Logo
joshx.cc / Privacy Radar
UK GDPR & Data Protection Act 2018

Privacy Notice

Last updated: August 2026

1. Data Controller & Scope

This Privacy Notice applies to all automated audit and suppression services operated by joshx.cc. We process your data exclusively to identify exposures across public directories and exercise your statutory data protection rights on your behalf.

Data Protection Contact: privacy@joshx.cc

2. Lawful Basis for Processing (UK GDPR Article 6)

  • Consent (Article 6(1)(a)): You provide affirmative, explicit consent when initiating an audit and authorizing automated removals.
  • Contractual Necessity (Article 6(1)(b)): Processing is necessary to execute the search, discovery, and suppression actions requested.
  • Legitimate Interests (Article 6(1)(f)): Maintaining minimal rate-limiting logs (IP address and timestamp) to protect platform infrastructure against abuse.

3. Personal Data Collected & Purpose

Data Field Primary Purpose Downstream Third Parties
Full Name Electoral roll query & GDPR Article 17 notices 192.com, B2B Brokers
UK Phone Number TPS registration & Caller-ID delisting TPS (PECR), Truecaller, Sync.me
Email Address Breach leak auditing & confirmation notices Statutory broker privacy teams
Postcode / City Electoral roll lookup filter & TPS locality verification 192.com, UK TPS

4. Data Retention & Automatic Minimization

In accordance with UK GDPR Article 5(1)(e) (Storage Limitation), raw identity records are retained only as long as necessary to complete autonomous worker cycles. Audit logs older than 30 days are automatically anonymized, stripping all personal identifiers while retaining zero-PII metrics.

5. Your Statutory Rights

Under the Data Protection Act 2018, you maintain the right to access your stored audit logs, request immediate erasure of active session records, or revoke authorization at any time by contacting privacy@joshx.cc.