Privacy Policy
Last updated: 31 March 2026
This Privacy Policy explains how DataProducts ("we", "us", "our") collects, uses, and protects your personal data when you use SanctionLog ("Service") at sanctionlog.com.
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data We Collect
When you subscribe to the Service, we collect:
• Email address
• Name (optional)
• Payment information (processed by Stripe — we do not store card details)
• Subscription status and history
• Email engagement data (opens, clicks) via our email service provider
We do not collect sensitive personal data. We do not require you to provide your date of birth, address, or phone number.
2. How We Use Your Data
We use your personal data to:
• Deliver the weekly newsletter to your inbox
• Process and manage your subscription and payments
• Send service notifications (e.g. payment failures, subscription renewal reminders)
• Respond to support queries
• Improve the Service based on engagement analytics
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
3. Legal Basis for Processing
We process your personal data on the following legal bases:
• Contract performance — to deliver the subscription service you have signed up for
• Legitimate interests — to improve the Service and prevent fraud
• Legal obligation — where required by law
4. Data Sharing
We share your data with the following third-party service providers solely to operate the Service:
• Stripe — payment processing (stripe.com/privacy)
• Brevo (Sendinblue) — email delivery (brevo.com/legal/privacypolicy)
• Ghost Foundation — newsletter platform (ghost.org/privacy)
All processors are bound by data processing agreements and operate in compliance with UK GDPR.
5. Data Retention
We retain your personal data for as long as your subscription is active and for 2 years after cancellation, unless a longer retention period is required by law.
You may request deletion of your data at any time by contacting us at [email protected].
6. Your Rights
Under UK GDPR, you have the right to:
• Access the personal data we hold about you
• Correct inaccurate personal data
• Request deletion of your personal data ("right to be forgotten")
• Object to processing of your personal data
• Request restriction of processing
• Data portability
• Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
7. Cookies
Our website uses minimal cookies necessary for the operation of the subscription portal (session management and authentication). We do not use advertising or tracking cookies.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. Payment data is handled exclusively by Stripe and is never stored on our servers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email. The current version is always available at sanctionlog.com/privacy.
10. Contact
For privacy-related queries or to exercise your rights, contact us at: [email protected]
DataProducts, England, United Kingdom.