ATLAS / 14

Privacy by design

As little data as possible. As much protection as needed.

Data minimisation begins with product decisions. Location is optional; analytics stays off until explicit consent; form data is separated and retained for limited periods.

Protect young people

Direct waitlist sign-up from 16; younger users are directed to a parent or carer.

Data used for its stated purpose

Personal information supports your use of Apprentice Atlas and is neither sold nor used for personalised advertising.

Clear retention

Delete unconfirmed sign-ups after seven days, and leads and confirmed entries on defined schedules.

Launch data flows

The public site works without an account. The partner form stores organisation and contact details to handle an enquiry. The waitlist stores email, market, platform, consent version and timestamps. Analytics loads separately and only after consent; search terms and form messages are not sent as event properties.

• No CMS or lead table through the public Data API.

• No service secrets in the browser.

• Server-side validation, bot protection and rate limits.

• Separate staging and production projects.

When something goes wrong

Security and privacy reports are prioritised by impact. Affected processing can be stopped, a key rotated or a feature withdrawn. Statutory notification duties are assessed with qualified advice. Legal review before launch includes children’s privacy and the need for a DPIA.

• security@ for technical vulnerabilities.

• privacy@ for rights and data questions.

• Traceable incident timeline.

• No public launch approval before the legal gate.

Let’s plan the next stage together.

Contact us