Privacy

What this website collects

Very little, and only when you act. This page covers the website. How the platforms handle learner and programme data is a separate matter, described on our security and privacy page.

What we collect

Browsing these pages requires nothing from you. We collect information in exactly three situations.

What you type into the contact form

Your name, email address and message, plus your organisation and a subject line if you choose to give them. You decide what to put in the message, so please do not include sensitive personal information you would not want held in a business record.

How you arrived, if you came from a campaign

If a link you followed carried campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), we record them. We also record the referring website when it is not one of our own pages. This is stored in your browser for the current tab only, is never sent anywhere until you submit the form, and is discarded when you close the tab.

Your light or dark mode preference

Stored in your browser so the site does not flash the wrong theme on your next visit. It never leaves your device.

That a page was read, and roughly for how long

We record which page was opened, when, the website you came from (its name only, never the full address), whether you are on a phone, tablet or computer, and how long the page was actually visible. We measure this ourselves — no other company is involved and nothing is shared.

A rough location, worked out and then forgotten

Your device’s IP address reaches our server, as it must for any website to reply to you. We use it while answering that one request to work out a country, and then we discard it. It is never written into the visit records, so we cannot go back and identify anyone from them — including if we were asked to.

A short-lived security log, kept separately

Like any server exposed to the internet, ours keeps a short access log that does include the address a request came from. That is what lets us recognise an attack, block a source that is probing us, and answer the question "what happened" after the fact — it is a security measure, not a measurement one. These logs are capped in size and roll over within a few weeks, they are never joined to the visit records above, and nothing from them reaches our analytics.

Which network you came from — the organisation, not you

From the same address, in the same moment, we also work out what kind of network you arrived on (home or mobile, a business, a university, a government network, a data centre) and, where the network is a large one, who operates it — “Comcast”, “Jisc”, a named university. This describes the network, not you: it is looked up in a public registry of who owns which part of the internet, the same information anyone can read, and nothing about your visit is sent anywhere to find it out.

And we will not name a small network at all

A large internet provider covers millions of people, so naming it says almost nothing about any one of them. A small network can cover a single office, or one person. So we simply do not record the name of any network smaller than about four thousand addresses — those visits are recorded as a category and nothing more. On top of that, our own reports never show an organisation with fewer than three visits, so a single visit from one place is never displayed as its own line.

A daily count that cannot follow you

To count how many people visited rather than how many pages were opened, we turn your address and browser into a short scrambled code using a secret that changes every night. The old secret is thrown away, so tomorrow the same person produces a completely different code. There is no way to connect one day to the next — we have deliberately made that impossible for ourselves as well.

When something breaks in your browser

If a piece of our code fails while you are on a page, your browser tells us what went wrong — the error message, the technical trace, which page it happened on and whether you are on a phone or a computer. We use it to fix the fault. It is not connected to anything else we record, so it cannot be linked back to your visit, and it goes nowhere but our own server. We also record how quickly pages load and settle, for the same reason and in the same way.

And we delete it after 90 days

The detailed records above are kept for 90 days and then deleted. What remains is a daily total — how many pages were opened, by roughly how many people — which describes nobody. This runs automatically rather than when someone remembers, and the code will not let us publish a period here that it does not actually enforce.

What we do not do

  • No advertising or tracking cookies. In fact this site sets no cookies at all; the two things we remember use your browser’s own storage.
  • No third-party scripts. Nothing on these pages loads code from another company, so no one else observes your visit.
  • No profile of you. Your address is never written into the visit records, and the daily code that counts visitors is designed so it cannot be linked across days. The security log described above is kept apart from all of it and is never used to build a picture of anyone.
  • No cross-site tracking. We cannot see what you do anywhere else, and nothing we record leaves this site.
  • No selling or sharing. We do not sell personal information and we do not pass it to anyone for their own marketing.

Where your enquiry goes

Submitting the contact form creates a record in our own project-management system, which is where we track enquiries so that none is lost and someone is accountable for replying. It runs on infrastructure we operate rather than a third-party CRM, and the record holds what you submitted along with the campaign details described above. Access is limited to the people who need it to respond to you.

We use campaign information to understand which of our activities bring people to us. It is attached to your enquiry rather than used to build a profile of you, and we do not track you across other websites.

How long we keep it

We keep your enquiry for as long as we are dealing with it, and for up to 24 months after our last contact with you, so that we have context if you get back in touch. If a working relationship begins, the records that relationship generates are kept for as long as it lasts and for as long as we are then required to keep business records. Ask us to delete your enquiry sooner and we will, unless we are legally required to retain it.

Your choices

You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Just write to us and say so. You do not need to use a particular form of words, and we will not ask you to justify the request.

If you would rather we did not record how you found us, remove the campaign parameters from the link before you open it, or open the site in a private window. The form works exactly the same either way, and we would rather you contacted us without attribution than not at all.

Changes

If what we collect changes, this page changes with it. We would rather describe the position accurately than keep a policy broad enough to cover things we do not actually do.

Asking us about this

Questions about this page, or a request about your own information, go to privacy@hsinc.ai. The contact form reaches us just as well if you would rather use that.

Contact us