Press "Enter" to skip to content

Privacy Policy

Important

Privacy Policy

Last updated:

Important: The ordinary contact form and ordinary email are not intended for unsolicited highly sensitive material. This site’s work can involve disability, health, criminal justice and legal-dispute information, so you may sometimes choose to send special category or criminal offence data. I will only retain and use that information where it is necessary for a request I have agreed to handle and where an appropriate legal basis and condition apply. Information that is not needed will be deleted.

Contents
  1. Controller and contact details
  2. What this policy covers
  3. Information collected
  4. Security telemetry and fingerprinting
  5. Signed internal-link provenance
  6. Cookies and similar technologies
  7. Analytics and search reporting
  8. Purposes and lawful bases
  9. Automated security rules
  10. AI-assisted drafting
  11. Recipients and service providers
  12. International transfers
  13. Retention
  14. Your rights
  15. Security measures and incidents
  16. Children
  17. Secure submissions and policy changes

1. Controller and contact details

I am Kieron JH, founder of The Reasonable Adjustment, and I am the data controller for the processing described in this policy.

Privacy contact: [email protected]

I am not required to appoint a Data Protection Officer. Privacy questions and rights requests should be sent to the address above.

2. What this policy covers

This policy covers personal data processed through:

  • the public website and its Cloudflare edge Worker;
  • contact forms, email and secure submission tools;
  • security telemetry, alerts and operational statistics;
  • analytics and search-performance services; and
  • advocacy or correspondence that I have agreed to handle.

It does not make third-party websites part of my service merely because I link to them. Their own privacy notices apply when you leave this site.

3. Information collected

Information you provide

  • Email and direct contact: your name, email address, message content, attachments and any other information you choose to provide.
  • Formspree contact forms: the form fields you submit and technical submission metadata made available by Formspree, such as IP address and user agent.
  • Advocacy material: information necessary for a matter I have agreed to consider. This may include special category data or criminal offence data where relevant and lawful.

Information generated when the site is used

  • Edge request data: IP address, ASN and network organisation, country or region, Cloudflare data-centre location, request time, requested path and query, referrer, request ID, HTTP/TLS details, user agent, client hints and fetch-navigation headers.
  • Client telemetry: browser and operating-system information, screen and viewport size, language, timezone, navigation type, page-history count, visibility state, touch capability, logical processor count, approximate device memory where exposed, and GPU or browser-rendering information where the browser makes it available.
  • Pseudonymous identifiers: visitor, session, page-view, fingerprint, browser-profile and hardware-profile keys used to recognise repeat activity and correlate security events. These are not intended to reveal a person’s name, but they can still be personal data because they may distinguish or reconnect visits.
  • Navigation provenance: signed internal-link markers, their validation status, and whether navigation appears direct, external, search-originated, signed internal or unmarked internal.
  • Security outcomes: risk signals, scores, interstitials, challenge outcomes, temporary blocks or delays, and links between events that meet configured correlation rules.
  • Aggregate operational statistics: counts of requests, visitors and sessions; traffic sources; guard actions; high-score events; protected-page requests; 404s; and leading paths, networks and countries.

I do not use these signals to discover a visitor’s real-world identity. Network allocation labels, device similarities and behavioural correlations are indicators only. They can be wrong and are not treated as proof of a person’s employer, identity or intention.

4. Security telemetry and fingerprinting

The site uses Cloudflare and a custom edge Worker to monitor abuse, automated enumeration, suspicious navigation sequences, repeated access to protected material and other activity that may threaten the site’s security or integrity.

The Worker can combine request metadata with browser-provided telemetry to create pseudonymous profile keys and compare activity across visits or networks. It may also use public network-allocation information to label an ASN or IP range, including ranges that appear associated with institutions. A label is an allocation clue, not identity verification.

Security analysis can include:

  • rate and navigation patterns;
  • direct, external, search and internal-link provenance;
  • missing, invalid or replayed security markers;
  • protected, old or guessed paths;
  • browser, device and rendering consistency;
  • pseudonymous profile reuse across networks or identities; and
  • clusters of events sharing a distinctive URL, marker or synthetic-browser signature.

Selected events may be sent to private Discord channels as detailed technical alerts. Alerts can include the requested path, IP address, ASN or organisation, country, user agent, request ID, pseudonymous identifiers, device/browser signals, scores, relevant historical observations and the action taken.

Every three hours, and once daily at UK midnight, the Worker may also send an aggregate operational summary to Discord. These summaries are designed to report counts and leading categories rather than reproduce each individual request. The underlying short-lived statistics events are stored in Cloudflare KV for up to four days.

Lawful basis: legitimate interests under Article 6(1)(f), namely operating, securing and defending the website; detecting abuse; maintaining reliable records; and understanding whether security rules are proportionate. A Legitimate Interests Assessment is available here: Legitimate Interests Assessment (PDF).

5. Signed internal-link provenance

Eligible links generated on this website may include a short signed src marker. The marker is used to verify that a navigation was generated by this site’s own HTML rather than copied, altered or manufactured elsewhere.

The compact marker contains:

  • a format version;
  • the WordPress object ID of the page containing the link;
  • the eligible link’s position on that source page; and
  • a shortened cryptographic signature tied to the destination path.

It does not contain your name, email address, IP address, visitor ID or device profile. The secret used to create the signature is not sent to the browser.

The edge Worker validates the marker before the request reaches WordPress. The marker may be removed from the origin request and from the visible browser URL after processing. The Worker can retain the validation result and decoded source/link position as part of security logging.

A missing or invalid marker is not automatically treated as hostile. Direct article visits can arise from bookmarks, search results, external links, copied URLs, old cached pages or privacy settings. Marker status becomes more significant only when combined with other indicators, such as a confirmed homepage-to-unmarked-page sequence, protected content, watched networks, abnormal navigation headers or linked probe-like activity.

6. Cookies and similar technologies

The site does not use advertising cookies or behavioural-advertising pixels. Plausible Analytics is cookieless. The security system does, however, use cookies and similar storage that are treated as necessary for security, session continuity, challenge handling and requested site functionality.

Security and service cookies

Cookie or category
tra_vid and fp_static
Purpose
Pseudonymous visitor/fingerprint continuity, repeat-visit recognition and abuse prevention.
Typical duration
Up to 12 months.
Cookie or category
tra_sid
Purpose
Short session continuity and navigation correlation.
Typical duration
30 minutes.
Cookie or category
tra_pv
Purpose
Short page-view deduplication and request coordination.
Typical duration
60 seconds.
Cookie or category
tra_home_src
Purpose
Short-lived confirmation that the homepage was recently served, used to assess the next internal navigation.
Typical duration
Up to 5 minutes and normally cleared after the next eligible request.
Cookie or category
tax_*, challenge and guard-state cookies
Purpose
Remembering verification, strike, warm/proof and temporary mitigation state so a visitor is not repeatedly challenged on every request.
Typical duration
Usually 90 seconds to 30 minutes; some specific high-confidence mitigation states can last up to 5 days.
Cookie or category
Notice/acknowledgement cookies
Purpose
Remembering that a security or privacy notice has recently been shown.
Typical duration
Usually 30 minutes to 24 hours.

The precise cookie names and durations can change as the security implementation is adjusted, but they are not used for advertising or sale of data. Blocking essential security cookies may cause repeated challenges or prevent some protected pages from working normally.

7. Analytics and search reporting

  • Plausible Analytics: aggregated, cookieless audience measurement.
  • Google Search Console and Search Console Insights: aggregate information about how pages appear and perform in Google Search, such as clicks, impressions and query trends.
  • Bing Webmaster Tools: aggregate search-visibility and indexing information relating to Bing.
  • Cloudflare: operational, performance and security information generated at the edge.

These services are used to understand site operation and discoverability, not to create advertising profiles of visitors on this website.

8. Purposes and lawful bases

Main purposes and lawful bases

Purpose
Website operation, security, abuse prevention and defence of the service
Information used
Edge request data, pseudonymous identifiers, telemetry, navigation provenance, risk signals, security outcomes and alerts.
Lawful basis
Legitimate interests, Article 6(1)(f).
Purpose
Operational statistics and service improvement
Information used
Aggregate usage, traffic source, path, network, country, error and security-action counts.
Lawful basis
Legitimate interests, Article 6(1)(f).
Purpose
Responding to enquiries and managing agreed work
Information used
Name, contact details, message content, attachments and relevant matter information.
Lawful basis
Legitimate interests, steps at your request before a contract, or performance of a contract where applicable.
Purpose
Special category data in an agreed advocacy matter
Information used
Only information necessary for the agreed purpose.
Lawful basis
An Article 6 basis plus an applicable Article 9 condition, which may include explicit consent under Article 9(2)(a).
Purpose
Criminal offence data in an agreed matter
Information used
Only information necessary for the agreed purpose.
Lawful basis
An Article 6 basis plus a valid Article 10 and Data Protection Act 2018 condition. If no suitable condition applies, the information will not be retained for that purpose.
Purpose
Compliance, disputes and legal claims
Information used
Relevant correspondence, evidence, security records and account information.
Lawful basis
Lawful obligation, legitimate interests, or establishment, exercise or defence of legal claims as applicable.

9. Automated security rules and manual review

The Worker uses automated rules to score and classify requests. Depending on the combination of signals, it may:

  • record a request or send an alert;
  • show an interstitial or verification page;
  • redirect a visitor through a short verification flow;
  • temporarily slow a request; or
  • temporarily block a high-confidence automated or abusive pattern.

These controls affect access to the website only. They are not used to make employment, credit, healthcare, legal or other decisions that produce legal or similarly significant effects.

Scores and profile matches are probabilistic. A VPN, shared device, privacy tool, cached link, network change or common hardware configuration can produce an innocent match. Where the evidence is weak, the system is intended to log or challenge rather than make a definitive attribution.

If you believe a security restriction was applied incorrectly, email [email protected] with the approximate date, time, page and any request ID shown. I will review the available records.

10. AI-assisted drafting

I may use third-party AI services, including OpenAI’s ChatGPT, to help organise material, draft correspondence, summarise documents or improve clarity. AI is a drafting aid, not the decision-maker.

  • Minimisation: I limit input to what is reasonably necessary and redact or pseudonymise identifiers where practical.
  • Sensitive matters: where a matter contains special category or criminal offence data, I consider whether an AI tool is necessary and use more restrictive controls or Temporary Chat where appropriate. If suitable controls are not available, I avoid submitting identifiable sensitive content.
  • Training controls: I use available account controls to limit use of content for model improvement where appropriate.
  • Human review: I review and edit outputs before use. No legal or similarly significant decision is made solely by AI.
  • Retention: AI-assisted working chats are kept only while useful to an active matter and are normally deleted within 12 months. Provider-side deletion and safety-retention periods are governed by the provider’s current terms and privacy information.

OpenAI’s current privacy and data-control information is available through its privacy policy and Data Controls FAQ.

11. Recipients and service providers

  • Cloudflare: hosting-edge, security, performance, Workers and KV storage.
  • Plausible Analytics: cookieless aggregate analytics.
  • Formspree: contact-form transmission and, depending on account configuration, submission storage.
  • Google: Search Console and Search Console Insights.
  • Microsoft: Bing Webmaster Tools.
  • Discord: private delivery and storage of security alerts and aggregate operational summaries.
  • OpenAI: AI-assisted drafting where used.
  • Email and hosting providers: delivery, storage, backup and operation of communications and website content.

The contractual role of a provider can vary by service and context. Each provider’s own privacy information explains its independent processing. I do not sell or rent personal data.

12. International transfers

Some service providers operate globally and may process information outside the UK. Where UK personal data is transferred internationally, I rely on the provider’s applicable safeguards, which may include UK adequacy regulations or data bridges, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses, or another lawful transfer mechanism.

The exact location and safeguard can depend on the provider, service and account configuration. Provider privacy notices and contractual terms should be read alongside this policy.

13. Retention

I keep information only for as long as reasonably necessary for the purpose for which it was collected. Current operational periods include:

Typical retention periods

Category
Page-view and homepage-sequence state
Typical period
Usually 60 seconds to 5 minutes.
Category
Session and ordinary guard state
Typical period
Usually 30 minutes or less.
Category
Specific temporary mitigation markers
Typical period
Usually 90 seconds to 24 hours; some configured high-confidence states can last up to 5 days.
Category
Pseudonymous visitor and fingerprint cookies
Typical period
Up to 12 months.
Category
Client-profile correlation records
Typical period
Up to 30 days.
Category
Short-lived statistics events in Cloudflare KV
Typical period
Up to 4 days.
Category
Aggregate counters and operational trend records
Typical period
Up to 90 days unless reset earlier.
Category
Discord security alerts and incident records
Typical period
Up to 6 months, unless required longer for a live abuse investigation, complaint or legal claim.
Category
Routine correspondence and Formspree submissions
Typical period
Normally up to 12 months after the matter becomes inactive, unless deletion is requested earlier or longer retention is justified.
Category
Agreed advocacy material
Typical period
For the duration of the agreed purpose and a reasonable close-out period, then deleted or reduced unless a lawful reason requires longer retention.

Retention may be extended where reasonably necessary to investigate repeated abuse, respond to a complaint, comply with law, or establish, exercise or defend legal claims. I review the continuing need and delete or minimise the information when that reason ends.

14. Your rights under UK data protection law

Depending on the circumstances, you may have rights to:

  • request access to your personal data;
  • have inaccurate information corrected;
  • request erasure;
  • request restriction of processing;
  • receive portable data where the right applies;
  • object to processing based on legitimate interests;
  • withdraw consent where consent is relied upon; and
  • ask for human review of an automated security restriction.

Rights are not absolute and depend on the legal basis, purpose and applicable exemptions. I normally respond within one month. I may ask for proportionate information to verify your identity, particularly where a request concerns security logs or pseudonymous identifiers.

To exercise a right: email [email protected].

ICO complaint: You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint/. I would appreciate the opportunity to address the issue first, but you do not have to contact me before approaching the ICO.

15. Security measures and incidents

I use measures appropriate to a small independent service, including HTTPS, Cloudflare edge protection, restrictive security headers, access controls, account security, two-factor authentication on key services where available, encrypted or locked devices, data minimisation and separation of public content from private correspondence.

No system is completely secure. If a personal-data incident occurs, I will assess the risk, take reasonable containment steps and notify the ICO or affected people where the law requires it.

16. Children

The site is aimed at a general and adult audience and is not designed to collect information directly from children. If I learn that a child has submitted personal data without an appropriate reason or involvement of a responsible adult, I will assess and delete it where appropriate.

17. Secure submissions and policy changes

For highly sensitive material, use one of the following rather than the ordinary public contact form:

Show PGP public key
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQENBGjgzEoBCAC1f7v296odbZkd/1YcRWq5nF89vcbgssfwTUn/ljpmWA4fbTew
gqVI1My8FQfaeAKNK6ItMDy6bX9H3Ks6cwYT/sMbI3qX9bl6TgpL3cSLsclLwhv+
ilhRTPkEt1d1VoiWpKFNdYme32D4mUQ7bkGSkLBLUvQuhhXlmVz6Oz/4W/0lSXYS
mABUPPr/VVTYIOCPkUsxO35YmoOZFohZSBwjNo0qA4huMlle+mKYiYu/ApE1Yl+B
BAFITuafDD8hJyXnQVsIY4M79kNP0mef9hxJLkV/RL0IN+D6pD8/0Gn9/FO755eg
Com6UQUbmvJUy7c4h64p4uCcs51liUME2t2RABEBAAG0QlRoZSBSZWFzb25hYmxl
IEFkanVzdG1lbnQgPGFkdm9jYWN5QHRoZXJlYXNvbmFibGVhZGp1c3RtZW50LmNv
LnVrPokBTgQTAQgAOBYhBMwbkJWq1QzDjLZ8QrbuO4b5qZmJBQJo4MxKAhsDBQsJ
CAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJELbuO4b5qZmJgQsIAKMqO7Lc4ytTC93r
nnJyJR/vtk/+IRiOCMf5mdyqB3fcUzFbvsTN1t7Ybl8eUITOqKW67SpVUrN6LmqK
bvKb4mcE6tNE9iWXm7dVNzmmKRm5dgWRYXrtcfLz5h2BpqyxQ08ZQTCyBvOmXDG7
JS7BSCo+GNMEjxf4zYg/dkdJI3IXWtRLW3Ul1kLo/pennKe99D6arYQJyMQp/pUF
O6WfWCCUxuYnTbafJVhUpxxvgr5ss+dEfxKUTicHWN310h5QK3Si1R6fcvyawxh1
0Rtxz5Ng4I/pohlXtAUw7rB2NnPqlLADcsyPFrkMslhQ+FLyp1BvCXeRSXef8Mj3
eiu1joS5AQ0EaODMSgEIAMmGeDOV+psOf1XakNqDZackakFn9n3braG0GemtMsSK
qBaN86wRVJ4Wm+OkxkDnX6WdH7FZvwAA0qDylRdgXwyLlaHTPtMkvSYDMBLd/Ejb
0kOAng3s0WXMgHmM2IPAg9WA6/jBANFAtJT5a5qxQnFtVPhh3yi/y6KSPdbW3PyY
KpPA030kGFULX6N/4M+TZx09rONJsTtqGPOUl7kpYjLydy1yGT1PIvnDcvq8h3Gm
ONlBp3X89g7MGefkozqNSc+hwKXLw3Chn2sOWi8KDf4E4+m0E2p9eF6tylew9tjV
ZYM1rPb+QPgll3ifY2mhMMzeQP0AOcNN1y2vllzPz0cAEQEAAYkBNgQYAQgAIBYh
BMwbkJWq1QzDjLZ8QrbuO4b5qZmJBQJo4MxKAhsMAAoJELbuO4b5qZmJRBcH/ji8
ynCJVBxFAzMUc96krzlfbLo8oJmImmy19oUWvqDHW626kgveZPfjvtQc+iGqhQd9
iJG2IB2yRic2jqvQvqiGccxaKHKND6oTlyW4q9dwZaaTUvtshulICBeIpknyeFB0
sXaUEwcm/XcjtnB+IH6+kZemAWPLrT9gofw/puUnLbmbPv57cu42ocEsw9tJl4gG
Pg9BuLPTkDIjBKHD9UK+rCf8/CrP457cFH0XmojoepPNn/YA6V+cvqaz31IwK+bO
qXw+ZNmwYqEHxo9jqzsA2HrkzBvPtlZdGzzUGzWyH75kQAPI9MNL89xqqb6XoqVu
oDIDOw3/+G60wWUgwHE=
=u8MU
-----END PGP PUBLIC KEY BLOCK-----

Changes to this policy

I may update this policy when the service, security controls, providers or legal requirements change. Material changes will be recorded in the changelog and the revised date will appear at the top of the page.


If you have a privacy question, email [email protected].

Comments are closed.

Mission News Theme by Compete Themes.