Skip to main content
Privacy notice

Privacy notice

IndexFair is an independent analytics platform that aggregates public reviews of regulated operators into anonymous composite scores. This notice describes what data we process, why, what we keep, and what you can ask us to do about it.

§1

Who this notice is for

Draft · awaiting counsel sign-off

This notice covers everyone whose data we may process — including authors of public reviews on third-party platforms that we ingest. We do not run user accounts, do not host a review form, do not accept reviews submitted directly to us, and do not collect identifiable analytics about site visitors (we use Plausible, a privacy-friendly page-counter, with no IP-address linkage).

§2

What we process

Draft · awaiting counsel sign-off

Our reviews substrate is data scraped from public review platforms. We do not retain full verbatim review text. We persist short aspect-level audit excerpts (≤200 characters, attributed to source) and structural quality signals sufficient to reproduce the aggregate score. Audit excerpts never enter a public response or rendered page. We compute a SHA-256 content hash of every ingested review at extraction time as a defensive record (see §5).

Aggregate output (the 0–10 composite score) is anonymous statistical output: it carries no individual-level inference and is not personal data of any reviewer.

§3

Sources by category

Draft · awaiting counsel sign-off
CategoryExamplesWhat we ingest
Review platformsMay include, for example: Trustpilot, AskGamblers, Casino Guruaggregate ratings; complaint records; no public user excerpts
App storesMay include, for example: Apple App Store, Google Playplatform-published aggregate ratings; review-volume counts
Public forumsMay include, for example: Redditaggregate sentiment derived from public forum posts
Social mediaMay include, for example: X (Twitter), Facebookaggregate sentiment derived from public social posts
Regulator complaintsMay include, for example: BBB, CFPB, UKGC/ADR, Reclame Aquipublic complaint and ombudsman records
Public registersMay include, for example: UKGC, FCA, Companies Houselicence status, sanctions, corporate ownership records

The public category catalogue and its explicitly labelled examples are published at /sources. Each brand evidence disclosure shows the current category-level mix for that market; exact provider names and per-source weights are not published. The aggregate-only persistence rule is defined in our public methodology — see /methodology.

§4

Why we process — and the legitimate-interest balancing test

Draft · awaiting counsel sign-off

Our lawful basis is legitimate interest. The purpose is consumer protection in regulated markets where the harm profile (financial loss, addiction-adjacent risk) is substantial and where independent aggregated analysis is in short supply. Necessity holds because direct consent from thousands of pseudonymous reviewers is not feasible. The balancing favours processing because the source content was published publicly with the manifest intent to influence exactly this kind of evaluation, because our processing is aggregate-only, and because the purge of verbatim text is a demonstrable minimisation measure.

The full Legitimate-Interest Assessment (LIA) document is held internally and made available to data-protection authorities on request. Counsel reviews the LIA before this notice is signed; the founder signs.

We rely on the disproportionate-effort exemption (UK GDPR Art. 14(5)(b)) for individual notification: notifying every reviewer of every ingested platform individually is not feasible and would be disproportionate to the processing impact. This public notice, together with the rights described in §6, is the substitute.

§5

What we keep, and for how long

Draft · awaiting counsel sign-off
  • Verbatim review text: not retained. Verbatim text travels through our extraction pipeline only while a classification job is in flight and is purged immediately after. We do not keep a copy.
  • Short audit excerpts (≤200 characters): retained alongside the aspect rating they support. They carry source attribution, remain audit-only, and are excluded structurally from public query DTOs and rendered pages.
  • Content hash + provenance metadata: retained under the legal-claims exemption (UK GDPR Art. 17(3)(e)) so that a published score can be defended in a defamation forum — see methodology. The hash proves an input existed; it cannot reconstruct its contents.
  • Aggregate scores and score snapshots: retained indefinitely as the public published record. These are anonymous statistical output and not personal data of any reviewer.
  • Privacy-contact submission metadata: retained only as long as needed to reply and to maintain an audit trail for our records of processing. We do not retain personally identifying content beyond what is necessary to reply.

Numeric retention periods for the metadata classes above are proposed by counsel and signed by the founder before this notice is published; this draft does not invent them.

§6

Your rights

Draft · awaiting counsel sign-off

You may ask us to:

  • Access the data we hold about you. Given our substrate, the typical answer is short: we hold aggregate-only data about businesses, not about individuals.
  • Correct a brand fact you believe is wrong — file the request via the form at /privacy/contact.
  • Erase reviewer-linked metadata and the evidence quote drawn from your review. We delete the quote and reviewer-linked metadata, recompute the affected aggregate on the normal batch cadence, and write an audit-log entry. We retain the content hash under the legal-claims exemption.
  • Object to processing under our legitimate-interest basis. We consider every objection on the merits; the same outcome as erasure applies if the objection prevails.
  • Complain to a supervisory authority (in the UK: the Information Commissioner’s Office, ico.org.uk).

File any of the above through /privacy/contact. We aim to acknowledge every submission within 30 calendar days, in line with UK GDPR Art. 12(3) timing.

§7

Special-category content

Draft · awaiting counsel sign-off

Gambling reviews can incidentally disclose addiction or health information. Our extraction rule is that bounded audit excerpts never persist content revealing the reviewer’s health status, addiction, or other special-category traits. No audit excerpt is public. Where such content appears in the original review it is excluded from retention; the underlying signal still contributes to the aggregate score only via structural quality signals.

§8

Who is responsible — and how to contact us

Draft · awaiting counsel sign-off

IndexFair is operated by the site operator. The data-protection contact point is /privacy/contact. The public-facing email address is published on the contact form. Where required, the site operator is the data controller for the processing described in this notice.

The formal legal name and registered address of the responsible entity are proposed by counsel and signed off by the founder before this notice is published; this draft does not invent them.

§9

Updates to this notice

Draft · awaiting counsel sign-off

Substantive changes to this notice are versioned alongside the methodology in the public changelog. The version of this notice that applied at any given date can be reconstructed from the changelog history.


Notice versionv0.1.0 (draft)·unsigned — counsel review pending

Reviews handling: /policies/reviews. Editorial firewall: /policies/firewall. Methodology: /methodology.