Privacy notice for this hub
This is the privacy notice for the transparency hub itself — the site you're reading now (UK GDPR Article 13). Each application we run has its own declaration on the applications page. A site built to watch data-handling should be plain about its own, so here it is.
Who we are
The data controller is The Liberal Democrats, 1 Vincent Square, London SW1P 2PN.
Our Data Protection Officer can be reached at data.protection@libdems.org.uk.
What we hold
- Your account — your name and email address from your Lib Dem sign-in, so we can show you your own requests and nobody else's.
- Your requests — the rights requests you make and the email addresses you ask us to search for, held while we fulfil them.
- Complaint records — what you told us when you complained, and how to reach you about it.
- The do-not-contact list — a one-way fingerprint (a SHA-256 hash) of each suppressed address. Think of it as a wax seal: the same address always produces the same seal, so we can check "is this address on the list?" — but the seal cannot be melted back into the address. We never store the addresses themselves.
- The audit trail — an append-only record of every meaningful action taken here: who did what and when, in categorical labels, never the content of your requests.
Why, and on what legal basis
- Running the rights-handling service — the law obliges us to facilitate your data protection rights and our statutory complaints process (legal obligation, UK GDPR Article 6(1)(c)), and we have a legitimate interest in operating shared compliance infrastructure to do it well (Article 6(1)(f)).
- The suppression list — a legal obligation: honouring objections to direct marketing under UK GDPR Article 21 requires a list of who has objected, and that list must outlive the data it suppresses.
How long we keep it
- Rights requests and complaints: scrubbed of personal content 12 months after closure — we keep only the statistical shell (kind, dates, outcome).
- Audit trail: kept for 6 years, matching the limitation period for statutory claims.
- Export bundles (your downloadable data): deleted after 30 days.
- Suppression list entries: kept until you ask us to remove one — deliberately, so the objection outlives everything else.
Who else sees it
No one. This hub is self-hosted on our own infrastructure and uses no third-party processors — no external analytics, no tracking, no outsourced email lists. The machine-readable version of this notice declares an empty processors list, and that emptiness is the honest answer.
Your rights
Everything on the rights page applies to this hub's own records too: access, rectification, erasure, portability, restriction and objection — exercised from the portal, answered within a month, usually much faster.
Two ways to complain
Both routes are open to you, as equals — you never need to use one before the other:
- To us, via our electronic complaint form (DPA 2018 s.164A) — acknowledged within 30 days.
- To the regulator, the Information Commissioner's Office (ICO) — make a complaint (DPA 2018 s.165).
Changes to this notice
This notice lives in the hub's source repository and is version-controlled in git, so every change is recorded, attributable and reviewable — the same standard we apply to code. We won't pretend a notice was always what it currently says; the history is the history.