The Script Meridian globe mark Script Meridian A community of Frontier
and Radio users
Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, who ever sees it, and the rights you hold over it. Written to be read rather than to be survived.

Version 3.2 · Effective 1 September 2026 · Supersedes all previous versions · Ask a question about this document

1. Who we are and how to reach us

Script Meridian (“Script Meridian”, “we”, “us”) publishes this website, operates the Script Meridian community list, and provides the consulting services described on the services page. For the purposes of the UK GDPR, the EU GDPR and comparable legislation, Script Meridian is the data controller for the personal data described in this policy.

We do not employ a statutory Data Protection Officer, because our processing does not meet the thresholds that require one. Privacy enquiries are handled by a named partner and answered within five working days.

2. The short version

This section is a summary. It is not a substitute for the detail that follows, but it is accurate.

  • This website runs no analytics, no advertising, no tracking pixels and no third-party scripts of any kind. Every file it loads comes from our own server.
  • The contact and community forms validate in your browser. In the published static build they do not transmit anything to us at all; where the forms are connected to our mail system, the contents are emailed to us and stored with our correspondence.
  • We store two keys in your browser's local storage: your light or dark reading preference, and whether you dismissed the storage notice. Neither is a cookie and neither leaves your device.
  • Our web server keeps access logs for 30 days, with IP addresses truncated after 24 hours.
  • We never sell personal data, and we have never shared it for advertising purposes.
  • You can ask us what we hold, ask for a copy, ask for corrections, or ask us to delete it.

3. The personal data we collect

3.1 Information you give us deliberately

WhereWhatRequired?
Contact formName, email address, organisation, telephone number, subject, budget band, message body, consent flagName, email, subject, message and consent are required; the rest are optional
Community post formName, email address, board, message body, consent flag All required
Newsletter formEmail addressRequired
Community membershipDisplay name, email address, subscription preferences, posting historyDisplay name and email required
Client engagementsContact details for named individuals, billing details, and whatever appears in the systems we are engaged to work onAs set out in the engagement contract

3.2 Information collected automatically

Our web server writes an access log entry for each request: the requested path, the HTTP status, the number of bytes served, the referring page where the browser supplies one, the user-agent string, and the requesting IP address. IP addresses are truncated to their network portion after 24 hours; the truncated records are deleted after 30 days.

We do not operate any analytics platform, first- or third-party. There are no tracking pixels, no fingerprinting scripts, no session recording and no A/B testing infrastructure on this site.

3.3 Information from third parties

We occasionally receive contact details from a client who introduces us to a colleague or a supplier. Where that happens we tell the person within one month of receiving their details, and explain where the details came from.

3.4 Special category data

We do not seek, and have no use for, special category data as defined in Article 9 of the GDPR — data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation. Please do not include such information in a message to us. If it reaches us inside a system we are auditing, it is handled under the confidentiality and minimisation terms of the engagement contract and is never copied out of the client's environment.

4. Why we process it, and our lawful basis

PurposeLawful basisOur reasoning
Replying to an enquiryLegitimate interests, and steps prior to entering a contract You wrote to us asking for a reply; answering is the obvious expectation.
Delivering a paid engagementPerformance of a contract We cannot do the work without processing the contact and access details it requires.
Operating the community listConsent, withdrawable at any time You chose to join; one email removes you.
Sending the monthly newsletterConsent Explicit opt-in, with an unsubscribe link in every issue.
Keeping access logsLegitimate interests Necessary to diagnose faults, detect abuse and keep the service available.
Keeping accounting recordsLegal obligation Tax and company law require retention for a defined period.
Establishing or defending legal claimsLegitimate interests Limited to what is necessary, and only where a claim is live or reasonably anticipated.

Where we rely on legitimate interests, we have carried out and documented a balancing assessment. You may ask for a summary of that assessment by writing to [email protected], and you have the right to object to that processing as described in section 7.

5. How long we keep it

CategoryRetentionThen what
Enquiry that does not become an engagement24 months from the last message Deleted from mail and from the enquiry record
Enquiry that becomes an engagement7 years from the end of the engagement Deleted, except accounting records held for the statutory period
Community membership recordFor as long as the membership is active, then 12 months Account deleted; posts anonymised rather than removed, to keep threads readable
Newsletter subscriptionUntil you unsubscribe, then 30 days Address removed; a one-way hash is kept only to prevent accidental re-subscription
Web server access logs30 days (IP truncated at 24 hours)Deleted
Security incident records6 yearsDeleted
Accounting and tax recordsAs required by law, currently 7 yearsDeleted

Backups follow a separate cycle. Encrypted backups are retained for 35 days on a rolling basis, so data you ask us to delete may persist in a backup for up to 35 days after deletion from live systems. Restored backups are reconciled against deletion requests before being returned to service.

6. Who we share it with

We do not sell personal data. We have never sold personal data. We do not share personal data for advertising, profiling or list-building purposes.

We share personal data only with the following categories of recipient, each under a written contract that restricts them to acting on our documented instructions:

  • Hosting provider — operates the servers on which this site and our mail are held. Located in the European Union and the United States.
  • Email service provider — transmits and stores our correspondence and the community list.
  • Accounting service — processes invoices and statutory records.
  • Professional advisers — lawyers, auditors and insurers, where a specific matter requires it.
  • Public authorities — only where we are legally required to disclose, and only after checking that the request is valid and proportionate. Where we are permitted to tell you about such a request, we will.

If Script Meridian were to be acquired or merged, personal data would form part of the transferred assets. We would notify affected individuals before the transfer took effect and before any change in how their data is used.

7. International transfers

Script Meridian is established in the United States and works with clients in the United Kingdom, the European Economic Area and elsewhere. Personal data may therefore be transferred outside the country in which you live.

Where personal data is transferred out of the UK or EEA, we rely on one of the following safeguards:

  • An adequacy decision by the European Commission or the UK government covering the destination.
  • The Standard Contractual Clauses adopted by the European Commission, with the UK International Data Transfer Addendum where the UK GDPR applies, supported by a transfer risk assessment.
  • Your explicit, informed consent to a specific transfer, where no other basis is available.

You may request a copy of the relevant safeguard, with commercially confidential terms redacted, by writing to [email protected].

8. Your rights

Subject to the conditions and exemptions in applicable law, you have the following rights. Exercising any of them is free, and we will not treat you differently for having done so.

  1. Access. Ask whether we hold personal data about you, and receive a copy together with an explanation of how it is used.
  2. Rectification. Have inaccurate data corrected and incomplete data completed.
  3. Erasure. Ask us to delete personal data where there is no continuing lawful basis for holding it.
  4. Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  5. Portability. Receive data you provided, in a structured, commonly used, machine-readable format, and have it sent directly to another controller where technically feasible.
  6. Objection. Object to processing based on legitimate interests. Where you object to direct marketing, we stop immediately and without exception.
  7. Withdraw consent. Where processing relies on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before it.
  8. Automated decisions. Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We make no such decisions.
  9. Complain. Lodge a complaint with a supervisory authority, which in the UK is the Information Commissioner's Office and in the EEA is the authority for your country of residence. We would appreciate the chance to resolve the matter first.

8.1 How to make a request

Write to [email protected] with enough information for us to identify your records. We respond within one calendar month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you within the first month if we do. Where we cannot identify you from the information provided, we will ask for more — and we will not use anything you send for that purpose for any other reason.

8.2 Residents of California and other US states

Where state privacy legislation applies to you, you additionally have the right to know the categories of personal information collected, disclosed and sold; the right to delete; the right to correct; the right to opt out of sale or sharing; and the right not to be discriminated against for exercising any of them. We do not sell or share personal information as those terms are defined in that legislation. Requests may be sent to the same address and are verified by confirming control of the email address on the record.

9. Security

We apply the following measures, and review them annually:

  • TLS 1.2 or 1.3 for every connection to this site and to our mail systems, with HSTS enabled.
  • Encryption at rest for backups and for any working copy of client material.
  • Multi-factor authentication on every administrative account without exception.
  • Least-privilege access, reviewed quarterly, with access removed on the day a person leaves.
  • Separate credentials for each client environment; no shared logins, ever.
  • Encrypted, verified backups, with a restore drill performed quarterly.
  • A written incident response procedure, rehearsed annually.
  • No production data on personal devices, and full-disk encryption on all work devices.

No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach that is likely to result in a risk to your rights and freedoms, we notify the relevant supervisory authority within 72 hours and notify affected individuals without undue delay where the risk is high.

If you believe you have found a vulnerability, please write to [email protected]. We acknowledge within 48 hours, we will not pursue legal action against good-faith research conducted without accessing other people's data, and we are happy to credit you when a fix ships.

10. Children

This website and our services are intended for a professional audience and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to [email protected] and we will delete it promptly.

11. Local storage, cookies and tracking

This site sets no cookies. It stores two keys in your browser's local storage:

  • sm.theme — whether you chose light or dark reading.
  • sm.cookies — whether you dismissed the storage notice, so it stops reappearing.

Two further keys are written only if you use a form: sm.lastEnquiry, so the confirmation page can show you what you submitted, and sm.subscriber, so the newsletter field remembers that you subscribed. All four stay on your device, are never transmitted, and can be removed by clearing site data for this domain. The cookie policy covers this in full.

12. Changes to this policy

We review this policy at least annually and whenever our processing changes materially. The version number and effective date at the top of this page always reflect the current text, and previous versions are retained and available on request.

Where a change materially affects how we use personal data we already hold, we will give notice — by email to list members and clients, and by a prominent notice on this site — at least 30 days before the change takes effect, and where the law requires consent we will ask for it rather than assume it.

Questions come to a person

Privacy questions about this site or an engagement are answered by a named partner, not a ticket queue. Write to [email protected] or use the contact form.