Privacy Policy
Privacy Policy for Example Journal
- Effective date
- 2026-09-23
01Introduction
This Privacy Policy explains how Example Media Ltd (fictional) processes personal information in connection with Example Journal at https://example.com. It takes effect on 2026-09-23. It is based on the service practices described by its operator and should be read together with notices shown when information is collected.
02Who operates this service
Example Media Ltd (fictional) is the business responsible for this policy and is established in Ireland, with a postal address at 1 Example Street, Example City.
03Scope
This policy applies to the website offered under the Example Journal name. It does not govern independent third-party services that publish their own privacy terms.
05Sources of information
Information comes from users directly and automatic collection from the devices used to access the service. Information received from another source is handled for the purposes described in this policy and subject to applicable restrictions.
06How we use information
Information is used for providing and securing the service; managing accounts, support, payments, and communications; and analytics and product improvement. It may also be used to prevent misuse, establish or defend legal claims, meet legal obligations, and enforce service terms where those activities are relevant and permitted.
07Messages and email
The service sends marketing messages using Mailchimp. Contact details are used for delivery, service administration, and the purposes described when the details are collected.
Marketing messages can be stopped through the unsubscribe link in every newsletter. The operator measures message opens or link interactions; those events are used to understand delivery and engagement.
08EU legal bases for processing
For processing governed by the EU GDPR, the relied-on legal bases are performance of a contract or steps requested before a contract, consent, and legitimate interests. The operator's purpose-to-basis mapping is: newsletter and analytics: consent; publishing the website: contract; security and abuse prevention: legitimate interests. Legitimate interests include keeping the website secure and preventing abuse, balanced against affected rights and expectations. Consent can be withdrawn for future processing at any time without affecting processing that was lawful before withdrawal.
09UK legal bases for processing
For processing governed by the UK GDPR, the relied-on legal bases are performance of a contract or steps requested before a contract, consent, and legitimate interests. The operator's purpose-to-basis mapping is: newsletter and analytics: consent; publishing the website: contract; security and abuse prevention: legitimate interests. Legitimate interests include keeping the website secure and preventing abuse, balanced against affected rights and expectations. Consent can be withdrawn for future processing at any time without affecting processing that was lawful before withdrawal.
10Cookies and tracking technologies
The service uses essential storage and cookies and analytics technologies. The operator states that non-essential technologies are handled as follows: non-essential technologies start only after the user consents. Preferences can be reviewed or changed through the Cookie settings link in the website footer. Browser controls may also limit storage, but blocking essential storage can prevent features from working.
11Analytics
The service uses standard product analytics with Google Analytics to understand service operation, usage, errors, and improvements. Analytics data may include technical, device, interaction, approximate-location, and identifier information according to the selected configuration and provider controls.
12Sharing and disclosures
Information may be disclosed to service providers for the purposes described in this policy, subject to contracts and legal limits where required. It may also be disclosed to authorities, courts, advisers, or transaction counterparties when reasonably necessary for law, safety, claims, or a business reorganization. Selected service providers include Cloudflare and Mailchimp.
13International transfers
Information may be processed outside Ireland. The stated location and safeguard approach is: European Commission standard contractual clauses. For EU information, the transfer mechanism is: European Commission standard contractual clauses. Users may request information about the mechanism used. For UK information, the transfer mechanism is: European Commission standard contractual clauses. Users may request information about the mechanism used.
14Data retention
The retention model is: records are kept while the account or relationship remains active and for a justified period afterward. Records may be kept longer when reasonably necessary for security, disputes, tax, accounting, fraud prevention, legal obligations, or enforcement. Deletion or de-identification follows the stated model and applicable law.
15Security
The operator uses encryption and access restrictions, selected according to the nature and risk of the information. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.
16Children's privacy
The service is intended for a general audience. If the operator learns that information was collected from a child contrary to the stated audience or applicable law, it will take reasonable steps to delete it and may ask for age or authority verification.
17Your choices and privacy rights
Depending on location and processing, users may ask to access, correct, delete, restrict, or receive information; withdraw consent; unsubscribe; object; or opt out of sale, sharing, or targeted advertising. Requests are supported through the consent and preference tool or by email to privacy@example.com. The operator may verify identity and authority, apply legal exceptions, and explain a denial and available appeal where required.
18European Economic Area privacy rights
The EU GDPR has applied since May 25, 2018. Where it applies, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the competent supervisory authority. Rights depend on the processing, lawful basis, and statutory exceptions. Requests may be made through the consent and preference tool or at privacy@example.com.
19United Kingdom privacy rights
Where the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, apply, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the UK Information Commissioner's Office. Rights depend on the processing, lawful basis, and statutory exceptions. Requests and data-protection complaints may be made through the consent and preference tool or at privacy@example.com. The operator will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate without undue delay, keep the complainant informed, and communicate the outcome.
20Third-party links and services
The service integrates or links to Cloudflare and Mailchimp. Those providers may act independently and publish separate privacy terms. The operator is not responsible for an independent service's practices, and users should review its notice before supplying information.
21Changes to this policy
This policy may be updated to reflect service, legal, or operational changes. The current version will be posted at https://example.com with a revised effective date. Additional notice or consent will be provided only when required by applicable law.