1. Who we are
This website ("the Site") is operated by James Evans ("we", "us", "our"), the data controller responsible for your personal data.
The Site is a purely personal activity with no business elements (writing is a hobby), so the UK GDPR and the DPA 2018 don't actually apply. This statement is therefore not legally necessary.
- Contact for privacy matters: james@starshipsandsorcery.co.uk
If you have any question about this statement or about how we handle your personal data, please use the contact details above.
2. What this statement covers
This statement explains what personal data we collect through the Site, why we collect it, the legal basis we rely on, who we share it with, how long we keep it, and — importantly — the rights you have under UK data protection law and how to use them.
3. The personal data we collect, and why
3.1 Newsletter sign-up
When you join our mailing list ("Join the crew") we collect:
- your email address (and any name you choose to give us);
- the fact and date of your consent, and confirmation that you completed the double opt-in step.
We use this only to send you news about new releases, deals and occasional updates. We will not send you marketing unless you have asked us to.
- Lawful basis: your consent (UK GDPR Article 6(1)(a)), and we rely on consent for the marketing emails themselves under the Privacy and Electronic Communications Regulations (PECR).
3.2 Enquiries
If you email us, we process the contents of your message and your contact details so we can reply and keep a record.
- Lawful basis: our legitimate interests (UK GDPR Article 6(1)(f)) in responding to and managing enquiries.
3.3 Website logs and security
The Site is flat HTML and CSS; we keep no logs.
3.4 Cookies and analytics
None — we don't track you or your activity on the site.
4. Who we share your data with
We do not sell your personal data. We share it only with service providers ("processors") who help us run the Site and the mailing list, and only as needed:
- Newsletter provider: MailerLite — stores the mailing list and sends our emails on our behalf.
- Web hosting provider: Mythic Beasts — hosts the Site.
International transfers. MailerLite is based in the US, so your personal data may be stored outside the UK.
5. How long we keep your data
- Mailing list data: kept until you unsubscribe or ask us to delete it, after which it is removed immediately.
- Enquiry emails: kept for 24 months from the date of last communication.
6. Your rights under UK data protection law
Under the UK GDPR and the Data Protection Act 2018 you have the following rights. Most are free to use, and we will not treat you differently for using them.
- The right to be informed — to know how we use your data. This statement provides that information.
- The right of access — to get a copy of the personal data we hold about you, and related information (a "subject access request" or SAR).
- The right to rectification — to have inaccurate data corrected and incomplete data completed.
- The right to erasure ("the right to be forgotten") — to have your data deleted in certain circumstances, for example where you withdraw consent and we have no other basis to keep it.
- The right to restrict processing — to ask us to pause our use of your data in certain circumstances while a concern is resolved.
- The right to data portability — to receive the personal data you gave us (such as your mailing-list details) in a structured, commonly used, machine-readable format, and to have it sent to another organisation where technically feasible. This applies to data we process by automated means on the basis of your consent or a contract.
- The right to object — to object to processing based on our legitimate interests. You also have an absolute right to object to direct marketing at any time, after which we will stop.
- Rights relating to automated decision-making and profiling — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out this kind of automated decision-making.
- The right to withdraw consent — where we rely on your consent (for example, the newsletter), you can withdraw it at any time, and it is as easy to withdraw as it was to give. Withdrawing consent does not affect processing carried out before you withdrew it. To withdraw consent, use the unsubscribe link at the bottom of the newsletter.
7. How to exercise your rights
The quickest options:
- To stop marketing emails: click the "unsubscribe" link at the bottom of any email we send. This also withdraws your consent for future marketing.
- For everything else: email us at james@starshipsandsorcery.co.uk telling us which right you want to use and enough detail for us to find your data.
What you can expect from us:
- We will respond without undue delay and within one month of receiving your request. If your request is complex or you have made several, we may extend this by up to two further months — if so, we will tell you within the first month and explain why.
- There is normally no charge. We may charge a reasonable fee, or decline, only if a request is manifestly unfounded or excessive (for example, repetitive), and we will explain our reasons if so.
- We may ask you to verify your identity before we act, so that we don't disclose your data to the wrong person.
- For a subject access request, we will carry out a reasonable and proportionate search for your data.
8. How to complain
If you are unhappy with how we have handled your personal data or a request, please contact us first using the details in section 1 — we would like the chance to put things right. We will acknowledge your complaint within 30 days, look into it without undue delay, keep you updated, and tell you the outcome.
You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time:
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
9. Changes to this statement
We may update this statement from time to time. When we do, we will change the "Last updated" date at the top and, where the change is significant, take reasonable steps to let you know.