Privacy Policy
In force from 16 September 2020. Version 3.1.
This policy explains what avorz.com records when you read the wire, what an account stores, why we hold it, how long we keep it, and what you can require us to do. It applies to avorz.com, its feeds, its newsletters and its account area.
1. Who is responsible
avorz.com is operated by a company established in the European Economic Area, which acts as the data controller for the processing described here. Our corporate identity, registered address and company number are provided on request to contact@avorz.com and are set out in full in our licensing agreements.
For all data protection matters, including requests to exercise your rights, write to contact@avorz.com. We respond to every request; we do not require you to hold an account in order to make one.
2. What we collect when you read without an account
Most people never sign in, and nothing on that path identifies you personally.
- Request logs. The address requested, the date and time, the HTTP status, the referring address where your browser sends one, a coarse user-agent string, and your IP address with the final octet removed before the record is written (for IPv6, truncated to the /48 prefix).
- Aggregate counts. Read counters are incremented against the item, not recorded against a reader. There is no identifier connecting a count to you, and we cannot reconstruct what any individual has read.
We do not load analytics services, advertising networks, tag managers, social widgets, session recorders, heat maps or fingerprinting scripts. There is no third-party code on the wire.
3. What an account stores
- Your email address, used to sign you in and to send only what you have asked for.
- Saved items and followed tags, created and removed entirely by you.
- Session records: a session identifier, the device and browser type, the time of last use, and an approximate location derived from the IP address at sign-in, shown so you can recognise and revoke a session you did not start.
- Correspondence you send us, retained with the reply.
We do not record which items you open, how long you spend reading, what you search for, or what you filter by. Feed density, filters and sort order exist only in the page for the length of your visit.
4. Why we process it, and on what legal basis
| Processing | Purpose | Legal basis (UK/EU GDPR) |
|---|---|---|
| Request logs | Operating the service, diagnosing faults, preventing abuse and denial-of-service | Legitimate interests, Article 6(1)(f) |
| Account data | Providing the account features you asked for | Performance of a contract, Article 6(1)(b) |
| Session records | Keeping you signed in and letting you revoke access | Performance of a contract, Article 6(1)(b), and legitimate interests in security, Article 6(1)(f) |
| Newsletter and job alerts | Sending messages you asked to receive | Consent, Article 6(1)(a), withdrawable at any time |
| Correspondence | Answering you and keeping a record of what was answered | Legitimate interests, Article 6(1)(f) |
| Responding to lawful orders | Complying with binding legal obligations | Legal obligation, Article 6(1)(c) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is limited to what is necessary to run a public news service securely. You may object to it at any time under section 9.
5. What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done either.
- We do not build reading profiles, interest profiles or audience segments, and the wire is not personalised: signed in or signed out, every reader receives the same chronological feed.
- We do not carry advertising, sponsorship or paid placement, so no third party sets a commercial context around what you read.
- We do not use automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Article 22.
- We do not seek special category data. If you send it to us in correspondence, we process it only to answer you and delete it with the correspondence.
6. Cookies and similar technologies
There is no cookie banner on avorz.com because there is nothing to consent to. We set one cookie, and only after you sign in.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| Session token | Keeps you signed in to your account | Until you sign out, or 90 days of inactivity | Strictly necessary |
This cookie is exempt from the consent requirement in Article 5(3) of the ePrivacy Directive because it is strictly necessary to provide a service you have expressly requested. We use no analytics, advertising, measurement or attribution cookies, no local storage for tracking, and no device fingerprinting.
7. How long we keep things
| Data | Retention |
|---|---|
| Raw request logs | 14 days, then deleted; aggregate counts without identifiers are kept indefinitely |
| Account data | Until you delete the account, which takes effect immediately |
| Session records | Until revoked, or 90 days after last use |
| Newsletter and alert subscriptions | Until you unsubscribe, plus a suppression record so we do not contact you again |
| Correspondence | 24 months from the last message |
| Records of rights requests | 36 months, as evidence that we handled them properly |
8. Who else sees it
We use a small number of suppliers to run the service: hosting and content delivery, transactional and newsletter email delivery, and error monitoring. Each acts as a processor under a written contract meeting Article 28 requirements, processes data only on our documented instructions, and may not use it for its own purposes. A current list of these processors is available on request to contact@avorz.com.
We disclose personal data to a public authority only where we are legally compelled. Where the law permits us to tell you, we tell you before disclosing. We publish annually the number of legal requests received and the number complied with.
If the service is ever transferred to another operator, personal data may transfer with it. Account holders will be notified in advance and given the opportunity to export and delete their data first.
9. International transfers
Our infrastructure is located in the European Economic Area by default. Where a processor stores or accesses data outside the EEA or the United Kingdom, we rely on one of the following: an adequacy decision of the European Commission or the UK government; or the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved, supported by a transfer impact assessment and by supplementary technical measures including encryption in transit and at rest.
You may request a copy of the relevant transfer safeguards from contact@avorz.com.
10. Your rights in the EEA and the United Kingdom
You have the right to obtain confirmation of whether we process your data and a copy of it; to have inaccurate data corrected; to have data erased; to restrict processing; to receive data you provided in a portable, machine-readable format; to object to processing based on legitimate interests; and to withdraw consent at any time without affecting processing already carried out.
You can exercise the most important of these yourself, immediately and without asking us: the account area lets you export everything we hold about you as JSON and delete the account outright. For anything else, write to contact@avorz.com.
We answer within one month of receiving a request. Where a request is complex we may extend this by up to two further months and will tell you why within the first month. We do not charge for responding, and we do not require identity documents unless we have a genuine doubt about who is asking.
You also have the right to lodge a complaint with a supervisory authority, in particular in the country where you live, where you work, or where you believe an infringement occurred. Complaining to us first is not a precondition, though we would rather have the chance to put something right.
11. Your rights in the United States
The following applies to residents of California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia and other states with comparable privacy legislation.
In the preceding twelve months we collected the following categories of personal information: identifiers (an email address for account holders; truncated IP addresses in logs) and internet or network activity (pages requested, timestamps, browser type). We collect these directly from you and automatically from your device. We use them only for the purposes in section 4. We disclose them only to the processors described in section 8, for those same purposes.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended. We do not collect sensitive personal information for the purpose of inferring characteristics, so there is no right to limit its use. We do not knowingly collect personal information from anyone under 16.
Subject to verification, you have the right to know what we have collected, to obtain a copy of it, to have it corrected, to have it deleted, and not to be discriminated against for exercising any of these rights. We do not offer financial incentives for personal information. To exercise a right, use the export and deletion controls in the account area, or write to contact@avorz.com. We respond within 45 days and may extend once by a further 45 days where reasonably necessary. An authorised agent may act for you with written permission that we may verify with you directly.
We honour the Global Privacy Control browser signal. In practice this changes nothing about how we treat you, because we do not sell or share personal information in the first place.
If we decline a request in whole or in part, you may appeal by replying to our decision. We will answer the appeal in writing within 45 days and tell you how to contact your state attorney general if you remain dissatisfied.
12. Children
The wire is intended for a general adult audience. We do not knowingly create accounts for anyone under 16, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, write to contact@avorz.com and we will delete it.
13. Security
Data is encrypted in transit and at rest. Access to production systems is restricted to named staff who need it, protected by multi-factor authentication, and logged. Sign-in uses single-use links rather than passwords, which removes the risk of password reuse entirely. No system is immune from compromise; where a breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours and notify you directly where the risk is high.
14. Changes to this policy
This policy is versioned and dated. Where a change affects what we collect, why, or how long we keep it, we announce it to account holders before it takes effect. Superseded versions remain available so that a past practice can be checked against the text that was in force at the time.
Version 3.1 — in force 16 September 2020. Questions and requests: contact@avorz.com.