Privacy

What the desk knows about a reader, by design

The headshot desk collects the minimum data required to publish a desk. The privacy notice explains what data the desk holds, what data the desk never holds, and the rights a reader has under the relevant data protection regulation. The desk does not sell reader data. The desk does not share reader data with third parties for advertising.

Privacy notice illustration

Data the desk holds

Minimum data, by design

The headshot desk collects the minimum data required to publish a desk. The desk does not require a reader to register an account to read any desk. The desk does not require a reader to submit personal data to access any guide, brief or newsroom item. The desk does not run a newsletter signup that is required to read the desks.

For desk inquiries submitted via the contact page, the desk holds the inbound message and the email address for as long as it is operationally needed. The desk deletes the message after the inquiry is closed. The desk does not share the message with any third party for advertising or marketing.

The desk does not hold passwords, payment data, KYC documents, government identifiers or any piece of information that the desk does not need to publish a desk. The desk does not set tracking cookies for advertising. The desk's analytics are anonymous and aggregated.

Reader rights

What a reader can ask the desk to do

Access

A reader can ask the desk for a copy of the data the desk holds about them. The desk replies within a reasonable window with the data the desk has on file.

Correction

A reader can ask the desk to correct data the desk holds. The desk verifies the correction against the canonical source and updates the data on file.

Deletion

A reader can ask the desk to delete the data the desk holds. The desk deletes the data after the inquiry is closed and confirms in writing.

Cookies

What cookies and similar technologies the desk uses

The desk does not set tracking cookies for advertising. The desk's analytics are anonymous and aggregated. The desk's session management uses the minimum required cookies to keep the reader logged in to a desk inquiry for the duration of the inquiry. The desk does not use third-party advertising cookies on any surface.

The desk's CSS and JavaScript are served from the central headshotin.com domain. The fonts are served from the public Google Fonts CDN with a preconnect for performance. The desk's og-image is served from the central domain. There are no third-party widgets on the desk that track the reader.

Third-party

What the desk never shares with a third party

The desk never shares a reader's contact details with a third party. The desk never shares a reader's reading history with a third party. The desk never shares a reader's desk-inquiry content with a third party. The desk's only use of a reader's data is to reply to the reader, and the desk's only use of the reply is to close the inquiry.

The desk's analytics are anonymous and aggregated. The desk does not set tracking cookies for advertising. The desk's CSS and JavaScript are served from the central headshotin.com domain. The desk's fonts are served from the public Google Fonts CDN with a preconnect for performance. There are no third-party widgets on the desk that track the reader.

For readers who are concerned about a third-party surface that uses the headshot brand name or logo without authorisation, the desk routes the report to the security contact listed on the contact page. The desk does not share the report with the third-party surface. The desk does not share the report with any third party. The desk's editorial role is to publish the verification standard, not to chase phishing surfaces.

Retention

How long the desk holds the data it has

For desk inquiries, the desk holds the inbound message and the email address for as long as it is operationally needed. The desk deletes the message after the inquiry is closed. The desk's standard retention period is thirty days after the last reply. The desk does not retain the message for marketing, for analytics, or for any other purpose.

For server logs, the desk retains the logs for thirty days. The logs are aggregated and anonymous. The logs do not identify a reader by name, email, or any other personal identifier. The logs are used for performance monitoring and security review, and the logs are deleted after the retention period.

Data minimisation

How the desk applies the data-minimisation principle to every page

The data-minimisation principle is the desk's editorial standard for any piece of data the desk holds. The principle is simple: the desk holds only the data the desk needs to publish a desk. The desk does not hold data the desk does not need. The desk does not hold data the desk could use for marketing, for analytics, or for any other purpose.

For every piece of data the desk holds, the desk can answer four questions. What is the data? Why does the desk hold the data? How long does the desk hold the data? When does the desk delete the data? The four questions are the desk's editorial discipline, and the desk applies the discipline to every piece of data the desk holds.

For a reader who writes in via the contact page, the desk holds the inbound message and the email address. The desk holds the data to reply to the reader. The desk holds the data for thirty days after the last reply. The desk deletes the data after the retention period. The four questions are answered in the desk's privacy notice.

For a reader who does not write in via the contact page, the desk holds no personal data. The desk's analytics are anonymous and aggregated. The desk's CSS and JavaScript are served from the central headshotin.com domain. The desk's fonts are served from the public Google Fonts CDN with a preconnect for performance. There are no third-party widgets on the desk that track the reader.

Breach response

What the desk does if a personal-data breach is identified

If a personal-data breach is identified — for example, a contact-page submission is exposed through a misconfiguration — the desk's standard practice is to publish a public note on the newsroom within one hour. The note names the breach, the data affected, the date the breach was identified, and the steps the desk is taking to contain the breach.

The desk's standard practice is to notify the affected readers directly within seventy-two hours of identifying the breach. The notification is sent to the email address the reader used in the contact-page submission. The notification includes the data affected, the date the breach was identified, and the steps the reader can take to mitigate the breach.

The desk's standard practice is to publish a stand-alone correction within seven days of identifying the breach. The correction covers the root cause of the breach, the steps the desk has taken to fix the root cause, and the steps the desk is taking to prevent a similar breach in the future. The correction is the desk's editorial record of the breach, and the correction is updated when the root-cause analysis is complete.

Advertising

Why the desk's editorial surface is advertising-free

The headshot site is advertising-free. The desk does not run display advertising. The desk does not run video advertising. The desk does not run sponsored content. The desk does not run native advertising. The desk's editorial surface is the central URL, and the surface does not carry any advertising load.

The decision is editorial, not technical. A platform site that runs advertising must reconcile the editorial boundary with the advertiser's brief. The reconciliation is not always compatible. The headshot desk chose the editorial path because the editorial path keeps the desk's role simple: the desk publishes reads, the reader reads the desk, the URL is the limit of the surface.

The desk's only commercial surface is the play entry route at /Login/playnow. The route is a single first-party URL. The route is reached via the header CTA or the mobile sticky bar. The route is disclosed on every page where the route appears. The route is the desk's only commercial surface; the desk does not run any other commercial surface.