Privacy notice
This notice sets out what data Inside the Operator collects from readers, why it is collected, how long it is retained, and what a reader can ask us to do about it under UK GDPR and the Data Protection Act 2018.

Data collected on this site
Inside the Operator is a static publication. The site does not run reader accounts, does not accept comments, does not run a forum, does not host any transactional workflow, and does not carry advertising. In ordinary browsing the site collects only the technical data any web server writes to its access log, which is the requesting IP address, the browser user-agent string, the URL of the page requested, and the timestamp of the request. That data is used to detect abusive traffic, to size infrastructure, and to identify malformed requests worth investigating. It is not used for any marketing, profiling, or advertising purpose, because none of those functions run on this site.
Where a reader emails the editor at [email protected], the email itself is the data collected. Emails are read by James Callaghan, stored in the editor's mailbox, and retained for as long as the correspondence remains an active thread or a live correction record. No email received by the editor is shared with any third party outside the site's editorial process, and no email address is added to any marketing list, because there is no marketing list to add to.
Cookies and analytics
Inside the Operator does not set any cookie on a reader's browser for advertising, targeting or cross-site tracking. Session cookies used strictly to remember display preferences may be set where required for accessibility purposes; those cookies expire at the end of the browser session and are not shared with any third party. The site does not run a third-party advertising script and does not embed third-party tracking pixels. The Google Search Console verification meta tag, where present, does not set a cookie and does not transmit reader data.
Aggregate analytics, where used, are limited to first-party server-side counts that read only the technical data described in the previous section. The site does not use browser fingerprinting, does not use any client-side analytics library that transmits data to a third party, and does not use a consent-management platform to gate content behind a cookie banner, because the site does not set the class of cookie that would require one under the Privacy and Electronic Communications Regulations. Reader browsing on this site is functionally anonymous.
How long we retain data
Server access log data is retained for a rolling ninety days for abuse detection and infrastructure sizing purposes, after which the log lines are deleted. Backups of the access log are held on the same rolling schedule and are not carried forward beyond the retention window. Where a specific incident, such as a malformed request pattern warranting review, requires a longer retention on a defined subset of log lines, that subset is held for the duration of the review and deleted at its close.
Editor correspondence is retained for as long as the thread remains active, and archived thereafter to a mailbox held under the same UK-based hosting arrangement. Where a correction has been applied to a page, the underlying correspondence supporting the correction is retained for a rolling twelve months so that a subsequent reviewer could audit the correction process end to end. No data collected on this site is transferred outside the United Kingdom for any purpose.
Your rights under UK GDPR and Data Protection Act 2018
Under UK GDPR and the Data Protection Act 2018 a reader has a set of statutory rights over any personal data this site holds on them. Those rights include the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to object to processing, and the right to data portability where applicable. Requests can be made by emailing the editor at [email protected], and a written response will be provided within the one-month statutory window set by the regulations.
The lawful basis on which this site holds server access log data is the site operator's legitimate interest in detecting abuse and sizing infrastructure, balanced against the reader's fundamental rights and freedoms. The lawful basis on which the editor's mailbox holds correspondence is the reader's own initiation of the correspondence and the site's legitimate interest in maintaining a correction record. Where a request under UK GDPR would conflict with a legal obligation to retain a specific record, the response will explain the conflict and any partial fulfilment available.
How to reach us and the ICO
The editor is contactable at [email protected]. This is the address for any subject access request, correction, deletion request, or general query about the data this site holds. The editor will acknowledge receipt within one working day and provide a substantive response within the one-month statutory window. Where a request cannot be fulfilled in full, the response will explain the reason and any partial fulfilment that is available under the applicable exemption.
A reader who is not satisfied with the site's handling of a personal data matter has the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk. The ICO is the UK's independent regulator for data protection and can be reached on 0303 123 1113 during standard working hours. Nothing on this page is legal advice, and nothing here restricts a reader's statutory rights under UK GDPR or the Data Protection Act 2018. If gambling is causing harm, the National Gambling Helpline on 0808 8020 133 is a free, confidential, 24-hour service and remains the recommended first call regardless of any privacy question a reader may separately want to raise with the editor.
Talk to someone today
The National Gambling Helpline is free, confidential and open 24 hours a day, seven days a week.
