1. Who we are
TDisrupt (“TDisrupt”, “we”, “us”, “our”) is operated by SUF Digital UK Ltd, a company registered in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller of personal data collected through this website.
If you have any question about this policy or how we handle your data, contact our editorial and privacy team at [email protected]. Press and media enquiries go to [email protected].
2. What data we collect
Depending on how you use TDisrupt, we may collect the following categories of personal data:
- Email address and preferences: when you subscribe to our newsletter or briefings, we collect your email address and the subscription choices you make.
- Contact and correspondence data: your name, email address, subject and message content when you use a contact form or email us, including tips, corrections and press enquiries.
- Technical data: IP address, browser type and version, device type, operating system, screen resolution, language, referring URL and time zone.
- Usage data: pages viewed, articles and briefs read, time on page, clicks, scroll depth, search queries and the path you take through the site.
- Cookie and similar-technology data: identifiers stored on your device by cookies, local storage or pixels (see the Cookies section below).
- Push notification data: if you opt in, a device or browser token that lets us send you alerts about breaking stories.
- Advertising data: where advertising is displayed, identifiers and interest or contextual signals used to serve and measure ads.
We do not knowingly collect special category data (such as health, religion or political opinions) and ask that you do not send it to us. Our site is not directed at children under 13, and we do not knowingly collect their data.
3. How we collect your data
- Directly from you: when you subscribe, submit a form, email us, or change your preferences.
- Automatically: through server logs, cookies and similar technologies as you browse the site.
- From third parties: from our analytics, newsletter, push-notification, hosting and advertising providers, who act on our behalf or, in the case of advertising partners, in their own right.
4. Why we use your data
We use personal data only for specified purposes:
- Newsletters and briefings: to send the editorial emails you have asked for, manage your subscription and measure how emails perform.
- Analytics: to understand how readers use the site, which stories resonate, and where we should invest editorially.
- Security and fraud prevention: to protect the site, detect abuse, block spam and bots, and keep our systems reliable.
- Site improvement: to fix bugs, test features, improve performance and accessibility, and develop new products.
- Push notifications: to deliver breaking-news alerts if you have opted in.
- Advertising: where used, to display, measure and improve advertising and to support our independent journalism.
- Responding to you: to reply to enquiries, tips, corrections and press requests.
- Legal compliance: to meet legal, regulatory and accounting obligations and to establish or defend legal claims.
5. Legal basis for processing
Under UK GDPR we must have a lawful basis for each use of your data. We rely on the following:
| Purpose | Lawful basis |
|---|---|
| Newsletters and marketing emails | Consent (Art. 6(1)(a)); you can withdraw at any time |
| Push notifications | Consent (Art. 6(1)(a)) |
| Non-essential cookies (analytics, advertising) | Consent, as required by PECR |
| Security, fraud prevention, essential site operation | Legitimate interests (Art. 6(1)(f)) |
| Site improvement and aggregate analytics | Legitimate interests, or consent where cookies require it |
| Responding to enquiries and press requests | Legitimate interests |
| Tax, accounting, regulatory and legal claims | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance them against your rights and freedoms and will not proceed where your interests override ours. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
6. Third-party services and sharing
We do not sell your personal data. We share it only with trusted service providers who help us run TDisrupt, under written contracts that require them to protect it and use it only on our instructions. Categories include:
- Hosting and infrastructure providers: to serve the website, store content and deliver it securely.
- Analytics providers: to measure traffic and usage, and report aggregate trends.
- Newsletter and email delivery providers: to store subscriber lists, send emails and track delivery.
- Push-notification providers: to register devices and deliver alerts.
- Advertising partners and networks: where advertising is shown, to serve, measure and limit ads. These partners may act as independent controllers of the data they collect via their own cookies.
- Professional advisers, auditors and legal authorities: where necessary to comply with law or protect our rights.
If SUF Digital UK Ltd or TDisrupt is involved in a merger, acquisition or restructuring, your data may be transferred to the successor, who will be bound by this policy or must notify you of changes.
8. How long we keep your data
We keep personal data only for as long as necessary for the purposes set out above, including to satisfy legal, accounting or reporting requirements. As a guide:
- Newsletter subscriptions: until you unsubscribe, after which we keep a minimal suppression record so we do not email you again.
- Contact and press correspondence: generally up to 24 months after the matter closes, unless a longer period is needed for legal reasons.
- Analytics and log data: retained in identifiable form for a limited period and then deleted or anonymised.
- Cookie data: for the lifetime of each cookie, which is generally 13 months or less.
- Push notification tokens: until you opt out or the token expires.
When data is no longer needed, we delete it or irreversibly anonymise it.
9. Your rights under UK GDPR
You have the following rights over your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Deletion: ask us to erase your data in certain circumstances (the “right to be forgotten”).
- Restriction: ask us to pause processing of your data in certain circumstances.
- Objection: object to processing based on legitimate interests, and to direct marketing at any time.
- Portability: receive your data in a structured, commonly used format where processing is based on consent or contract.
- Withdrawal of consent: withdraw consent at any time, for example by using the unsubscribe link in any email.
To exercise any right, email [email protected]. We may need to verify your identity, and will respond within one month, extendable by up to two further months for complex requests. There is normally no fee.
You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve your concern first, so please contact us.
10. International data transfers
Some of our service providers are located, or store data, outside the United Kingdom, including in the European Economic Area and the United States. Where personal data is transferred outside the UK, we ensure it is protected by at least one of the following safeguards:
- The country is covered by UK “adequacy regulations”, including the UK Extension to the EU–US Data Bridge for certified US recipients.
- The transfer is governed by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
- Another lawful transfer mechanism or exception under UK GDPR applies.
Contact us if you would like more information about the safeguards applied to a particular transfer.
11. How we protect your data
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure, including:
- Encryption of data in transit using HTTPS/TLS.
- Access controls, least-privilege permissions and authentication for staff and contractors.
- Vetting of service providers and contractual data protection commitments.
- Regular updates, monitoring and backups of our systems.
- Procedures to detect, investigate and, where required, report personal data breaches to the ICO and affected individuals.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to keep your data safe.
12. Links to other websites
TDisrupt articles and briefs link to external sites and embed third-party content such as social posts or videos. We do not control these sites and are not responsible for their privacy practices. We encourage you to read their policies before sharing personal data.
13. Changes to this policy
We may update this policy to reflect changes in our practices, technology or the law. The “last updated” date at the top shows when it was last revised. For material changes we will take reasonable steps to notify you, such as a notice on the site or an email to subscribers, and where required we will seek fresh consent.
14. Contact us
- Privacy and general enquiries: [email protected]
- Press and media enquiries: [email protected]
- Data controller: SUF Digital UK Ltd, United Kingdom