Privacy Policy

How Ethical Founder Law collects, uses, stores and protects your personal data — including cookies, analytics, email, your GDPR and CCPA rights, and how to make a data request.

Effective date: 4 September 2026

This policy explains what personal data law.ethicalfounder.com (“we”, “us”, “this site”) collects, why, how long we keep it, and what rights you have over it.

Controller and contact point: Ethical Founder Law, a project of Ethical Founder. Data enquiries: admin@ethicalfounder.com.

1. Our core commitment

We publish articles. We do not run a case-intake business.

We do not sell your personal data. We do not sell, share or transfer reader information to law firms, claim buyers, factoring companies, insurers or brokers. That is a deliberate structural choice, explained in our Editorial Policy, and it is the single most important thing on this page.

2. What we collect

Information you give us voluntarily

  • Email correspondence. If you write to admin@ethicalfounder.com we receive your email address, your name if you give it, and whatever you choose to include in your message.
  • Newsletter or update subscriptions, where offered: your email address and the date and source of your consent.
  • Comments, where enabled: the name, email address and content you submit, plus your IP address and browser user agent.

Information collected automatically

  • Server log data. Like effectively every website, our hosting infrastructure records IP address, browser type and version, operating system, referring URL, pages requested, and timestamps. This is used for security, abuse prevention and diagnostics.
  • Cookies and similar technologies. Details in our Cookie Policy.
  • Analytics data, where analytics are in use: pages viewed, approximate location derived from IP (usually city or region level), device category, and referral source. This is used in aggregate to understand which guides are useful.

What we deliberately do not collect

We do not ask for, and you should never send us, details of your legal case, medical records, settlement documents, financial account numbers, government identification numbers, or any other sensitive personal information. As set out in our Disclaimer, such communications are not privileged and not confidential. If you send them unsolicited, we will delete them.

3. Why we process your data, and on what legal basis

PurposeData usedLawful basis (UK/EU GDPR)
Replying to your enquiry or correctionEmail, name, message contentLegitimate interests; performance of a request
Site security, abuse and fraud preventionLog data, IP addressLegitimate interests
Measuring which content is usefulAggregate analyticsConsent, where required
Sending updates you asked forEmail addressConsent
Meeting legal obligationsAs requiredLegal obligation

You may withdraw consent at any time; withdrawal does not affect processing already carried out.

4. Third parties that process data on our behalf

We use a small number of standard service providers, each of which may process limited data as part of delivering this site:

  • Hosting and infrastructure — serves the site and maintains security logs.
  • Content delivery and caching — improves load speed; may set functional cookies.
  • Email delivery — where you have subscribed to updates.
  • Analytics — where in use, to measure aggregate readership.
  • Embedded content — third-party media (for example video) may set its own cookies when you interact with it.

Each processor handles data under its own privacy terms. We do not authorise any of them to sell your data.

Some of these providers operate outside your country, including in the United States. Where personal data of UK/EU residents is transferred internationally, it is done under appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

5. How long we keep data

  • Email correspondence: up to 24 months after the matter is closed, unless a correction record needs to be retained longer for editorial accountability.
  • Newsletter subscriptions: until you unsubscribe, plus a suppression record so we do not re-contact you.
  • Server logs: typically 30 to 90 days, per our host’s standard retention.
  • Analytics: aggregate and retained per the analytics provider’s configured retention period.

6. Your rights

Depending on where you live, you have some or all of the following rights.

Under UK and EU GDPR, you may request: access to your data; correction of inaccurate data; erasure; restriction of processing; portability; and objection to processing based on legitimate interests. You also have the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner’s Office.

Under the California Consumer Privacy Act (CCPA/CPRA), you may request disclosure of the categories and specific pieces of personal information collected, deletion of that information, and correction of inaccuracies. You have the right to opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of. We will not discriminate against you for exercising any right.

Under India’s Digital Personal Data Protection Act, you may request access, correction, erasure and grievance redressal. Grievances go to admin@ethicalfounder.com.

How to exercise a right

Email admin@ethicalfounder.com with PRIVACY REQUEST in the subject line, describing what you want. We will respond within 30 days, and may need to verify your identity before acting — usually by confirming control of the email address concerned.

7. Children

This site is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.

8. Security

We use HTTPS across the site, restrict administrative access, and keep our platform and plugins updated. No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. Please do not send us sensitive information by email.

9. Data breaches

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the period required by law, and notify affected individuals directly where the risk is high.

10. Do Not Track

Browsers send Do Not Track signals inconsistently and there is no agreed standard for honouring them. We do not currently respond to DNT signals. You can control cookies directly through your browser and through the options in our Cookie Policy.

11. Changes to this policy

We may update this policy to reflect changes in our practices or the law. Material changes will be signalled by updating the effective date at the top of this page, and where the change is significant, by a notice on the site.

12. Contact

admin@ethicalfounder.com — or via our contact page.

See also our Terms & Conditions, Cookie Policy and Disclaimer.