Privacy notice

Privacy Notice & Cookie Policy

TriageForge · triageforge.co.uk · UK GDPR · DPA 2018 · DUAA 2025

This notice explains what personal data the TriageForge website collects, why we collect it, how long we keep it, and what rights you have under the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Data (Use and Access) Act 2025 (DUAA), whose data protection provisions came into force on 5 February 2026.

Plain-English summary. This website sets no cookies, uses no tracking and runs no analytics scripts. The server keeps standard web-server logs for 30 days, for security. We don't sell, share or trade personal data. If you email us, we keep the correspondence as long as we need it to deal with your enquiry, and then delete it. You can complain to us directly, and to the regulator.

1. Who we are (data controller)

The data controller for personal data processed by this website is:

Stuart Paul Thomas, trading as TriageForge
Whitby, North Yorkshire, England
privacy@triageforge.co.uk · contact@triageforge.co.uk
ORCID: 0009-0008-4518-0064

All processing described in this notice is carried out in the United Kingdom. Where we are engaged to work on a client's systems or data, the client is normally the controller and we act as processor under a separate written agreement; this notice covers the website only.

2. What data we collect

This website collects only the data your browser sends automatically to any website you visit. It is recorded in standard Nginx web-server logs.

FieldExamplePurpose
IP address86.168.*.*Security, abuse prevention
Date and time22 May 2026 19:43Security monitoring
Page requested/privacy.htmlUnderstanding site usage
HTTP status code200 (OK)Error monitoring
Referrer URLgoogle.comHow visitors find the site
User agentChrome 147 on macOSCompatibility, abuse detection

If you email any of our addresses (contact@, privacy@, security@triageforge.co.uk), we also process the content of your message and any personal data you choose to include in it, so that we can reply and, where relevant, discuss and carry out an engagement.

3. Legal basis for processing

Server logs. Our legal basis is legitimate interests, Article 6(1)(f) UK GDPR. The interests are keeping the website and its infrastructure secure, detecting and preventing abuse and unauthorised access, and understanding aggregate patterns of use. We have weighed these against your interests and rights: the data is the minimum any web server records, it is kept for a short period, it is not used for profiling, marketing or advertising, and it is not combined with anything else to identify you.

A note on "recognised legitimate interests". The DUAA introduced a separate lawful basis of that name (Article 6(1)(ea) and Annex 1 UK GDPR), which removes the need for a balancing test. It is a closed list covering matters such as national security, public security, defence, emergencies, crime and safeguarding. Ordinary website security logging does not fall within it, so we do not rely on it and we have carried out the balancing test described above instead.

Email correspondence. Where you write to us about a possible engagement, our basis is Article 6(1)(b) — steps taken at your request before entering into a contract. For all other correspondence our basis is legitimate interests, Article 6(1)(f): reading and answering messages sent to us, and keeping a record of what was agreed. We do not treat inbound email as consent-based, because that would give a misleading impression that we would delete a business record on request when we may need to keep it.

4. Cookies and similar technologies

This website sets no cookies. No first-party cookies, no third-party cookies, no tracking, session, analytics or advertising cookies are used anywhere on triageforge.co.uk. We do not use localStorage, sessionStorage or any other means of storing information on your device, and we do not fingerprint your browser. There is therefore no consent banner, because there is nothing to consent to.

For completeness: regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) governs storing information on, or reading information from, your device. The DUAA inserted a new Schedule A1 into PECR, in force 5 February 2026, which sets out when this may be done without consent — including storage strictly necessary to provide the service you asked for, storage solely for statistical purposes aimed at improving the service, and storage solely to adapt how a site appears or functions. The statistical and appearance exemptions apply only if you are given clear information and a simple, free means of objecting. We rely on none of these exemptions, because we store nothing.

5. Third-party services

Google Fonts. This website loads three typefaces (IBM Plex Serif, IBM Plex Sans and IBM Plex Mono) from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Your browser makes that request directly, so your IP address and general request data are received by Google, which may process them outside the UK. Google states that it does not use font requests for tracking or profiling and does not set cookies via Google Fonts. If you would rather this did not happen, blocking those two hostnames will not stop the site working — only the typefaces will change.

Email. Our domain email is hosted with Google Workspace. When you email a @triageforge.co.uk address, your message and its metadata are processed by Google as our processor under the Google Workspace data processing terms.

Hosting. The website runs on Google Cloud Platform in the europe-west2 (London) region. Google acts as our processor under standard cloud hosting terms. Server logs stay in the UK. The only routine flow of data outside the UK is the Google Fonts request described above.

No analytics platforms, advertising networks, social-media trackers or other third-party services are used on this website.

6. How long we keep data

Server access logs: automatically rotated and deleted after 30 days. No log data is archived, exported or retained beyond this period.

Email correspondence: kept for as long as we need it to deal with your enquiry, plus a reasonable period afterwards — typically up to 24 months — to handle follow-ups. Records relating to a paid engagement are kept for six years from the end of the engagement, to meet tax and limitation requirements. After that they are deleted.

7. Who we share data with

Your personal data is not shared with any third party for marketing, profiling, analytics or commercial purposes, and is never sold. The only processors involved in running this website are the hosting and email providers named in section 5. We may disclose data where we are legally required to do so.

8. Your rights

Under the UK GDPR you have the right to access a copy of your personal data; to rectification of inaccurate or incomplete data; to erasure; to restriction of processing; to object to processing based on legitimate interests; and to data portability. Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email privacy@triageforge.co.uk. There is no fee.

How long we take. We respond without undue delay and in any event within one month. Under Article 12A UK GDPR, inserted by section 76 DUAA, that month runs from the latest of: the date we receive your request; the date we receive any information we reasonably need to confirm your identity; and the date any permitted fee is paid. If your requests are complex or numerous we may extend by up to two further months — we will tell you, and give our reasons, within the first month. If we need you to clarify what you are asking for, we will say so promptly.

When we search for your data we are required to make a reasonable and proportionate search, not an exhaustive one (section 78 DUAA).

9. Complaints

Complain to us first. Section 103 DUAA gives you the right to complain directly to the controller. Email privacy@triageforge.co.uk with the subject line “Data protection complaint”. We will acknowledge your complaint within 30 days and respond without undue delay. You do not have to complain to us first, but it is usually the quickest route.

Complain to the regulator. Until 30 September 2026 the UK data protection regulator is the Information Commissioner's Office (ICO). From that date, under sections 117 to 119 of the Data (Use and Access) Act 2025, the office of the Information Commissioner is abolished and its functions transfer to the Information Commission. It is the same regulator, with the same functions, contact details and complaints process.

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
ico.org.uk/make-a-complaint

Complaining to us does not affect your right to complain to the regulator or to seek a remedy through the courts.

10. Changes to this notice

We may update this notice. The current version is always at this address, and the date below reflects the most recent change.

Last updated: 16 September 2026