1. Scope and data controller

This policy applies to themp.org and direct correspondence with THEMP. The operator of themp.org determines how personal information covered by this policy is used. Privacy requests can be sent to sourceledger@themp.org.

2. Information that may be processed

  • Website request data: IP address, browser and device details, requested pages, referring page, timestamps, response codes and security events recorded by hosting, content delivery, DNS or security providers.
  • Correspondence: your name, email address, subject, message, attachments and routing metadata when you contact THEMP.
  • Request records: information needed to verify and answer a privacy, correction, reuse or legal request.

THEMP does not request account credentials, payment card details, government identifiers or special-category personal data. Please do not include such information in a message.

3. Contact form and email

The contact form prepares an email in your own email application. The website does not store the form fields in a database. Information is transmitted only if you send the prepared email, after which the providers used by you and THEMP will process it according to their own terms and privacy notices.

4. Purposes and legal bases

Where data protection law requires a legal basis, THEMP relies on:

  • Legitimate interests in delivering and securing the website, preventing abuse, responding to enquiries, checking source corrections and maintaining an accurate editorial record.
  • Steps requested by you when you ask about permission, attribution or another matter that may lead to an agreement.
  • Legal obligations and legal claims when information must be retained, disclosed or used to comply with law or protect legal rights.

5. Disclosures and service providers

Personal information may be processed by providers that support hosting, DNS, content delivery, security and email. It may also be disclosed to professional advisers, authorities or other parties when reasonably necessary to comply with law, enforce rights, investigate abuse, protect users or defend a legal claim. THEMP does not sell personal information or disclose it for cross-context behavioural advertising.

6. Cookies, analytics and preference signals

THEMP does not use advertising cookies, analytics trackers or profiling scripts. Essential infrastructure may still use short-lived technical identifiers for security, routing or load management. Because the site does not sell or share personal information for targeted advertising, browser-based opt-out signals such as Global Privacy Control do not change the site's behaviour.

7. Retention

Correspondence is kept only as long as reasonably needed to answer the enquiry, document a correction or permission, prevent abuse, meet legal duties or establish and defend legal claims. Infrastructure providers set their own log and backup schedules. When information is no longer required, it is deleted or de-identified where reasonably practicable.

8. International processing

Hosting and email providers may process information in more than one country. Where applicable law requires transfer safeguards, the relevant provider or controller may rely on an adequacy decision, approved contractual clauses or another lawful transfer mechanism.

9. Security

THEMP uses reasonable administrative and technical measures appropriate to the limited information it handles. No internet transmission, email system or storage method can be guaranteed completely secure. You are responsible for limiting your message to information necessary for the enquiry.

10. Your privacy rights

Depending on your location and the circumstances, you may have rights to request access, correction, deletion, restriction, portability or an objection to processing, and to withdraw consent where consent is the legal basis. You may also have the right to complain to your local data protection or privacy authority.

Send requests to sourceledger@themp.org. THEMP may request information reasonably necessary to verify the request, locate the relevant record and prevent unauthorised disclosure. Rights may be limited by applicable law and by the rights of others.

11. United States state privacy notices

If a state privacy law applies, residents may exercise the rights granted by that law and may use an authorised agent where permitted. THEMP does not sell personal information, share it for cross-context behavioural advertising, use it for targeted advertising or use sensitive personal information to infer characteristics. THEMP will not discriminate against a person for exercising an applicable privacy right.

12. Children

The site is not directed to children under 18, and THEMP does not knowingly collect personal information from children. If you believe a child has provided personal information, email the address above so the matter can be reviewed.

13. External links

Research pages link to independent websites. THEMP does not control their content, security or privacy practices. Review the destination site's notice before providing information.

14. Changes to this policy

THEMP may revise this policy to reflect changes in services, providers, law or data practices. The effective date at the top identifies the current version. Material changes apply prospectively unless applicable law requires otherwise.

15. Contact

THEMP privacy enquiries:
sourceledger@themp.org