FIRST LIGHT is the data controller for everything described in this notice. That means we decide what gets collected and what happens to it, and we are the ones answerable for it.
For anything to do with your data — a question, a correction, a deletion, or any of the rights set out in section 7 — write to [email protected]. It reaches us directly.
We have not appointed a Data Protection Officer, and we are not required to: we are not a public authority, we do not monitor anyone on a large scale, and we do not process special-category data.
Only what you type into a form, plus the page you submitted it from. We do not buy data about you, and we do not build a profile of you from anywhere else.
The free-text fields are yours to fill as you like. Please do not put anything in them that falls into the special categories under Article 9 of the GDPR — health or injury details, racial or ethnic origin, religious or political beliefs, sexual orientation, biometric data. We do not ask for any of it, we have no use for it, and we will delete it if it arrives.
Our forms carry a hidden field that only automated submissions fill in. It collects nothing about you.
Legitimate interests — Article 6(1)(f). You wrote to us about working together; reading that message and replying to it is what both sides expect, and it does not override your rights or freedoms.
That is the whole purpose. We use what you send to understand what you are asking and to answer it. Nothing else.
A form submission passes through a small number of service providers who act as processors for us, under contract, on our instructions only. They may not use your data for their own purposes.
We use no advertising trackers, no analytics cookies, and no third-party embeds that profile you. The typefaces are served from this site rather than from a font network, so simply reading this page sends your IP address to nobody but our host.
Both providers above are US-headquartered and may process data outside the UK and EEA. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and both providers self-certify under the EU–US and UK–US Data Privacy Framework. You can ask us for details of the safeguards that apply to your data.
We will disclose data to a public authority only where the law requires it of us.
Deletion means deletion from our live systems. Backups roll off on their own schedule and are not searched or used for any other purpose in the meantime.
Under the GDPR you have the following rights over your data. Exercising any of them costs nothing, and we will answer within one month.
Write to [email protected]. We may ask you to confirm who you are before we act, so that nobody else can use these rights against you.
If you think we have handled your data badly, tell us first — we would rather fix it. You do not have to, though. You can complain directly to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the data protection authority of the country you live or work in, or where the issue arose.
If we change how we handle what you send us, this notice changes with it and the date at the top moves. Material changes affecting data we already hold are sent to the email address you gave us.