OpenStat.uk

Privacy Policy

How we collect, use and protect personal information through the OpenStat website, public dashboards and related forms.

Last updated: · OpenStat

1. Who controls your information

OpenStat is a public-data and statistical dashboard platform operated by Isodev Limited, a company registered in England and Wales under company number 16866628, with its registered office at Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ.

Isodev Limited, operating OpenStat, is the data controller for personal information used for OpenStat's own purposes. This includes information collected through openstat.uk, dashboard-suggestion and contact forms, newsletter subscriptions, business communications, website-security records, server logs, rights requests and complaints. As controller, we determine why and how that information is used.

This policy applies to the OpenStat website, public dashboards, forms, newsletters and related communications. It does not govern independent third-party websites, source publishers or platforms linked from OpenStat.

In this policy, “personal information” and “personal data” mean information relating to an identified or identifiable living person. Information that has been irreversibly anonymised so that no individual is reasonably identifiable is not personal data. Pseudonymised information remains personal data where it can be linked to a person using additional information.

Related documents

This policy should be read with our Cookie Policy, Terms of Use and Data Practices.

2. Information we collect

You can view public OpenStat dashboards without creating an account or directly providing your name. We collect limited personal information when you choose to provide it, communicate with us, subscribe to updates, submit a dashboard suggestion or correction, or when our systems generate records needed to operate and secure the Website.

  • Dashboard suggestions, corrections and contact forms: your name, email address, organisation where provided, request details, attachments where enabled, and information included in your message.
  • Newsletter records: your email address, name where requested, subscription status, consent evidence, delivery information, and unsubscribe or suppression records.
  • Technical and security information: IP address, browser and device information, operating system, requested pages, timestamps, referring page, cookie choices, server and application logs, error information, form-submission records, rate-limiting records, and indicators of suspected misuse or malicious activity.
  • Rights requests and complaints: contact details, correspondence, the nature of the request or complaint, information reasonably needed to verify identity or authority, and records of our investigation and response.

Where the information comes from

We normally receive personal information directly from you or generate limited technical records through normal Website operation. We may also receive information from an authorised representative or from a source publisher where necessary to investigate a data, rights or licensing issue.

If information about another person is supplied to us, the person providing it is responsible for ensuring that the disclosure is lawful and that any required privacy information has been provided.

Information we do not ordinarily request

Our website forms are not designed to collect passwords, private cryptographic keys, full payment-card details, passport copies, medical records, special-category information, criminal-offence information, children’s information or other high-risk personal information. Please do not submit such information through general forms.

If we receive information that is clearly excessive or unrelated, we may delete it, restrict access to it or ask for a reduced or appropriately redacted version.

3. How and why we use personal information

We use personal information only where we have an appropriate lawful basis. The purposes and bases that most commonly apply are:

  • Dashboard suggestions, corrections and enquiries: to assess a request, investigate an issue, respond to you and improve OpenStat. We rely on our legitimate interests in operating and developing the platform.
  • Newsletter and optional electronic communications: to send communications you requested or that are otherwise permitted. We normally rely on consent and applicable electronic-marketing rules. You may unsubscribe at any time.
  • Website operation, fraud prevention and security: to deliver pages, maintain sessions, record cookie choices, limit abusive submissions, diagnose faults, investigate attacks and protect systems and users. We rely on legitimate interests, legal obligations and the rules governing storage and access technologies.
  • Data, rights, licensing and legal matters: to investigate source or correction reports, respond to rights holders, obtain professional advice, comply with lawful requests and establish, exercise or defend legal rights. We rely on legal obligations and legitimate interests.
  • Rights requests and data protection complaints: to verify, investigate, respond, keep people informed and demonstrate how the matter was handled. We rely on legal obligations and legitimate interests in maintaining appropriate compliance records.

Legitimate interests

Where we rely on legitimate interests, we consider the purpose, whether the processing is necessary, whether it is reasonably expected, and the possible effect on individuals. Safeguards may include collecting less information, restricting access, reducing retention, using aggregated information or offering an opt-out.

Required information

Required fields are identified on our forms. You do not have to submit a dashboard suggestion, correction, enquiry or newsletter subscription, but without necessary contact or request information we may be unable to respond or investigate the matter.

Consent and changing purposes

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before it was withdrawn. We will not use personal information for a materially incompatible new purpose unless the law permits or requires it, and we will provide further information or seek consent where required.

We do not sell personal information or disclose it for third-party advertising.

4. How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, security and dispute-management requirements. Our normal approach is:

  • Enquiries, dashboard suggestions and correction reports: normally for up to 24 months after the last meaningful contact or final decision.
  • Newsletter subscriptions: until you unsubscribe or the list is discontinued. We may retain a minimal suppression record afterwards so that we continue to respect your preference.
  • Routine server and diagnostic logs: normally for up to 90 days. Security, rate-limiting or incident records may be kept for up to 12 months or longer where necessary to investigate an incident or protect legal rights.
  • Cookie and consent records: for the period reasonably required to remember and demonstrate your choice, as described in our Cookie Policy.
  • Rights requests and data protection complaints: normally for up to six years after closure where needed to demonstrate compliance or manage related claims.

A record may be kept for longer where it is subject to a legal hold, active dispute, fraud or security investigation, regulatory request or unresolved complaint. It may be deleted sooner where the purpose has ended and no legal or operational reason requires continued retention.

Deleted information may remain temporarily in protected backups until the relevant backup is overwritten in the normal cycle. During that period, it is kept beyond ordinary use and remains protected.

We periodically review retention and securely delete, anonymise or restrict information that is no longer required.

5. Who we share personal information with

We disclose personal information only where necessary and proportionate. Recipients may include:

  • website hosting, cloud infrastructure, database, backup and security providers;
  • business email, newsletter, form and collaboration providers;
  • authorised employees and contractors who need access for their responsibilities and are subject to appropriate confidentiality obligations;
  • accountants, insurers, solicitors, auditors and other professional advisers;
  • courts, regulators, law-enforcement bodies, tax authorities or other recipients where disclosure is required or permitted by law; and
  • a prospective buyer, investor or successor in connection with a genuine financing, restructuring, sale or transfer of all or part of the business, subject to appropriate protections.

Where a provider acts as our processor, we require appropriate contractual commitments concerning instructions, confidentiality, security, subprocessors and assistance with data-protection obligations. Some recipients, including professional advisers, insurers, courts and regulators, may act as independent controllers for their own purposes.

International transfers

Some providers may store or access personal information outside the United Kingdom. Where this creates a restricted international transfer, we use an available lawful mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law. Where required, we assess the transfer and apply additional contractual, organisational or technical safeguards.

You may contact us for further information about the categories of recipients and safeguards relevant to your information. We may withhold details that would compromise security, confidentiality or another person’s rights.

6. Public dashboard data and personal information

OpenStat is designed primarily around aggregate, statistical and institutional public data. Where practicable, we prefer datasets that do not require us to publish information about identifiable individuals.

Some source publications may lawfully contain information about identifiable people, such as public office-holders, elected representatives, published professional roles or other information intentionally made public by an authoritative source. Where such information is relevant to a dashboard, we consider the source, purpose, necessity, proportionality and applicable legal conditions before displaying it.

We do not intentionally use OpenStat to publish private personal information, confidential records, leaked datasets, credentials, direct-marketing lists or information obtained unlawfully. We may remove or restrict material where its privacy, provenance or reuse position cannot be established to a reasonable standard.

Dashboard view counts may be recorded using aggregate server-side counters. We do not intentionally attach those counts to named users or use them to build advertising profiles.

Users must not attempt to re-identify individuals from data presented as anonymous or aggregate. Further operational principles are described in our Data Practices.

7. Cookies, children and automated processing

Cookies and similar technologies

OpenStat uses cookies and similar storage or access technologies for website operation and security. Where any optional technology requiring consent is introduced, it will not be used before the required consent is given. Further details are available in our Cookie Policy.

Children

OpenStat is a general public-data website and is not designed to knowingly collect personal information directly from children. Please contact us if you believe a child has submitted personal information through a form without appropriate authority.

Automated processing

We do not use personal information collected through OpenStat to make decisions about individuals based solely on automated processing where the decision produces legal or similarly significant effects.

8. Security

We use technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. Measures are selected according to the nature and risk of the processing and may include encrypted connections, multi-factor authentication, role-based access, least-privilege permissions, secure configuration, secrets management, security updates, backups, logging, monitoring, supplier review, confidentiality obligations and incident-response procedures.

Access is limited to people and providers who need the information for an authorised purpose. We review safeguards in light of the information involved, available technology and the possible impact of a breach.

Users should keep their devices and browsers updated, protect any credentials used with third-party services, and promptly report suspected security issues affecting OpenStat.

No internet transmission or storage system can be guaranteed completely secure. Please avoid sending unnecessary sensitive or confidential information through general website forms. If we identify a personal-data breach, we will investigate, contain and remediate it and make any notifications required by law.

9. Your rights and complaints

Depending on the circumstances and lawful basis, you may have rights to:

  • be informed about how your personal information is used;
  • request access to your personal information;
  • have inaccurate or incomplete information corrected;
  • request erasure or restriction where the legal conditions apply;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • withdraw consent at any time where processing relies on consent; and
  • challenge certain significant decisions made solely by automated means, where applicable.

Your right to object

Where we rely on legitimate interests, you may object based on your particular situation. We will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. Your right to object to direct marketing is absolute.

How to exercise a right

Email privacy@openstat.uk with the subject line “Data Protection Rights Request” and enough information to help us identify the relevant records. Requests are normally free of charge. We may request proportionate evidence of identity or authority where reasonably necessary.

We respond without undue delay and normally within one calendar month after receiving a valid request and any information reasonably required to confirm identity or clarify the request. Where the law permits an extension because of complexity or the number of requests, we will explain this within the initial response period.

Data protection complaints

Email privacy@openstat.uk with the subject line “Data Protection Complaint”. Please explain what happened, when it occurred and the outcome you are seeking.

We will acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep you informed where necessary and communicate the outcome without undue delay.

You may also complain to the Information Commissioner’s Office. Contacting us first gives us an opportunity to address the matter but does not affect your right to approach the ICO or seek another legal remedy.

10. Changes to this policy

We may update this policy to reflect changes to our services, systems, suppliers, processing activities, legal obligations or regulatory guidance. The current version will be published on this page with a fixed last-updated date.

Where a change materially affects how we use personal information already collected, we will take reasonable steps to draw attention to it and obtain consent where the law requires it. Previous versions may be made available on request where reasonably practicable.

11. Contact

OpenStat Privacy
Email: privacy@openstat.uk
Legal operator and controller: Isodev Limited, company number 16866628
Registered office: Bartle House, 9 Oxford Court, Manchester, England, M2 3WQ

For a rights request, use the subject line “Data Protection Rights Request”. For a complaint, use “Data Protection Complaint”. Please do not send passports, driving licences, financial records, production credentials or other sensitive information unless we specifically request an appropriate and proportionate form of verification through a suitable method.

You may act through an authorised representative. We may ask for evidence that the representative is authorised and may still need to verify the identity of the person whose information is concerned.