A clear, non-marketing description of the personal data SQ Magazine processes about EEA and UK readers, why we hold it, and how to take it back. This page is a companion to the Privacy Policy.
Who Holds the Data
SQ Magazine is operated by Barry Elad as the named controller under Article 4(7). No DPO is appointed; the operator handles all GDPR correspondence directly at media@sqmagazine.co.uk.
Data Inventory
The following is the complete set of personal data we touch in the ordinary course of running the site.
Reader-side, set without identification
- Anonymized analytics records from Google Analytics 4 (IP-anonymized, no Google Signals, no remarketing audiences)
- HTTP server logs at the host: IP, URL, timestamp, user agent. Used for abuse detection and rotated within 30 days
Reader-side, set with explicit action
- Newsletter: email address, subscription date
- Comments: name, email (hidden), IP (hidden, held in WP logs), comment text
- Contact form: name, email, message body
We do not collect:
- Phone numbers
- Postal addresses
- Payment data (we do not sell anything)
- Special-category data under Article 9 (race, religion, health, biometrics, sexual orientation, political views, trade union membership)
If a reader includes special-category data inside a comment or contact message, we apply the standard retention rules and do not process it further.
Why We Are Allowed to Hold Each Item (Article 6)
| Item | Lawful basis |
|---|---|
| Newsletter address | (a) Consent |
| Optional analytics cookies | (a) Consent |
| Comment data | (f) Legitimate interests in moderation |
| Aggregated analytics for editorial decisions | (f) Legitimate interests |
| Security logs | (f) Legitimate interests in defending the site |
| Contact form replies | (b) Honoring a specific reader request |
We have a written Legitimate Interests Assessment for every (f) basis. It is available to a supervisory authority on request.
How Long We Keep Each Item
- Analytics: up to 14 months in GA4
- Newsletter: until you unsubscribe, plus 30 days suppression
- Comments: while the article is online; deleted on request
- Contact submissions: 24 months from last reply
- Server logs: 30 days, longer only if a security investigation is active
Rights You Hold Under the Regulation
The seven core rights, with the relevant article number:
- Article 15, Access. We send a copy of your data
- Article 16, Rectification. We correct anything inaccurate
- Article 17, Erasure. We delete, subject to the exceptions in 17(3) (notably, our journalistic-purposes exemption under Article 85)
- Article 18, Restriction. We freeze processing while a question is open
- Article 20, Portability. We export the data you gave us in JSON
- Article 21, Objection. You can object to any (f)-basis processing, including marketing
- Article 7(3), Withdrawal of consent. You can revoke consent at any time
Article 22 (automated decision-making) is not engaged because we do not run any automated decisioning that produces legal or similarly significant effects.
Exercising a Right
Send an email to media@sqmagazine.co.uk with the subject line “GDPR Request: [Right]” (for example, “GDPR Request: Erasure”). A simple email is sufficient. We will reply within one month under Article 12(3), extendable by two months for complex requests with notice given inside the first month.
We may verify your identity before acting, particularly for access and erasure requests, to comply with Recital 64.
Cross-Border Transfers
Some processors operate in jurisdictions outside the EEA and the UK. We rely on:
- The 2021 European Commission Standard Contractual Clauses
- The UK International Data Transfer Addendum (IDTA) where UK GDPR applies
- The EU to US Data Privacy Framework and the UK to US Data Bridge for certified US recipients
If you want the list of processors and the transfer mechanism in force for each, request it under Article 15.
Where to Complain
Article 77 lets you complain to your local regulator. The ones most relevant to our readership:
- UK: Information Commissioner’s Office, ico.org.uk
- Republic of Ireland: Data Protection Commission, dataprotection.ie
- Other EEA states: the directory at edpb.europa.eu
- Switzerland: edoeb.admin.ch
Revision Cadence
We revise this document whenever our processors or data flows change. The date below records the last substantive review rather than a fixed schedule, so it moves only when the policy itself does. Last reviewed: May 5, 2026.