Privacy · candidate policy

Collect deliberately. Keep access scoped.

This page describes the implemented candidate behavior. Legal controller identity, final retention periods, backup expiry and production subprocessors still require owner review before launch.

Public browsing and samples

Public programme pages and deterministic examples require no account. Synthetic example data contains no participant or customer records. This candidate does not add third-party analytics to private shared-plan views.

Unsaved plans

Planner answers remain in the current page unless you deliberately save or share. Do not enter confidential free text. The PDF is generated in your browser.

Saved plans and owner access

A deliberate save creates an opaque owner session in a secure HttpOnly cookie and stores a plan with an opaque public ID. The ID alone is not authority. Owner reads, changes, shares and exports must recheck the owner session.

Read-only shared links

A shared link contains a high-entropy bearer grant in the URL fragment. Anyone with the link can view its immutable, sanitised snapshot until expiry or revocation. The credential remains visible to page JavaScript and can remain in browser address/history. Each read and export rechecks the hashed grant, scope, expiry, revocation and snapshot version. Shared access grants no edit authority. Revocation cannot retract copies already viewed or downloaded.

Enquiries

Name, email, optional organisation, selected topic and message are used for the requested service response. Optional marketing consent is independent. A successful acknowledgement means the request was persisted; it does not mean email delivery, a quote or booking.

Deletion and retention

Production retention periods and operator deletion procedures are not yet approved. The local database is isolated development evidence, not a production customer system. Use the privacy contact route once an approved public service channel is configured.