Privacy
This notice explains how personal information is used when you use this website, when we analyse a publicly published funeral director website, when we send a report or outreach message, when a unique report link receives first-party browser engagement, when we record first-party website analytics on public pages, when Premium interest is recorded, when you opt out of further contact, or when you contact us.
Last updated: 2 September 2026
Who we are
This notice covers the funeral director website-check service offered under the PublishSentry brand during Market Validation. That includes operator-run public website checks, evidence-based reports, limited B2B outreach using published role-based business emails, first-party report engagement signals, Premium interest signals, opt-out/suppression, and contact enquiries. Public customer accounts, password sign-in for funeral customers, Premium billing and automatic customer monitoring are not part of the live public product in this mode.
PublishSentry is operated by Ehsan Fathi, a sole trader trading as PublishSentry. Ehsan Fathi is the data controller for the personal information described in this notice.
Correspondence address: 5 Brayford Square, London, E1 0SG, United Kingdom. This is a service address, not a registered office.
Privacy questions: hello@publishsentry.com, or use the Contact form.
Information you provide to us
You may provide personal information directly in these ways:
- Premium interest — if you indicate interest in planned Premium monitoring (for example from a report or the pricing page), we record the website / domain, optional report reference, timestamp, and source of the signal. We do not require a name, account or payment details to record interest, and no payment is taken for interest signals.
- Outreach opt-out — if you use the unique “do not contact us again” link in an outreach email, we process the business email address already associated with that outreach (and related website information) so we can keep a suppression record. No account or login is required.
- Contact form — when you contact us, we collect your name (required), email address (required), enquiry type (required), and message (required). You may also optionally provide a website address and, where relevant, a report link.
Information from public websites
When a website is checked, information contained in publicly accessible pages and documents may be processed. This can include business information and, where it has been published on the website, personal information such as names, roles, ownership information or business contact details.
This information comes from the public website and documents being checked. Checks do not require website credentials, do not bypass authentication or access controls, and do not access private customer or case-management systems.
For Market Validation outreach, we may also use a published role-based business email address found on the website (for example addresses such as info@, office@ or enquiries@), together with the source page URL where that address was published. We do not guess personal name-based email addresses for cold outreach.
For more about how scanning is bounded and what happens when a site blocks access, see our Security and Bot information pages.
Technical information
Depending on how you use the website, limited technical information may be processed, including:
- IP address — used server-side with the Contact form for short-lived abuse/rate-limit protection. The visitor IP address is not included in the normal internal enquiry email.
- Browser / user-agent information — recorded in limited operational logs for some public report requests. For first-party report engagement we store only a short classified family (browser, scanner, or unknown), not the full user-agent string.
- Security and anti-abuse information — such as Contact form rate-limit records, honeypot checks and form-open timing checks.
- Service channel and request timing — for example which product site handled a Contact form submission and when it was received.
- Essential cookies and similar storage — described in our Cookies page. The public Funeral site does not use customer account session cookies as a normal browsing feature in Market Validation Mode.
This technical information is used to operate the service, protect against abuse, diagnose technical problems, and maintain security.
Report engagement
When someone opens a unique Funeral report link in a browser and the page remains visible for a short period, or uses selected report actions, we may record a first-party engagement event against that report token. A raw server request for the report URL is not treated as a confirmed view, because email-security scanners may fetch links automatically.
These events are used only as operator decision-support. They are not shown in customer copy and are not used to send automatic follow-up messages. They do not prove that a named person read the report.
We do not use email tracking pixels, wrapped report links, recipient query parameters, or a third-party analytics service for this. We do not store full IP addresses for report engagement. We may keep a first-party browser session key in session storage so the same short visit is not counted repeatedly. That key is not a cookie and is not used across other websites.
If this description needs a formal legal review, treat the current wording as a factual processing note rather than an expansive compliance claim.
Website analytics
On public marketing and service pages we record first-party website analytics. The sole purpose is to produce aggregate statistics about how those pages are used, so we can improve the websites and services. This is separate from unique-report engagement. Opening `/r/` report links is not counted as ordinary website analytics.
We may record the page path, product surface, time, a classified referrer type and referring domain, sanitised marketing parameters (`utm_source`, `utm_medium`, `utm_campaign` only), device/browser/OS family, coarse geography from the hosting platform (country, and region or city when supplied without us storing the IP address), and selected button or form actions. We do not store full IP addresses, exact screen size, fonts, canvas or hardware identifiers, typed form contents, or a persistent advertising identifier.
Same-tab grouping may use a first-party sessionStorage key (`ps_site_analytics_sid`). That is a PECR storage/access technology. It is not a cookie, but PECR still applies. We rely on the PECR statistical-purposes exception: the storage is used only to collect statistical information about use of this website. The key is a random value for that browser tab, ends when the tab or session ends, is not reused on a later visit, and is not shared with other websites or third parties. It is not correlated with report tokens, contact-form identity, or outreach recipients.
We do not use Google Analytics, Meta Pixel, session replay, or other third-party advertising or analytics services for this. We do not use these statistics for advertising, retargeting, individual sales decisions, lead scoring, or profiling. Analytics data is not sold. Prior analytics consent is not required for this statistical use. This storage is not claimed to be strictly necessary.
Raw or session-level analytics events are kept for a maximum of 24 hours so we can calculate aggregate statistics and show a short recent-activity window. They are then deleted. Long-term analytics are aggregate counts only (for example page totals and common paths) and are kept for 15 months. Those aggregates do not contain session identifiers and cannot be used to reconstruct an individual's browsing history.
You can object, simply and for free, without creating an account or contacting us. Use the Website analytics On / Off control on the cookie notice. If you turn analytics off, we do not create the session key and we do not send analytics events from that browser.
How we use personal information
The table below describes the main purposes for which personal information is used in connection with this funeral director Market Validation service, and the UK GDPR lawful basis we rely on for each purpose.
| Purpose | Information used | Lawful basis |
|---|---|---|
| Run operator-initiated public website checks and generate evidence-based reports | Website address, optional business name, check date/status, report reference, report contents, findings and evidence (including personal information published on the site) | Legitimate interests (Article 6(1)(f)) |
| Provide unlisted report access via a tokenised report link | Report reference/token, report contents, findings and evidence | Legitimate interests (Article 6(1)(f)) |
| Record first-party report engagement on a unique report link | Report token, event type, time, likely-automated and operator-context flags, a short user-agent family, optional first-party session key, and optional request timing. Full IP addresses are not stored for this purpose. | Legitimate interests (Article 6(1)(f)) |
| Record first-party website analytics on public pages | Page path, product surface, time, referrer class, sanitised UTM values, device/browser/OS family, optional coarse geography, optional same-tab session key, and selected action labels. Full IP addresses and form contents are not stored for this purpose. | PECR statistical-purposes exception for this first-party storage and access. Used only to produce aggregate website statistics. Not consent-based and not claimed as strictly necessary. |
| Analyse publicly available website information for the check | Public page/document content (which may include personal information published on the site), evidence URLs, excerpts, content hashes, findings | Legitimate interests (Article 6(1)(f)) |
| Contact corporate funeral businesses using published role-based business emails about a completed check / report | Business name, website, legal type used for eligibility, legal-type source URL (and optional company number / legal entity name), published role-based business email, source URL for that email, report reference, opt-out token, outreach send status and related timestamps | Legitimate interests (Article 6(1)(f)) |
| Record Premium interest signals (no account or payment) | Website/domain, optional report reference, timestamp, source (for example report page or pricing page) | Legitimate interests (Article 6(1)(f)) |
| Honour outreach opt-out / suppression requests | Business email address associated with the tokenised opt-out link, optional website/domain, opt-out timestamp, related campaign status updates | Legitimate interests (Article 6(1)(f)); we also keep suppression records so we can respect the request |
| Respond to Contact form enquiries | Name, email address, enquiry type, message, optional website address and report link, limited non-IP submission metadata | Legitimate interests (Article 6(1)(f)); contract / steps at your request (Article 6(1)(b)) only where you are clearly taking steps to enter a contract with us personally |
| Operate and protect the service against abuse | IP address and related anti-abuse signals for Contact form rate limiting; limited operational logs for some public report requests; essential security signals | Legitimate interests (Article 6(1)(f)) |
We do not sell personal information.
Your right to object
Where we rely on legitimate interests, UK GDPR gives you a right to object to that processing in certain circumstances. You can exercise that right by using our Contact form and explaining what processing you are objecting to. We will consider the objection under UK GDPR.
For first-party website analytics, you can object immediately with the Website analytics On / Off control on the cookie notice. That does not require an account, email, or a contact form.
For Market Validation outreach specifically, use the unique opt-out link in the outreach email (or open that tokenised outreach opt-out link) so we keep a suppression record and do not email that business address again for this outreach.
The right to object is not absolute. It mainly applies to processing that relies on legitimate interests. It does not mean every request will stop all processing immediately where another lawful basis or an overriding need still applies (for example retaining a suppression record so we can continue to honour an opt-out).
International transfers
Personal information may be processed outside the United Kingdom by organisations that help us run the service (for example application hosting, database hosting, and email delivery providers).
Where a restricted transfer outside the UK takes place, we use appropriate UK GDPR safeguards — specifically the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum — with our service providers. You can ask for more information about transfers using our Contact form.
How long we keep information
We keep personal information only for as long as needed for the Market Validation purposes below, unless a longer period is needed to deal with a legal claim or a specific security incident.
- Validation runs, reports and evidence — while needed to operate Market Validation (including report access, review and related outreach), and then deleted or anonymised when no longer needed for that purpose.
- Outreach campaign records — while needed for Market Validation outreach administration (send status, eligibility and related follow-up), and then deleted when no longer needed for that purpose.
- Premium interest signals — while needed to understand demand during Market Validation, and then deleted when no longer needed for that purpose.
- Report engagement events — while needed for Market Validation outreach administration, and then deleted when no longer needed for that purpose.
- Website analytics events — raw or session-level events for a maximum of 24 hours, then deleted after aggregation. Aggregate statistics with no session identifier for 15 months.
- Outreach suppression / opt-out — retained so we can continue to honour the request not to contact that address again for this outreach.
- Contact enquiries — up to 24 months.
- Operational and security logs — up to 30 days, unless a specific security incident requires longer preservation.
- Contact-form abuse-protection records — up to 15 minutes.
If you ask us to delete information we hold about you, we will assess the request under UK GDPR and act on it where we are required or able to do so. Suppression records may need to be kept so an opt-out continues to be respected.
Your data protection rights
Under UK GDPR you may have rights in relation to your personal information, including rights to:
- access the personal information we hold about you
- ask us to correct inaccurate information
- ask us to delete information in certain circumstances
- ask us to restrict processing in certain circumstances
- object to certain processing
- data portability, where that right applies
These rights are not absolute and may not apply in every case. To make a request, use our Contact form. We may need to verify your identity before acting on a request.
Complaints
If you have concerns about how we use personal information, you can contact us using our Contact form and we will try to resolve the issue.
You also have the right to complain to the UK Information Commissioner's Office (ICO). You do not have to contact us before complaining to the ICO. See the ICO's guidance on making a complaint.
Automated decision-making
PublishSentry uses automated checks to generate findings about publicly published website information. Those findings are factual observations about what was found on public pages and documents. They are not legal advice and are not a regulatory determination.
We do not use personal information to make solely automated decisions that produce legal effects, or similarly significant effects, on an individual within the meaning of UK GDPR Article 22.
Children and special category data
This service is intended for adult users in a business context (for example funeral directors and related professionals). It is not aimed at children.
Funeral regulatory checks do not seek special category personal data. Public websites and documents can occasionally contain a wide range of published information. If such information appears in public content processed for a check, the service is designed around business publication themes (such as pricing, terms and ownership disclosures), not around collecting special category data.
Security
For information about how PublishSentry approaches public website scanning and access controls, see our Security page.
Changes to this notice
We may update this notice when the service or our processing changes. The current version will be published on this page, and the “Last updated” date above will change when we make updates.
Contact us
To ask a privacy question, exercise a right, or object to processing, email hello@publishsentry.com or use the Contact form. Correspondence address: 5 Brayford Square, London, E1 0SG, United Kingdom.