Legal

Privacy policy

Last updated: June 2026. This policy explains how SafeOnline UK handles your personal information.

The short version: We collect as little data as possible. We do not sell or share your data with advertisers. We do not track children. Our email list is used only for threat alerts — nothing else. You can request deletion of your data at any time by contacting us.

1. Who we are

SafeOnline UK is a free digital safety resource for families, young people in the United Kingdom. We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

To contact us about data protection matters: use our contact form and select "General enquiry" — mark your subject as "Data protection".

2. What data we collect

When you browse the site

We collect standard server log data including your IP address, browser type, pages visited, and time of visit. This data is used solely for site analytics and security purposes. It is not used for advertising or shared with third parties.

When you subscribe to threat alerts

We collect your email address. Nothing else. This is used only to send you alerts when significant new online safety risks emerge. We use Netlify to process form submissions — see the third parties section below.

When you use our contact forms

We collect the name, email address, and message content you provide. We use this information solely to respond to your enquiry. Contact form data is processed via Netlify Forms.

When you use the family tech contract or family safety check

These tools run entirely in your browser. No data is transmitted to our servers. Nothing you enter into the contract builder or safety check is stored, logged, or accessible to us in any way.

3. How we use your data

We process your personal data on the following legal bases under UK GDPR:

We do not use your data for advertising, profiling, or automated decision-making. We do not sell your data. We do not share your data with any third party except as described in section 6 below.

4. Children and young people

This website is designed to be accessible to children, including the Kids & teens section. We take special care with younger users.

We do not knowingly collect personal data from children under 13. The tools designed for use by children (the kids section quizzes, scenarios, and information pages) do not require any personal information to be entered and do not collect any data.

The contact forms and email signup are intended for adults. If we become aware that we have inadvertently collected data from a child under 13, we will delete it immediately.

We comply with the ICO's Age Appropriate Design Code (Children's Code) and apply privacy-protective defaults to our platform design.

5. Cookies

We use only essential cookies necessary for the website to function. We do not use advertising cookies, tracking cookies, or third-party analytics cookies that share data with external services.

Essential cookies we use include session cookies that help the website function correctly. These are deleted when you close your browser. We do not require cookie consent for essential cookies under UK GDPR, but we do not set any non-essential cookies.

6. Third parties

Netlify

Our website is hosted by Netlify, Inc. Netlify processes form submissions (contact forms and email signup) on our behalf. Netlify is based in the United States and operates under appropriate Standard Contractual Clauses for UK data transfers. Netlify's privacy policy: netlify.com/privacy.

Tabler Icons and Google Fonts

Our website loads icons from Tabler Icons CDN (jsdelivr.net) and fonts from Google Fonts. These services may log your IP address as part of delivering the assets. Google Fonts privacy information: developers.google.com/fonts/faq/privacy.

External links

We link to external organisations including CEOP, Childline, the NSPCC, Ofcom, and others. Once you leave our site, their own privacy policies apply. We are not responsible for the privacy practices of external websites.

7. Your rights

Under UK GDPR, you have the following rights regarding your personal data:

To exercise any of these rights, please contact us. We will respond within one month as required by UK GDPR.

8. Data retention

9. Security

All data transmitted to and from this website is encrypted via HTTPS (TLS). We use Netlify's infrastructure, which includes industry-standard security measures including DDoS protection and regular security updates.

No method of electronic transmission or storage is 100% secure. If you become aware of any security vulnerability in our site, please contact us responsibly and we will address it promptly.

10. Contact and complaints

For any questions about this privacy policy or to exercise your rights, please contact us via our contact form.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator:

This policy was last reviewed in June 2026. We will update it when our data practices change and will note the date of update at the top of this page.