Back to site

Legal

Privacy Policy

Last updated: July 23, 2026

This policy explains how Rightsignal handles personal data when someone visits the website, submits a case, communicates with the team, purchases or receives services, or uses the client portal. It also explains the choices and rights available to individuals under applicable law.

1. Scope and roles

Rightsignal determines how personal data is used for website operation, case intake, service delivery, client support, security, and business administration. When a client provides data about another person for an authorized enforcement matter, Rightsignal may also process that information on the client's documented instructions and only for the requested work.

This policy applies to the public website, case-request forms, service correspondence, case workspaces, reports, and authenticated client-portal features. Third-party websites and platforms reached through external links are governed by their own privacy notices.

2. Personal data we collect

Please do not submit passwords, private keys, full payment-card details, or personal data that is not necessary for the case.

3. Sensitive and sexually explicit material

Some enforcement requests may concern intimate imagery, nudity, sexual content, identity documents, private account information, or data about a person's sex life or sexual orientation. Rightsignal treats this material as restricted evidence and processes it only where it is necessary, authorized, and permitted by applicable law.

A submission may be restricted, declined, or deleted if the sender cannot demonstrate lawful authority to provide the material.

4. Why we process data and the legal bases

Where data-protection law requires a legal basis, Rightsignal relies on one or more of the following:

When processing is based on legitimate interests, Rightsignal considers the necessity of the processing and the impact on the individuals concerned. Rightsignal does not make decisions producing legal or similarly significant effects solely through automated processing.

5. How we use personal data

6. Client portal and server sessions

The client portal uses a strictly necessary, signed server-session cookie named rs_portal_session. It is marked HttpOnly, Secure, and SameSite=Strict, expires after 12 hours, and is cleared when the user logs out. The cookie contains a signed account identifier and expiry information; it does not contain the account password.

Authenticated portal responses are marked not to be stored by shared browser caches. Portal pages may display case information from an approved case workspace, including Notion where configured. Users should keep credentials confidential and log out when using a shared device.

7. Local storage, cookies, and analytics

Case-request details are kept in the open form only while the user prepares and submits the request. Rightsignal does not save the full form payload, target URLs, contact details, evidence context, or case description in persistent browser local storage.

A message or free-scan request is stored securely on the server before email delivery is attempted. This prevents a temporary email-provider or network failure from losing the enquiry. Incomplete details may be retained with an internal manual-review flag. No enforcement work begins until Rightsignal verifies authority and agrees the scope. The browser does not retain a copy after the server confirms receipt.

After the server confirms receipt, the case ID and selected plan may be placed temporarily in sessionStorage solely to display the confirmation page. That one-time summary is removed when the confirmation page reads it and is also cleared when the browser tab closes.

Rightsignal uses strictly necessary session technology for authenticated features. Cloudflare may process network and request information to deliver, secure, and measure the website. Rightsignal does not sell personal data and does not use the website data described in this policy for third-party behavioural advertising.

8. Recipients and service providers

Personal data may be disclosed only as needed to the following categories of recipients:

Some reporting systems require complainant or rights-holder details. Rightsignal will include client-provided identity or authorization information only where it is necessary for the selected route.

9. International data transfers

Rightsignal, its service providers, and enforcement recipients may process data in countries other than the country where the user is located. Those countries may have different data-protection laws.

Where required, transfers are supported by an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, an applicable Data Privacy Framework, or another legally recognized safeguard. Rightsignal also uses vendor data-processing terms, purpose limitations, access controls, and data minimization as appropriate to the transfer.

10. Retention schedule

Rightsignal applies the following retention periods unless a longer period is required by law, an active dispute, or a documented legal hold:

Service providers may retain limited security, delivery, and compliance records under their own documented schedules and legal obligations. Data is anonymized or deleted when its applicable retention period ends.

11. Security

Rightsignal uses proportionate technical and organizational safeguards, including encrypted transport, restricted access, signed secure sessions, no-store controls for authenticated API responses, data minimization, and redaction of public proof materials. No internet transmission or storage system can be guaranteed to be completely secure.

12. Privacy rights

Depending on location and applicable law, an individual may have the right to:

Withdrawal of consent does not affect processing that was lawful before withdrawal. Rights are not absolute and may be limited by legal obligations, legal claims, security needs, or the rights of others. If required data is deleted or consent is withdrawn, Rightsignal may be unable to continue the relevant case or portal service.

13. How to submit a privacy or deletion request

Submit a request through the website contact form or reply to existing Rightsignal service correspondence. Start the message with Privacy Request and identify the request as Access, Correction, Deletion, Restriction, Portability, Objection, or Consent Withdrawal. Include the email address used for the case, the case ID if known, and the data or time period covered by the request.

Rightsignal may request proportionate information to verify identity and authority before disclosing or deleting data. Valid requests are answered within one month where required by applicable law. That period may be extended where the request is complex or numerous, with notice as required by law. Deletion is applied to active systems and then to backups through the retention cycle described above.

14. Minors

The service is intended only for persons aged 18 or older. Rightsignal does not knowingly accept clients or collect personal data directly from children. A person under 18 should act through a parent, guardian, attorney, agency, or other lawful representative. Users must not submit sexual or intimate material involving any person under 18.

If Rightsignal identifies or reasonably suspects that submitted material involves sexual exploitation of a minor, ordinary case processing may be suspended, access will be restricted, and the material may be preserved, deleted, or reported to competent authorities as required by applicable law and safety procedures.

15. Changes to this policy

This policy may be updated when services, providers, legal requirements, or data practices change. The revised version will be posted on this page with a new “Last updated” date. Material changes may also be communicated through the website, portal, or service correspondence.