Skip to content
OpenRegs

Legal

Privacy

This notice covers this website only. It does not cover the OpenRegs API, the MCP server, or any release you run yourself — those process no personal data of visitors to this site.

Draft — two facts are still missing

The contact address for privacy requests is not final, and the waitlist has no processor named below because none is connected yet (see The Cloud waitlist). Both are filled in before the waitlist starts accepting addresses; until then, treat this page as a complete description of what the site does and an incomplete one of who else is involved.

What this site does not do

  • No analytics. No analytics product is installed, in any form. Nothing counts you.
  • No cookies. The site sets no cookies and uses no local storage, which is why there is no cookie banner: there is nothing to consent to.
  • No third-party requests. Every asset, including the fonts, is served from this origin. Loading a page here contacts nobody else — no font CDN, no tag manager, no embedded media. That is still true of the waitlist page: when you submit the form, your browser talks to this site and to nothing else.
  • No advertising and no profiling. Nothing on this site is shared with an advertising network, and no automated decisions are made about you.

Server logs

The site is hosted on Vercel, which necessarily processes your IP address and the request your browser sends in order to serve the page. Those logs are used to operate and secure the site and for nothing else. We do not copy anything out of them, and nothing in this site's own code records an IP address, a user agent or any identifier.

The Cloud waitlist

The form on the Cloud page is a double opt-in waitlist. It is currently switched off: no store and no mail provider are configured, so the endpoint refuses every submission and answers on screen that it has stored nothing, rather than pretending to succeed. Everything below describes what happens once it is switched on.

What is stored

  • The email address you type, lower-cased so that a later erasure request cannot miss it.
  • Whether it is pending or confirmed, and the times of the signup, of ticking the consent box, and of confirming.
  • The path of the page the form was on — /cloud — so we know which page persuaded people. That is the entire extent of the attribution: no identifier, no referrer, no campaign parameters, no IP address, no user agent.

How the confirmation works

Submitting the form does not put the address on the list. It stores it as unconfirmed and sends one message containing a signed link that expires after 48 hours and works once. Only opening that link and pressing the button confirms the address. If you never do, the unconfirmed record is erased when the link expires and you hear nothing further. Every message we send also carries a permanent link that erases the address.

The legal basis is your consent, given by ticking the box and proven by the confirmation. You may withdraw it at any time, and withdrawing it is the same act as erasure — there is no suppression list left behind.

How long it is kept, and who else sees it

Unconfirmed addresses: 48 hours. Confirmed addresses: until you remove them, or until OpenRegs Cloud has launched and the waitlist has served its purpose, whichever is sooner. The address is used to tell you that Cloud is available and for nothing else — no newsletter, no drip campaign, and it is never sold, shared or handed to an advertising network.

Two processors are involved when the waitlist is switched on: whoever hosts the database the list lives in, and whoever delivers the confirmation message. Neither has been engaged yet, which is why neither is named here, and neither can be named after the fact — telling you where your address went once it has already gone is not a notice, it is an apology.

Your rights

Where the GDPR applies you have the right to access, rectify, erase, restrict and port your personal data, to object to processing, and to complain to your supervisory authority.

For the waitlist, erasure does not need us: open the removal link in any message we sent you, or go to the removal page and ask for a fresh link. Pressing the button deletes the record — it is not flagged, not suppressed and not archived, and a later export cannot show that the address was ever there.

For anything else, requests can be raised as an issue on the OpenRegs GitHub organisation until a dedicated contact address is published here. Do not put your waitlist address in a public issue — use the removal link instead.

Changes

This page changes with the site. Because it is versioned in the site's own repository, every change to it has a commit and a date attached.