MPThe Manchester Principles
How your data is handled

Privacy notice

Version 2026-08-15. This notice covers the consultation site for the Manchester Principles. It is written to be read, not to be survived.

Who is responsible

Controller: [CUSTODIAN BODY — name, registered address]. Until the summit appoints a custodian, the interim controller is the drafting group, contact [email protected].

Clause 5.3 applies to us as much as to anyone else: no commercial party with a material interest in mechanisms implementing the Principles should hold this data.

What we collect, and why

DataWhyBasisKept
Name, organisation, roleShown publicly beside your posts, so contributions carry attributionConsentUntil you delete your account
Email addressConfirming your account; the digest if you opted inConsentUntil you delete your account
Posts, amendments, supportsThe consultation recordConsentRetained as public record; anonymised on deletion
Hashed IP addressRate limiting and abuse prevention only. The raw address is never written to diskLegitimate interests30 days, then deleted automatically
One session cookieKeeping you signed inStrictly necessary90 days

No analytics. No advertising or tracking pixels. No profiling, and no automated decision-making.

Double opt-in

Registering sends exactly one confirmation email. Until you click the link in it we hold only your address and a timestamp, nothing is published, and no other mail is sent. Unconfirmed registrations are deleted automatically within 24 hours.

The weekly digest is separate, unticked by default, and withdrawable in one click from any digest email. Withdrawing it leaves your account and posts untouched.

Your rights

One honest caveat about erasure. Deleting your account removes your identity and contact details. Posts you have already made are anonymised — attributed to "Withdrawn account" — rather than destroyed, so the record of what was argued during the consultation stays intact. You consent to this at registration. If you need a specific post removed entirely, ask and we will consider it case by case.

Who else touches it

Two processors: Cloudflare (hosting and the D1 database) and Resend (the confirmation and digest emails). Both are bound by data-processing agreements. Data is stored in the EU/UK region where the platform offers it; where processing occurs outside the UK or EEA it is covered by the relevant standard contractual clauses or adequacy decision.

Security

TLS everywhere, a strict content-security policy, HTTP-only signed session cookies, Cloudflare Turnstile on registration, per-connection rate limits, and an append-only audit log of moderation and data-rights actions.

Moderation records

If a post of yours is hidden under the code of conduct, we keep the post, the reason and the name of the administrator who did it. That record is part of the accountability log described above and is included in any export you request. Hidden posts are not shown publicly.

Changes

If this notice changes materially we will email registered accounts and ask again for consent where the basis of processing changes. The version string at the top is stored against each registration, so we always know which notice you agreed to.

Last updated 15 August 2026 · Version 2026-08-15