Privacy Notice
00The short version
We ask for one thing: your email address, so we can send you occasional updates. We do not track you, we set no cookies, we run no analytics, and this page loads nothing from anyone else's servers. You have to confirm by email before we will send you anything, and every email we send carries a one-click unsubscribe. That is the entire arrangement. The rest of this notice is the detail the law requires us to give you, and it is written to be read rather than to be survived.
01Who is responsible for your data
The controller — the organisation that decides why and how your personal data is used, and the one you can hold to account — is:
| Legal name | Orcasci Ltd |
|---|---|
| Registered in | England and Wales |
| Company number | 07387280 |
| Registered office | 27/28 Eastcastle Street, London, W1W 8DH, United Kingdom |
| Trading as | OrcaSci |
| Privacy contact | privacy@orcasci.com — a monitored address that reaches a person who can act on your request. |
| Data protection officer | None appointed. The tests in UK GDPR Art. 37(1) — public authority, large-scale regular and systematic monitoring, or large-scale special-category processing — are not met by a single opt-in mailing list. We will appoint one if that changes. |
| Representative in the EU/EEA | None appointed, and none required. We assessed this against Art. 3(2) rather than assumed it — see §10. |
02What we collect, why, and on what legal basis
Everything below is collected at the moment you submit the signup form. We collect nothing from you at any other time, and nothing at all if you simply read the site.
| What | Why | Legal basis |
|---|---|---|
| Your email address | To send you the updates you asked for. | Consent — UK GDPR Art. 6(1)(a), and Regulation 22 of the Privacy and Electronic Communications Regulations 2003 (PECR), which requires consent for marketing email to individuals. |
| The date and time you signed up and confirmed; the exact wording you agreed to; the version of this notice that was live; and the page you signed up from | So that we can show what you agreed to and when, if we are ever asked to. | Legal obligation — Art. 6(1)(c), read with Art. 7(1), which requires a controller relying on consent to be able to demonstrate it. We store the sentence itself, not a reference to it, because a reference proves nothing if the sentence later changes. |
| A one-way fingerprint of your IP address | To stop the form being used to sign other people up, and to
rate-limit abuse. This is the only thing we derive from your
connection, and we do not record your browser, device or operating
system.
We do not store your IP address. It is passed through a keyed one-way hash at the moment of submission and the original is discarded. The stored value cannot be turned back into an address, and it is not used to locate or identify you. |
Legitimate interests — Art. 6(1)(f): preventing our form from being used to send unwanted mail to third parties. We balanced this against your interests and concluded it is proportionate because the identifier is irreversible; we would not reach the same conclusion if we kept the raw address. |
| Whether your address is unconfirmed, confirmed, or unsubscribed | To make sure only confirmed addresses are ever emailed, and that someone who has opted out is never added back by mistake. | Consent for the first two states. Legal obligation — Art. 21(3) — for the third: once you object to direct marketing we must stop, and keeping a record that you objected is how we honour that. |
03What we do not do
Stated plainly, because these are the questions worth asking of any site that takes an email address:
- We do not sell, rent, share, swap or licence your address to anyone. There is no arrangement under which a third party receives it for their own purposes.
- We run no advertising and no third-party analytics.
- We do not profile you and we make no automated decisions about you that produce legal or similarly significant effects. There is nothing to disclose under Art. 22 or Art. 13(2)(f), and we are saying so rather than leaving the section out.
- We do not ask for your name, employer, job title, or anything else. If you send us more than an email address, we did not ask for it.
- We do not buy, rent or import mailing lists. Every address on this list was typed into this form by the person it belongs to and then confirmed from that person's inbox.
04Do you have to give us your email address?
No. There is no statutory or contractual requirement to give it, you are under no obligation to, and nothing on this site is withheld from you if you do not. The only consequence of not giving it is that you will not receive the updates. (Art. 13(2)(e) requires us to tell you this, and the honest answer here is short.)
05How consent works, and how to take it back
Signing up is double opt-in:
- You submit the form. Your address is stored as unconfirmed.
- We email you a link. Nothing else is sent to you unless you open it.
- Opening the link confirms your address. Only confirmed addresses are ever mailed.
If you never confirm, the address is deleted automatically — see §07. If someone else typed your address in, doing nothing is enough: it will expire on its own and you will hear nothing further.
Withdrawing is as easy as giving. That is not a courtesy, it is Art. 7(3). Every email carries a one-click unsubscribe link, and you can write to privacy@orcasci.com at any time. Withdrawing does not make anything we did beforehand unlawful, and we will not ask you why.
06Cookies, tracking, and third-party content
This site sets no cookies. No session cookie, no preference cookie, no analytics cookie, no advertising tag, no tracking pixel. There is nothing here for a cookie banner to ask you about, which is why you have not been shown one.
It also loads nothing from anyone else's servers — no
hosted webfonts, no content-delivery network, no embedded video, no
third-party script. Every font, image and script on this page is served from
orcasci.com itself, and that restriction is enforced in the browser by a
default-src 'self' Content-Security-Policy rather than left to
good intentions.
This matters more than it sounds. Simply requesting a file from another company's server discloses your IP address to that company, whether or not anyone intended it — which is what the Munich court found in the Google Fonts case (LG München I, 20 January 2022, 3 O 17493/20). We do not manage that disclosure; we avoid making the request. Self-hosting all external resources has been a standing rule across this portfolio since 2026-04-06, and this page complies with it.
The only thing kept on your device is a small record in your browser's local storage: the address you typed and whether it was confirmed, so the page can tell you what you already did if you come back. It is never transmitted to us or to anyone else, it holds no identifier we could use to recognise you, and the page carries a visible Reset button that erases it. Because it is strictly necessary to provide something you asked for, it falls within the exemption in PECR reg. 6(4) and does not require consent.
07How long we keep things
| Record | Kept for | Then |
|---|---|---|
| Unconfirmed address | 30 days from signup | Deleted automatically, with its consent record. |
| Confirmed address | Until you unsubscribe, or until we stop sending updates altogether | Deleted, with its consent record. |
| Address after you unsubscribe | 30 days | Deleted. |
| Suppression entry — a one-way hash of the address, and nothing else | For as long as the list exists | Deleted when the list is. This is what stops you being re-added by mistake. It is a hash, not an address: it cannot be read, mailed, exported, or turned back into you, and it is the minimum record that can do the job. |
We keep the address itself for 30 days after you unsubscribe, and not longer, so that an accidental unsubscribe can be undone and a bounce can be reconciled. After that the readable address goes and only the hash remains. (A three-year retention of the address itself was considered and rejected: a suppression list does not need to be readable to work, and keeping an address for years in order to honour a request to stop is a poor answer to Art. 5(1)(c).)
08Who else handles your data
We keep the list in a database we control. These processors handle it on our written instructions under a contract meeting UK GDPR Art. 28, and for no purpose of their own:
| Processor | What they do | Where |
|---|---|---|
| Railway Corp. | Hosts the site and the database the list lives in. | europe-west4-drams3a (EU West Metal -- Amsterdam, Netherlands) |
| MailerSend (MailerSend, Inc., New York, US) | Delivers the confirmation email and the updates. | stored in the European Union (Google Cloud EMEA, Belgium); transferred to the United States under the UK Addendum to the EU Standard Contractual Clauses |
| Google Workspace (Google Ireland Limited) | Runs our hello@ and privacy@ mailboxes, so it handles any email you send us — including a request to exercise your rights. | Google's infrastructure, under the Google Workspace Data Processing Addendum and its transfer terms |
Beyond those, we would disclose your address only where we are legally required to — a court order, or a lawful demand from a regulator — and we would tell you unless we were prohibited from doing so.
09Sending data outside the UK
Your address does leave the UK, and this section says exactly where and under what.
Hosting. The site and the database run on Railway in Amsterdam, in the Netherlands. That is a transfer from the UK to the EU, and we rely on the UK adequacy regulations covering the EEA.
Email. This one is less simple, and the simple version would be misleading. Our email processor stores data in the European Union, but the company we contract with, MailerSend, Inc., is established in the United States, its sub-processors include a US company, and its own privacy policy states that personal data is transferred from the UK to the US. So this is a restricted transfer regardless of where the servers sit. We rely on the UK Addendum to the EU Standard Contractual Clauses, which is incorporated into our data processing agreement with them.
Our mailboxes. If you email hello@ or privacy@, that message is handled by Google Workspace, and Google may process it outside the UK under the transfer terms of its Data Processing Addendum. We mention it because writing to us is the way you exercise most of the rights in section 11, and it would be odd to describe those rights without saying who carries the letter.
A transfer risk assessment for that transfer is on file, and we will provide it on request.
10If you are in the EU or EEA
Orcasci Ltd is established in the United Kingdom. UK GDPR governs this processing, and it is the standard everything above is written to.
The EU GDPR can also reach a controller outside the Union, but only in the two situations set out in its Art. 3(2): where the controller offers goods or services to people in the Union, or where it monitors their behaviour in it. We have assessed this site against both, and our conclusion is that neither currently applies:
- Monitoring — no. There is nothing here to monitor with. No cookies, no analytics, no tracking pixel, no profiling, and no third-party request of any kind. Nobody's behaviour is observed on this site, in the Union or anywhere else.
- Offering — not on what this site currently does.
Recital 23 is explicit that the mere accessibility of a website from the
Union is not enough to establish an intention to offer services there.
This site is in English only, on a
.comdomain, quotes no currency, names no EU address, runs no advertising of any kind, claims no EU clientele, and does nothing to direct itself at any member state. Accepting an address that happens to be European is not the same as offering a service to Europe.
We have written that assessment down rather than assumed it, and we will re-run it if this site starts doing any of the things that would change the answer — advertising into the Union, publishing in a member-state language, naming EU customers or an EU address, or targeting the newsletter at readers there.
None of this reduces what you get. We apply the standard above to everyone who signs up, wherever they are, because running one honest practice is simpler than running several. If you are in the EEA and you think we have the analysis wrong, tell us at privacy@orcasci.com — and you can raise it with your national supervisory authority, which is free to reach its own conclusion.
11If you are in Switzerland
The Swiss Federal Act on Data Protection (nFADP, in force 1 September 2023) reaches processing outside Switzerland that has an effect there. That is a similar question to the one in §10, and on what this site currently does we reach a similar answer.
We are stating the Swiss position anyway. The nFADP's information duty (Art. 19) and its rights of access, correction and deletion (Art. 25–32) run closely parallel to what is already set out above, so writing one notice that meets the strictest of the standards it might touch costs us nothing and spares you having to work out which regime you fall under. Where the regimes differ, we apply the stricter.
If you are in Switzerland you may complain to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
12Your rights
Under UK GDPR — and, where they apply, the EU GDPR and the nFADP — you have the right to:
- Be informed — this notice, plus a copy on request.
- Access a copy of the personal data we hold about you.
- Rectify anything inaccurate.
- Erasure. On a mailing list this is simple and we will simply do it. Note that erasing your address does not by itself remove the suppression hash described in §07; if you want that removed too, say so, and understand that it becomes possible for you to be added again in future.
- Restrict processing while a dispute is resolved.
- Object — and to direct marketing specifically, which is an absolute right under Art. 21(2)–(3). There is no balancing test, no discretion on our side, and we will not ask you to justify it.
- Portability — receive your data in a structured, commonly used, machine-readable form.
- Withdraw consent at any time (§05).
Write to privacy@orcasci.com. There is no charge, we will not ask you to justify the request, and we will not require you to prove your identity beyond what is necessary to be sure we are answering the right person. Our response deadline is set by statute:
UK GDPR Art. 12(3) — response deadline: one month from receipt,
extendable by two further months where the request is complex,
provided we tell you within the first month and explain why.
If we get it wrong, complain to the Information Commissioner's Office — ico.org.uk/make-a-complaint, or 0303 123 1113. You do not have to raise it with us first, though we would rather you did.
13Keeping it safe
- The site is served over HTTPS only.
- Confirmation and unsubscribe links use cryptographically random tokens that cannot be guessed or enumerated.
- IP addresses are hashed under a server-side secret, never stored.
- Administrative access to the list requires a separate credential and is not reachable from the public site.
- The browser is prevented from loading third-party resources by policy, not merely by our not having added any.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO in line with Art. 33, and we will tell you directly where Art. 34 requires it.
14Changes to this notice
The version number and date at the top change whenever this notice does. Where a change materially affects what we do with data you have already given us, we will email you — and where the law requires fresh consent rather than notification, we will ask, rather than treat your silence as agreement.
Every signup record stores the version of this notice that was live when it was made, and the exact consent wording shown on screen at the time. Changing this page does not retroactively change what anyone agreed to.