Privacy Policy
Last updated: 28 July 2026
This policy explains what personal information is collected through ultramadlizzie.com, why it is collected, how long it is kept and what rights you have over it. It is written to meet the UK GDPR and the Data Protection Act 2018, and it applies to everyone who uses the site wherever you are in the world.
Who is responsible for your information
Ultra Mad Lizzie (“we”, “us”, “I”) is the data controller for information collected through this site. That means we decide why and how your personal information is used.
- Contact for privacy queries: [email protected]
What we collect and why
When you send a message through the contact form
The contact form asks for your name, email address and message. All three are required so that we can identify you and reply.
When you submit the form, two things happen. The message is emailed to us, and a copy is also saved in the website’s database. Alongside what you typed, the saved copy automatically records your IP address, your browser user agent and the page you submitted the form from. This technical information is recorded to help identify spam and abuse.
Why we are allowed to do this: where you are asking about coaching or another service, we rely on steps taken at your request before entering into a contract. For general enquiries we rely on our legitimate interest in responding to people who contact us. The technical anti-spam data is collected under our legitimate interest in keeping the site secure.
When you leave a comment on the blog
Comments require a name and email address, and you may optionally add a website address. Your name and any website you give are published publicly next to your comment. Your email address is never published.
When you comment we also record your IP address and browser user agent for spam detection. Your comment content, including anything personal you choose to write in it, is stored and displayed publicly, so please think carefully before including private details.
Comments are checked by an automated spam filter. To do this, the comment and the details submitted with it, including your IP address, are sent to Akismet, a service operated by Automattic. If the filter thinks a comment is spam it is held back rather than published.
The site also uses Gravatar for commenter profile pictures. When you comment, an anonymised code (a hash) generated from your email address may be sent to Gravatar so it can check whether you have an account and show your picture. Gravatar’s own privacy policy applies to that check.
If you tick the box to save your details for next time, those details are stored in cookies on your own device purely for your convenience. They last about a year and you can clear them at any time in your browser.
Why we are allowed to do this: your consent, given by choosing to submit a comment, together with our legitimate interest in moderating the site and preventing spam.
Cookies, analytics and traffic measurement
We use a consent banner so you can choose which non-essential cookies and similar technologies you accept. Strictly necessary cookies, which make the site work and keep it secure, are always active. Everything else only runs if you agree, and you can change or withdraw your choice at any time through the consent settings.
We use a privacy-focused analytics tool to understand which pages are popular and how people find the site. We use it to look at overall patterns, not to build profiles of individuals, and we do not use it for advertising.
For the current, itemised list of cookies in use, please see our Cookie Policy, which is kept up to date automatically as the site changes.
Why we are allowed to do this: your consent for non-essential cookies and analytics. Strictly necessary cookies rely on our legitimate interest in providing a working, secure website.
Security and server logs
Like almost all websites, our hosting and security systems automatically log technical information about visits, including IP addresses, pages requested, timestamps and browser details. This is used to detect attacks, block malicious traffic and diagnose faults. We rely on our legitimate interest in protecting the site and the people who use it.
Embedded content from other websites
Articles may include embedded content such as videos, images or social media posts. Embedded content from another website behaves exactly as though you had visited that website directly. Those sites may collect data about you, use cookies and monitor your interaction with the embedded content. We do not control that, and their own privacy policies apply.
Media you upload
If you send us images, please be aware that photographs can contain hidden location data (EXIF GPS). Anyone receiving the file could extract it. Please strip this information before sending images if you would rather not share your location.
What we never do
- We do not sell or rent your personal information to anyone.
- We do not share it for other organisations’ marketing.
- We do not add you to a mailing list because you sent an enquiry or left a comment. You would have to ask for that separately.
- We do not use your information to make automated decisions that produce legal or similarly significant effects, and we do not carry out profiling of that kind.
Who else handles your information
We use a small number of trusted suppliers to run the website. They act on our instructions and are not permitted to use your information for their own purposes. At the time of writing these include:
| Purpose | What they handle |
|---|---|
| Website hosting and backups | Everything stored on the site, including form messages and comments |
| Content delivery and security network | IP addresses and request data, to serve pages quickly and filter attacks |
| Email delivery | The contents of notification emails, including your message and email address |
| Spam filtering | Comment and form content, plus IP address and browser details |
| Website security monitoring | IP addresses, login attempts and traffic patterns |
| Website analytics | Aggregated usage data about pages and visits |
| Website maintenance and support | Administrative access for our web developer |
We may also disclose information if we are legally required to, for example in response to a valid request from a public authority, or where necessary to establish, exercise or defend legal claims.
Sending information outside the UK
Some of our suppliers are based outside the United Kingdom, including in the United States. Where personal information is transferred outside the UK, we take steps to make sure it remains protected to a standard equivalent to UK law. Depending on the supplier, this is achieved through UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or standard contractual clauses together with the UK International Data Transfer Addendum.
If you would like details of the safeguards used for a specific supplier, please contact us.
How long we keep things
| Information | How long |
|---|---|
| Contact form messages | Up to 24 months from your last contact with us, unless the enquiry becomes a coaching relationship, in which case business records are kept as long as legally required |
| Blog comments and their details | Indefinitely, so that discussion threads remain readable, unless you ask us to remove them |
| Security and server logs | Typically no more than 12 months |
| Analytics data | Aggregated, and retained only as long as useful for understanding site trends |
| Consent records | As long as needed to demonstrate that consent was given, then deleted |
Backups may hold copies for a further short period after deletion, until the backup itself expires on its normal cycle.
Your rights
Under UK data protection law you have the right to:
- Be informed about how your information is used, which is what this policy is for
- Request a copy of the personal information we hold about you
- Have inaccurate information corrected
- Ask us to delete your information, in certain circumstances
- Ask us to restrict how we use it, in certain circumstances
- Object to processing carried out on the basis of legitimate interests
- Data portability, meaning a copy in a commonly used machine-readable format, where processing is based on consent or contract and is automated
- Withdraw consent at any time, where we rely on consent. This does not affect anything done before you withdrew it
To exercise any of these, email [email protected]. We will respond within one month. There is normally no charge. We may need to verify your identity before acting, particularly for requests about comments, since anyone could claim to be a commenter.
If you are unhappy with how we have handled your information, you can complain to the UK’s supervisory authority, the Information Commissioner’s Office, at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
If you are outside the UK
The site is run from the United Kingdom, but visitors are welcome from anywhere, and we apply the standards in this policy to everyone.
European Economic Area and Switzerland. The rights listed above mirror those under the EU GDPR, and you may also complain to your local data protection authority.
United States. Residents of California and other states with comparable privacy laws may have rights to know what personal information is collected, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law. To make a request, use the contact address above.
Everywhere else. If local law gives you stronger rights than those described here, we will honour them. Just get in touch.
Children
This site is aimed at adults and we do not knowingly collect information from children under 13. If you believe a child has given us their information, please contact us and we will delete it. Coaching enquiries concerning anyone under 18 should be made by a parent or guardian.
Keeping your information secure
The site is served over an encrypted connection (HTTPS), sits behind a security and firewall service, and access to the administration area is restricted and protected. No system can be guaranteed completely secure, but we take reasonable technical and organisational measures to protect your information, and we will tell you and the Information Commissioner’s Office if a breach occurs that is likely to affect your rights.
Changes to this policy
We may update this policy as the site or the law changes. The date at the top always shows the current version. If we make a significant change to how your information is used, we will make that clear on the site rather than relying on you to check back.




