Skip to main content

Legal

Privacy policy

What we collect when you unlock a resource, why, how long we keep it, and how to have it removed.

Draft — needs review before launch

This describes what the platform actually does, accurately, but it has not been reviewed by counsel and is not yet a binding policy. Have a lawyer review it against the privacy laws that apply to your visitors — the retention periods and the legal basis for processing in particular — and fill in the controller details before launch.

What we collect, and when

Most of this site can be read without giving us anything. We collect personal data at exactly two points.

1. Unlocking a resource

Some resources ask for your name and email address before they open. That is the whole form — there is no password, no account, no organisation field and no email verification step.

Alongside those two fields we record, at the moment you first unlock:

  • which resource you unlocked, and the page you were on
  • the referring URL, and any UTM campaign parameters in the link you followed
  • a coarse device class — mobile, tablet or desktop. We do not store your full browser user-agent string
  • a country code, where our hosting provider supplies one

That attribution is recorded once, on first unlock, and is not re-captured on later visits.

2. Newsletter signup

The newsletter form collects your email address and, optionally, your organisation. Subscribing does not unlock gated resources; those are separate.

What we do with it

  • Give you access. Your unlock is remembered so you are not asked again on other resources.
  • Send compliance updates. Occasional emails about rule changes and new resources. Every one has a one-click unsubscribe.
  • Understand what is useful. We record which resources you view and download so we know what to produce more of.

We do not sell your details, and we do not share them with third parties for their own marketing.

The cookie we set

When you unlock a resource we set one cookie. Its properties are:

Name
cprc_unlock
Purpose
Remembers that you have unlocked, so you are not asked again.
Contents
A signed token holding your name, email and an internal visitor id — nothing else. It carries no CRM identifier.
Protections
HttpOnly, so page scripts cannot read it. Secure, so it is only ever sent over HTTPS. SameSite=Lax.
Lifetime
180 days by default. Clearing your cookies removes it.

This cookie is strictly necessary for the access you asked for. Separately, if analytics are enabled on this deployment, those providers set their own cookies — see the section below.

Where your data goes

  • Our own database. One record per email address. A repeat submission updates that record rather than creating a second one.
  • Our CRM. Your name, email and the attribution listed above are sent to our customer relationship system so we can manage the mailing list.
  • Analytics. Where configured, this site can use Google Analytics 4, Google Tag Manager and Microsoft Clarity. We deliberately do not pass your name or email address into any of them.

How long we keep it

[state retention periods here] — this needs a decision before launch. Two things need a number: how long a visitor record is kept after the last sign of activity, and how long the engagement log is kept.

Your choices

  • Unsubscribe from any email using the link in it. That stops the emails and does not remove your access.
  • Ask for a copy of what we hold about you, or ask us to correct it.
  • Ask us to delete it. We will remove your visitor record and engagement history.
  • Clear the cookie in your browser at any time. You will be asked for your name and email the next time you open a gated resource.

Use the contact page for any of these.

Children

This is a professional resource for people doing compliance work. It is not directed at children and we do not knowingly collect their data.

Changes

If we change how we handle your data we will update this page. Material changes will be described in the newsletter rather than made quietly.

Who is responsible

Data controller
[add legal entity name]
Registered address
[add registered address]
Privacy contact
[add privacy contact address]