Legal
Privacy
What this site collects
Reading collects nothing that identifies you. This website has no accounts, no advertising, no tracking pixels and no third-party embeds.
Reading it sets no cookies and writes nothing to your browser's local or session storage. No profile of your visit is built, purchased or sold. The one script is the traffic counter described below, which is anonymous and cannot identify you.
There are two places on this site through which you can hand over personal data, and in both you have to mean it: the membership application on Get Involved and the message form on Contact. Nothing else on the site transmits anything, and neither form is reachable by accident.
If you apply to join
Applying sends what you typed to the movement, where it is written to a database. Submitting the form does not make you a member: the record is marked as awaiting review, and a person decides. Until then, and afterwards, you are entitled to know exactly what is held.
A record holds seven things at most: your name, your email address, your country, the role you asked for, one area of interest, and — only if you choose to give them — your region or city and a message. There is no postal address, no telephone number and no date of birth. Nothing is inferred, enriched or bought in from anywhere else.
The two optional fields are the ones that can say most about you, so they are treated as carefully as your name. A region narrows a person far more than a country does, and a message is free text — which is where people mention an employer, a family situation or a legal one. Both are encrypted, and neither is ever written to the administrative log. If you would rather not give them, leave them empty; the application works exactly the same.
Why we are allowed to hold it
Belonging to a political movement implies a political opinion, which the General Data Protection Regulation treats as a special category of data under Article 9 and protects more strictly than ordinary personal data. We rely on your explicit consent, given when you applied, together with Article 9(2)(d), which permits a not-for-profit body with a political aim to process the data of its own members — provided the data is not disclosed outside the body without consent. It is not, and will not be.
How long it is kept
- While the membership stands, and no longer than the movement needs it.
- Deleted whenever you ask, without your having to give a reason.
- Nothing is deleted automatically on a timer, because an application awaiting review is somebody's application rather than something stale.
- The administrative log described below records that a record was created, changed or deleted, and by whom, but never its contents.
What the form itself does
Your name, address, region and message are encrypted before they are written down, in the same request — none of them is ever stored in readable form. The reply you see is identical whether or not the address was already on the roll, so the form cannot be used to test whether a particular person is a member. Applications are rate-limited per connection, which is a defence against a script filling the roll rather than a measure aimed at you.
Your details are never sold, never shared with another organisation, never used to build an advertising profile, and never passed to a third party for any purpose. No automated decision is made about you.
How it is protected
A membership list is exactly the kind of document that should never leak, so it is built on the assumption that one day something will go wrong. What follows is a description of the safeguards rather than a promise that nothing can happen. Correspondence sent through the contact form is held the same way.
- Your name, email address, region and message are encrypted before they are written down, with a key that is not kept in the database. A stolen copy of the database, or of a backup of it, decrypts to nothing.
- Your country is held unencrypted, because counting and organising by country is the reason the list exists. On its own it identifies nobody. Your region, which would narrow you down much further, is not treated this way — it is encrypted with the rest.
- Nobody signs in with a password. Administrative access requires a passkey held on a physical device, which cannot be guessed, phished or read out of a stolen database.
- Reading names or messages requires a second confirmation. Being signed in shows only counts; revealing any individual, or opening any letter, needs a fresh passkey touch valid for minutes. Someone who steals an active session gets statistics, not people.
- Every reading is logged — who looked, and when. Not merely every change: for a list like this, the act of looking is the thing worth recording. What was searched for is recorded as a one-way digest, so the log can confirm whether a particular person was looked up without itself becoming a list of names.
- There is no export function. The list cannot be downloaded as a file, because a file is the form in which such lists escape.
Nobody outside the movement's own administration can read any part of it, and no part of it is published anywhere, at any aggregation, without consent.
The two forms
The first is the membership application on Get Involved, described above.
The second is the message form on Contact. It holds your name, your email address, which function you addressed and what you wrote. Name, address and message are encrypted exactly as a member's details are — writing to an organisation is not the same as belonging to it, but the gap is thinner than it looks, and a letter saying you are thinking of joining is as disclosing as the roll itself.
Correspondence is kept until it has been dealt with and for no longer than answering it requires, is erased on request, and is never used to add you to the membership roll. Joining is a separate decision you have to make deliberately. No email addresses are printed on the contact page because each is published only when the function it belongs to exists and somebody is answerable for reading it.
Traffic figures
Visits are counted using Vercel Web Analytics, which is cookieless: it sets nothing on your device, stores no personal data, assigns you no identifier and cannot follow you between sites. It is served from this domain rather than from a third-party network, so loading a page discloses your visit to nobody else. This is why the site carries no consent banner — there is nothing to consent to.
What it produces is a count of page views and visitors, by page and by country. It is not linked to membership records, and it cannot be: the two hold nothing in common that would join them.
The administrative pages are excluded from the count, so the figures describe readers rather than our own editing.
Fonts and assets
Typefaces are served from this site rather than from a font network, so loading a page does not disclose your visit to a third party. All imagery is stored locally; nothing is hotlinked from another domain.
Server logs
Whoever hosts this site will keep ordinary web server logs, which typically include IP addresses, requested paths and timestamps. That is a function of the hosting arrangement rather than of this website, and the arrangement will be named here once it is settled.
Your rights
Under the General Data Protection Regulation you have rights of access, rectification, erasure, restriction, portability and objection in respect of personal data held about you. Where processing rests on consent, you may also withdraw that consent at any time, and withdrawing it is as straightforward as giving it was.
Those rights are real and the machinery to honour them exists: a record can be produced, corrected or deleted outright on request, and deletion means deletion rather than a flag on a row that is quietly kept.
One thing is missing, and we would rather say so than leave you to discover it.
Registration as a party or association has not completed, so no data controller can yet be named and no correspondence address is published — see the imprint. Until that is settled there is no address to which you can send a request with certainty of who will read it, and no supervisory authority with which a complaint could be lodged against a named controller.
That is a genuine gap, and it argues for waiting: if the absence of a named controller troubles you, do not apply yet. Nothing is lost by applying later. This page will name the controller, the address and the supervisory authority before the gap closes rather than after.
This note describes the site as it stands and is written to be read rather than to satisfy a checklist. It is not legal advice, and it will be replaced by a full privacy policy on registration.
