Privacy Policy
How Amazing Reviews Ltd collects, uses, stores and protects personal information gathered from readers, newsletter subscribers, contact-form enquiries and commercial partners of amazingreviews.co.uk.
Your data, in plain English, under UK GDPR
Amazing Reviews Ltd is the data controller for personal information collected through amazingreviews.co.uk. This policy explains, in plain English, what information we collect, why we collect it, how long we keep it, who we share it with, the lawful basis on which we process it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is written to be read by a normal human being, not a compliance auditor.
The categories of data we hold are limited on purpose. Reader data covers newsletter subscribers, contact-form enquiries and standard privacy-first site-analytics telemetry such as IP address, browser, referring URL and pages visited. We do not sell personal data to third parties, we do not share reader data with the brokers we cover, and we do not use reader data to build advertising profiles that follow you around the internet.
You have the right to access your data, correct it, delete it, restrict processing, port it to another service, object to processing based on legitimate interests, and complain to the Information Commissioner's Office. Requests are answered in writing within one UK calendar month, usually much faster. The contact details for exercising any right are in section 12 at the bottom of this page.
Last updated: 21 July 2026. Amazing Reviews Ltd (registered in England & Wales, 37th Floor, 1 Canada Square, Canary Wharf, London E14 9XQ) is the data controller for all personal information collected through amazingreviews.co.uk. Our nominated contact for data-protection matters is the Editor-in-Chief, reachable at info@amazingreviews.co.uk.
1. Information we collect
We collect two categories of information. First, information you provide directly, which includes your email address when you subscribe to the editorial briefing, your name and message when you use the contact form, and any additional context you volunteer in correspondence with the desk. Second, technical information collected automatically when you visit the site: IP address, approximate location derived from IP, browser type and version, device type, operating system, referring URL, pages visited, session duration and outbound-link clicks. This second category is standard for a UK-based publisher and is used solely to improve editorial coverage and site performance.
We do not collect special category data (health, ethnicity, religion, political opinion, biometric or genetic data) and we do not knowingly collect any personal information from anyone under the age of 18. If you believe a minor has submitted personal data through the site, please contact the desk immediately and we will delete it.
2. How we use your information
Contact details are used to respond to your enquiry, deliver the editorial newsletter you subscribed to, and, where you have consented, to send occasional updates about new broker reviews or market analysis. Technical data is used to understand which articles readers find useful, to detect and prevent malicious activity against the site, and to satisfy security-audit and troubleshooting obligations. We never sell personal data to third parties and we never share your details with the brokers we cover, even where we hold a commercial affiliate relationship with them.
3. Lawful basis for processing
Under UK GDPR we rely on four lawful bases. Consent covers newsletter subscription and any optional marketing communications. Legitimate interests covers privacy-first site analytics, fraud and security monitoring, and outbound-link click tracking used to detect broker-page abuse. Contract covers responses to your enquiries where you have asked the desk to help with a specific question. Legal obligation covers any disclosure required by UK court order, regulator or law-enforcement request. You can withdraw consent at any time by unsubscribing from the newsletter or emailing the desk.
4. Cookies, analytics and outbound-link tracking
We use a small number of strictly-necessary cookies to keep the site functional, plus a single privacy-first analytics cookie to understand aggregate readership. Outbound clicks to broker sign-up pages may be tagged with an affiliate parameter so that broker partners can attribute traffic; that tag identifies Amazing Reviews as the source, not you personally. Full technical detail sits in our separate Cookies Policy.
5. Data retention
Newsletter records are held for as long as you remain subscribed plus twelve months after unsubscription for audit and re-subscription-prevention purposes. Contact-form enquiries are held for twenty-four months to allow for follow-up correspondence and, where relevant, for defending or bringing legal claims. Server logs are retained for ninety days for security and troubleshooting. Editorial testing data connected to a specific broker review (screenshots of order tickets, funding evidence, spread captures) is retained for two years to support corrections and challenges from the broker in question.
6. Who we share your data with
We share data only with the small number of processors required to run the site: our email-delivery provider (for the newsletter), our privacy-first analytics provider (aggregate figures only), our web-hosting provider (for the site itself) and, if a security or legal matter arises, our external legal counsel and, if requested lawfully, UK regulators or law enforcement. Every processor operates under a UK GDPR-compliant data-processing agreement and is either UK-based or covered by the UK–EU adequacy decision or, where relevant, the UK addendum to the EU Standard Contractual Clauses.
7. International transfers
Where a processor stores or transmits data outside the UK, we ensure transfers rely on an adequacy decision (for example UK–EU or UK–Switzerland), the UK International Data Transfer Agreement, or the UK addendum to the EU SCCs with a Transfer Risk Assessment on file. We do not use processors based in jurisdictions that lack an appropriate transfer mechanism.
8. Security safeguards
The site runs behind TLS 1.3, with HSTS enabled and modern content-security-policy headers. Administrative access to reader data is restricted to named editorial-team members and protected by two-factor authentication. Processor selection is subject to a written security review before onboarding, and repeated annually. Any data-breach affecting reader information will be reported to the Information Commissioner's Office within 72 hours as required by UK GDPR, and affected readers will be notified directly where the breach is likely to result in a high risk to their rights and freedoms.
9. Your rights under UK GDPR
You have the right to be informed about how we use your data (this notice), to access the data we hold about you (a Subject Access Request), to have inaccurate data corrected, to have your data erased in most circumstances, to restrict processing while a dispute is being resolved, to portability of the data you supplied to us, to object to processing based on legitimate interests, and to withdraw consent at any time for consent-based processing. You also have the right to complain to the Information Commissioner's Office at any point. We will not treat you differently for exercising any of these rights.
10. Automated decision-making and profiling
We do not use your personal data for automated decision-making with legal or similarly significant effects, and we do not build behavioural profiles for advertising. Editorial content shown on the site is the same for every reader regardless of your browsing history.
11. Changes to this notice
We may update this policy from time to time to reflect regulatory changes or new processors. Material changes will be highlighted at the top of this page for at least thirty days and, for newsletter subscribers, notified by email. The "Last updated" date at the top of this notice always reflects the current version.
12. How to contact us or complain
To exercise any UK GDPR right, ask a question about this notice, or raise a complaint, email info@amazingreviews.co.uk, call 020 8058 3340, or write to Amazing Reviews Ltd, 37th Floor, 1 Canada Square, Canary Wharf, London E14 9XQ. You may also complain directly to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113 without contacting us first, although we would prefer the chance to resolve any concern with you directly before you do so.