What we hold, and why
This is the portal you sign in to. It is run by Jonny Elliott, and this page says plainly what it stores about you, who else can see it, how long it is kept and what you can do about any of it. Last updated 29 August 2026.
Who is responsible
Jonny Elliott is the data controller for everything in this portal. If you want to ask about any of it, or exercise any of the rights below, write to jonny@jonnyelliott.com and you will get an answer within a month.
What is stored
- Your account. Your name, your email address, and your password stored only as a one way hash. The hash cannot be turned back into your password, by us or by anybody who took a copy of it.
- Your details. Anything you put on your account page: job title, phone number, an alternative email, and whether you want to be emailed about updates and invoices.
- Your company. The registered name, address, company and VAT numbers your invoices are made out to. Everyone who signs in for your company can see and change these.
- Your project. The plan, what is outstanding, the updates we post, and everything you answer in the questionnaire.
- What you send us. Files you upload, with your name and the time against them.
- What you have taken with us. Courses and programmes, and how far through a course you are. This is yours alone: your colleagues cannot see it.
- Invoices. Number, date, amount, and whether it is paid.
- A security log. Sign ins, saves and uploads, kept for 90 days. It records the action, the time, your browser and platform, and the network your request came from narrowed to a prefix. Your full IP address is never written down.
We do not use analytics, advertising or tracking of any kind, and there are no third party scripts on any page. The only cookie is the one that keeps you signed in, which is why there is no banner asking you about cookies: there is nothing optional to ask about.
Why we are allowed to hold it
Most of it because we need it to do the work you have asked us to do, which is the contract we have with you. The security log because a portal holding client work has to be able to tell who did what, which is a legitimate interest of ours and of yours. Invoices because tax law requires us to keep them for six years.
Who else sees it
Nobody, other than the three companies that run parts of the portal for us. Each is bound by a contract that stops them using your data for anything else.
- Netlify. Hosts the portal and stores everything in it. Data is held in the European Union.
- Resend. Sends the emails: your login, a password reset, a note when a file arrives. They see the address and the message.
- Stripe. Takes payment for courses and programmes, if you buy one. They hold the card details; we never see them and never store them.
We do not sell anything to anybody, and nothing here is used to train anything.
How long it is kept
- Your account and project, for as long as you are a client and for two years afterwards, in case you come back.
- Files you send, for the life of the project and two years afterwards.
- The security log, 90 days.
- Password reset links, one hour, and once only.
- Invoices, six years, because we have to.
What you can do
You can take a copy of everything we hold about you, and ask us to delete it, from your own account page. No email, no waiting for somebody to get round to it.
You can also ask us to correct anything that is wrong, object to us holding something, or ask us to stop emailing you, and you can complain to the Information Commissioner at ico.org.uk if you are not happy with how we have handled it. We would rather you told us first.