Privacy & Cookies

Privacy Notice & Cookie Policy

This notice explains what personal data this website collects, why, and your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA).

This website uses no cookies, no tracking scripts, and no analytics services. Your browsing is not tracked, profiled, or shared with advertisers. Server logs are kept for 30 days for security, and are aggregated into a private rolling report (24-hour, 7-day, 30-day) that contains no individual IP addresses.

1. Data Controller

Stuart Thomas
Whitby, North Yorkshire, England
Email: stuartpaulthomas@gmail.com
ORCID: 0009-0008-4518-0064

This notice covers stuart-thomas.com only. Commissioned data-protection and security work is carried out through TriageForge, which has its own privacy notice.

2. What Data We Collect

This website collects only the data that your browser automatically sends when you visit any website. This is recorded in standard web server logs.

DataExamplePurpose
IP address86.168.xxx.xxxSecurity, abuse prevention
Date and time13 Apr 2026 08:43Security monitoring
Page requested/maritime-security.htmlUnderstanding site usage
HTTP status code200 (OK)Error monitoring
Referrer URLgoogle.comUnderstanding how visitors find the site
User agentChrome 147 on macOSEnsuring compatibility

This data is collected automatically by the Nginx web server. When it is aggregated into the rolling report (see section 6), each IP address is briefly looked up against public geolocation databases (db-ip.com, MaxMind GeoLite2) so the report can show country and organisation totals. The result is aggregated immediately and the individual IP address is not stored alongside it.

If you email me, I also process the content of your message and anything personal you choose to put in it, so that I can reply.

3. Legal Basis

The legal basis for processing server-log data is legitimate interests, Article 6(1)(f) UK GDPR. The interests are:

These interests are balanced against your rights. The data collected is the minimum any web server records, it is kept briefly, it is not used for profiling, marketing or advertising, and it is not combined with anything else to identify you.

A note on “recognised legitimate interests”. The Data (Use and Access) Act 2025 introduced a separate lawful basis of that name (Article 6(1)(ea) and Annex 1 UK GDPR), which removes the need for a balancing test. It is a closed list covering matters such as national security, public security, defence, emergencies, crime and safeguarding. Ordinary website security logging does not fall within it, so this site does not rely on it — the balancing test above applies instead.

The legal basis for email correspondence is also legitimate interests: reading and replying to messages sent to me.

4. Cookies

This website sets no cookies.

No first-party cookies, no third-party cookies, no tracking cookies, no session cookies, no analytics cookies and no advertising cookies are used anywhere on this website. Nothing is written to localStorage or sessionStorage, and your browser is not fingerprinted.

Because nothing is stored on or read from your device, no consent is required under regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR), and no cookie banner is shown.

For completeness: the DUAA inserted a new Schedule A1 into PECR, in force 5 February 2026, setting out when information may be stored on a device without consent — including where it is strictly necessary to provide the service you asked for, where it is solely for statistical purposes aimed at improving the service, and where it is solely to adapt how the site appears or functions. The statistical and appearance exemptions apply only if the user is given clear information and a simple, free way to object. This site relies on none of them, because it stores nothing.

5. Third-Party Services

Google Fonts. This website loads typefaces (Hanken Grotesk; a few standalone pages also load Inter, JetBrains Mono or Fraunces) from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Your browser makes that request directly, so your IP address and general request data are received by Google, which may process them outside the UK. Google states that it does not use font requests for tracking or profiling, and does not set cookies via Google Fonts. See the Google Fonts Privacy FAQ. Blocking those two hostnames will not stop the site working — only the typefaces will change.

No other third-party services, analytics platforms, advertising networks, or social media trackers are used on this website.

Outbound Links. This site links to external websites (GitHub, triageforge.co.uk, authenticwhitbyjet.co.uk). Those sites have their own privacy notices. Following a link does not share your personal data with them beyond the standard HTTP referrer header.

6. Data Retention

Server access logs are automatically rotated and deleted after 30 days. No log data is archived, exported, or retained beyond this period.

A rolling report (/ping/, accessible only to the site owner) is regenerated from the logs four times a day. It presents the last 24 hours, 7 days and 30 days in parallel, with a country-level map and a watchlist of organisations derived from public IP-range databases.

The report contains aggregated statistics only — page-view counts, country and continent totals, organisation names from public IP ranges. Individual IP addresses are not stored in it. It is overwritten on every regeneration, so nothing in it outlives the 30-day log window.

Email correspondence is kept for as long as needed to deal with your message, and then deleted.

7. Data Sharing

Your data is not shared with any third party for marketing, analytics, or commercial purposes, and is never sold.

Server logs are stored on a Google Cloud Platform virtual machine in the europe-west2 (London) region. Google acts as a processor under standard cloud hosting terms. Log data stays in the UK; the only routine flow of data outside the UK is the Google Fonts request described in section 5.

8. Your Rights

Under the UK GDPR you have the right to:

To exercise any of these rights, email stuartpaulthomas@gmail.com. There is no fee.

How long I take. I respond without undue delay and in any event within one month. Under Article 12A UK GDPR, inserted by section 76 of the DUAA, that month runs from the latest of: the date the request is received; the date I receive any information reasonably needed to confirm your identity; and the date any permitted fee is paid. If requests are complex or numerous I may extend by up to two further months — I will tell you, with reasons, within the first month. Searches in response to an access request must be reasonable and proportionate (section 78 DUAA), not exhaustive.

9. Complaints

Complain to the controller. Section 103 of the DUAA gives you the right to complain directly to the data controller. Email stuartpaulthomas@gmail.com with the subject line “Data Protection Complaint”. Your complaint will be acknowledged within 30 days and resolved without undue delay. You do not have to complain to me first, but it is usually quickest.

Complain to the regulator. Until 30 September 2026 the UK data protection regulator is the Information Commissioner’s Office (ICO). From that date, under sections 117 to 119 of the Data (Use and Access) Act 2025, the office of the Information Commissioner is abolished and its functions transfer to the Information Commission. It is the same regulator, with the same functions, contact details and complaints process.

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint

Complaining to me does not affect your right to complain to the regulator or to seek a remedy through the courts.

10. Changes to This Notice

This notice may be updated from time to time. The current version will always be available at this URL. Material changes will be noted with an updated date below.

Last updated: 16 September 2026