The Toaster Back to Law on Toast

Privacy Policy

PRIVACY POLICY: THE TOASTER

Last updated: 16/08/2026

This privacy policy explains how The Toaster (“Blog”) handles personal information. The Toaster is an editorial blog operated by Law on Toast and its contributors. It is intended to share practical, real-life legal experiences and commentary rather than purely theoretical legal material.

1. WHO IS RESPONSIBLE FOR YOUR INFORMATION?

The data controller is:

Law on Toast
info@lawontoast.com

If you have a question about this policy, want to withdraw consent, or want to exercise a data protection right, contact us using the email address above.

2. INFORMATION WE MAY COLLECT

Depending on how you use the Blog, we may process contributor information that you choose to provide, such as your name, photograph, job title, area of work, biography, social media link, location, professional experience, or other details included in an article or author profile.

We may process article and editorial information that you submit, including the content of your article and any personal information contained within it.

For authorised WordPress users, we may process account and administration information, such as usernames, email addresses, password information, login records, and account activity.

If you contact us, we may process information you provide, including your name, email address, message, and any attachments.

When the Blog is used, technical information may be generated or recorded, such as IP addresses, browser and device information, requested pages, dates and times, referring URLs, and security or error information recorded by the VPS, Nginx, WordPress, security tools, or hosting provider.

If Google Analytics has been enabled and you have given the required consent, we may also collect website usage information. This may include information about pages viewed, approximate location, device and browser information, and interactions with the Blog.

3. INFORMATION YOU CHOOSE TO PUBLISH

You decide what optional personal information to provide for an article or author profile. Please provide only information that you are comfortable making publicly available on the internet.

Do not include confidential information, privileged information, case details that identify someone, personal contact details, passwords, financial information, health information, or other sensitive information unless you have a lawful and documented reason to do so and have obtained every required permission.

If an article refers to a real person, client, case, workplace, or event, you must anonymise the information where appropriate and obtain any permissions required before submission. Law on Toast does not ask contributors to disclose confidential professional information.

Information published on the Blog may be visible worldwide, copied by other people, indexed by search engines, and retained in third-party caches or archives. Removing an article from the Blog may not remove copies that other people or organisations have already made.

4. HOW AND WHY WE USE INFORMATION

We may use personal information to publish and manage articles, author profiles, photographs, and editorial contributions; communicate with contributors and respond to enquiries; operate, secure, troubleshoot, and maintain the Blog and its WordPress installation; administer authorised WordPress accounts and password resets; prevent abuse, spam, fraud, unauthorised access, and other security issues; understand general Blog usage and improve the site where analytics consent has been obtained; and comply with legal obligations or deal with complaints and legal claims.

We do not sell personal information. We do not use contributor information for advertising or direct marketing unless we separately explain this and have an appropriate lawful basis for doing so.

5. LAWFUL BASES

For contributor names, profiles, photographs, biographies, and other optional details that are published at your request, where the contribution is genuinely voluntary and can be refused or withdrawn without disadvantage, we generally rely on your consent.

You can withdraw your consent by contacting us. Withdrawal does not affect processing that took place before consent was withdrawn. We may also need to retain a limited record of the request or relevant information where required by law or where necessary to establish, exercise, or defend legal claims.

If a contributor relationship involves a position of authority or another imbalance, we will not assume that consent is automatically valid. We will consider the appropriate lawful basis and safeguards for that situation.

For operating and securing the Blog, administering authorised accounts, responding to messages, and maintaining appropriate records, we generally rely on legitimate interests, contractual necessity where applicable, or legal obligations. We consider the effect on individuals before relying on legitimate interests.

For non-essential analytics cookies and similar technologies, we rely on your consent where required by applicable law. You can refuse or withdraw analytics consent without losing access to the Blog.

If we need to process special category information, such as information concerning health, political opinions, religious or philosophical beliefs, trade union membership, biometric data used for identification, sex life, or sexual orientation, we will not do so through the normal contributor process. Please contact us first so that the appropriate legal condition and safeguards can be considered.

6. WHO MAY RECEIVE INFORMATION?

Personal information may be processed by service providers that help us operate the Blog. These may include the VPS hosting provider and its infrastructure providers; the domain or DNS provider and Cloudflare, if Cloudflare is used for DNS, security, or traffic management; WordPress and carefully selected WordPress plugins; Google Analytics, where analytics is enabled and the required consent has been obtained; an SMTP or transactional email provider used to send password resets and administrative messages; and backup, security, and monitoring providers where configured.

These providers should process information only as necessary to provide their services and subject to appropriate contractual or other safeguards.

We may also disclose information where required by law, where necessary to protect the Blog or its users, or in connection with legal advice, insurance, complaints, disputes, or legal proceedings.

7. INTERNATIONAL PROCESSING

The Blog may be accessed from anywhere in the world, and some of our service providers may process information outside the UK.

Where personal information is transferred internationally and UK data protection law requires safeguards, we will use appropriate safeguards for the transfer and can provide further information on request.

8. COOKIES AND ANALYTICS

WordPress may use essential cookies for authorised logins, security, session management, and administration. These cookies are necessary for the relevant functions of the Blog.

Google Analytics uses non-essential analytics technologies to help us understand how the Blog is used. Analytics should only be loaded after a visitor has given the required consent. The Blog does not treat merely continuing to browse the website as consent.

You can refuse or withdraw analytics consent using the Blog’s cookie settings, where provided, or by contacting us. If no appropriate cookie consent control is installed, analytics must remain disabled until an appropriate consent mechanism is configured.

9. HOW LONG WE KEEP INFORMATION

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required by law or is necessary in connection with legal claims.

Published contributor information will generally be retained while the relevant article or profile remains published, unless removal is requested or another lawful reason requires its retention.

Contributor submissions and editorial correspondence will generally be retained for as long as reasonably necessary to manage the contribution and any related editorial, legal, or safeguarding matter.

WordPress account information will generally be retained while the account is active and for a limited period afterwards where necessary for security or legal record-keeping.

Security and access logs will normally be retained for no longer than 30 days, unless an incident, investigation, or legal obligation requires longer retention.

Backups will be retained according to the backup rotation configured for the VPS, after which they will be securely deleted or overwritten.

Analytics information will be retained according to the Google Analytics retention settings configured for the Blog.

10. YOUR RIGHTS

Subject to applicable legal conditions and exceptions, you may have the right to ask for a copy of personal information we hold about you; ask us to correct inaccurate or incomplete information; ask us to delete information; ask us to restrict how we use information; object to processing based on legitimate interests; receive certain information in a portable format; and withdraw consent where processing is based on consent.

To exercise any of these rights, email info@lawontoast.com. We may need to verify your identity before responding. We normally respond within one month, subject to applicable law and any permitted extension where a request is complex or where multiple requests have been made.

You also have the right to complain to the UK Information Commissioner’s Office if you have concerns about how your personal information has been handled.

11. SECURITY

We use reasonable technical and organisational measures to protect personal information. These may include access controls, secure connections, WordPress and server updates, backups, and restricted administrator access.

No internet service or method of electronic storage can be guaranteed to be completely secure.

If you believe personal information has been exposed or an account has been accessed without permission, contact us immediately at info@lawontoast.com.

12. CHILDREN

The Blog is not directed at young children. Please do not submit information about a child or publish a child’s personal information without the appropriate permissions, lawful basis, and safeguards.

13. CHANGES TO THIS POLICY

We may update this policy when The Toaster, Law on Toast’s technology, or our processing activities change.

The latest version of this privacy policy will be published on this page together with the date on which it was last updated.