Skip to main content
Postroom

Legal

Privacy Policy

Last updated: 5 October 2026

This policy explains what data Postroom collects, why we collect it, how we use it, and the rights you have over it. It applies to everything we run under the postroom-hq.com domain, including postroom-hq.com, audit.postroom-hq.com, and any audit reports or outreach emails we send.

Postroom is a trading name of The Garden Network Limited, a company registered in England and Wales (Companies House 16552976). When this policy says “we”, “us”, or “Postroom”, that’s who it means. The Garden Network Limited is the data controller for all personal data described below.

1. What we collect

1.1 Contact form and audit form

When you submit the contact form or request an audit on postroom-hq.com, we collect:

  • Your name
  • Your email address
  • Your role, organisation, and list size (audit form only)
  • Any message you write us
  • Your Mailchimp API key, if you choose to connect your account

Form submissions are delivered to our team inbox via Resend. We do not store contact form submissions in a database. Audit submissions are processed as described in section 1.2.

1.2 Mailchimp audit data

If you connect your Mailchimp account by providing an API key on audit.postroom-hq.com, we use that key to read aggregate programme data only:

  • List size and growth rate
  • Campaign send history over the last 90 days
  • Aggregate open, click, bounce, and unsubscribe rates
  • Automation titles and structure (not content)
  • Segmentation and tag structure (counts, not member identities)
  • Account-level deliverability and authentication settings

We do not read, retrieve, or store any individual subscriber email addresses, names, donor records, or other personally identifiable information from your Mailchimp account.

A Mailchimp API key is not read-only. It gives full access to the Mailchimp account it was created in, so please treat it like a password. Our audit only reads the aggregate data listed above, but the key itself could do more. We suggest you create a key just for this audit and delete it in Mailchimp once you have your report.

We keep the key in our database (Supabase, London region) alongside your audit record. Only our server can read it, and it is never sent to your browser. We do not add our own encryption on top of the database’s. It stays there until you ask us to delete it (email privacy@postroom-hq.com) or you delete the key in Mailchimp, which stops it working at once.

1.3 Newsletter content we audit

For our outbound charity-sector outreach (see section 2.3), we may read newsletters that a UK charity has sent publicly to us or to an archived list we have access to. Newsletters are public marketing content and contain no personal data of donors or subscribers. We score the newsletter against our audit framework and use the resulting observation in our outreach email.

1.4 Charity contact information

For B2B outreach to UK charity comms and fundraising leads, we maintain an internal contacts database sourced from:

  • The UK Charity Commission public register
  • Charity websites (publicly listed staff contact details)
  • LinkedIn (publicly listed professional contact details)
  • Newsletters the charity has chosen to send publicly

We hold name, professional email, role, and the charity they work for. We do not hold home addresses, personal phone numbers, or any special-category data.

1.5 Analytics

We do not currently run any analytics on postroom-hq.com or audit.postroom-hq.com. If that changes we will use a cookieless tool and update this policy first.

1.6 Error tracking

We use Sentry to capture application errors so we can fix bugs. Sentry receives the URL where an error occurred and a stack trace. If an error happens, Sentry may also record a short replay of the page, with all text and media masked. Sentry does not receive your Mailchimp API key or any Mailchimp data.

2. How we use it, and our lawful basis

Under UK GDPR we must have a lawful basis for processing every piece of personal data. Ours are as follows.

2.1 Generating your audit report

Lawful basis: consent and contract. By submitting the audit form and providing your Mailchimp API key, you are asking us to run the audit. We use your contact details to deliver the report, and your Mailchimp data to generate it.

2.2 Responding to contact form submissions

Lawful basis: consent.When you fill in our contact form, you’re asking us to respond. You can ask us to stop contacting you at any time by emailing support@postroom-hq.com.

2.3 Outbound B2B outreach to UK charities

Lawful basis: legitimate interest. We send one-to-one personal emails to comms and fundraising leads at UK charities, offering to share an observation from one of their newsletters and the option of a free audit. We rely on legitimate interest under UK GDPR Article 6(1)(f) on the following basis:

  • The recipients are professionals at registered charities, contacted at their work email about a service relevant to their job
  • The contact details are publicly published by the charity or the individual themselves
  • We send a personal one-to-one email, not a marketing broadcast
  • Every email includes a clear opt-out and the basis on which we contacted you
  • We honour opt-outs immediately and permanently across all our systems

If you’d rather not be contacted, reply with “unsubscribe” or email support@postroom-hq.com and we will remove you from our database. You can also object to our use of legitimate interest at any time (see section 5).

2.4 Improving our audit framework

Lawful basis: legitimate interest.We use the aggregate, de-identified output of audits we run (scores against the seven dimensions, identified gaps, recommendations generated) to improve our benchmark thresholds and our reporting framework. This use is aggregate only. We never expose one client’s data to another, and we never use one client’s data to generate another client’s report.

3. Who we share it with (sub-processors)

Postroom does not sell, rent, or trade personal data. We share data with a small number of trusted infrastructure providers, each bound by data processing agreements:

  • Vercel (USA, EU data residency where supported) - application hosting
  • Supabase (EU region: eu-west-2, London) - database for audit runs and our internal contacts database
  • Anthropic (USA) - Claude API, used to generate the narrative portion of the audit report and outreach drafts. Anthropic does not train on data passed via API.
  • Resend (USA) - transactional email delivery for contact forms and audit reports
  • Microsoft 365 (Outlook) - for sending and receiving outbound charity-sector outreach
  • Sentry (USA, EU data residency enabled) - error tracking
  • Mailchimp (USA) - when you connect your own Mailchimp account for an audit, we read from it using the API key you provide, via the official SDK. We do not write to your account. Connecting your Mailchimp account remains governed by your existing agreement with Mailchimp.

Where personal data is transferred outside the UK or EEA, we rely on adequacy decisions, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses, depending on the destination country and provider.

4. How long we keep it

  • Mailchimp API keys - kept in our database with your audit record until you ask us to delete them or you delete the key in Mailchimp
  • Audit reports - retained for the charity that requested the audit, accessible via a unique link, deleted on request
  • Charity contacts database - entries are retained while a charity remains active on the Charity Commission register, or until we receive an opt-out, whichever is sooner
  • Outreach drafts and sent records - retained for 90 days from creation, then automatically purged. Suppression records (opt-outs) are retained indefinitely to honour the opt-out.
  • Contact form submissions - retained in our team inbox for as long as the enquiry is active, deleted on request

5. Your rights

Under UK GDPR you have the right to:

  • Ask for a copy of the personal data we hold about you
  • Ask us to correct anything that’s wrong
  • Ask us to delete your data
  • Ask us to restrict how we use it
  • Object to our use of legitimate interest as a lawful basis (this is the relevant basis for the charity contacts database and outbound outreach)
  • Ask us to port your data to another provider
  • Withdraw consent at any time, where we rely on consent (this does not affect processing before withdrawal)

To exercise any of these, email privacy@postroom-hq.com. We aim to respond within 14 days and will always respond within 30 days as required by law.

You also have the right to complain to the UK Information Commissioner’s Office (the ICO) at ico.org.uk if you think we’re mishandling your data. We’d appreciate the chance to address it directly first, but it’s your right either way.

6. Security

We protect your data with encrypted connections (TLS), a database that only our server can read, and secrets held in environment settings rather than in our code. No system is perfectly secure. If a breach puts your personal data at risk, we will tell the ICO within 72 hours where the law requires it, and tell you without undue delay where the risk to you is high.

7. Cookies

postroom-hq.com and audit.postroom-hq.com do not use marketing, advertising, or third-party tracking cookies. We do not use Google Analytics or any other analytics tool. audit.postroom-hq.com may set strictly necessary cookies to keep you signed in to your audit account. These do not require consent under PECR.

8. Children

Postroom’s services are for UK organisations and the professionals who run them. They are not directed at children and we do not knowingly collect personal data from anyone under 18.

9. Changes to this policy

If we change this policy, we’ll update the date at the top and, for material changes, notify anyone with an active audit account by email. The current version of this policy always lives at postroom-hq.com/privacy.

10. Contact us

Privacy questions, data subject requests, and complaints: privacy@postroom-hq.com

General questions and unsubscribe requests: support@postroom-hq.com

Postal address:
The Garden Network Limited
Companies House 16552976 (England and Wales)
Registered office: Concorde Road, Concorde Park, Maidenhead, England, SL6 4BY