InAutoNews

Privacy notice

What this site records about you, why, how long it keeps it, and what you can make us do about it.

Most publications collect a great deal about their readers because the tools are free and somebody might want the numbers later. We have gone the other way, mostly because almost none of it is any use to us and all of it is a liability.

The short version

We set no advertising or tracking cookies. We use no third party analytics. We do not store your IP address anywhere. Nothing here follows you between visits or between sites. If you write to us or join the mailing list we keep what you sent, because otherwise we could not answer you or send you anything.

The rest of this page is the detail behind those sentences, in the order a reader actually meets them.

Who is responsible

InAutoNews is published by Data Reach Ltd, a company registered in England and Wales, which is the data controller for everything described on this page.

Write to us about any of it through the contact page, or directly to editor@inautonews.com. We have not appointed a data protection officer, because we are not required to and pretending otherwise would only add a title to the same inbox.

When you read a page

Every page view is counted, on our own server rather than by a third party. What is recorded is the page you opened, the site you arrived from if there was one, whether the request looked like it came from a crawler, and a one way fingerprint used to tell one visitor from another within a single day.

That fingerprint is a digest of your IP address and browser string mixed with a secret that changes at midnight. It cannot be turned back into either. Because the secret rotates daily, the same person visiting tomorrow produces a completely different fingerprint, so visits cannot be joined into a history of one reader by anybody, ourselves included.

No IP address is stored. No cookie is involved in any of this. Raw rows are kept for 45 days and then folded into daily totals with nothing per visitor left in them.

Beyond that, our hosting provider keeps ordinary web server logs for a short period for security and diagnostics, as every host does. Those logs contain IP addresses and are not used by us for analytics.

This site is rebuilding an archive of several hundred thousand addresses, so requests for pages that have not been restored yet are common and useful. When one arrives, we log the path, the status code we returned, the referring page, and whether the visitor appeared to be a crawler.

A real person arriving from another site at a broken address is the clearest evidence that the address is worth restoring, which is why this log exists at all. It is subject to the same 45 day rule and stores no IP address.

When you write to us

The contact form stores your name, your email address, your subject and message, the article you attached it to if you did, the page you were on when you sent it, and your browser's user agent string. Not your IP address. The last two are kept because they are how we tell a genuine correction from an automated submission.

The message is saved to our editorial queue first and emailed to the editor second, so a mail problem delays somebody noticing rather than losing what you sent. We use what you send us to answer you and to act on it, and for nothing else. We do not add you to the mailing list because you wrote to us.

When you join the mailing list

We store your email address, the page you subscribed from, and the dates you confirmed and unsubscribed. No name, and nothing about what you read.

Subscription is double opt in. One email goes out asking you to confirm, and if you ignore it the address is never used again. Every email carries a one click unsubscribe, and unsubscribing is permanent unless you deliberately sign up and confirm a second time.

The address is never sold, never shared with anyone for their own purposes, and never used to identify you elsewhere on the site.

Cookies

Two cookies are set by the software that runs the site: a session cookie, which carries no identifier of a person, and a cross site request forgery token, which exists to stop another website submitting a form in your name. Both are what UK law calls strictly necessary, which is why you are not asked to consent to them.

There are no analytics cookies and no advertising cookies. Every cookie this site sets is listed individually on the cookies page.

Our lawful bases

Under UK GDPR we have to say which legal ground each use rests on, so here they are.

  • Counting page views and logging broken links. Legitimate interests: understanding what is read and which parts of the archive to rebuild next. We reduced the intrusion to the point where the data cannot be tied to a person across days, which is what makes that balance come out the way it does.
  • Answering your message. Legitimate interests in running a correspondence, and in most cases performing a step you asked for.
  • Sending the newsletter. Your consent, given by confirming the subscription, withdrawable at any time from any email we send.
  • Publishing journalism that mentions people. Legitimate interests, relying on the exemption for journalism in the Data Protection Act 2018.
  • Security, fraud prevention and keeping the site up. Legitimate interests, and in places a legal obligation.

How long we keep things

  • Page view rows. 45 days, then aggregated into daily totals with no per visitor data.
  • Broken link records. 45 days, then aggregated the same way.
  • Messages you send us. Kept while the matter is live, and afterwards as part of the editorial record where the message led to a correction. Reviewed annually, and deleted on request unless we need it to defend a legal claim.
  • Mailing list entries. Until you unsubscribe. The record of an unsubscribe is kept afterwards, because it is the only way to be certain we do not email you again.
  • Server logs. Held by our hosting provider for a short period and not used by us.

Who else sees any of it

We do not sell data and we do not share it for anyone else's marketing. A small number of suppliers process data on our behalf, under contract and on our instructions only: the company that hosts the site and its database, and the provider that delivers our email. That is the whole list.

Nothing about you is sent to an advertising network, and nothing about you is sent to the AI model providers our editorial tooling uses. Reader data and editorial tooling are kept apart on purpose, and the reasoning is set out on the AI and automation page.

We would disclose information if a court or a regulator lawfully required it, and we would tell you unless we were forbidden from doing so.

Where the data is held

Data is held in the United Kingdom or the European Economic Area. Where a supplier processes anything outside that, it is under the safeguards UK data protection law requires, such as the International Data Transfer Agreement or an adequacy decision.

Images we have not yet copied locally are served by redirecting your browser to the Internet Archive, which will therefore see that request and applies its own privacy policy to it. Nothing else on a page here loads from another company's servers.

Security

The site is served over HTTPS, the editorial back office is not publicly reachable and requires an account, and access to the database is limited to the people who need it. Passwords are stored hashed. We keep the amount of personal data on hand small enough that a breach would be embarrassing rather than serious, which is a deliberate security measure and not an accident of scale.

If we ever suffered a breach likely to result in a risk to your rights, we would report it to the Information Commissioner within 72 hours and tell affected people where the law requires it.

Your rights

Under UK GDPR you can ask us to do all of the following, free of charge, and we will answer within one month.

  • Access. A copy of the personal data we hold about you.
  • Rectification. Correction of anything inaccurate.
  • Erasure. Deletion, where we have no overriding reason to keep it.
  • Restriction. That we stop using it while a dispute about it is resolved.
  • Objection. That we stop relying on legitimate interests in your case, which we must honour absolutely where it concerns direct marketing.
  • Portability. A machine readable copy of what you gave us, where it was given by consent or under a contract.
  • Withdrawal of consent. At any time, without affecting what was lawful before you withdrew it.

Ask through the contact page or at editor@inautonews.com. We may need to confirm who you are before handing over personal data, which is a protection for you rather than an obstacle. Because we hold so little, most access requests are answered in full within days.

If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk, or by telephone on 0303 123 1113. We would rather you came to us first, but it is your right either way and nothing here is conditional on it.

Articles that mention you

Journalism is treated differently under data protection law, and it has to be: a publication that had to delete an article whenever somebody in it objected could not report on anything. The exemption in the Data Protection Act 2018 covers material processed with a view to publication in the public interest.

We still take these requests seriously and answer them individually. Where the information is inaccurate, that is a correction and it is handled under the corrections policy. Where it is accurate but you believe its continued publication is disproportionate, tell us why and we will weigh it. Sometimes the answer is to remove a detail rather than an article.

We do not remove articles because they are unflattering, and we do not remove them because a reputation management firm has asked. Where we do remove one, the address says the page is gone rather than pretending it never existed.

Children

This is a trade and enthusiast news site written for adults. It is not directed at children, and we do not knowingly collect anything from anyone under 13. The mailing list is for adults. If you believe a child has given us personal information, tell us and it will be deleted.

Changes to this notice

The date at the foot of this page is the date it was last reviewed. Where a change materially affects what we do with your data, we will say so on the page before it takes effect rather than after, and subscribers will be told by email.

This notice describes what the site actually does today, not what it might do one day. If you find a claim on this page that the site contradicts, that is a fault and we want to hear about it.

Last reviewed .