Privacy
Privacy notice
Last revised Jul 06, 2026 — replaces the notice of Mar 02, 2025
This notice covers alopromos.com and the ledger we send by email. It is written to be read, not to be survived. If anything here is unclear, mail contact@alopromos.com and we will answer in plain language.
Who is responsible
Alo Promos OÜ, Roseni 7, 10111 Tallinn, Estonia, is the controller of the personal data described here. We have no data protection officer — the editors handle these requests themselves. Write to contact@alopromos.com for anything in this notice.
What we collect
We keep as little as the publication can run on. In practice that is:
- Your email address, if you ask to receive the ledger. Nothing else is required — we do not ask for a name, a country, or a date of birth.
- The date you subscribed and the address you subscribed from, so we can show consent was given if it is ever disputed.
- Delivery outcomes for each issue: whether it was accepted, bounced, or marked as spam by the receiving server. This tells a dead address from a quiet reader and keeps our sending reputation honest.
- Whether an issue was opened, and which links were used, in aggregate. We use it to judge whether a window was worth writing up. It is not attached to a profile and we do not act on one reader’s behaviour.
- Server logs for this website: IP address, timestamp, page requested, and the browser’s user-agent string, recorded by our host for security and traffic counting.
- The contents of your email, if you write to us — kept as long as the correspondence is live.
What we do not collect
No advertising trackers, no analytics that follow you between sites, no data bought from or matched against a third-party broker, and no attempt to work out who you are beyond the address you gave us. This site sets no cookies. The only third-party request a page makes is to Google Fonts for the two typefaces the design uses.
The legal basis for keeping it
For the ledger itself, your consent — you asked for it, and withdrawing consent stops it. For delivery records and server logs, our legitimate interest in running a working, secure mail service. For correspondence, the legitimate interest in answering you. Where we rely on legitimate interest, you can object using the address above and we will weigh it and reply.
How long we keep it
- Your address: until you unsubscribe or ask for erasure.
- Addresses that go quiet: removed after eighteen months with no opened issue. We would rather shrink the list than mail into the void.
- Consent and delivery records: twelve months after the address is removed.
- Aggregate open and link counts: twenty-four months, then deleted.
- Server logs: thirty days.
- Correspondence: twenty-four months after the last message.
Who else sees it
Our email delivery provider and our web host process data on our instructions under written agreements, and only to run the service. Both operate inside the European Economic Area. We do not sell, rent, lend, or trade the list, and we never send on another party’s behalf — no issue you receive from us is somebody else’s mail wearing our masthead. We would disclose data if a court or a competent authority lawfully required it, and we would tell you unless barred from doing so.
Leaving, and your other rights
Every issue carries an unsubscribe link at the foot. It works on the first click — no confirmation step, no survey, no counter-offer. Mailing contact@alopromos.com works just as well, and we remove the address the same working day.
Under the GDPR you may also ask us to give you a copy of what we hold, correct it, erase it, restrict what we do with it, hand it to you in a portable format, or object to processing based on legitimate interest. Ask by email; we reply within thirty days and we charge nothing. We ask no security questions beyond being able to send our answer to the address in question.
If we handle a request badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn) or to the authority where you live. We would rather you told us first.
Security, and children
The site is served over HTTPS and the list is held on access-controlled systems with encryption at rest. No arrangement is perfect; if a breach ever affects your data we will tell you and the supervisory authority within the deadlines the law sets. The ledger is written for adults and we do not knowingly keep addresses belonging to anyone under sixteen — tell us if one has reached us and it goes.
Changes to this notice
When this notice changes materially we say so in the next issue rather than quietly editing the page. The revision date sits under the title above, and the previous version is available on request.