Privacy policy
Please read this first. This policy is a thorough starting point, not finished legal advice. It should be reviewed by a solicitor or a data protection officer, and checked against what this organisation actually does, before the site goes live. It is an ordinary page in the admin and can be edited like any other, so keeping it accurate is a page edit rather than a development job.
Last updated: the date this page was last saved in the admin. Replace this line with a fixed date when the policy is signed off.
Who we are
Rainbow Coders Software Development Limited ("Rainbow Coders", "we", "us") is the data controller for the personal data described in this policy. That means we decide why your personal data is used and how. Our registered address is Wellington Place, Leeds, LS1 4AP, and we are registered with the Information Commissioner's Office under registration number ZC180535.
Where we build or maintain software for a client and handle personal data held in that client's systems, we act as a processor on that client's documented instructions, not as a controller. In that situation the client's own privacy notice governs, and this policy does not apply to that data.
How to contact us about your data
- By email: hello@rainbowcoders.test, marking the message for the attention of the person responsible for data protection.
- By post: Data Protection, Rainbow Coders Software Development Limited, Wellington Place, Leeds, LS1 4AP.
- By telephone: 0113 496 0123.
We have not appointed a statutory Data Protection Officer, because we are not required to. The named contact above is responsible for data protection questions and will answer them.
What this policy covers
This policy covers this website, the client and member areas that sit behind it, the enquiry and application forms, and the email we send in the course of running projects. Where we link to somebody else's site, their own privacy notice applies once you leave ours, and we have no control over what they do.
It applies to people in the United Kingdom under the UK GDPR and the Data Protection Act 2018, and to people in the European Economic Area under the EU GDPR. Where those two regimes differ, the difference is called out.
What we collect, and from whom
Different people give us different things, so it is set out separately below rather than as one list that is only half true of anybody.
Site visitors
If you only read the site, we collect very little. Our web server records the request itself: the page asked for, the time, the response code and the browser's user agent string, together with the IP address the request came from. Those logs exist so that we can diagnose faults and detect abuse, and they are not used to build a profile of you.
If you answer the cookie banner, we record your choice: which categories you allowed, when, which version of the banner and of this policy were in force, the page you were on and your browser's user agent. We record your IP address only in a form that cannot be read back: hashed with a secret unique to this installation, or truncated, or not at all, depending on the setting in force. The raw address is never stored. That record exists because the law requires us to be able to demonstrate that consent was given.
People who make an enquiry
If you use the contact form or the project enquiry form, we collect the name, email address, telephone number and organisation you choose to give us, together with whatever you tell us about the work. If a spam check is enabled on the form, Cloudflare receives technical signals about the request in order to decide whether it is automated.
Clients
If you commission work we hold your account details and sign-in credentials, your contact details and those of the people you nominate, the brief and scope of each project, the messages exchanged through the client area, files you upload, invoices and payment records, and the audit trail of decisions taken on each project.
Members
If you work through the network we hold your account and sign-in credentials, your contact details, your public profile including any photograph and biography you supply, your declared skills, your hourly rate, the work offered to and accepted by you, what you delivered and when, any conduct flags raised against you by an administrator, and the performance figures calculated from that history.
Applicants
If you apply to join the network we hold your application, the skills and experience you declare, links you provide to your own work, and our assessment of it. If we do not take the application forward we keep enough to know that we considered it and why.
Where the data comes from
Almost all of it comes directly from you. A small amount is generated by us in the course of the work, such as project notes, performance figures and audit entries. Some is generated automatically by the systems described above, such as server logs and consent records. We do not buy personal data, and we do not enrich what you give us from third party sources.
Special category data
We do not ask for special category data, which means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation. We do not ask for criminal offence data either.
If you volunteer something of that kind in a message, for example telling us about a health condition affecting a deadline, we hold it only because you sent it to us, we do not use it for any purpose beyond replying to you, and we would rely on your explicit consent under Article 9(2)(a) for as long as we retained it. Please do not send us special category data unless you have to.
Why we use it, and our lawful basis
Every use of personal data needs a lawful basis under Article 6 of the UK GDPR. Ours are set out purpose by purpose below, rather than as a single blanket claim, because a lawful basis that covers everything usually covers nothing.
| What we do with it | Lawful basis |
|---|---|
| Answering an enquiry and preparing a brief or a quotation | Article 6(1)(b), steps taken at your request before entering into a contract |
| Running a commissioned project: scope, messages, files, delivery and acceptance | Article 6(1)(b), performance of a contract |
| Operating a member's engagement: offers of work, delivery, review and payment | Article 6(1)(b), performance of a contract |
| Invoicing, accounting and keeping tax records | Article 6(1)(c), compliance with a legal obligation |
| Assessing an application to join the network | Article 6(1)(f), legitimate interests, and Article 6(1)(b) once an engagement is offered |
| Keeping the site secure, throttling sign-in attempts and detecting abuse | Article 6(1)(f), legitimate interests |
| Keeping an audit trail of decisions taken on a project | Article 6(1)(f), legitimate interests, and Article 6(1)(c) where a record must be kept |
| Calculating member performance figures used to decide who is offered work | Article 6(1)(f), legitimate interests |
| Setting non-essential cookies and running analytics or marketing tags | Article 6(1)(a), consent, given through the cookie banner |
| Recording that consent was given, so that we can demonstrate it | Article 6(1)(c), compliance with a legal obligation |
| Sending you email about a project you are involved in | Article 6(1)(b), performance of a contract |
Where we rely on legitimate interests
Legitimate interests is only available where our interest is real, where the processing is necessary to achieve it, and where our interest is not overridden by your rights and freedoms. We have carried out a balancing test for each of the purposes above that relies on it, and we will provide a copy of the assessment on request.
- Security and abuse prevention. Our interest is keeping accounts, project files and client data from being taken. The processing is limited to request metadata and sign-in attempts, it is what any competent operator would expect, and the alternative is a site that can be attacked freely. We consider the balance clearly in favour of processing.
- The audit trail. Our interest is being able to show who decided what, and when, if a project is later disputed. Entries record the actor, the action and the time, and nothing more than is needed to make the record meaningful. Both clients and members benefit from a record that cannot be quietly rewritten, so the balance favours processing.
- Member performance figures. Our interest is offering work to the people most likely to deliver it well. The figures are drawn from the member's own history with us and nothing else, a member can see their own score and the reasons behind it, and no decision is taken automatically. A member may object, and we explain the effect of objecting below.
- Assessing applications. Our interest is deciding, fairly and consistently, who joins the network. Only the material an applicant chose to send us is used. The balance favours processing, and an applicant may ask us to delete the application at any point.
You have the right to object to any processing that relies on legitimate interests. See the rights section below.
Consent, and taking it back
Where we rely on your consent, you can withdraw it at any time and it is as easy to withdraw as it was to give. Withdrawing consent does not make what we did beforehand unlawful, but we stop when you tell us to. For cookies, the reopen control on every page takes you straight back to the choices; see the cookie policy.
How long we keep it
We keep personal data only for as long as there is a reason to, and the reason is stated alongside each period. Where a period is expressed as a number of years after the end of a relationship, it runs from the last substantive contact.
| What | How long | Why |
|---|---|---|
| Web server request logs | 90 days | Long enough to investigate a fault or an attack, short enough not to become a store of browsing history |
| Cookie consent records | 12 months by default, set in the admin | To demonstrate consent was given for as long as it could be questioned. The period is configurable and old records are purged automatically |
| Enquiries that do not become projects | 12 months | Enquirers often come back, and the earlier conversation is what makes the second one useful |
| Client records, project briefs, scope and correspondence | 6 years after the end of the engagement | The limitation period for a contract claim in England and Wales |
| Project files and deliverables | 6 years after the end of the engagement, unless the contract says otherwise | To be able to answer a question about what was delivered |
| Invoices, payments and accounting records | 6 years from the end of the accounting period | Required by HMRC and the Companies Act |
| Member records, work history and conduct flags | 6 years after the end of the engagement | The limitation period, and the basis on which payment was made |
| Unsuccessful applications | 12 months | To answer a query about the decision, and to recognise a repeat application |
| The audit trail | 6 years | The record exists to be produced if a project is disputed, so it outlives the project |
| Sign-in attempt records | 90 days | Throttling and intrusion detection only |
At the end of a period the data is deleted, or anonymised so that it can no longer be connected to a person. Backups are overwritten on their own cycle, so a record deleted from the live system may persist in a backup for a short period afterwards; it is not restored to the live system.
Who we share it with, and where it goes
We do not sell personal data, we do not rent it, and we do not share it for anybody else's marketing. It is shared only where it is necessary, and only with the categories of recipient below.
Processors acting on our instructions
- Hosting and infrastructure. The provider that runs the servers this site and its database sit on. They can technically reach the data in order to operate the platform, and are contractually forbidden from using it for anything else.
- Email delivery. The provider that carries our outgoing email. They handle the address and the content of each message in order to deliver it.
- Bot protection. Where the spam check is switched on, Cloudflare receives technical signals about a form submission in order to judge whether it is automated. It does not receive what you typed into the form.
- Analytics and advertising. Only where you have consented to the relevant cookie category. The current list is in the cookie policy, which is the page to check because it reflects what is actually switched on.
- Accounting and payment. Our accountants and our bank, in relation to invoicing and payment.
Every processor is engaged under a written contract that meets Article 28: they act only on our documented instructions, keep the data confidential, apply appropriate security, help us respond to your requests, and delete or return the data at the end of the engagement.
Members and clients
Clients and members do not have access to each other's contact details. Every message, file and decision passes through an administrator, and that is enforced by how the system is built rather than being a matter of policy. A member sees the brief and the scope of the work they are offered, not who the client is, unless the client has agreed to be identified.
Others
We may disclose personal data to our professional advisers where we need advice, to a court or a regulator where we are legally obliged to, and to a buyer or their advisers if the business is sold, in which case the data continues to be protected by this policy until they issue their own.
International transfers
We aim to keep personal data within the United Kingdom and the European Economic Area. Some providers, particularly for email and bot protection, operate globally, so a transfer outside those areas can happen.
Where it does, we rely on one of the following, and on nothing else:
- Adequacy. The destination is covered by UK adequacy regulations or an EU adequacy decision, so no additional safeguard is needed.
- The UK International Data Transfer Agreement (IDTA), or the EU standard contractual clauses read with the UK Addendum, for transfers out of the United Kingdom.
- The EU standard contractual clauses adopted by the European Commission, for transfers out of the European Economic Area.
In each case we carry out a transfer risk assessment before the transfer begins, and put supplementary measures in place, such as encryption in transit and at rest, where the assessment shows they are needed. You can ask us for a copy of the safeguard relied on for a particular transfer, and we will provide it or explain why part of it must be redacted.
Your rights
The UK GDPR and the EU GDPR give you the following rights. Not every right applies to every piece of processing, and where one does not apply we will tell you which and why rather than simply refusing.
Article 15: the right of access
You can ask whether we hold personal data about you, and if we do, for a copy of it together with an explanation of why we hold it, who we share it with, how long we keep it and where it came from. This is often called a subject access request. We provide the copy free of charge; we may charge a reasonable fee for further copies of the same information.
Article 16: the right to rectification
You can ask us to correct personal data that is inaccurate, and to complete data that is incomplete. If we have shared the data with anybody else, we tell them about the correction unless that is impossible or would take disproportionate effort.
Article 17: the right to erasure
You can ask us to delete personal data where we no longer need it, where you have withdrawn the consent it relied on, where you have successfully objected to it, or where it has been processed unlawfully. The right is not absolute: we can refuse where we are legally required to keep the data, such as accounting records, or where we need it to establish, exercise or defend a legal claim.
Article 18: the right to restrict processing
You can ask us to stop using personal data while a dispute about its accuracy or about our lawful basis is resolved. We keep the data but do not otherwise use it, except to defend a legal claim or with your consent, and we tell you before the restriction is lifted.
Article 19: notification to recipients
Where we correct, delete or restrict data, we tell everybody we have shared it with, unless that is impossible or would take disproportionate effort. You can ask us who those recipients were.
Article 20: the right to data portability
Where we process data you gave us, by automated means, on the basis of consent or a contract, you can ask for a copy in a structured, commonly used, machine-readable format, and you can ask us to send it directly to another controller where that is technically feasible.
Article 21: the right to object
You can object to processing that relies on legitimate interests, including the member performance figures and the audit trail. We stop unless we can show compelling legitimate grounds that override your interests, or we need the data for a legal claim. If you object to the performance figures we will tell you plainly what that means: we can stop ranking you, but we cannot then offer you work on the basis of that ranking. You can object to direct marketing at any time and we stop immediately, with no balancing test and no exceptions.
Article 22: automated decision making
You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. Our position is set out in the next section.
Withdrawing consent
Where processing relies on your consent you can withdraw it at any time, and doing so is as straightforward as giving it was. For cookies, use the reopen control that appears on every page. For anything else, tell us using the contact details at the top of this policy.
How to exercise a right, and how long we take
Write to us using any of the contact details at the top of this policy and say which right you are exercising. You do not need to use a particular form of words or fill in a form. We may ask for enough information to be satisfied of your identity, so that we do not hand your data to somebody else.
We respond within one month of receiving the request. Where a request is complex, or where you have made several, we may extend that by up to two further months, and we will tell you within the first month that we are doing so and why. There is no charge unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, and we will explain which and why.
Automated decisions, profiling and cookies
Automated decision making and profiling
We do not take decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. Article 22 of the UK GDPR is therefore not engaged.
We do carry out one activity that amounts to profiling, and it is described here so that it is not a surprise. Members are given a performance score calculated from their own history with us: whether work was completed on time, whether it was right first time, how often offers are accepted, how quickly messages are answered, how much work has been completed, and whether any conduct flag is open. That score orders the list of members an administrator sees when deciding who to offer a piece of work to.
The decision itself is always taken by a person. The score is a starting point for that person, not a gate, and an administrator can and does offer work to somebody the score did not put at the top. A member can see their own score, the weighting behind it and the reasons given for it, can ask us to correct anything factually wrong in the history it is calculated from, and can object to the profiling under Article 21.
Cookies and similar technologies
This site sets a small number of cookies that are strictly necessary for it to work, and will set nothing else unless you agree to it. Non-essential cookies are blocked until you consent, and any script that would set one is held inert in the page until then rather than merely being asked not to.
The full list of cookies, what each is for, how long it lasts and whether it is ours or a third party's, is in the cookie policy. That page also carries the control for changing or withdrawing your consent.
Security, and what happens if something goes wrong
How we protect personal data
We take appropriate technical and organisational measures, as Article 32 requires. In practice that means:
- Passwords are stored as Argon2id hashes and are never stored, logged or emailed in a readable form.
- Sessions are fingerprinted, expire on inactivity, and are re-issued whenever a privilege changes.
- Every form that changes anything is protected against cross-site request forgery, and every database query uses prepared statements, so submitted data can never be executed as an instruction.
- Anything an administrator writes as formatted text is passed through an allowlist sanitiser before it is ever shown, so a stored script cannot reach another user's browser.
- Uploaded files are stored outside the web root and are served only through a controller that checks who is asking. There is no guessable public address for a project file.
- Access is limited to the people who need it for their role, and administrators, clients and members each see only their own area.
- A tamper-evident audit trail records who did what, so an unauthorised change can be identified rather than merely suspected.
- Traffic is encrypted in transit, and backups are taken and tested.
No system is perfectly secure, and anybody who tells you otherwise is selling something. What we can promise is that the measures above are real, are reviewed, and are not decorative.
If there is a personal data breach
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. If one happens we investigate immediately, contain it, and record it in our internal breach log whether or not it is reportable.
Where the breach is likely to result in a risk to people's rights and freedoms, we notify the Information Commissioner's Office without undue delay and in any event within 72 hours of becoming aware of it. If we cannot provide the full picture within that time we notify what we know and follow up with the rest. Where an EU supervisory authority is the relevant one, we notify them on the same timescale.
Where the breach is likely to result in a high risk to you, we tell you as well, without undue delay, in plain language: what happened, what data was involved, what we are doing about it, and what you should do.
Where we are acting as a processor for a client, we tell that client without undue delay so that they can meet their own obligations.
Complaints, children and changes to this policy
If you are unhappy with how we have handled your data
Please tell us first, using the contact details at the top of this policy. We would rather put something right than have you find out from a regulator that we got it wrong. You do not have to come to us first, and nothing here affects your right to go straight to a supervisory authority.
Complaining to the Information Commissioner's Office
If you are in the United Kingdom, you have the right to complain to the Information Commissioner's Office, which is the UK supervisory authority for data protection.
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Complaining to an EU supervisory authority
If you are in the European Economic Area, you have the right to complain to the supervisory authority in the country where you live, where you work, or where the matter you are complaining about happened. The European Data Protection Board publishes a list of national authorities and their contact details at edpb.europa.eu.
You also have the right to an effective judicial remedy under Article 79, which means you can take the matter to court rather than, or as well as, complaining to a regulator.
Children
This site and the services behind it are meant for people acting in a business capacity, and are not directed at children. We do not knowingly collect personal data from anybody under 13, and we do not offer information society services directly to children.
If you believe a child has given us personal data, tell us using the contact details above and we will delete it. Where we ever rely on consent from somebody under 13 in the United Kingdom, we would need the authorisation of a person holding parental responsibility, as section 9 of the Data Protection Act 2018 requires; the age threshold differs across the European Economic Area, between 13 and 16 depending on the member state.
Changes to this policy
We review this policy at least once a year, and whenever we change what we do with personal data. The current version is always the one on this page, and the date it was last changed is shown at the top.
Where a change is significant, for example a new purpose, a new category of recipient or a new international transfer, we do not rely on you happening to reread the page. We tell people we hold an account for by email before the change takes effect, and where the change affects what you have consented to, we raise the cookie policy version so that the banner asks you again rather than assuming your old answer still stands.