Privacy Notice
Last updated: August 2026
1. Data Controller & Scope
This Privacy Notice applies to all automated audit and suppression services operated by joshx.cc. We process your data exclusively to identify exposures across public directories and exercise your statutory data protection rights on your behalf.
Data Protection Contact: privacy@joshx.cc
2. Lawful Basis for Processing (UK GDPR Article 6)
- Consent (Article 6(1)(a)): You provide affirmative, explicit consent when initiating an audit and authorizing automated removals.
- Contractual Necessity (Article 6(1)(b)): Processing is necessary to execute the search, discovery, and suppression actions requested.
- Legitimate Interests (Article 6(1)(f)): Maintaining minimal rate-limiting logs (IP address and timestamp) to protect platform infrastructure against abuse.
3. Personal Data Collected & Purpose
| Data Field | Primary Purpose | Downstream Third Parties |
|---|---|---|
| Full Name | Electoral roll query & GDPR Article 17 notices | 192.com, B2B Brokers |
| UK Phone Number | TPS registration & Caller-ID delisting | TPS (PECR), Truecaller, Sync.me |
| Email Address | Breach leak auditing & confirmation notices | Statutory broker privacy teams |
| Postcode / City | Electoral roll lookup filter & TPS locality verification | 192.com, UK TPS |
4. Data Retention & Automatic Minimization
In accordance with UK GDPR Article 5(1)(e) (Storage Limitation), raw identity records are retained only as long as necessary to complete autonomous worker cycles. Audit logs older than 30 days are automatically anonymized, stripping all personal identifiers while retaining zero-PII metrics.
5. Your Statutory Rights
Under the Data Protection Act 2018, you maintain the right to access your stored audit logs, request immediate erasure of active session records, or revoke authorization at any time by contacting privacy@joshx.cc.