Privacy Policy
Last updated: 12 July 2026
Privacy Policy
Last updated: 12 July 2026
1. Overview
The spencers.zone framework (“spencers.zone,” “the spencers.zone framework,” “the framework,” “we,” “us” or “our”) is operated by Spencer Ledger, volunteers and various third-parties. The phrases “them” or “they” refer to any third parties (as outlined in the Vendor List). The phrases “you,” “your,” “yours,” “yourself,” “visitors,” and “users” refer to people who access the spencers.zone framework in any way.
This Privacy Policy is designed to comply with the European Union and United Kingdom General Data Protection Regulations (EU and UK GDPR). The spencers.zone framework is built specifically for residents of the UK or EU. Consequently, our data protection frameworks may not comply with jurisdictions outside the UK and EU, such as the USA's Health Insurance Portability and Accountability Act (HIPAA). To ensure regulatory compliance, please don't upload healthcare information to any part of the framework and if you live outside the UK or EU, you are advised not to use the framework.
By visiting or using any part of the framework or its tools, services and features, you confirm you have agreed to the Use Agreement and have read and understood this Privacy Policy and Google's Cookie Policy. You can find additional information about your rights and choice in Section 5 and 9 of the Privacy Policy below.
The latest version of this Privacy Policy will be available on this page (/privacy-policy). We reserve the right to update, rectify or modify this Privacy Policy at any time. Significant policy changes will be notified to visitors via a notice on the homepage. It is your responsibility to review this page periodically. Continued use of this site after changes have taken effect constitutes your acceptance of the updated policies.
2. Legal Compliance
We adhere to all relevant data protection laws and regulations, designed for but not limited to the UK Data Protection Act 2018 (DPA) and the UK and EU GDPR. All data is originally collected by third party services, but may be stored internally after collection, depending on the data type. Spencer Ledger is the data controller. Visit the contact page for more information on how to contact us regarding GDPR or other data protection laws.
We believe in full transparency regarding how your data is handled. As required by the UK/EU GDPR, we inform you about the types of data collected by third parties which are listed in the aforementioned Vendor List, which also includes links to their respective privacy policies in accordance with the UK Data (Use and Access) Act 2025.
The spencers.zone framework does not engage in automated decision-making activities that could impact your rights under the UK or EU GDPR.
We use third party services to maintain the operational integrity, functionality and performance optimisation of the framework. Each of these services has their own privacy policies, which we encourage you to review. These services are responsible for their own compliance with data protection laws, and we have taken steps to ensure we only partner with reputable providers who comply with UK/EU GDPR.
3. Information You Provide
When you interact with certain parts of the framework, such as submitting forms or completing questionnaires, we collect the personal data you explicitly provide (for example, you email address with the contact form). We also record and maintain any communication preference you select, such as opting out of future contact.
To protect your data, we may require identity verification before processing requests under the UK or EU GDPR. This process is reserved strictly for exceptional circumstances where we have reasonable doubts regarding the identity of the person making the request.
Required Documentation: In these rare instances, you may be asked to provide a valid form of ID, such as a recent utility bill, passport or driving licence.
Data Minimisation: You are permitted (encouraged, even) to redact or blur non-essential personal information on such documents.
We'll let you know if verification is required, alongside the consequences of non-compliance. Failure to provide requested verification data may result in the denial of your request.
4. How We Use Your Information
When we process your information, we do so for the following purposes:
Maintaining your preferences: If you opt-out of certain or all communications, we will retain a record of your choice indefinitely to ensure we respect your request and do not contact you in the future.
Communicating with you: To communicate with you, e.g. via email.
Improving our services: We analyse visitor data to identify bugs and trends before they impact your experience. This broad data helps us understand our audience demographics and helps optimise the framework. Please see Section 9(b) for full details on how this data is collected.
Security: Vendors like Cloudflare may use your information to foster the safety, security and integrity of the framework.
Third parties: Your information is shared with third party vendors, if:
you give us explicit permission to share you information;
you provide it by using the framework's services or features that are embedded with third parties (these will be noted), or;
you provide your information to a third party service through the framework (e.g. a Tally form).
Enforcement: We may use your information to prevent you from accessing the framework in the future. Please see Section 7 of the Use Agreement for full details.
Complying with local law: We won't voluntarily disclose your personal data to law enforcement or government authorities. We will only share information when strictly compelled to do so by a valid, legally binding court order, warrant, or subpoena that complies with applicable data protection regulations (including but not limited to EU and UK GDPR).
5. Your Rights under UK and EU GDPR
A brief overview of your rights are below. For full information regarding your rights, refer to the local regulator. For the UK, this is the Information Commissioner's Office: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/.
Right to Access: You have the right to request access to any personal data that may be held about you by third-parties.
Right to Rectification: If you believe that any personal data being held about you is incorrect or incomplete, you have the right to request its correction.
Right to Erasure: You can request the deletion of your personal data under certain circumstances, such as if the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing: You have the right to request the restriction of processing your data in certain situations.
Right to Data Portability: You can request that your personal data be transferred to another service provider in a structured, commonly used, and machine-readable format.
Right to Object: You have the right to object to the processing of your data in certain situations.
If you wish to exercise any of these rights or have concerns about your data, please contact us at privacy@spencers.zone.
6. Data Protection Queries
If you have any questions about how we handle your data, please contact privacy@spencers.zone with the subject title "Data Protection Inquiry."
7. Third Party Services and Infrastructure
We use trusted third party service providers (Data Processors) to host our website, manage our infrastructure, and deliver our services. Your data may be processed by such providers for the purposes outlined on the Vendor List.
Please note that some of these providers may transfer and process data outside the United Kingdom or European Economic Area (EEA). Please see Section 8 for details on how we secure these transfers.
8. Data Transfers
Your personal information may be transferred to countries other than where you live, such as, for example, the United States. The framework's vendors also stores some information (e.g. cookies) locally on the devices you use to visit our site.
Your personal information may be transferred to countries that do not have the same data protection laws as the country in which you initially provided the information. For example, data we store may be accessible to law enforcement and national security authorities under the circumstance we are served a court order or a warrant. Legal regimes outside of the United Kingdom or European Economic Area may allow authorities more access than the UK/EU would.
The main cohort of the framework is hosted on Google Cloud (vendor V01), the framework rely on them to transfer personal information which is subject to European Region data protection laws, which include:
Adequacy decisions: Google (and other vendors) may, in accordance with Article 45 of the UK and EU GDPR, transfer personal information to recipients that are in a country that European Commission, UK or Swiss data protection supervisory authorities have confirmed, by decision, offers an adequate level of data protection. We rely on these adequacy decision provided by Google to recipients located in the UK, European Union or Switzerland.
See also: European Union adequacy decisions and Swiss adequacy decisions
Data Privacy Frameworks: Vendors may transfer their data to their applicable corporate entity based away from the UK or EU from the EEA, Switzerland and the UK pursuant to the Data Privacy Frameworks. An adequacy decision was adopted for the EU-US Data Privacy Framework, Swiss-US Data Privacy Framework and the UK Extension to the EU-US Data Privacy Framework (each individually and jointly, the “Data Privacy Frameworks”).
9. Cookies, Tracking and Analytics
9(a): Cookies
Parts of the framework, including The Spencer Ledger Website (www.spencers.zone) are powered by Google Cloud and Sites. When you visit such subdomains, Google may deploy technical cookies necessary for security, network management, and to remember your banner preference (such as whether you have dismissed our notice).
Control: These are essential for the specific part of the framework to function. You can block them via your browser settings, though some parts of the site may stop working as intended.
More Info: You can review how Google manages these technologies in their Cookie Policy.
9(b): Tracking and Analytics
We also collect analytics when you click a link that leads to an external website. We process this data based on our legitimate interests (Article 6(1)(f)). Our interests are to monitor website performance, secure our systems, analyse outbound traffic, and ensure transparency by informing our users when they are navigating away from the framework.
What we collect: When you click a tracked link, Short.io (vendor V05) automatically processes standard, temporary web server logs. This includes your IP address (which is anonymised or truncated), a timestamp, your user agent and, in some cases, the referring webpage. This processing doesn't rely on tracking cookies that are stored on your device.
Data Processor & Transfers: Similar to Section 8, Short.io acts as our data processor for this. Because they are located outside the UK/EEA, we ensure that appropriate legal safeguards, such as SCCs, are actively maintained to protect your personal data during transmission.
10. Children's Privacy
The Spencer Ledger Website is an informational site, and the wider framework has other services, but neither are directed at, or intended for, children under the age of 16. We do not knowingly solicit or collect personal data from minors.
If you are a parent or guardian and believe that your child has provided us (or our vendors) with personal information, please contact us immediately at privacy@spencers.zone. Upon notification, we'll investigate and permanently delete the data from our records and request the same from our vendors.
11. Retention of Your Data
11(a): Retention Principles
The spencers.zone framework adheres to the storage limitation of the UK and EU GDPR. We retain your personal information for no longer than is necessary to fulfil the specific purposes for which it was collected, or to comply with applicable statutory or regulatory requirements.
11(b): Retention Periods
Contact History: If you communicate with us directly via email or on our contact forms, your personal data and message history will be automatically deleted 365 days after our last date of contact.
Analytics Data: Aggregate, server-side analytics (e.g. connection logs managed by our vendors) are overwritten or anonymised according to their standard lifecycle schedules.
11(c): Your Right to Erasure
Under Article 17 of both the UK and EU GDPR, you have the right to request the erasure of your personal data at any time. You do not need to wait for our automatic deletion cycles. To exercise this right, please submit an Article 17 request to our data controller at privacy@spencers.zone. We will process your request without undue delay in accordance with the regulatory guidelines.
12. Complaints Process
We allow you to complain about a response you received or how a UK GDPR process went, in accordance with the Data (Use and Access) Act 2025. You may forward your complaints to privacy@spencers.zone and they will be reviewed within 1 calendar month. You can always complain to the ICO if you believe we have not complied with UK GDPR.
13. Email Data Handling
Emails sent to @spencers.zone or @spencerledger.com addresses are processed by Swiss-based provider Proton AG (vendor V08).