Privacy Policy
Last updated: June 2025
1. Who we are
Cross Shaped is a personal blog operated by Tom Attwood, based in the United Kingdom. For the purposes of UK data protection law, Tom Attwood is the data controller.
If you have any questions about this policy or how we handle your personal data, you can contact us via tomattwood.me.
2. What data we collect
We may collect the following types of personal data:
- Usage data — pages visited, time spent on pages, referring URLs, and browser/device type, collected automatically via analytics tools.
- Contact information — if you contact us directly (e.g. by email), we may retain your name and email address to respond to your enquiry.
- Cookies — please see our Cookie Policy for full details.
We do not collect sensitive personal data, financial information, or data from children under 13.
3. How we use your data
We use the data we collect to:
- Operate and improve the website and its content.
- Understand how visitors use the site (analytics).
- Respond to any enquiries you send us.
- Comply with our legal obligations.
Our lawful bases under UK GDPR are: legitimate interests (analytics and site improvement) and contract / consent (responding to enquiries).
4. Sharing your data
We do not sell your personal data. We may share limited data with trusted third-party service providers who help us operate the website (such as hosting providers and analytics services). These providers process data only on our behalf and are bound by appropriate data processing agreements.
We may also disclose data where required by law or to protect the rights, property, or safety of ourselves or others.
5. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law. Analytics data is typically retained for no longer than 26 months.
6. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data (the "right to be forgotten").
- Object to or restrict our processing of your data.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us via tomattwood.me. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
7. Third-party links
Our site may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
8. Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date. We encourage you to review this page periodically.