Skip to main content
Editorial reference only. Independent editorial knowledge base on digital journalism. No accreditation, no qualification, no award of any kind, and no guarantee of employment or publication.
Newsroom Horizon

Privacy · GDPR notice

Privacy notice

What this site stores, why the two storage keys exist, how Consent Mode v2 is configured, what happens to correspondence, and how to exercise your rights with the Data Protection Commission as supervisory authority.

Not legal advice. This notice describes how this particular site operates. It is not a template and not advice to other publishers; take qualified advice on your own arrangements.
01

1. Who controls the data

This notice explains how personal data is handled in connection with the newsroomhorizon.com website. The controller is Newsroom Horizon Ltd, CRO 712845, registered in Ireland, with its registered address at 12 Fenian Street, Dublin 2, D02 XY45, Ireland. Correspondence about this notice, and any request to exercise a right described below, should be sent to [email protected] with the subject line “Privacy”.

The notice covers the website only. It does not cover any third-party service you may use to reach the site, such as a search engine or a social platform, each of which processes your data under its own terms and its own responsibility. Nothing in this notice is legal advice, including to other publishers who may read it as an example.

02

2. What this site does not do

It is easier to describe the absences first, because they remove most of the questions people usually have. This site installs no analytics tag, no advertising tag, no conversion pixel, no heat-mapping script and no session recorder. It loads no hosted fonts, no content delivery network, no embedded video, no map widget, no social button and no comment system. There are no external requests of any kind: the stylesheet, the script and the three vector graphics are all served from this domain.

There is no account system, no login, no newsletter and no mailing list, and nothing is for sale. The contact page carries a short enquiry form, and apart from that form no page asks you for your name, your address or any other identifying detail. The only personal data this desk ordinarily holds is the content of correspondence that a reader chooses to send, whether by email or through that form.

03

3. Information stored on your device

Two small values may be stored on your device, both of them essential to functions you have asked for. The first records that you acknowledged the entry notice, so that it is not shown again on every page. The second records your choice on the consent bar, so that the bar does not reappear after you have decided. Each is written both to local storage and to a first-party cookie with a maximum age of one year, and neither contains an identifier, a profile or anything about what you read.

The cookie page lists both keys with their exact names, purposes and lifetimes, and provides a control that clears the consent choice and reopens the bar. You can also clear both values at any time through your browser’s own settings. Clearing them has no effect other than causing the notice and the bar to appear again.

04

4. Consent Mode v2 on this site

Every page declares default consent states in the document head, before anything else runs. Advertising storage, advertising user data and advertising personalisation are set to denied. Analytics storage is set to denied. Functionality storage and security storage are granted, because they are necessary for the site to work. A wait period of 500 milliseconds is declared so that any consent update is applied before other behaviour.

If you select “Allow measurement” on the consent bar, the analytics signal is updated to granted and your choice is stored. All three advertising signals remain denied permanently and are never updated to granted under any circumstances. Because no measurement or advertising tag is installed on this site, granting the analytics signal currently causes nothing to be collected; the mechanism exists so that the site’s declared state is accurate and auditable from the first page view.

05

5. Server logs

Like any website, this site is delivered by a web server, and the hosting infrastructure may record ordinary technical information as part of delivering and protecting the service: the requesting network address, the time of the request, the file requested, the response status, the referring address where the browser supplies one, and the user-agent string. This information is generated by the hosting layer rather than by any script on the page.

Where such logs contain personal data, the lawful basis is legitimate interests under Article 6(1)(f) of the GDPR — specifically, operating the service, diagnosing faults and protecting against abuse. Logs are not used to build reader profiles, are not combined with any other source, are not shared for marketing and are retained only for the short period necessary for those purposes.

06

6. Correspondence and the enquiry form

If you email the desk, the message and the address it came from are processed in order to answer you. The enquiry form on the contact page is treated in exactly the same way: the fields it submits — your name, your email address, the subject you selected and your message — are used only to answer that enquiry and for no other purpose. The lawful basis for either route is legitimate interests under Article 6(1)(f) — responding to an enquiry from the person who sent it — or, for a data-protection request, compliance with a legal obligation under Article 6(1)(c).

Correspondence from both routes is kept only for as long as it takes to deal with the matter and any reasonable follow-up, after which it is deleted. It is never used for marketing, never added to any list, and never disclosed to a third party except where disclosure is required by law; the only recipients are the hosting provider and the email provider described in section 9. The form offers no marketing option because there is no marketing to opt into, and the consent box on it confirms one thing only: that what you have entered may be used to reply.

Please do not send confidential source material, identity documents, health data, passwords or other credentials, or personal data about other people, by email or through the form. Neither is a secure submission channel and neither can offer protection for such material.

Data categories and how each one is handled
CategoryWhere it comes fromPurpose and lawful basisRetention
Technical log dataThe hosting layer, on every requestDelivering the site, diagnosing faults, protecting against abuse — legitimate interests, Article 6(1)(f)Short operational period only
Notice and consent valuesWritten to your own device when you acknowledge the notice or answer the consent barRemembering a choice you have made — necessary for a function you asked for; clearable at any timeOne year maximum, or until you clear them
Email correspondenceThe message you choose to send to the published addressAnswering your enquiry — Article 6(1)(f), or Article 6(1)(c) for a data-protection requestUntil the matter and any follow-up are closed
Enquiry-form fieldsName, email address, subject and message, as submitted by you on the contact pageAnswering your enquiry — Article 6(1)(f), or Article 6(1)(c) for a data-protection request; never marketingUntil the matter and any follow-up are closed

No category above is used to build a reader profile, and none is combined with any other source. There is no category of special-category data on this site, because none is sought and readers are asked not to send any.

07

7. Your rights

Under the GDPR you have the right of access to your personal data, and rights to rectification, erasure, restriction of processing, data portability where applicable, and objection to processing carried out on the basis of legitimate interests. Where processing is based on consent, you may withdraw that consent at any time, and withdrawal is as easy as giving it.

Requests should be sent to [email protected] with the subject line “Privacy”. Proportionate verification of identity may be requested, but only where it is genuinely necessary to establish that a request comes from the person concerned. In practice, because this site holds so little, most access requests can be answered by confirming that no record beyond the correspondence itself exists.

08

8. Supervisory authority and complaints

The supervisory authority for data protection in Ireland is the Data Protection Commission. You have the right to lodge a complaint with it, or with the supervisory authority in the member state of your habitual residence, place of work or the place of the alleged infringement. You do not have to contact this desk first, although raising the matter directly is usually faster.

The Data Protection Commission is named here as the relevant public authority. That is a statement of the statutory position and not a claim of any relationship: this site is not registered with, approved by or supervised by the Commission in any capacity beyond the ordinary obligations that apply to any controller, and holds no accreditation from it.

09

9. Transfers, recipients and security

This desk does not sell, rent or share personal data. There are no advertising partners, no data resellers and no analytics processors. The only recipients of any personal data are the hosting provider that delivers the site and the email provider that carries correspondence, each acting as a processor under contract and only to the extent necessary to provide those services.

The site is served over an encrypted connection and consists of static files, which removes the classes of risk associated with databases and user accounts. The enquiry form is posted over the same encrypted connection, and what it submits goes to the desk as correspondence rather than into any reader database, because there is none. Cookies set by the site use the SameSite=Lax attribute. No special category data is sought or knowingly processed, and readers are asked not to send any.

10

10. Children and changes to this notice

The site is a general-interest editorial reference intended for adults. It is not directed at children, does not knowingly collect data from them, and contains no feature that would require age verification. It also contains nothing that a younger reader could not safely read.

This notice is reviewed on the same cycle as the rest of the site, at least once every twelve months, and is amended whenever the site’s technical arrangements change. Material changes are described in the notice itself rather than applied silently. The version in force is the one published on this page at the time you read it.

Questions about privacy

Does this site collect my personal data?

Only what you choose to send: an email, or the four fields of the enquiry form on the contact page. Beyond that and ordinary hosting logs, nothing. There is no account system, no mailing list and no measurement or advertising tag.

What happens to what I type into the contact form?

It is used to answer your enquiry and nothing else, on the same lawful basis as an email, kept only until the matter and any reasonable follow-up are closed. It is never used for marketing and reaches no recipient beyond the hosting and email providers.

What are the two stored values for?

One records that you acknowledged the entry notice; the other records your choice on the consent bar. Neither contains an identifier or anything about what you read, and both can be cleared from the cookie page or in your browser.

Why declare Consent Mode if there are no tags?

So that the site’s declared state is accurate and auditable from the first page view, with all advertising signals denied from the outset and permanently.

How do I complain?

Write to the desk with the subject line “Privacy”, or contact the Data Protection Commission directly. You are not required to approach this desk first.