Skip to content
Project Universal Universal UK resort updates
Privacy and data protection

Privacy policy

A plain-English explanation of the personal data Project Universal uses across the website, community, installed app, alerts, optional analytics and any store features.

Last reviewed 3 August 2026
The essentials

Your data is used to provide the feature you choose

Project Universal does not sell personal data and does not use it for personalised advertising. Optional analytics, email updates and phone notifications require a choice from you and can be switched off independently.

ControllerProject Universal, United Kingdom.
Privacy contactDedicated contact-form request route.
No data salesPersonal information is not sold or rented.
Human contactPrivacy requests and complaints can be submitted online.
Who is responsible

The data controller

Project Universal is the controller of personal data used for this website and its connected community, PWA, email, push and store functions. It is an independent UK service and is not part of Universal, Comcast or NBCUniversal.

Contact Project Universal

Use the contact form for a privacy request, objection, complaint or question. Select “Privacy, data rights or complaint” so the request can be routed and reviewed appropriately.

Separate services

Stay Near Universal and websites reached through external links have their own controllers and privacy information. This policy applies only to processing controlled by Project Universal, even where an external card or player appears on this site.

Information collected

What Project Universal may know about you

The information depends on which features you use. Browsing without signing in requires less information than using an account, alerts or checkout.

Details you provide

Name, email address, public username, country, password hash, profile fields, avatar, preferences, contact messages, comments, reports, submitted articles and media, newsletter choices, and order or billing details where a store is offered.

Technical and security data

IP address, browser and device information, timestamps, session and consent identifiers, sign-in history, security events, form-verification results, referral or page path, and records used to prevent spam, fraud or unauthorised access.

App and engagement data

Push endpoint and encryption keys, notification permission and delivery status, PWA install or open signals, email confirmation and delivery status, likes, notification state and—only after analytics consent—page views and selected interactions.

Public information

A public username, avatar, enabled profile, comments and published contributions are visible to other people and may be indexed or shared. Do not include private information that you do not want made public.

Editorial sources

Reporting may include information obtained from public records, official documents, public events, first-hand observation, correspondents, contributors or other lawful sources. This can include names, roles, statements and incidental images of people.

Sensitive information

Project Universal does not ask users to provide special-category or criminal-offence data through ordinary community or contact features. Avoid submitting it unless genuinely necessary and lawful; unnecessary sensitive material may be removed.

Purpose and lawful basis

Why the data is used

More than one lawful basis can apply to the same activity. “Legitimate interests” means the proportionate interests identified below, balanced against your rights unless UK law provides a recognised legitimate-interest basis that does not require that balancing test.

Contract or requested steps

Accounts and requested services

Create and administer accounts, authenticate users, provide profiles, comments, contributor tools, notification preferences, downloads and purchases you request.

Consent

Email, push and optional analytics

Send new-post email, enable browser or PWA notifications, and load Google Analytics 4 only after the relevant opt-in. Consent can be withdrawn without affecting earlier lawful processing.

Legitimate interests

Security, moderation and improvement

Protect accounts and networks, prevent spam and fraud, keep evidence of misuse, moderate contributions, diagnose faults, measure essential service health and improve a safe, reliable editorial community.

Legitimate interests

Independent reporting

Research, document and publish matters of public interest relating to the Universal UK project. Where applicable, processing for journalism and publication is assessed under the Data Protection Act’s special-purposes framework; it is not treated as a blanket exemption.

Legal obligation

Rights, complaints and records

Respond to data-protection rights and complaints, keep records required by consumer, tax or accounting law, and disclose information where a valid legal duty applies.

Legitimate interests or legal claims

Enquiries and disputes

Answer questions, consider corrections, preserve relevant evidence, obtain professional advice and establish, exercise or defend legal claims.

Your right to object

You may object to legitimate-interest processing

You have the right to object where processing is based on legitimate interests, including relevant profiling. Project Universal will stop unless it can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You have an absolute right to object to direct marketing at any time. Use the contact form or email the privacy address above.

Feature detail

How optional services work

Email subscriptions

The system records the address, signup source, consent wording and time, confirmation and unsubscribe status, plus limited anti-abuse information. Double opt-in confirms the address before new-post mail is enabled. A minimal suppression record may be retained after unsubscribe so mail is not restarted accidentally.

Phone and PWA alerts

After device permission, the server stores the endpoint and cryptographic keys supplied by the browser push service, limited user-agent data, status and delivery outcomes. A signed-in member ID may be associated. Disable alerts on the site or in device settings.

Google Analytics 4

After acceptance, measurement ID G-CNCRGL0BC0 can process online identifiers, approximate location, device/browser information, page views and selected events, including consented PWA and notification signals. It is used for service measurement, not personalised advertising.

Community features

Accounts link profile details, settings, comments, likes, reports, moderation status and security information. Passwords are stored as hashes rather than readable passwords. Permanent account deletion removes the account and connected community content from the active community system, subject to lawful records and backup cycles.

Contact and corrections

Contact forms send the supplied name, email, subject, message, contact category, timestamp and IP address to the Project Universal inbox. The information is used to review, answer and, where relevant, evidence the enquiry, correction, rights request or complaint.

Store and payments

If the store is enabled, Project Universal processes order, product, licence, price, coupon, delivery and contact records. Stripe or another disclosed payment processor handles card payment data under its own privacy terms; Project Universal receives transaction status and identifiers rather than full card details.

Recipients

Who may receive personal data

Only the information reasonably needed for each service is shared. Providers are expected to process it under applicable law and contractual or service controls.

Hosting and infrastructure

Website, database, backup, logging and email infrastructure providers that keep the service available and secure.

Cloudflare

Turnstile receives technical and network signals to protect forms from automated abuse. Cloudflare may also provide network security or delivery services.

Google

Google Analytics receives consented measurement data. YouTube can receive device and request data when an embedded player is loaded or used.

Spotify and media providers

An embedded podcast or external media player can receive IP address, browser and interaction information under the provider’s own privacy terms.

Push providers

Apple, Google, Mozilla, Microsoft or another browser/device provider routes requested notifications to the subscription endpoint.

Payment and professional services

Payment processors, accountants, insurers, legal advisers or other specialists may receive data necessary for a transaction, compliance or a legal claim.

Authorities and legal recipients

Information may be disclosed where required by law, court order or a valid authority request, or where necessary to protect rights, safety and security.

The public

Information deliberately published through profiles, comments or articles is available to readers, search engines and people who share or archive the page.

Project Universal does not sell personal data, does not provide it to data brokers and does not permit Google Analytics to run before the site records analytics consent.

International processing

Data outside the UK or EEA

Some technology providers operate internationally. Where personal data is transferred from the UK or EEA to a country without an applicable adequacy decision, Project Universal relies on an available lawful safeguard appropriate to the transfer, such as the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, and supplementary measures where required. Contact Project Universal for information about safeguards relevant to a particular provider.

UK visitors

The principal framework is the UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, together with PECR for electronic communications and device storage.

EEA visitors

Where EU GDPR applies, Project Universal intends to respect its transparency, lawful-basis, transfer and individual-rights requirements. Mandatory rights under the law of your country remain available.

Storage limitation

How long information is kept

Retention is reviewed by purpose, legal requirements, dispute periods, security needs and whether the information remains accurate and necessary.

Accounts and communityWhile the account is active, then deleted or anonymised following closure, subject to short backup cycles and records needed for security, moderation or legal claims.
Published editorial materialMay remain in the public archive while it retains editorial, historical or public-interest value, with corrections, updates, restriction or removal considered where appropriate.
Email and pushActive until withdrawn, disabled or expired. Limited consent, suppression and delivery records may remain as needed to prove choices, prevent further contact and diagnose delivery.
Enquiries and complaintsFor the time needed to respond and a reasonable follow-up or legal-claims period; longer where an unresolved dispute or legal obligation requires it.
Security and moderationRoutine logs are kept for a limited operational period. Records linked to abuse, bans, fraud or an incident may be kept longer to protect users and the service.
Orders and accountingNormally for up to six years after the relevant financial period or transaction, where needed for UK accounting, tax, consumer or legal-claims records.
Analytics and consentAnalytics identifiers and device storage follow the periods described on the cookies page. Server consent records remain only as long as reasonably needed to demonstrate and respect the choice.
Your legal rights

Access, correct, delete or control your data

Rights depend on the circumstances and lawful basis and may be subject to legal exemptions, including protections for other people and, where applicable, journalism.

Be informedUnderstand what data is used and why.
AccessRequest a copy of your personal data.
RectificationCorrect inaccurate or incomplete information.
ErasureAsk for deletion where the right applies.
RestrictionLimit certain processing while an issue is resolved.
PortabilityReceive eligible consent/contract data in a reusable format.
ObjectChallenge legitimate-interest processing and direct marketing.
Withdraw consentStop future consent-based processing at any time.

Requests are normally answered without undue delay and within one month after any identity verification reasonably needed. A complex request may take up to two additional months where the law permits; Project Universal will explain an extension within the first month. Requests are normally free, although the law permits a reasonable fee or refusal for manifestly unfounded or excessive requests.

Automation and children

Safeguards for people

No significant automated decisions

Spam, security, fraud and moderation tools may flag or restrict activity for review, but Project Universal does not currently use personal data to make solely automated decisions that produce legal or similarly significant effects. Contact the site if an automated control appears to have affected you incorrectly.

Children’s information

The service is a general-audience news platform and is not designed specifically for children. Anyone under 13 should not create an account or submit personal data. Under-18s should use interactive features with a parent or guardian. A parent or guardian can ask Project Universal to review or remove a child’s information.

Protection

Security and data incidents

Project Universal uses proportionate technical and organisational controls such as password hashing, protected sessions and forms, access controls, anti-abuse checks, provider security, backups and monitoring. Access is limited to people and providers who need it for an authorised purpose.

No internet service can promise absolute security. If a personal-data breach is likely to risk people’s rights and freedoms, Project Universal will assess notification to the relevant supervisory authority and affected people within the legal requirements that apply.

Concerns and complaints

Complain to Project Universal or a regulator

Project Universal complaint

Submit a privacy complaint electronically through the contact form or privacy email. Project Universal will acknowledge it within 30 days, investigate it appropriately and communicate the outcome without undue delay, in line with the UK complaints procedure now in force.

United Kingdom

You may complain to the Information Commissioner’s Office. The ICO generally recommends raising the concern with the controller first, but that does not remove your right to contact it.

European Economic Area

Where EU GDPR applies, you may complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred. You may also contact Project Universal first so the issue can be investigated directly.

Changes and questions

Keep this notice with your records

This policy may change when features, providers or law change. Material changes apply prospectively, and the review date identifies the current version. Contact Project Universal if you need an accessible copy or information about a particular processing activity.