Privacy Policy
Last updated: 8 September 2026
This policy explains what personal data THELEGENDRY collects through this website, why we collect it, how long we keep it and what rights you have over it. It is written to meet the information duties in Article 13 of the UK and EU General Data Protection Regulation.
Plain summary. We collect what you type into our partnership enquiry form, and standard technical information your browser sends to our server. We use it to reply to you and to run the site securely. We do not use advertising or analytics trackers, we do not sell your data, and there is nothing on this site that follows you around the internet.
1. Who is responsible for your data
The controller for the processing described here is:
| Service | THELEGENDRY (thelegendry.com) |
|---|---|
| Privacy contact | privacy@thelegendry.com |
| Partnerships | partnerships@thelegendry.com |
Written enquiries reach the person responsible for this site directly. We have not appointed a Data Protection Officer, as we do not meet the thresholds in Article 37 GDPR. Full provider details will be published here and in a legal notice once the operating entity for THELEGENDRY is established; until then, the contact address above is the route to a person who can act on your request.
2. What we collect, and why
Partnership enquiries
When you use the enquiry form we receive your company, name, work email address, optional phone number, partnership type, indicative budget band and the message you write. We use this to assess the enquiry and to reply to you.
Legal basis: Article 6(1)(b) GDPR, steps taken at your request before entering into a contract. Where an enquiry does not lead to a contract, our continuing interest in keeping a record of business contacts rests on Article 6(1)(f), legitimate interests.
Providing this information is voluntary, but without an email address we cannot reply to you.
Email correspondence
If we exchange email, we keep the correspondence and the contact details in it, so that a conversation picked up months later still makes sense. Legal basis: Article 6(1)(b) and (f).
Server and security data
Our hosting provider records standard request data: IP address, timestamp, the page requested, HTTP status, referrer and browser user-agent. This is unavoidable in operating a web server and we use it to keep the service available and to detect abuse such as automated form submissions or credential-stuffing attempts. Legal basis: Article 6(1)(f), our legitimate interest in operating the site securely.
Staff portal accounts
People working with THELEGENDRY may hold an account on our internal portal, which stores a name, email address, role and a hashed password. Passwords are stored using bcrypt and are never held in a readable form. Legal basis: Article 6(1)(b), performance of the working relationship. This does not apply to website visitors.
3. Cookies and tracking
The public pages of this website set no cookies at all. There are no advertising, analytics or profiling cookies, and no third-party trackers, pixels or embedded widgets. Web fonts, images and scripts are served from our own server, so opening a page does not disclose your IP address to any other company. You can verify this in your browser's developer tools: the public pages make no requests to any domain other than thelegendry.com.
The staff portal, which is not part of the public site, sets one strictly necessary cookie to keep a signed-in session. Under ยง25(2) TDDDG a cookie strictly necessary to provide a service the user has requested does not require consent, so there is no consent banner on this site. If we later add analytics, we will ask for consent before anything non-essential loads, and refusing will be as easy as accepting.
4. Who else processes your data
We keep the number of parties involved deliberately small. Each of these acts as a processor on our written instructions:
| Processor | What they do | Where |
|---|---|---|
| Railway Corp. | Hosting for the website, application and PostgreSQL database | United States |
| Microsoft Ireland Operations Ltd. | Business email and outbound mail delivery (Microsoft 365 / Graph) | EU, with US parent access |
| Domain registrar and DNS provider | Domain registration and DNS resolution for thelegendry.com. Handles the lookup only; it does not receive form content. | Varies by provider |
We do not sell personal data, and we do not share enquiry details with the creators we represent until a partnership is being actively discussed and you would expect us to.
5. Transfers outside the EEA
Some of the providers above process data in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. You may request a copy of the safeguards in place by writing to the address in section 1.
6. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not lead to a partnership | 24 months from last contact, then deleted |
| Enquiries and correspondence tied to a contract | As required by commercial and tax law, then deleted |
| Server and security logs | Short-lived, retained by our host for operational purposes only |
| Portal accounts | For as long as the person works with us, then deleted |
7. Your rights
Under Articles 15 to 21 GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy
- Correct data that is inaccurate or incomplete
- Erase your data where we no longer have grounds to keep it
- Restrict processing while a dispute about accuracy or grounds is resolved
- Portability, receiving data you gave us in a machine-readable form
- Object to processing based on legitimate interests, including at any time to direct marketing
- Withdraw consent where processing is based on it, without affecting what happened before
Write to privacy@thelegendry.com and we will respond within one month. You also have the right to complain to a supervisory authority, in particular in the country where you live or work.
8. Security
The site is served over HTTPS only. Passwords are hashed with bcrypt and never stored in readable form. The internal portal requires authentication and applies role-based access, so an account only reaches the applications it has been granted. Database access is restricted to the application. Public forms are rate-limited to slow automated abuse.
No system is perfectly secure, and we would rather say so than imply otherwise.
9. Changes to this policy
We will update this page when our processing changes, and will change the date at the top. Where a change materially affects you, we will say so rather than relying on you to notice.