Legal

Privacy

What this site collects, and what the platform holds.

Reach Infrastructure Ltd, trading as Censio, is the data controller for this website and for the account data of organisations holding a Censio agreement. Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. Company number 16987152.

This notice covers two separate things, and they should not be confused with one another: what this WEBSITE collects, and what the PLATFORM holds on a customer’s behalf. The second matters more, and the answer is narrower than most people expect.

What this website collects

No advertising trackers, no third-party analytics profile, no cross-site identifiers, and no cookie wall. The site writes one item to your browser’s session storage, censio.gate.v1, recording that you have already seen the entrance so it does not run again on every page. It is cleared when the tab closes, it never leaves your device, and it identifies nothing about you.

Server logs from our hosting provider record request metadata — IP address, timestamp, path, user agent — for operational security and abuse prevention. They are retained for 30 days and are not used to build a profile of a visitor.

If you write to us, we hold the correspondence while the enquiry is live and for 24 months afterwards, so a conversation resumed a year later does not start from nothing.

What the platform holds

Sealing operates on a digest. What is anchored is a cryptographic fingerprint of a record, not the record itself. We do not need the content in order to make it verifiable, so in the ordinary case we do not hold it.

Where a customer sends evidence for assessment, that evidence is processed on their instruction and we act as processor rather than controller. It is retained for the term of the agreement and deleted on termination, subject to the exception below.

We cannot see who verifies a record. Verification does not route through us and there is deliberately no telemetry on it. A verification service that logs its own queries can be compelled to disclose them, which would defeat the point of the design.

The one thing that cannot be deleted

An anchor is a commitment to an external timestamp authority and, where dual anchoring is live, to a public chain. Once committed it cannot be withdrawn by us or by anyone else — that irreversibility is the property the whole protocol rests on.

An anchor carries no personal data. It is a digest and an epoch position. But it is permanent, and we would rather state that here than have a customer discover the limits of erasure at the moment they need to exercise it.

Your rights

Access, rectification, erasure
hello@censio.io
Portability and restriction
hello@censio.io
Objection to processing
hello@censio.io
Complaint to the regulator
ico.org.uk

Requests are answered within one month, as UK GDPR requires. Where a complex request needs longer, we will say so inside that month and explain why.

Transfers and sub-processors

Site hosting and email are provided by processors that may operate outside the United Kingdom. Transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

The current sub-processor list is provided to customers under agreement and is updated with notice before any addition takes effect. It is not published here, for the same reason the evidence provider set is not: naming them would disclose a customer’s supply chain as well as ours.

This notice

Version
1.0
In force from
8 September 2026
Superseded versions
Kept, and available on request

Bring the record with the judgment.