Draft dated 28 September 2026
Privacy Draft
1. Present status and controller gap
ProgtiProj is a pre-launch editorial prototype at progtiproj.com. No legal person or organisation has been identified as its operator or data controller. As a result, the site must not begin collecting inquiry, newsletter, analytics or advertising data. A real controller must be named with a service address and working contact route before launch.
The proposed contact address is editor@progtiproj.com, but it is unverified and unmonitored. It cannot presently support privacy requests. No data protection officer has been appointed, and this draft does not claim one is required.
2. Data handled by the current static site
The editorial inquiry form asks for a name or pen name, email address, inquiry type, message and acknowledgement. JavaScript validates those fields locally in the visitor's browser and prevents submission. The form has no action, no transmission method and no receiving endpoint. ProgtiProj does not receive or store those values. Visitors should still use invented, non-sensitive details because browser extensions, shared devices or local browser features may observe entered text outside this site's control.
The site stores one consent preference in browser local storage under a ProgtiProj-specific key. Its value records either optional or essential. Optional measurement is not active, so both choices cause no analytics or advertising tag to load. The value remains on the device until the visitor clears site storage or changes it through browser controls. The footer provides a control to reopen the choice banner.
Ordinary web hosting, once configured, may create short-lived technical logs containing an internet address, request time, requested path, response status and browser metadata. No host was supplied, so actual log fields, location and retention are unknown. They must be documented before launch.
3. Cookies and similar storage
The preview sets no analytics, advertising or marketing cookies. Essential browser storage remembers the consent choice so the banner does not reappear on every page. This storage supports the visitor's requested preference. Choosing optional currently records preference only; it does not authorise any hidden tag because none exists.
| Category | Purpose | Current state | Duration |
|---|---|---|---|
| Essential preference | Remember cookie choice | Active local storage | Until visitor clears it |
| Analytics | Audience measurement | Inactive | None |
| Advertising | Ad measurement or targeting | Inactive | None |
If future measurement is introduced, this table, the banner and the lawful-basis analysis must be updated before the tag is enabled. Consent must be as easy to withdraw as to give.
4. Public images and international requests
Article and homepage photographs use deterministic remote public-image URLs. When a page requests one, the remote media host receives the visitor's internet address and browser request metadata needed to return the file. The request may be processed outside the UK depending on that host's infrastructure. The images use a no-referrer policy, carry no visitor identifier and are not gated by the cookie choice because they are ordinary media requests rather than analytics.
The Open Graph image in page metadata uses the same public-image family and may be requested by messaging or indexing services when a link is shared. No image content has yet received visual or licence review. Before traffic, the operator should review and preferably self-host approved images. Self-hosting would reduce third-party requests, after which this section must be revised.
5. Purposes and lawful bases
At present, local form validation serves the visitor's request to preview the interface, and essential preference storage remembers the visitor's selection. No inquiry processing, newsletter, profiling, remarketing or advertising measurement occurs.
A future controller would need to assign a lawful basis under the UK GDPR for each activity. Consent may be appropriate for optional measurement and direct electronic communications. Legitimate interests may be considered for proportionate security logs, subject to a documented balancing assessment. Steps requested before entering a contract are unlikely to apply unless a real service offer exists. This publication currently offers none.
6. Retention
ProgtiProj retains no form submissions because none are sent. Consent preference remains locally until cleared. Future hosting logs need a short, stated retention period chosen by the operator and host. Connected inquiries would require a published period tied to correction handling or correspondence, followed by deletion or justified archival retention. Indefinite “just in case” retention is not acceptable.
7. Sharing, processors and transfers
No processor contracts or host were supplied. The remote image request is the only known external data disclosure controlled by current page content. A future host, mailbox provider, form processor or measurement service would need to be identified by category, governed by appropriate terms and assessed for international transfers. Where information leaves the UK, the controller must use a lawful transfer mechanism and assess practical protections.
ProgtiProj does not currently sell personal data, share it for behavioural advertising or make automated decisions about visitors.
8. UK data protection rights
Depending on the activity and lawful basis, people may have rights to be informed, access personal data, correct inaccurate data, erase data, restrict processing, receive portable data, object to processing and avoid solely automated decisions with significant effects. Consent can be withdrawn for future processing. These rights are not absolute, and a controller may need to retain limited information where law permits or requires it.
A real request route must verify identity proportionately and respond within the applicable statutory period. The current mailbox cannot do that. If a concern is not resolved after launch, a person may complain to the UK's independent supervisory authority for data protection. The authority's official public service should be used to find current complaint channels. This generic wording avoids presenting an unverified contact detail.
9. Security
The static form's no-send design avoids central collection. That is a data-minimisation choice, not a security guarantee. Future processing would need encrypted transport, access controls, updates, backups, incident handling, least-privilege access and tested deletion. Sensitive vulnerability reports should use a separately designed route rather than the general editorial form.
10. Children and sensitive data
The publication is general educational reading and does not knowingly target children or seek special-category data. Visitors should not place health information, political views, biometric information, criminal allegations, credentials or confidential source code into the preview form. A future operator must assess audience and age-related duties before collection.
11. Changes and contact
Material changes should receive a new effective date and a plain explanation. Enabling a form, analytics or advertising would be material. The controller's real name, address and monitored privacy contact must appear here before that happens.
For now, review the no-send inquiry explanation, the proposed terms and the operator gap. The unverified address is editor@progtiproj.com.
Current limitation
Without an identified controller and reviewed processing record, this draft cannot support public collection or satisfy all operator-specific duties under the UK GDPR and Data Protection Act context.