Who this policy applies to
This policy describes the personal data collected by CA Info, an independent consumer-warning website that publishes bankroll and session coaching for adults. The policy is written to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations (PECR). The controller of any personal data collected via this site is the site's owner, contactable at the email address on the contact page.
What we collect
The site is a static publication with no user accounts, no forms, no comments and no on-site log-in. In practice this means we collect almost no personal data. What we do collect:
- Standard web-server access logs (IP address, request path, user-agent string, timestamp) retained for a limited period for security and abuse-mitigation purposes.
- Email correspondence you initiate with us via the address on the contact page, stored on the underlying mail-provider infrastructure.
We do not use third-party advertising trackers, retargeting pixels, session-recording tools, heatmap services, or fingerprinting scripts. We do not sell data. We do not share access logs with any external party except where required by law.
Cookies
The site does not set any first-party analytics or marketing cookies. It may set functional cookies strictly necessary to serve pages (for example, a load-balancer session cookie on the underlying hosting infrastructure). A more detailed breakdown is on the cookies page. If, in the future, we add anything that changes this, we will update both the cookies page and this privacy notice with a dated change entry.
Lawful basis
Our lawful basis for the limited processing described above is legitimate interests under Article 6(1)(f) UK GDPR — specifically the operator's interest in running a secure, functioning website and responding to inbound correspondence from readers. Where you contact us directly, we also rely on your consent under Article 6(1)(a) in respect of any data included in the message itself.
Retention
Web-server access logs are retained for no longer than 90 days from the date of the request, unless a longer retention is required to investigate a specific security incident. Email correspondence is retained for as long as the exchange is active plus a reasonable follow-up window; older correspondence is deleted on an annual review cycle.
Your rights
Under UK GDPR you have the right to access the personal data we hold about you, to request rectification of inaccuracies, to request erasure where the lawful basis for holding the data no longer applies, to object to processing based on legitimate interests, and to lodge a complaint with the Information Commissioner's Office (ICO). To exercise any of these rights, please write to the email address on the contact page with enough information for us to identify the record you are asking about.
International transfers and hosting
The site's hosting infrastructure and email provider may be based inside or outside the UK. Where personal data is transferred outside the UK, we rely on the mechanisms recognised under UK GDPR — adequacy decisions, standard contractual clauses, or equivalent safeguards — to protect that data.
Security
The site is served over HTTPS with modern TLS. The underlying host and mail provider are subject to their own security controls, including at-rest encryption of stored logs and messages. We do not process card payments, we do not hold account balances, and we do not maintain a user database, so the surface for a personal-data breach is materially smaller than at a commercial site. No security posture is perfect; if you become aware of a specific vulnerability affecting reader data, please report it via the email address on the contact page and we will investigate promptly.
Data from persons under 18
CA Info is not directed at anyone under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe a minor has sent us personal data — for example, in an email — please contact us and we will delete it on receipt.
Changes to this policy
We update this policy when material changes are made to the site's data practices. The "last updated" date at the top of this page reflects the most recent change; smaller wording updates that do not change the substance of the policy may be made without a dated entry. If a change materially expands what we collect or how we process it, we will flag the change with a summary at the top of this page for a reasonable period after publication.