Privacy and Cookies Policy
Effective date: 27 July 2026
1. Who is responsible
Tobias Ellwood is the controller of personal data collected through this website. This notice applies to tobiasellwood.org and the connected publication at newsletter.tobiasellwood.org.
For privacy questions or to exercise your rights, email [email protected].
2. Personal data, purposes and lawful bases
- Contact enquiries: your name, email address, message and related correspondence. We use these details to respond to you and manage the enquiry. The lawful basis is our legitimate interest in communicating with people who contact us; where your enquiry concerns possible services, the basis may also be steps taken at your request before a contract.
- Newsletter subscriptions: your email address and membership preferences, plus delivery and engagement events such as whether an email was delivered, opened, clicked or unsubscribed. We use these details to send the updates you request, operate the mailing list and understand aggregate performance. The lawful basis for sending newsletters is your consent. Where limited engagement statistics qualify for the statistical-purpose exception under UK law, our lawful basis for the related personal-data processing is legitimate interests. You can withdraw consent, unsubscribe or object to statistical tracking at any time.
- Security and delivery data: IP address, browser and device information, request time, and a Cloudflare Turnstile verification token when you use the contact form. We use this information to prevent spam, abuse and attacks and to operate the site securely. The lawful basis is our legitimate interest in protecting the website and its users.
- Storage preferences: when you dismiss the storage notice, the site stores that preference in your browser so it does not show the notice repeatedly.
Please do not include sensitive personal information in a general contact message unless it is necessary for your enquiry. We do not use website data for solely automated decisions or profiling that produces legal or similarly significant effects.
3. Service providers and recipients
We do not sell personal data. We disclose it only where needed to operate the site, respond to you, comply with law or protect legal rights. Providers that may process data on our behalf include:
- Mailgun, which relays contact-form email;
- Cloudflare, which provides Turnstile abuse protection;
- Ghost, which manages newsletter members and email subscriptions;
- jsDelivr, which delivers the official Ghost signup software;
- our website hosting and email providers; and
- professional advisers, regulators or public authorities where disclosure is legally required.
4. International transfers
The website's primary application server is located in the European Economic Area (EEA).
Some providers may process personal data outside the United Kingdom or European Economic Area. Where data protection law requires safeguards, transfers are made under an adequacy regulation or decision, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, as applicable. Contact us if you would like information about the safeguard used for a particular transfer.
5. How long we keep data
- Contact enquiries and correspondence are kept while we handle the enquiry and afterwards only for as long as reasonably needed for follow-up, record-keeping or legal claims. We review retained correspondence and delete it when it is no longer needed.
- Newsletter membership data is kept until you unsubscribe or ask us to delete it. We may retain the minimum information needed to record an opt-out and honour it.
- Individual newsletter delivery and engagement events are kept only as long as needed to operate and improve the publication, then deleted or aggregated.
- The application keeps an IP-based rate-limit record in memory for about 10 minutes and an email-based, one-way hashed rate-limit record for about one hour.
- The notice-dismissal preference remains in your browser until you clear this site's stored data.
Providers may retain limited security, delivery and backup data under their own documented retention schedules.
6. Cookies, browser storage and embedded content
We do not currently use advertising or audience-measurement cookies on the main website. We use browser storage only to remember that you dismissed the storage notice. The contact page loads Cloudflare Turnstile, a security service that may process technical data or use storage that is necessary to detect abuse.
Some pages display content hosted by third parties, including Flourish visualisations and media embedded in published Ghost posts. When you load embedded content, its provider receives technical information such as your IP address and may use cookies or similar technologies under its own policy. You can block third-party cookies or clear stored data using your browser settings, although this may prevent embedded content from working.
7. Your rights
Depending on the circumstances and the law that applies, you may have rights to access your personal data; correct inaccurate data; request deletion or restriction; receive certain data in a portable format; object to processing based on legitimate interests; and withdraw consent at any time without affecting earlier lawful processing. These rights are not absolute.
To make a request, email [email protected]. We may ask for information needed to verify your identity. You may complain to the UK Information Commissioner's Office. If EU data protection law applies to you, you may also complain to the supervisory authority in your EU country.
8. Security and policy changes
We use proportionate technical and organisational measures to protect personal data. No internet service is completely secure, so please use the contact details above if you believe your data may be at risk.
We may update this notice when our services, providers or legal obligations change. The effective date at the top shows when it was last revised.