjusting communication preferences within the Account;
(c) adjusting cookie preferences by means of the consent management mechanism made available on the Website; or
(d) contacting the Company at the privacy contact identified in Section 2.
10.3 The withdrawal of consent to the Newsletter or to non-essential cookies does not affect a User’s access to Editorial Content or Digital Publications to which the User is entitled, and does not affect the Company’s ability to send service communications that are necessary for the performance of a contract or required by law.
11. Special Categories of Personal Data
11.1 The Company does not seek to collect and does not intentionally process special categories of Personal Data within the meaning of Article 9(1) GDPR and Article 9(1) UK GDPR, namely Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person’s sex life or sexual orientation. Nor does the Company process Personal Data relating to criminal convictions and offences within the meaning of Article 10 GDPR, save where strictly necessary for the establishment, exercise or defence of legal claims.
11.2 Users are requested not to disclose special categories of Personal Data to the Company in correspondence, submissions or Account fields where such disclosure is not necessary. Where such data is disclosed unsolicited, it will be processed only to the extent necessary to respond to the communication and will be deleted as soon as it is no longer required.
11.3 The Company does not draw inferences from Content Access and Usage Data concerning the philosophical, religious or political beliefs of any User. The fact that a User reads Editorial Content concerning a particular subject is not treated by the Company as an indication of that User’s beliefs or opinions.
12. Personal Data Relating to Children
12.1 The Website and the Services are directed to adults and are not intended for children. The Company does not knowingly collect Personal Data from children.
12.2 Accounts, Memberships and purchases of Digital Publications are available only to individuals who have attained the age of eighteen (18) years, or such greater age of majority as applies in their jurisdiction of residence.
12.3 Where processing is based on consent and is offered in relation to information society services, the Company does not knowingly rely on the consent of a child below the age of sixteen (16) years, or such lower age, not below thirteen (13) years, as may be provided by the law of the relevant Member State pursuant to Article 8(1) GDPR. In the United Kingdom, that age is thirteen (13) years.
12.4 In the United States, the Company complies with the Children’s Online Privacy Protection Act and does not knowingly collect Personal Data from children under the age of thirteen (13) years. The Company does not have actual knowledge that it sells or shares the Personal Data of consumers under sixteen (16) years of age, within the meaning of the CCPA.
12.5 Where the Company becomes aware that Personal Data has been collected from a child in circumstances not permitted by applicable law, it will delete that data without undue delay and, where an Account exists, close that Account. A parent or guardian who believes that a child has provided Personal Data to the Company should contact the privacy contact identified in Section 2.
13. Cookies and Similar Technologies
13.1 The Company uses cookies and similar technologies, including local storage, pixels and software development kits, on the Website. Detailed information concerning the categories of cookies used, their purposes, their providers, their duration and the means of managing them is set out in the Cookie Policy, which forms part of this legal framework.
13.2 Cookies are classified as follows:
(a) Strictly necessary cookies, which are required for the operation of the Website, including authentication, session management, load balancing, security and the recording of consent preferences. These cookies are placed on the basis of the Company’s legitimate interests and, in the European Economic Area and the United Kingdom, fall within the exemption provided by Article 5(3) of Directive 2002/58/EC and Regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003. They cannot be disabled through the consent management mechanism.
(b) Functional cookies, which record preferences such as language, display settings and saved items.
(c) Analytics cookies, which measure audience and the use of Editorial Content, as described in Section 14.
(d) Marketing cookies, where used. The Website does not use marketing or advertising cookies and does not permit third-party advertising networks to place cookies on the Website.
13.3 Cookies falling within categories (b), (c) and (d) are placed only where the User has given prior consent by means of the consent management mechanism displayed on first access to the Website. Consent may be adjusted or withdrawn at any time by means of the same mechanism, which remains accessible from the Website.
13.4 Users may also configure their browser to refuse or delete cookies. Refusal of strictly necessary cookies may impair the functioning of the Website, including the ability to sign in to an Account or to access Digital Publications.
14. Analytics
14.1 The Company uses Google Analytics, a web analytics service provided by Google Ireland Limited for Users in the European Economic Area, the United Kingdom and Switzerland, and by Google LLC for Users elsewhere (together, “Google“), in order to understand how the Website and the Editorial Content are used and to improve them.
14.2 Google Analytics processes Technical and Device Data and Content Access and Usage Data, including a truncated Internet Protocol address, pages viewed, session duration, referral source, approximate geographic location and device characteristics.
14.3 The Company applies the following measures in respect of Google Analytics:
(a) analytics cookies and equivalent identifiers are set only after the User has given prior consent, where consent is required under applicable law;
(b) Internet Protocol address truncation or anonymisation is enabled, so that the full Internet Protocol address is not stored;
(c) Google Consent Mode is implemented so that analytics signals are adjusted in accordance with the User’s consent choices;
(d) data sharing with Google for advertising purposes, Google Signals and advertising personalisation features are disabled, and the Company does not use Google Analytics data for advertising;
(e) data retention within Google Analytics is configured to the shortest period consistent with the Company’s analytical requirements, as specified in Annex II; and
(f) a data processing agreement incorporating the European Commission’s Standard Contractual Clauses and, in respect of the United Kingdom, the International Data Transfer Addendum, is in place with Google.
14.4 Google acts as a Processor in respect of the analytics processing described in this Section. Google may, however, act as an independent controller in respect of certain limited processing carried out for the purposes of maintaining and securing its own services. Information concerning Google’s practices is available in Google’s privacy policy and in Google’s business data terms.
14.5 Users may prevent Google Analytics from collecting data by withholding or withdrawing consent by means of the consent management mechanism, or by installing the browser add-on made available by Google for that purpose.
14.6 The Company does not combine Google Analytics data with Identity and Account Data for the purpose of identifying individual Users, and does not use analytics data to make decisions concerning individual Users.
14.7 The Company does not currently use any additional analytics, performance monitoring, error reporting or content delivery services beyond those identified in this Privacy Policy.
15. Payment Processing
15.1 Payments in respect of Memberships, subscriptions and one-time purchases of Digital Publications are processed by the following payment providers:
(a) Stripe — Stripe Payments Europe, Limited and its affiliates;
(b) PayPal — PayPal (Europe) S.à r.l. et Cie, S.C.A. and its affiliates;
(c) Paddle — Paddle.com Market Limited and its affiliates; and
(d) such other payment providers as the Company may engage from time to time, as identified in Annex I.
15.2 Payment credentials are collected directly by the payment provider. Payment card numbers, card verification values, bank account credentials and equivalent payment instruments are transmitted directly to the payment provider through the provider’s own secure environment and are not received, viewed or stored by the Company. Payment providers maintain certification under the Payment Card Industry Data Security Standard.
15.3 The Company receives from the payment provider only the information necessary to fulfil the order, to maintain accounting and tax records and to manage disputes, including the transaction identifier, the amount and currency, the date and time, the payment status, the billing name and address, the country of residence for tax purposes, the payment method type and, where provided, a partial payment instrument identifier.
15.4 Controller status of payment providers. Payment providers act as independent controllers, or as joint controllers with the Company in respect of clearly defined processing operations, in relation to the processing they carry out for their own purposes, including fraud prevention, anti-money laundering, sanctions screening, regulatory reporting and the operation of their payment networks. Such processing is governed by the payment provider’s own privacy notice.
15.5 Merchant of record. Where a payment provider acts as merchant of record in respect of a transaction, that provider is the seller of record for the purposes of that transaction and is responsible for the calculation, collection and remittance of applicable indirect taxes, and processes the purchaser’s Personal Data as a controller for those purposes. Paddle acts as merchant of record where Paddle is used to process a transaction. Stripe and PayPal act solely as payment service providers unless otherwise stated in their applicable terms.
15.6 Users are advised to consult the privacy notices published by the relevant payment providers, which are accessible from those providers’ websites.
16. Memberships and Subscriptions
16.1 The Company operates Memberships and recurring subscriptions with periods of one (1), three (3), six (6), nine (9) and twelve (12) months. Subscriptions renew automatically at the end of each period unless cancelled.
16.2 In order to administer Memberships and subscriptions, the Company processes Identity and Account Data, Membership and Subscription Data and Transaction and Payment Data for the purposes of:
(a) verifying entitlement and granting access to subscription-only Editorial Content and Digital Publications;
(b) initiating renewal at the end of each subscription period and requesting payment through the relevant payment provider;
(c) sending renewal reminders, payment failure notices and expiry notices, where required by applicable consumer protection law or by the Company’s own practice;
(d) recording cancellations and ensuring that access continues until the end of the paid period; and
(e) maintaining records of entitlements, payments and cancellations for accounting, tax and evidential purposes.
16.3 A User may cancel a subscription at any time through the Account settings. Cancellation prevents further renewal; access to the Services continues until the expiry of the period already paid for. Cancellation does not of itself result in the deletion of the Account or of the associated Personal Data. Deletion of the Account may be requested separately in accordance with Section 29.
16.4 Membership system provider. The Company uses membership and subscription management platform, a self-hosted membership and subscription management plugin, operated within the Company’s own hosting infrastructure. Membership and subscription data are processed and stored on the Company’s servers hosted by Hostinger. Membership and subscription management platform is used solely as software installed on the Company’s infrastructure and does not act as an independent data processor in respect of Membership Data, except where strictly necessary for software licensing, updates or technical support. International transfers, if any, are governed by the Company’s hosting arrangements and the applicable safeguards identified elsewhere in this Privacy Policy.
16.5 The Company does not use Membership and Subscription Data, or Content Access and Usage Data, to determine the price offered to any individual User.
17. Newsletters and Editorial Communications
17.1 The Newsletter is distributed only to individuals who have subscribed to it. Subscription is effected by the submission of an electronic mail address together with an affirmative indication of consent.
17.2 Double opt-in. Following submission of an electronic mail address, a confirmation message is sent to that address. The address is added to the distribution list only after the recipient has confirmed the subscription. The Company records the date, time and source of the subscription and of the confirmation.
17.3 Existing customers. Where permitted under Article 13(2) of Directive 2002/58/EC, Regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 or an equivalent provision of applicable law, the Company may send editorial communications concerning its own similar publications to an individual whose electronic mail address was obtained in the course of a sale, provided that the individual was given a clear opportunity to object at the time of collection and is given such an opportunity in each subsequent communication.
17.4 In jurisdictions where an opt-out regime applies, including under the United States CAN-SPAM Act of 2003, the Company includes accurate sender information, a truthful subject line, a valid postal address and a functioning unsubscribe mechanism in every commercial electronic mail message, and gives effect to unsubscribe requests promptly and in any event within the period prescribed by applicable law. In Canada, the Company complies with Canada’s Anti-Spam Legislation.
17.5 Every Newsletter contains a clearly identified unsubscribe link. Unsubscribing takes effect without undue delay. Following unsubscription, the electronic mail address is retained on a suppression list for the sole purpose of ensuring that no further communications are sent, in accordance with Annex II.
17.6 Engagement measurement. Where the Company measures whether a Newsletter has been opened or whether links within it have been selected, such measurement is carried out only with the recipient’s consent where consent is required under applicable law, and the resulting information is used only to assess the effectiveness of editorial communications and to maintain list hygiene. Recipients may configure their electronic mail client to prevent the automatic loading of remote images, which limits such measurement.
17.7 Newsletter provider. [TO BE COMPLETED — identify the newsletter distribution provider, its legal entity, the location of processing, the transfer safeguards applied and the retention configuration.] The newsletter provider acts as a Processor on behalf of the Company under a written data processing agreement complying with Article 28 GDPR.
17.8 Service communications relating to an Account, a Membership, a subscription, a purchase, a renewal, a payment failure or a change to the legal framework are not marketing communications. They are necessary for the performance of the contract or required by law and cannot be declined while the contractual relationship subsists.
18. Digital Publications, Downloads and Protection of Editorial Content
18.1 Where a User downloads a Digital Publication in PDF or EPUB format, the Company records the fact of the download, the Digital Publication concerned, the date and time, the Account associated with the download and the Internet Protocol address from which the download was requested.
18.2 This processing is necessary for the performance of the contract, for the verification of entitlement, for the enforcement of any applicable limits on the number of downloads, and for the protection of the intellectual property rights subsisting in the Digital Publications.
18.3 Identifying marks. Digital Publications supplied to Users may contain a personalised identifying mark linking the copy to the Account through which it was obtained. Such marks are applied for the purpose of deterring and, where necessary, investigating unauthorised reproduction or distribution, on the basis of the Company’s legitimate interests in protecting its intellectual property. The Company does not use such marks for any other purpose and does not disclose them to third parties save where necessary for the establishment, exercise or defence of legal claims.
18.4 The Company monitors for patterns indicative of misuse, including systematic or automated downloading, credential sharing and the circumvention of access controls. Where such patterns are detected, the Company may restrict or suspend access in accordance with the Terms of Service.
19. Third-Party Distribution Channels
19.1 Certain Digital Publications are made available through third-party distribution channels, including Amazon KDP editions distributed by Amazon.com, Inc. and its affiliates.
19.2 Where a Digital Publication is purchased through such a channel, the transaction is concluded between the purchaser and the operator of that channel. The Company is not the controller of the Personal Data collected by that operator and does not receive the purchaser’s name, electronic mail address, payment details or address from that channel. The processing of the purchaser’s Personal Data in connection with such a transaction is governed by the privacy notice of the channel operator.
19.3 The Company receives from such channels only sales, royalty and performance reporting, which is generally aggregated. Where any such reporting includes information relating to identifiable individuals, the Company processes it only for the purposes of accounting, royalty administration, tax compliance and the assessment of the performance of its publishing programme.
19.4 Reviews, ratings and comments published by purchasers on third-party distribution channels are published on those channels and are governed by the terms and privacy notices of the channel operator.
20. Social Media Channels
20.1 The Company maintains official channels on Instagram, Facebook, X, LinkedIn, YouTube and Pinterest for the purpose of publishing editorial announcements and engaging with readers.
20.2 The operators of those platforms determine the purposes and means of the processing carried out on their platforms and act as controllers in respect of that processing, including in respect of the placing of cookies, the tracking of users across services and the profiling of users for advertising purposes. The Company has no control over, and accepts no responsibility for, such processing. Users are advised to consult the privacy notices and settings of the relevant platforms.
20.3 Joint controllership in respect of page statistics. Where a platform provides the Company with aggregated statistical reporting concerning the Company’s channel or page, and where, in accordance with the judgment of the Court of Justice of the European Union in Wirtschaftsakademie Schleswig-Holstein (C-210/16), the Company and the platform operator jointly determine the purposes and means of the underlying processing, the Company and the platform operator act as joint controllers in respect of that processing. The essence of the arrangements between the Company and the relevant platform operator is set out in the joint controller addendum published by that operator. Data subjects may exercise their rights against either joint controller; the platform operator is primarily responsible for providing the information required under Articles 13 and 14 GDPR in respect of such processing and for responding to requests concerning it.
20.4 The Company processes Social Media Data for the purposes of responding to comments, messages and mentions, moderating its channels, and understanding the reach of its editorial publications. The Company does not transfer Social Media Data to its own systems save where necessary to respond to an enquiry.
20.5 The Website does not embed social media plug-ins that transmit data to the platform operator before the User has given consent. Where social media content is embedded, it is embedded by means of a mechanism that requires the User’s prior affirmative action, or by means of an enhanced privacy mode that limits the setting of cookies.
21. Use of Artificial Intelligence
21.1 The Company uses artificial intelligence solely as an editorial tool. Artificial intelligence may assist with research, drafting, editing, translation and the generation of AI-generated Illustrations.
21.2 Every publication is reviewed, edited, verified and approved by a human editor before publication. Artificial intelligence is not the author of any Editorial Content or Digital Publication. Editorial responsibility rests at all times with the Company and its human editors.
21.3 In relation to Personal Data, the Company observes the following commitments:
(a) No training on User data. The Company does not use Personal Data relating to Users, Subscribers, newsletter recipients or correspondents to train, fine-tune or otherwise develop artificial intelligence or machine learning models, whether its own or those of third parties.
(b) Contractual restrictions on providers. Where an artificial intelligence tool is used in the editorial process and that tool is operated by a third party, the Company uses configurations and contractual arrangements that prohibit the provider from using the Company’s inputs and outputs for the training or improvement of the provider’s models, and that provide for the deletion of inputs and outputs within a defined period. Such providers act as Processors under written data processing agreements complying with Article 28 GDPR.
(c) Minimisation of input data. The Company does not input Personal Data relating to Users, Subscribers or correspondents into artificial intelligence tools, save where strictly necessary and where the applicable safeguards are in place. Editorial material submitted to such tools is minimised and, wherever possible, pseudonymised.
(d) AI-generated Illustrations. AI-generated Illustrations are not generated from Personal Data relating to Users. The Company does not use artificial intelligence to generate images depicting identifiable living individuals in a manner that would be misleading, and applies its Editorial Policy to the review and approval of all such material.
(e) Accuracy. Material produced with the assistance of artificial intelligence is verified by a human editor before publication. Where Editorial Content refers to identifiable individuals, the Company takes reasonable steps to verify factual accuracy and to distinguish clearly between factual description and critical interpretation, in accordance with the Editorial Policy.
21.4 The Company does not use artificial intelligence to make decisions concerning individual Users, and does not use artificial intelligence for the purposes of profiling, pricing, credit assessment, content personalisation directed at identified individuals, or the automated evaluation of personal aspects relating to a natural person.
21.5 The Company monitors developments in artificial intelligence governance, including Regulation (EU) 2024/1689 (the Artificial Intelligence Act), and applies transparency measures in respect of artificially generated or manipulated content in accordance with applicable law and with the AI Policy.
21.6 OpenAI. The Company uses OpenAI artificial intelligence services as editorial tools for research assistance, drafting assistance, editing assistance, translation assistance and AI-generated illustrations. To the extent that Personal Data is processed through such services, processing is subject to the safeguards implemented by OpenAI, including applicable Standard Contractual Clauses and other lawful international data transfer mechanisms where required by applicable law.
22. Automated Decision-Making and Profiling
22.1 The Company does not carry out automated decision-making, including profiling, which produces legal effects concerning a data subject or which similarly significantly affects a data subject within the meaning of Article 22 GDPR and Article 22 UK GDPR.
22.2 Certain operations are automated for technical and security purposes, including automated fraud screening performed by payment providers, automated detection of anomalous access patterns, and automated enforcement of download limits. Where an automated measure results in the restriction or suspension of access, the User may request human review by contacting the Company, may express their point of view and may contest the decision, in accordance with the Terms of Service and Section 29.
22.3 The Company does not engage in cross-context behavioural advertising and does not construct advertising profiles of Users.
23. User-Generated Content, Correspondence and Editorial Submissions
23.1 Where a User submits a comment, correspondence, an editorial submission or other material to the Company, the Company processes the Personal Data contained in that material for the purposes of considering, responding to and, where applicable, publishing it.
23.2 Where the Company publishes material submitted by a User, including a name or attribution, it does so only with that User’s knowledge and, where required, consent, and in accordance with the Editorial Policy.
23.3 Users should not include Personal Data relating to third parties in submissions or correspondence unless necessary and unless entitled to do so. Where such data is included, the User warrants that its provision to the Company is lawful.
23.4 Unsolicited editorial submissions are retained in accordance with Annex II and are deleted where the Company does not intend to enter into a contractual relationship with the submitting party, unless retention is necessary for the establishment, exercise or defence of legal claims.
24. Recipients and Disclosure of Personal Data
24.1 The Company discloses Personal Data only where necessary and only to the following categories of recipient:
(a) Processors engaged by the Company to perform services on its behalf, including hosting and infrastructure providers, content delivery networks, the membership and subscription platform, the newsletter distribution provider, the analytics provider, electronic mail delivery providers, customer support tools, backup providers, security services and, where applicable, artificial intelligence tools used in the editorial process. Each Processor is engaged under a written contract complying with Article 28 GDPR and Article 28 UK GDPR, is bound by confidentiality, may process Personal Data only on the Company’s documented instructions, and is subject to appropriate technical and organisational measures. A list of the categories of Processors engaged is set out in Annex I.
(b) Payment providers, in the capacities described in Section 15.
(c) Third-party distribution channels, in the capacities described in Section 19.
(d) Social media platform operators, in the capacities described in Section 20.
(e) Professional advisers, including lawyers, accountants, auditors and insurers, where necessary for the provision of professional services to the Company and subject to obligations of professional confidentiality.
(f) Public authorities, courts, regulators and law enforcement bodies, where disclosure is required by law, by court order or by binding regulatory request. The Company assesses the lawfulness and proportionality of each such request, requires that it be made in the proper legal form, discloses only the minimum information necessary, and, where legally permitted, notifies the affected data subject.
(g) Parties to a corporate transaction, including any prospective purchaser or transferee in connection with a merger, acquisition, reorganisation, insolvency or transfer of all or part of the Company’s business or assets, subject to appropriate confidentiality undertakings and to the continued application of the standards set out in this Privacy Policy.
24.2 The Company does not disclose Personal Data to third parties for those third parties’ own marketing purposes, and does not sell Personal Data.
24.3 Annex I
25. International Transfers of Personal Data
25.1 The Company operates internationally and provides Services to Users worldwide. Personal Data may therefore be transferred to, stored in or accessed from countries other than the country in which the data subject resides, including countries that have not been the subject of an adequacy decision.
25.2 Where Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a third country, the Company ensures that the transfer is made on the basis of one or more of the following mechanisms:
(a) an adequacy decision adopted by the European Commission under Article 45 GDPR, adequacy regulations made by the United Kingdom Secretary of State under the UK GDPR, or a recognition of adequacy issued by the Swiss Federal Council;
(b) the Standard Contractual Clauses adopted by the European Commission by Implementing Decision (EU) 2021/914, together with, in respect of transfers from the United Kingdom, the International Data Transfer Agreement or the International Data Transfer Addendum to the Standard Contractual Clauses issued by the Information Commissioner, and, in respect of transfers from Switzerland, the Standard Contractual Clauses as adapted by the Federal Data Protection and Information Commissioner;
(c) certification of the recipient under the EU–US Data Privacy Framework, the UK Extension to the EU–US Data Privacy Framework or the Swiss–US Data Privacy Framework, where applicable;
(d) binding corporate rules approved by the competent supervisory authority; or
(e) a derogation provided for in Article 49 GDPR, including where the transfer is necessary for the performance of a contract concluded in the interest of the data subject, or where it is necessary for the establishment, exercise or defence of legal claims. Derogations are relied upon only occasionally and only where no other mechanism is available.
25.3 Where the Standard Contractual Clauses are relied upon, the Company carries out a transfer impact assessment in accordance with the recommendations of the European Data Protection Board, taking into account the law and practice of the destination country, and implements supplementary measures where necessary. Such measures may include encryption in transit and at rest, pseudonymisation, access controls, data minimisation and contractual commitments to challenge unlawful requests for disclosure and to publish transparency reporting.
25.4 A copy of the safeguards applied to a particular transfer may be obtained, subject to the redaction of commercially confidential information, by contacting the privacy contact identified in Section 2.
25.5 The Company’s principal Processors process and/or store Personal Data in the European Economic Area, Cyprus, the United Kingdom, the United States and such other jurisdictions as may be required for the provision of their respective services, subject to appropriate safeguards for international data transfers where required by applicable law.
26. Retention of Personal Data
26.1 The Company retains Personal Data only for as long as is necessary for the purposes for which it was collected, including for the purposes of satisfying legal, accounting, tax, regulatory or reporting requirements, and for the establishment, exercise or defence of legal claims.
26.2 In determining the appropriate retention period, the Company considers the nature, sensitivity and volume of the Personal Data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing, whether those purposes may be achieved by other means, and the applicable legal requirements.
26.3 The retention periods applied by the Company are set out in Annex II.
26.4 On expiry of the applicable retention period, Personal Data is deleted or irreversibly anonymised. Anonymised information may be retained and used indefinitely for statistical and editorial planning purposes.
26.5 Personal Data contained in backup systems is deleted in accordance with the Company’s backup rotation cycle. Where deletion from live systems has been effected but a copy remains in a backup, that copy is isolated from active processing until it is overwritten in the ordinary course.
27. Security of Processing
27.1 The Company implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR and Article 32 UK GDPR. Those measures include:
(a) encryption of data in transit by means of Transport Layer Security across the Website and the Services, and encryption of data at rest where appropriate;
(b) storage of Account passwords in hashed and salted form only;
(c) role-based access controls, the principle of least privilege, and multi-factor authentication for administrative access;
(d) network security measures, including firewalls, rate limiting and protection against automated abuse;
(e) segregation of production and non-production environments;
(f) logging and monitoring of access to systems containing Personal Data;
(g) regular backups and tested restoration procedures;
(h) confidentiality undertakings binding all personnel with access to Personal Data, and training in data protection;
(i) due diligence in the selection of Processors and contractual imposition of equivalent security obligations; and
(j) periodic review and testing of the effectiveness of the measures applied.
27.2 Notwithstanding the measures described above, no method of transmission over the internet and no method of electronic storage is entirely secure. The Company cannot guarantee absolute security.
27.3 Users are responsible for maintaining the confidentiality of their Account credentials, for using a unique and sufficiently strong password, and for notifying the Company promptly of any suspected unauthorised access to their Account.
28. Personal Data Breach Notification
28.1 The Company maintains procedures for the detection, investigation, containment, assessment and recording of personal data breaches.
28.2 Where a personal data breach occurs and is likely to result in a risk to the rights and freedoms of natural persons, the Company notifies the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of it, in accordance with Article 33 GDPR.
28.3 Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Company communicates the breach to the affected data subjects without undue delay, in accordance with Article 34 GDPR, unless one of the exemptions in Article 34(3) applies.
28.4 The Company complies with any additional breach notification obligations arising under the law of other jurisdictions, including the notification requirements of United States state data breach notification statutes.
28.5 The Company maintains an internal record of all personal data breaches, including the facts relating to the breach, its effects and the remedial action taken.
29. Rights of Data Subjects under the GDPR and UK GDPR
29.1 Subject to the conditions and exemptions provided by applicable law, data subjects have the following rights.
29.2 Right of access (Article 15). The right to obtain confirmation as to whether Personal Data concerning the data subject is being processed and, where that is the case, access to that data and to the information specified in Article 15(1), together with a copy of the Personal Data undergoing processing.
29.3 Right to rectification (Article 16). The right to obtain the rectification of inaccurate Personal Data and the completion of incomplete Personal Data. Much of the Identity and Account Data may be corrected directly within the Account.
29.4 Right to erasure (Article 17). The right to obtain the erasure of Personal Data where one of the grounds in Article 17(1) applies. This right does not apply where processing is necessary for compliance with a legal obligation, for the establishment, exercise or defence of legal claims, or for exercising the right to freedom of expression and information.
29.5 Right to restriction of processing (Article 18). The right to obtain the restriction of processing in the circumstances specified in Article 18(1), including where the accuracy of the Personal Data is contested or where the data subject has objected to processing pending verification of the Company’s grounds.
29.6 Right to data portability (Article 20). The right to receive Personal Data provided to the Company, in a structured, commonly used and machine-readable format, and to transmit that data to another controller, where processing is based on consent or on a contract and is carried out by automated means.
29.7 Right to object to direct marketing (Article 21(2)). The right to object at any time to the processing of Personal Data for direct marketing purposes, including any associated profiling. This right is absolute; where it is exercised, the Company ceases such processing immediately.
29.8 Right to object to processing based on legitimate interests (Article 21(1)). The right to object at any time, on grounds relating to the data subject’s particular situation, to processing based on Article 6(1)(f). Where such an objection is made, the Company ceases processing unless it demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or unless the processing is required for the establishment, exercise or defence of legal claims.
29.9 Right to withdraw consent (Article 7(3)). The right to withdraw consent at any time, as described in Section 10.
29.10 Rights in relation to automated decision-making (Article 22). The right not to be subject to a decision based solely on automated processing producing legal effects or similarly significantly affecting the data subject, as described in Section 22.
29.11 Right to lodge a complaint (Article 77). The right to lodge a complaint with a supervisory authority, as described in Section 36.
29.12 How to exercise these rights. Requests may be submitted to the privacy contact identified in Section 2. To protect the rights of data subjects, the Company may request information reasonably necessary to verify the identity of the requesting party. Such verification information is used solely for that purpose and is deleted once verification is complete.
29.13 Response times. The Company responds to requests without undue delay and in any event within one (1) month of receipt. That period may be extended by two (2) further months where necessary, taking into account the complexity and number of requests, in which case the Company informs the data subject of the extension and of the reasons for it within one (1) month of receipt of the request.
29.14 Fees. Requests are dealt with free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may charge a reasonable fee reflecting administrative costs or refuse to act, in each case giving reasons.
29.15 Authorised agents. A request may be made by an authorised agent, provided that the agent supplies written authorisation signed by the data subject, and provided that the Company is able to verify the identity of the data subject.
30. Additional Information for Residents of California
30.1 This Section applies to residents of the State of California and supplements the remainder of this Privacy Policy. Terms used in this Section have the meanings given to them in the CCPA.
30.2 Categories of personal information collected in the preceding twelve months. The Company has collected the following categories of personal information, as enumerated in Cal. Civ. Code § 1798.140(v):
| Statutory category | Collected | Examples | Source | Business or commercial purpose | Disclosed for a business purpose to |
|---|---|---|---|---|---|
| Identifiers | Yes | Name, electronic mail address, username, Internet Protocol address, unique online identifiers, Account identifier | Consumer; automatic collection | Provision of the Services; Account administration; support; security; communications | Hosting and infrastructure providers; membership system provider; newsletter provider; analytics provider; payment providers; professional advisers |
| Customer records information (Cal. Civ. Code § 1798.80(e)) | Yes | Name, billing address, payment method type, partial payment instrument identifier | Consumer; payment providers | Order fulfilment; accounting; tax compliance; dispute management | Payment providers; accounting and professional advisers |
| Commercial information | Yes | Records of Digital Publications purchased or downloaded; Membership and subscription records; consideration paid | Consumer; automatic collection; payment providers | Provision of the Services; entitlement verification; accounting; editorial planning | Hosting and infrastructure providers; membership system provider; payment providers |
| Internet or other electronic network activity information | Yes | Browsing history on the Website; interaction with Editorial Content; search queries; interaction with the Newsletter | Automatic collection | Operation and improvement of the Website; audience measurement; security | Hosting and infrastructure providers; analytics provider; newsletter provider |
| Geolocation data (approximate only) | Yes | Country, region or city derived from the Internet Protocol address | Automatic collection | Tax determination; security; audience measurement; content availability | Hosting and infrastructure providers; analytics provider; payment providers |
| Audio, electronic, visual or similar information | Yes, where submitted | Content of correspondence and submissions | Consumer | Response to enquiries; editorial administration | Support and electronic mail providers |
| Professional or employment-related information | Yes, where submitted | Professional affiliation of contributors and correspondents | Consumer | Editorial and contractual administration | Professional advisers; accounting providers |
| Inferences drawn from the above | Limited | Aggregated editorial and audience insights | Derived | Editorial planning | None |
| Sensitive personal information | Limited — see § 30.4 | Account log-in in combination with a password or credential permitting access to the Account | Consumer | Authentication and Account security only | Hosting and infrastructure providers |
| Biometric information; genetic data; precise geolocation; racial or ethnic origin; religious or philosophical beliefs; union membership; contents of mail, electronic mail or text messages not directed to the Company; health, sex life or sexual orientation information | No | — | — | — | — |
| Education information | No | — | — | — | — |
30.3 No sale and no sharing of personal information. The Company does not sell personal information and does not share personal information for cross-context behavioural advertising, within the meaning of the CCPA. The Company has not sold or shared personal information in the preceding twelve (12) months, and does not sell or share the personal information of consumers under sixteen (16) years of age. The Company does not offer any financial incentive in exchange for the retention or sale of personal information.
30.4 Sensitive personal information. The only category of sensitive personal information processed by the Company is an Account log-in in combination with a password or credential permitting access to the Account. That information is used solely for the purpose of authenticating the User and securing the Account. The Company does not use or disclose sensitive personal information for purposes other than those permitted by Cal. Civ. Code § 1798.121(a) and the regulations made under it, and does not use it to infer characteristics about any consumer. Accordingly, the right to limit the use and disclosure of sensitive personal information does not give rise to any limitation that the Company is not already applying.
30.5 Retention. The Company retains each category of personal information for the periods set out in Annex II, and does not retain personal information for longer than is reasonably necessary for the disclosed purposes.
30.6 Rights of California residents. Subject to verification and to the exceptions provided by law, California residents have the following rights:
(a) Right to know. To request disclosure of the categories and specific pieces of personal information collected; the categories of sources; the business or commercial purposes for collection; the categories of third parties to whom personal information is disclosed; and the categories disclosed for a business purpose.
(b) Right to delete. To request the deletion of personal information collected from the consumer, subject to the exceptions in Cal. Civ. Code § 1798.105(d), including where retention is necessary to complete a transaction, to comply with a legal obligation, to detect security incidents, or to exercise free speech or ensure the right of another consumer to exercise free speech.
(c) Right to correct. To request the correction of inaccurate personal information.
(d) Right to opt out of sale or sharing. As the Company neither sells nor shares personal information, no “Do Not Sell or Share My Personal Information” mechanism is required. The Company nevertheless gives effect to opt-out preference signals as described in Section 33.
(e) Right to limit the use and disclosure of sensitive personal information, as described in Section 30.4.
(f) Right to non-discrimination. The Company does not discriminate against consumers who exercise their rights, including by denying goods or services, charging different prices, providing a different level or quality of service, or suggesting that any of these will occur.
(g) Right to appeal. Although the Company is not legally required to provide a separate appeal procedure under the California Consumer Privacy Act or other United States state privacy laws, the Company voluntarily accepts requests for review where a data subject believes that a privacy rights request has been incorrectly refused. Such requests may be submitted to the Company’s privacy contact identified in this Privacy Policy. The Company will review the request in good faith and respond within a reasonable period.
30.7 How to exercise these rights. Requests may be submitted to the privacy contact identified in Section 2. The Company will acknowledge receipt within ten (10) business days and will respond within forty-five (45) calendar days, subject to one extension of a further forty-five (45) days where reasonably necessary, of which the consumer will be notified.
30.8 Verification. The Company verifies the identity of the requesting party to a reasonable degree of certainty by matching identifying information supplied in the request against information held in the Company’s records. Where a request concerns specific pieces of personal information, a higher standard of verification is applied.
30.9 Authorised agents. An authorised agent may submit a request on behalf of a California resident where the agent provides written permission signed by the consumer, and where the consumer verifies their own identity directly with the Company and confirms that the agent is authorised to act on their behalf.
30.10 Shine the Light. California Civil Code § 1798.83 permits California residents to request information concerning the disclosure of personal information to third parties for those third parties’ direct marketing purposes. The Company does not make such disclosures.
31. Additional Information for Residents of Other United States Jurisdictions
31.1 This Section applies to residents of United States states that have enacted comprehensive consumer privacy legislation, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, and to residents of any other state whose legislation subsequently takes effect, in each case to the extent that such legislation applies to the Company.
31.2 Subject to verification and to the exceptions provided by the applicable statute, residents of those states have the right to:
(a) confirm whether the Company processes their personal data and to access that data;
(b) obtain a copy of their personal data in a portable and, to the extent technically feasible, readily usable format;
(c) correct inaccuracies in their personal data;
(d) delete personal data provided by or obtained about them;
(e) opt out of the processing of personal data for the purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects; and
(f) where applicable, opt in to the processing of sensitive data.
31.3 The Company does not engage in targeted advertising, does not sell personal data and does not carry out profiling in furtherance of decisions producing legal or similarly significant effects. The rights described in paragraph 31.2(e) therefore do not give rise to any processing from which a consumer needs to opt out.
31.4 Appeals. Where a request is refused, the requesting party may appeal that decision by contacting the privacy contact identified in Section 2 and stating that the communication constitutes an appeal. The Company will inform the requesting party in writing of the outcome of the appeal, together with a written explanation of the reasons, within sixty (60) days of receipt, or such shorter period as the applicable statute requires. Where an appeal is denied, the requesting party will be provided with a means of contacting the Attorney General of the relevant state to submit a complaint.
31.5 Nevada. Residents of Nevada may submit a request that the Company not sell certain covered information, as defined in Nevada Revised Statutes Chapter 603A. The Company does not engage in such sales.
31.6 Washington and Nevada health data. The Company does not collect consumer health data within the meaning of the Washington My Health My Data Act or Nevada Senate Bill 370.
32. Additional Information for Other Jurisdictions
32.1 Switzerland. The Company processes Personal Data relating to individuals in Switzerland in accordance with the Federal Act on Data Protection. Data subjects in Switzerland have rights of access, rectification, erasure, objection and data portability, and may lodge a complaint with the Federal Data Protection and Information Commissioner.
32.2 Canada. The Company processes personal information relating to individuals in Canada in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation. Individuals have the right to access and to request correction of their personal information and may complain to the Office of the Privacy Commissioner of Canada. The Company complies with Canada’s Anti-Spam Legislation in respect of commercial electronic messages.
32.3 Brazil. The Company processes Personal Data relating to individuals in Brazil in accordance with Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018). Data subjects have the rights of confirmation, access, correction, anonymisation, blocking or deletion, portability, information as to sharing, information concerning the consequences of refusing consent, and revocation of consent, and may petition the Autoridade Nacional de Proteção de Dados.
32.4 Australia. The Company processes personal information relating to individuals in Australia in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Individuals may complain to the Office of the Australian Information Commissioner.
32.5 Japan. The Company processes personal information relating to individuals in Japan in accordance with the Act on the Protection of Personal Information.
32.6 South Africa. The Company processes Personal Data relating to individuals in South Africa in accordance with the Protection of Personal Information Act, 2013. Data subjects may complain to the Information Regulator.
32.7 Other jurisdictions. Where the Company provides Services to Users in other jurisdictions, it complies with applicable local data protection and electronic communications law. Where local law confers rights more extensive than those set out in this Privacy Policy, those rights apply.
33. Do Not Track and Opt-Out Preference Signals
33.1 There is at present no uniform industry or legal standard for responding to “Do Not Track” browser signals. The Website does not respond to Do Not Track signals.
33.2 The Website does recognise and give effect to opt-out preference signals transmitted by a browser or extension in a manner that complies with applicable law, including the Global Privacy Control. Where such a signal is received, the Company treats it as a valid request to opt out of the sale and sharing of personal information and of targeted advertising, notwithstanding that the Company does not engage in such activities, and, where technically feasible, applies it to the setting of non-essential cookies.
34. Third-Party Websites and Services
34.1 Editorial Content may contain hyperlinks to websites, publications, archives, databases and services operated by third parties. Such links are provided for editorial and reference purposes.
34.2 The Company does not control and is not responsible for the content, privacy practices or security of third-party websites or services. The inclusion of a hyperlink does not constitute an endorsement. Users are advised to consult the privacy notice of any third-party website before providing Personal Data to it.
35. Changes to this Privacy Policy
35.1 The Company may amend this Privacy Policy from time to time in order to reflect changes to the Services, to the Company’s processing activities, to the Processors engaged, or to applicable law or regulatory guidance.
35.2 The version number, the effective date and the date of the most recent revision are stated at the head of this document. Superseded versions are archived and made available on request.
35.3 Where an amendment is material — in particular where it introduces a new purpose of processing, a new category of recipient, a new category of Personal Data, or a change to the legal basis relied upon — the Company will provide notice to registered Users by electronic mail or by a prominent notice on the Website in advance of the amendment taking effect, and, where the amendment requires consent, will obtain that consent before implementing it.
35.4 Continued use of the Website or the Services following the effective date of an amendment constitutes acknowledgement of the amended Privacy Policy, save in respect of any processing for which consent is required.
36. Complaints and Supervisory Authorities
36.1 The Company invites data subjects to raise any concern regarding the processing of their Personal Data with the Company in the first instance, by contacting the privacy contact identified in Section 2. The Company will investigate and respond without undue delay.
36.2 Data subjects nevertheless have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.
36.3 Lead supervisory authority. The Company is not established in the European Union. Data subjects residing in the European Union may lodge a complaint with the supervisory authority of the Member State in which they habitually reside, work, or where the alleged infringement occurred, without prejudice to any other administrative or judicial remedy.
36.4 United Kingdom. Data subjects in the United Kingdom may lodge a complaint with the Information Commissioner’s Office.
36.5 The exercise of the right to lodge a complaint is without prejudice to any other administrative or judicial remedy, including the right to an effective judicial remedy against a controller or processor under Article 79 GDPR and the right to compensation under Article 82 GDPR.
37. Contact
37.1 Enquiries, requests and complaints concerning this Privacy Policy or the processing of Personal Data by the Company should be addressed as follows:
| Purpose | Contact |
|---|---|
| Data protection and privacy matters | privacy@darcked.com |
| Exercise of data subject rights | privacy@darcked.com |
| User support | support@darcked.com |
| General correspondence | official@darcked.com |
| Postal correspondence | official@darcked.com |
| Data Protection Officer, where designated | privacy@darcked.com |
| Representative in the European Union, where designated | privacy@darcked.com |
| Representative in the United Kingdom, where designated | privacy@darcked.com |
37.2 In order to enable the Company to respond efficiently, correspondence should identify the right or matter concerned and provide sufficient information to enable the Company to locate the relevant records.
ANNEX I — Categories of Recipients and Processors
The following table identifies the categories of Processors and other recipients engaged by the Company, the purpose of the engagement and the location of processing. The Company reviews and updates this Annex as its arrangements change.
| Category | Provider | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| Hosting and infrastructure | Hostinger International Ltd. | Operation of the Website and storage of data | Cyprus / EEA (depending on selected data center) | EU Standard Contractual Clauses (SCCs); UK International Data Transfer Addendum, where applicable |
| Content delivery network | Hostinger International Ltd. (where CDN services are provided as part of the hosting infrastructure) | Delivery of Editorial Content and Digital Publications; security | Cyprus / EEA (depending on the selected data centre) | EU Standard Contractual Clauses (SCCs); UK International Data Transfer Addendum, where applicable |
| Membership and subscription system | Repute Infosystems Pvt. Ltd. | Administration of Memberships, subscriptions and entitlements | Not applicable / [TO BE COMPLETED] | Membership functionality is provided through the Repute Infosystems Pvt. Ltd. operating within the Company’s self-hosted CMS installation. Membership data is stored within the Company’s hosting environment and is not processed by Repute Infosystems Pvt. Ltd. as an independent data processor, except where strictly necessary for licensing, updates or technical support. |
| Payment provider | Stripe | Payment processing | European Economic Area; United States | Standard Contractual Clauses; UK Addendum; Data Privacy Framework, where applicable |
| Payment provider | PayPal | Payment processing | European Economic Area; United States | Standard Contractual Clauses; UK Addendum |
| Payment provider | Paddle | Payment processing; merchant of record where applicable | United Kingdom; European Economic Area; United States | Standard Contractual Clauses; UK Addendum |
| Additional payment providers | N/A | Payment processing | N/A | N/A |
| Analytics | Google Analytics (Google Ireland Limited / Google LLC) | Audience measurement | European Economic Area; United States | Standard Contractual Clauses; UK Addendum; EU–US Data Privacy Framework |
| Newsletter distribution | Hostinger Reach (Hostinger International Ltd.) | Distribution and administration of the Newsletter | European Union, United Kingdom and other jurisdictions as necessary for the provision of the service | EU Standard Contractual Clauses (SCCs); UK International Data Transfer Addendum, where applicable |
| Transactional electronic mail | [TO BE COMPLETED] | Delivery of service communications | [TO BE COMPLETED] | [TO BE COMPLETED] |
| User support platform | Hostinger International Ltd. | Management of enquiries and support correspondence | European Economic Area (depending on selected data center) | EU Standard Contractual Clauses (where applicable); UK International Data Transfer Addendum |
| Artificial intelligence tools used in the editorial process | OpenAI, (DALL-E) | Editorial research, drafting assistance, editing assistance, translation assistance and AI-generated illustrations | United States (and other locations as described in OpenAI’s documentation) | Standard Contractual Clauses (where applicable); EU–US Data Privacy Framework (where applicable) |
| Backup and disaster recovery | Hostinger International Ltd. | Continuity and restoration | Cyprus / EEA (depending on selected data center) | EU Standard Contractual Clauses (SCCs); UK International Data Transfer Addendum, where applicable |
| Professional advisers | Traverse Limited, Legal Department | Legal, accounting, audit and insurance services | [TO BE COMPLETED] | Not applicable / [TO BE COMPLETED] |
| Third-party distribution channels | Amazon.com, Inc. and affiliates (Amazon KDP) | Distribution of Amazon KDP editions — independent controller | United States; European Economic Area; other jurisdictions in which Amazon operates | Not applicable — independent controller |
| Social media platforms | Meta Platforms; X Corp.; LinkedIn Corporation; Google LLC (YouTube); Pinterest, Inc. | Operation of official channels — independent or joint controllers | United States; European Economic Area; other jurisdictions in which the respective platform operates | Not applicable — independent or joint controllers |
ANNEX II — Retention Schedule
| Category of Personal Data | Retention period | Basis for the period |
|---|---|---|
| Identity and Account Data (active Account) | For the duration of the Account | Necessary for the performance of the contract |
| Identity and Account Data (following closure or deletion of the Account) | Deleted or anonymised within thirty (30) days of closure, save where retention is required under another entry in this Annex | Storage limitation |
| Membership and Subscription Data | For the duration of the Membership and thereafter for the limitation period applicable to claims arising from the contract — Three (3) years following termination of the Membership or Subscription, unless a longer retention period is required by applicable law or necessary for the establishment, exercise or defence of legal claims. | Establishment, exercise or defence of legal claims |
| Transaction and Payment Data; invoices; accounting records | The statutory accounting and tax retention period applicable in the Company’s jurisdiction, ordinarily between ten (10) and twenty (20) years. | Compliance with a legal obligation |
| Records of refunds, chargebacks and payment disputes | Records relating to refunds, chargebacks and payment disputes are retained for the period required by applicable law and, where necessary, for the establishment, exercise or defence of legal claims. | Compliance with a legal obligation; defence of legal claims |
| Content Access and Usage Data linked to an Account | Twenty-four (24) months from the date of the relevant activity, after which the data is anonymised | Legitimate interests; storage limitation |
| Records of downloads of Digital Publications | For the duration of the Account and for twelve (12) months thereafter, or for such longer period as is necessary to investigate suspected infringement | Legitimate interests in the protection of intellectual property |
| Technical and Device Data; server logs | Twelve (12) months, or such shorter period as is consistent with security requirements; security incident logs may be retained for twenty-four (24) months | Legitimate interests in security |
| Analytics data held within Google Analytics | Fourteen (14) months, or such shorter period as the Company configures — [TO BE COMPLETED to confirm the configured period] | Storage limitation |
| Cookie consent records | Twelve (12) months from the date on which consent was given or last confirmed, or such shorter period as applicable guidance requires; the record of consent is retained for the duration of the applicable limitation period | Accountability |
| Newsletter and Marketing Data (active subscription) | Until unsubscription or until the recipient has been inactive for a continuous period of twenty-four (24) months, after which the record is deleted | Consent; storage limitation |
| Newsletter suppression list | Retained indefinitely, in minimised form, for the sole purpose of preventing further communications | Compliance with the withdrawal of consent |
| Communications Data (support and general correspondence) | Twenty-four (24) months from the closure of the matter, unless retention is necessary for the establishment, exercise or defence of legal claims | Legitimate interests; storage limitation |
| Unsolicited editorial submissions | Six (6) months from the date of receipt, unless a contractual relationship is entered into | Storage limitation |
| Contributor, Correspondent and Rights-Holder Data (contractual) | For the duration of the contract and thereafter for the applicable limitation period and any applicable accounting retention period | Performance of a contract; legal obligation |
| Records of data subject requests and responses | Three (3) years from the date of the response | Accountability |
| Personal data breach records | Five (5) years from the date of the incident | Accountability |
| Records relating to intellectual property notices, complaints and legal claims | For the duration of the matter and thereafter for the applicable limitation period | Establishment, exercise or defence of legal claims |
| Backups | Backups are retained in accordance with the Company’s backup retention policy and securely deleted or overwritten in accordance with the Company’s data retention practices – ordinarily between thirty (30) and ninety (90) days. | Continuity; storage limitation |
Where a retention period stated in this Annex is exceeded by a mandatory statutory retention requirement applicable to the Company, the statutory requirement prevails.
End of Privacy Policy.
