Last updated: 17 August 2026
We collect the least we can, keep it for the shortest time that is useful, and protect it while we hold it. This page sets out how that works in practice. The Privacy Policy describes what we collect; this page describes the rules we apply to it.
Information is encrypted in transit. Access is limited to people who need it to run the service or investigate misuse, and that access is logged. Our suppliers are bound by contract to the same standards. No system is perfectly secure, and we will not claim otherwise; if a breach affects you we will tell you and notify the regulator where required.
Set out in the Privacy Policy. In short: account data while the account exists, warnings only while they are useful, misuse reports for as long as needed to act and to handle appeals, technical logs briefly.
Some of our providers operate in other countries. Where information is transferred, we use recognised safeguards so it stays protected to the same standard.
You can ask us to:
We will respond within one month. There is no charge unless a request is excessive, and we will explain if we cannot do what you have asked.
If you are unhappy with how we have handled your information, tell us first and we will try to put it right. You also have the right to complain to your national data protection authority. In the United Kingdom that is the Information Commissioner’s Office.
For any data protection request or question, use the contact page and mark it for data protection.