A draft, not yet in force. It still needs XONIK's registered name, registered address, contact address, governing law and date they take effect. Until then this describes accurately what the software does, and it is not a document anybody should rely on.

Privacy notice

In force from [not yet in force]

What Dispatch holds about people, why, and for how long. The controller for the people who use the panels is [registered name], registered at [registered address]. Questions, requests and complaints go to [contact address], and we answer within 30 days.

What we hold

What we do not hold

We do not collect LinkedIn profile data about people who have not interacted with your posts, build audience or lead databases, scrape anything, or run advertising or behavioural analytics. There are no third-party trackers in the panels. We do not use anything here to train a model, ours or anybody else's.

Why we are allowed to

Account people, content, approvals Performing the contract with your organisation
Audit log, sign-in addresses, throttling Our legitimate interest in keeping the service secure and being able to show what happened
LinkedIn tokens Performing the contract, on the authorisation the member gave through LinkedIn's own sign-in
Invoices and payment records A legal obligation

Who else sees it

The current list, with each provider named, is on the security page and is kept there rather than here so it cannot go out of date quietly. Nobody else sees it. We do not sell personal data, and there is no circumstance in which we would.

Where it lives, and transfers

The database and the graphics sit on one server in the region named on the security page. Where a provider necessarily processes data outside that region, the transfer relies on the standard contractual clauses or on an adequacy decision, whichever applies to that provider.

How long

Every table has a written rule and the deletion runs on a schedule rather than on a query filter. The rules, and whether anything is overdue, are published on the security page. In summary: another member's profile data for 24 hours, comments and mentions for six weeks, reporting figures for a year, approvals for seven years because that is how long the question they answer gets asked, and everything else for as long as the account exists. Invoices are kept as long as tax law requires.

When an account is erased, everything under it goes with it — immediately, permanently, and including the image files on disk. One audit row survives recording that an erasure happened, without the content.

Your rights

Access, correction, erasure, restriction, objection and portability. Export and erase are both buttons in the panel, so two of these do not require asking us: the export is a complete archive of everything the account holds, in formats that open without us. For the rest, write to [contact address].

Where an agency uses Dispatch for its clients, the agency is the controller for that content and we are its processor; a request about it should go to them and we will help them answer it.

You can complain to the supervisory authority where you live or work. In the UK that is the Information Commissioner's Office; in the EU, your national authority. We would rather you told us first, but you do not have to.

Cookies

One, called session. It is what keeps you signed in. It is HttpOnly, SameSite=Lax, and expires after twelve hours. There are no analytics or advertising cookies, which is why Dispatch has no cookie banner: there is nothing to consent to.

Automated decisions

None. Nothing here decides anything about a person automatically, and nothing is profiled.

Assisted drafting

Parts of Dispatch are assisted by a language model: research briefs, draft post copy, and the written summary in the monthly report. What is sent to it is the brief or the draft you are working on. LinkedIn member data is not sent to it — not the names, headlines or photographs of people who comment on your posts, and not your account holders' personal data. The model provider is named in the sub-processor list on the trust page, along with what it can see.

Assembled with the help of a language model. Check each figure against the source shown beside it before acting on it.

If something goes wrong

If personal data is exposed, we will tell the affected accounts and the supervisory authority within 72 hours of becoming aware, and say what we know even where that is not yet everything.

Changes

If this notice changes materially we will email the accounts it affects before it takes effect. The date at the top is when the current version started.