Privacy Notice
Effective 27 July 2026
This notice explains what personal information ELEVEN28 collects through https://1128club.com, why it is collected, how long it is kept and what you may ask us to do with it. It covers this website only.
ELEVEN28 is an independent business operating under its own name. It is not an incorporated company, and it has no separate corporate identity behind it. ELEVEN28 is the controller of the personal information described here, and can be reached at privacy@1128club.com.
We correspond by email. There is no public postal address for this site.
1. Information you give us
The only form on this website that asks for personal information is the request for consideration. When you submit it we record the following, because each is part of the request itself:
- your name;
- your email address;
- your organisation;
- your primary industry;
- your country;
- your website;
- the name of the person who proposed you, if you give one; and
- the statement of intent you write.
We also record the date and time of the submission. We do not ask for, and the form cannot accept, financial details, identity documents or special category data as defined by data protection law. Please do not include such information in your statement of intent.
Our lawful basis is our legitimate interest in assessing requests for consideration and in deciding who to admit to a private institution. You may object to that processing at any time using the contact details in section 9.
A request for consideration does not create a member account and does not give access to the member area.
2. Information collected automatically
This website runs first-party analytics. It is built and hosted by us and sends nothing to an advertising network. What it records, and the choice you have over it, is set out in full in our Cookie & Analytics Notice. In summary, for each page you view we record the page address, the page title, the referring page, how far down the page you scrolled, how long the page was actively in front of you, your browser language and a coarse screen-size band; and we derive from your request a two-letter country code, a coarse region name, a device type (mobile, tablet or desktop), a browser family and an operating system.
We do not store your IP address. It is converted into a one-way hash, mixed with a secret and the current date so that the same address produces a different value the following day, and that hash is deleted after 72 hours. It exists only to enforce rate limits and to exclude abusive traffic.
Our lawful basis for measurement that does not identify you is our legitimate interest in understanding how our writing is read. Where the measurement relies on storing an identifier on your device, we rely on your consent — see the Cookie & Analytics Notice.
Our hosting provider also keeps short-lived server logs, which include IP addresses, for security and operational purposes.
3. The member area
If you hold a member account we store your email address, your name, a one-way bcrypt hash of your password (never the password itself) and the time you last signed in. Signing in sets a single cookie, e28_session, which holds a signed session token. It is marked HttpOnly, Secure and SameSite=Lax, expires after seven days and is strictly necessary to keep you signed in.
We also record failed sign-in attempts, both against the email address used and against a one-way hash of the network address they came from, so that we can slow down and block password-guessing. We do not store the address itself. Those records are deleted when you sign in successfully, and swept automatically once they are no longer needed.
Our lawful basis is the performance of our agreement with members, and our legitimate interest in protecting accounts from unauthorised access.
4. What we do not do
- We do not sell personal information.
- We do not share it for advertising, and we run no advertising or cross-site tracking technology.
- We do not build profiles of you across other websites.
- We make no automated decision that produces a legal or similarly significant effect on you. Every request for consideration is read and decided by a person.
- We do not send marketing email to addresses collected through the consideration form unless you have separately asked us to.
5. Who we share it with
We use a small number of service providers to run this website. They process personal information on our instructions and are not permitted to use it for their own purposes:
- Netlify — hosting, content delivery and serverless functions.
- Neon — the managed PostgreSQL database in which submissions, analytics events and member records are stored.
- an external notification service of our choosing — a transactional email or messaging provider, used for one purpose only: delivering the internal alert that tells us a request for consideration has arrived. It receives your name, email address, organisation, industry, country, website and an opening extract of your statement of intent.
We will also disclose information where we are required to by law, or where it is necessary to establish, exercise or defend a legal claim.
Some of these providers operate infrastructure outside the United Kingdom and the European Economic Area. Where personal information is transferred outside those areas we rely on the safeguards each provider offers, including the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses.
6. How long we keep it
- Requests for consideration, and the internal review notes attached to them: 24 months after our latest meaningful contact with you — not from the date you submitted — unless we need to keep the information for an active relationship, an unresolved dispute or a legal obligation. You may ask us to erase it sooner.
- Individual analytics events: 13 months, after which they are deleted automatically. Aggregated daily counts, which identify nobody, are kept indefinitely.
- The hashed request value described in section 2: 72 hours.
- Failed sign-in records: deleted on a successful sign-in, and swept automatically thereafter.
- Member account records: for as long as the account exists, and for a short period afterwards to meet our legal obligations.
- Administrative audit records of sign-ins and editorial actions: retained as a security record.
7. Security
The site is served over HTTPS only, with HSTS and a strict content security policy. Database connections require TLS. Passwords are stored only as bcrypt hashes. Access to submissions is limited to authenticated administrators, and every administrative action is recorded in an audit log.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority, and you where the law requires it.
8. Your rights
Subject to the conditions in data protection law, you may ask us to:
- give you a copy of the personal information we hold about you;
- correct it if it is wrong;
- erase it;
- restrict how we use it;
- provide it in a portable form; or
- stop processing it where we rely on legitimate interests, including for analytics.
You may withdraw analytics consent at any time from the Cookie & Analytics Notice page, without affecting anything done before you withdrew it.
We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
9. Contacting us, and complaining
Email privacy@1128club.com about anything in this notice, including a request under section 8.
If you are not satisfied with our response you may complain to the Information Commissioner’s Office, the United Kingdom’s independent data protection regulator. Its guidance on making a complaint, and the ways to do so, are at https://ico.org.uk/make-a-complaint/.
We would ask you to raise it with us first, so we have the chance to put it right.
10. Changes
If we change how we handle personal information we will update this page and the effective date at the top of it. Material changes will be described at the top of the page for a reasonable period.