Privacy
Policy
paulfaulkner.com (“Website”) is owned and operated by Paul Faulkner, trading as The Rogue Protocol (“we”, “us”, “our”, “the Operator”). We are committed to protecting your personal data and handling it responsibly, transparently, and in accordance with applicable privacy law.
This Privacy Policy explains what personal data we collect, on what legal basis we process it, how we use it, who we share it with, and what rights you hold over it. It applies to all users of this Website and associated Services, wherever you are located.
Data Controller: Paul Faulkner / The Rogue Protocol, Unit 161661, PO Box 7169, Poole, BH15 9EL, United Kingdom. Contact: privacy@paulfaulkner.com
This Policy should be read alongside our Terms & Conditions and Cookie Policy, which are incorporated by reference.
Data We Collect
We collect only the personal data necessary to provide our Services and fulfil our legitimate business purposes. We do not collect sensitive personal data (special category data under UK GDPR) unless you choose to share it voluntarily in a communication with us.
| Category | Data Collected | How Collected |
|---|---|---|
| Identity Data | First name, last name | Contact forms, subscription sign-up |
| Contact Data | Email address | Contact forms, subscription sign-up |
| Enquiry Data | Message content, enquiry type, situation brief | Contact form submissions |
| Technical Data | IP address (anonymised), browser type, OS, screen size, referring URL, pages visited, time on site | Google Analytics (with IP anonymisation enabled) |
| Usage Data | Content accessed, links clicked, session duration | Google Analytics, Google Tag Manager |
| Marketing Preferences | Subscription status, consent records, unsubscribe history | Substack / email platform |
| Transaction Data | Subscription tier, payment status (no card data stored by us) | Stripe / Substack payment processing |
We do not collect payment card data directly. All payment processing is handled by third-party payment processors (Stripe via Substack) who are PCI-DSS compliant. We receive only summary transaction data.
Legal Basis for Processing
Under the UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:
| Purpose | Legal Basis |
|---|---|
| Responding to contact form enquiries | Legitimate interests (responding to prospective clients) |
| Sending newsletters and publications you subscribed to | Consent (opt-in at point of subscription) |
| Processing subscriptions and payments | Contract performance |
| Website analytics and performance monitoring | Legitimate interests (improving Website experience) |
| Complying with legal obligations | Legal obligation (e.g., tax records, regulatory requirements) |
| Fraud prevention and security | Legitimate interests (protecting the business and users) |
Where we rely on legitimate interests, we have carried out a balancing test and are satisfied that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests — see Section 07.
How We Use Your Data
We use the personal data we collect for the following purposes:
- To respond to enquiries submitted via the contact form
- To deliver subscription publications and paid content you have purchased
- To process and manage subscription payments
- To send marketing communications where you have opted in (newsletters, dispatches, publication updates)
- To analyse Website usage and improve performance and user experience
- To detect, investigate, and prevent fraudulent or harmful activity
- To comply with legal and regulatory obligations
- To enforce our Terms & Conditions
We will never sell, rent, trade, or share your personal data with third parties for their own marketing purposes. Data is shared with service providers only where necessary to operate the Services described above, and under appropriate data processing agreements.
Third-Party Service Providers
We engage the following third-party data processors who may handle your personal data on our behalf. All processors are required to handle data in compliance with UK GDPR and applicable privacy law.
| Provider | Purpose | Data Location |
|---|---|---|
| Substack | Publication platform, newsletter delivery, subscription management, payment processing | USA (Standard Contractual Clauses apply) |
| Formspree | Contact form submission processing and delivery | USA (Standard Contractual Clauses apply) |
| Google Analytics (GA4) | Website analytics — IP anonymisation enabled | USA (Standard Contractual Clauses apply) |
| Google Tag Manager | Tag and tracking script management | USA (Standard Contractual Clauses apply) |
| Stripe | Payment processing (via Substack) | USA/EU (PCI-DSS compliant) |
| Google Fonts | Font delivery (may log IP address) | USA (Standard Contractual Clauses apply) |
Where processors are located outside the UK or EEA, we ensure appropriate safeguards are in place — typically Standard Contractual Clauses (SCCs) approved by the ICO or the European Commission, or reliance on adequacy decisions where applicable.
We do not use MailerLite. Any references to MailerLite in previous versions of this Policy are superseded by this version.
Cookies & Tracking
This Website uses cookies and similar tracking technologies. Cookies are small text files stored on your device that help us operate the Website and understand how it is used.
We use the following categories of cookies:
- Essential cookies — strictly necessary for the Website to function. Cannot be disabled without impairing core functionality. No consent required under PECR.
- Analytics cookies — Google Analytics GA4, used to understand user behaviour and improve the Website. IP anonymisation is enabled. These cookies require your consent.
- Functional cookies — remember your preferences (e.g., cookie consent choices).
You can manage your cookie preferences at any time via the cookie settings on this Website. Withdrawing consent for analytics cookies will not affect the functionality of the Website.
For full details of cookies set on this Website, see our Cookie Policy at paulfaulkner.com/cookie-policy/
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:
| Data Type | Retention Period |
|---|---|
| Contact form enquiries | 3 years from date of last contact, or until you request deletion |
| Subscriber data (active) | For the duration of the subscription plus 12 months |
| Subscriber data (unsubscribed) | 12 months from unsubscribe date (suppression list retained to honour opt-out) |
| Transaction records | 7 years (UK tax and accounting legal requirement) |
| Analytics data | 14 months (GA4 default — anonymised) |
| Consent records | 3 years from date of consent (regulatory requirement) |
At the end of the applicable retention period, data is securely deleted or anonymised.
Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights in relation to your personal data:
To exercise any of the above rights, submit a written request to privacy@paulfaulkner.com. We will respond within 30 days of receipt, as required by UK GDPR. We may request proof of identity before processing your request.
We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to comply.
International Data Transfers
Some of our third-party service providers are based outside the United Kingdom and European Economic Area. Where personal data is transferred to countries without an adequacy decision from the UK government, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the ICO or European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules where relevant
By using this Website, you acknowledge that your data may be transferred, stored, and processed in countries outside the UK. We take all reasonable steps to ensure that any such transfers comply with applicable data protection law and that your data remains protected to the standards required by UK GDPR.
Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
- SSL/TLS encryption for all data transmitted via this Website
- Access controls limiting data access to authorised personnel only
- Use of reputable, security-audited third-party processors
- Regular review of security practices and data handling procedures
While we take data security seriously, no system is entirely immune to risk. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
Children’s Privacy
This Website is not directed to individuals under the age of 18 and we do not knowingly collect personal data from minors. If you believe that a child under 18 has provided personal data to us without appropriate parental consent, please contact us immediately at privacy@paulfaulkner.com and we will take steps to delete that data promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The “Last Updated” date at the top of this page will reflect the date of the most recent revision.
For material changes that significantly affect how we process your personal data, we will provide prominent notice on this Website and, where appropriate, notify active subscribers by email. We encourage you to review this Policy periodically.
Continued use of the Website following the posting of a revised Policy constitutes your acceptance of the revised terms.
The current version of this Policy is always available at: paulfaulkner.com/privacy/
Contact & Complaints
For all privacy-related enquiries, Subject Access Requests, or to exercise any of your data protection rights, contact us at:
Unit 161661
PO Box 7169
Poole
BH15 9EL
United Kingdom
Email: privacy@paulfaulkner.com
We will acknowledge receipt of your request within 5 working days and respond in full within 30 days. If your request is complex or numerous, we may extend this period by a further two months, in which case we will inform you within the initial 30-day period.
If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Wycliffe House, Water Lane
Wilmslow, Cheshire
SK9 5AF
Tel: 0303 123 1113
Web: ico.org.uk
