Legal
Privacy policy
What we collect, why we have it, how long we keep it, and what you can make us do about it.
Last updated 19 August 2026
Who is responsible
The data controller for Our Elected EU News is [to be completed before launch: registered legal name and address of the controller]. Data-protection enquiries go to official@ourelected.com.
What we collect
If you create an account
Your email address and authentication credentials, handled by our authentication provider — we never see your password. A profile record holding the display name and avatar you choose, and whether you have completed onboarding.
Security and abuse-prevention records
Requests to protected parts of the site generate security records containing the IP address, browser user-agent string, the resource requested and the outcome, plus rate-limiting counters. These exist to detect credential stuffing, scraping and abuse. They are not used to build a profile of you and are not sold or shared for advertising.
If you subscribe
Subscription status and the identifiers our payment processor issues. Full card details go to the processor directly and are never received or stored by us.
If you upload a file
Files you upload are stored in a location scoped to your account and are not readable by other readers.
Advertising and cookies
Cookies strictly necessary to run the site — keeping you signed in, protecting forms against cross-site request forgery — are set on every visit and cannot be switched off without breaking the site.
Advertising is not currently served on this site. When it is, this section will describe the advertising partner, the identifiers it uses, and the consent controls — before the first ad renders, not after.
Why we are allowed to hold it
- Performance of a contract — running your account and any subscription.
- Legitimate interests — keeping the service secure, preventing abuse, and keeping a record of administrative actions. We hold the minimum that achieves this.
- Consent — advertising and analytics cookies that are not strictly necessary, and any newsletter. Withdrawable at any time.
- Legal obligation — tax and accounting records for payments.
How long we keep it
Security event records are kept for 90 days, rate-limiting records for 30 days, and administrative audit records for 365 days, after which they are permanently deleted by an automated job. Payment-event records are kept for 90 days beyond processing. Account and profile data is kept while the account exists.
Your rights
Under the GDPR you can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Account holders can export their data and delete their account directly from account settings; deletion removes the account and its profile and content, while the minimum security and financial records we are required or permitted to keep are retained for the periods above.
You can also complain to a supervisory authority — in the EEA, the authority where you live or work. Ours is [to be completed before launch: lead supervisory authority / establishment country].
Who else processes it
We use service providers to host the database and authentication, to deliver the site, to send email, and to process payments — and, when advertising is live, to serve it. Some operate outside the EEA; those transfers rely on the European Commission’s standard contractual clauses or an adequacy decision. Providers act on our instructions, except the advertising partner, which is an independent controller for the advertising described above.
Changes
Material changes are announced on this page with a new date, and the page is dated at the top so you can tell whether it has moved. Related reading: our terms and security policy.