Privacy Policy
What is collected, why it is used, who may receive it, how long it is kept and how to ask for correction or deletion.
The data fiduciary
This policy explains personal data processed through the website and paid literary services.
1. Who this policy covers
RDC Unsaid is the public-facing name of a literary studio operated from India. For a paid project, the legal contracting party and billing address are identified in the accepted quotation or invoice.
This policy covers visitors, subscribers, members, contributors, commission enquirers, clients, interview participants and people who contact or report content. It does not control independent third-party websites linked from RDC Unsaid.
Only what has a purpose
Different features ask for different information.
2. Categories of personal data
| Context | Examples |
|---|---|
| Website use | IP address, device and browser data, timestamps, requested pages, security and error logs, analytics identifiers and cookie choices. |
| Newsletter and contact | Email address, name, message, service interest and communication history. |
| Membership | Screen name, email, password hash, date of birth, gender choice, city, country, language, optional phone, occupation, special date, referral source and “why words matter” description. |
| Contributor publishing | Submission text, title, language, form, collection, creative-process disclosure, publication choices, acceptance records, moderation and complaint history. |
| Commissions | Client details, brief, interviews, recordings where agreed, source files, drafts, factual corrections, rights instructions, invoices, payments and project communications. |
| Reports and grievances | Reporter details, page URL, allegation, evidence, contributor response, review notes and outcome. |
Payment card details are ordinarily processed by the payment provider and are not intended to be stored by RDC Unsaid.
Data needs a job
RDC Unsaid processes information only for stated and lawful purposes.
3. Why personal data is used
- Provide, secure and troubleshoot the website;
- Create and recover member accounts;
- Publish writing under the chosen screen name;
- Display contributor profiles and “why words matter” descriptions after publication;
- Respond to enquiries and deliver commissioned services;
- Conduct interviews, prepare drafts and manage approvals;
- Send requested service, account, reset, transaction and newsletter communications;
- Process payments, invoices, tax and accounting records;
- Record policy acceptance and protect contractual rights;
- Prevent fraud, abuse, spam, infringement and unauthorised access;
- Review complaints, remove content and comply with legal obligations;
- Analyse aggregate website use and improve the service.
Where consent is required, the request will describe the purpose in clear language. Necessary account, security, contract and legal processing may continue where permitted even if optional marketing consent is withdrawn.
Publishing changes the audience
A screen name and submission are deliberately made public.
4. Information visible to visitors
Published contributor writing, title, language, form, collection, screen name and public contributor description are visible to all visitors and may be indexed by search engines. Do not place private contact details or sensitive personal information inside a submission unless you intend to make it public and have the right to do so.
Member email addresses, passwords, date of birth, phone, city, country and other private profile fields are not intended to be displayed publicly.
Service providers, not data buyers
RDC Unsaid does not sell personal data to advertisers.
5. Who may receive personal data
Data may be shared with providers used for hosting, database, email, analytics, security, payment, printing, storage, transcription, delivery, professional advice and technical support. They receive only the information reasonably needed for their role and are expected to handle it under applicable terms and safeguards.
Data may also be disclosed where required by law, to respond to lawful authority, investigate fraud or security, protect rights and safety, complete a business reorganisation, or resolve a complaint.
Private commission material is not used for portfolio or publicity without the separate permission described in the Confidentiality Protocol.
Small files, named purposes
Necessary cookies keep sessions working; analytics helps understand the room.
6. Cookies and similar technology
RDC Unsaid may use necessary cookies for security, sessions, remembered login, preferences and form protection. These are required for features requested by the user.
Google Analytics or a similar service may collect pseudonymous usage information such as pages visited, device type and approximate location. Browser controls, privacy tools and available consent settings may be used to limit non-essential tracking.
Password-reset and remembered-login tokens are designed to be stored as secure hashes or protected cookies rather than readable passwords.
Not forever by default
Retention reflects the purpose, legal obligations and the sensitivity of the material.
7. How long data is kept
- Member account data is kept while the account is active and for a limited period after closure to complete deletion, security and dispute processes.
- Published writing remains until removed by the contributor or RDC Unsaid, subject to limited backup and complaint records.
- Newsletter details remain until unsubscribe or suppression is needed to honour an opt-out.
- Unconverted enquiries are ordinarily reviewed for deletion after 24 months of inactivity.
- Raw commission recordings are ordinarily deleted within 90 days after final delivery and non-essential drafts within 180 days, unless another period is agreed or a dispute or legal duty requires retention.
- Invoices, payment, tax, policy-acceptance, rights and contractual records are kept for periods required by law or reasonably needed to establish legal rights.
- Security and access logs are ordinarily kept for a limited period proportionate to investigation and protection needs.
Backups may retain deleted data until the relevant backup cycle expires. Deleted data is not restored for ordinary use.
Reasonable safeguards
No system is risk-free, but passwords and private stories should not be treated casually.
8. Security
RDC Unsaid uses reasonable technical and organisational measures such as password hashing, secure sessions, access controls, rate limiting, token expiry, restricted database credentials and service-provider safeguards.
Users should use a unique password, protect devices, sign out on shared computers and avoid sending unnecessary sensitive information. Report suspected account compromise promptly.
If a personal-data breach creates a material risk, RDC Unsaid will investigate, contain it where possible and give notices required by applicable law.
Access, correction and erasure
Privacy rights should have a reachable door.
9. Your privacy rights
Subject to applicable law and necessary verification, you may request information about your personal data, correction of inaccurate data, deletion of data no longer needed, withdrawal of optional consent, grievance redressal and nomination where the law provides it.
Some data may be retained where necessary for law, fraud prevention, security, accounting, contractual rights, a legal claim or the rights of another person. Removing a public submission may not immediately remove search-engine caches or copies shared independently by others.
Newsletter consent may be withdrawn through the unsubscribe route. Optional promotional consent does not affect service or account communications.
Extra care below eighteen
The site should not collect a child's data casually.
10. Children
A person under eighteen should use membership and publishing features only with permission from a parent or legal guardian. RDC Unsaid may request confirmation and may restrict or remove an account where appropriate consent is absent.
Do not publish identifying or sensitive information about a child without a lawful basis and careful consideration of the child's safety and dignity.
Data may cross a border
Web infrastructure can involve providers outside India.
11. International processing
Hosting, email, analytics, payment or other providers may process data in countries outside the user's location. RDC Unsaid will use providers and contractual or technical safeguards considered reasonable for the service and applicable law.
Versioned privacy
A material change receives a new effective date.
12. Changes, contact and grievance resolution
Material changes to this policy will be posted with an updated version and date. Where required, fresh notice or consent will be obtained.
Privacy requests and grievances may be sent to rdc@rdcunsaid.com. Include the account email, the request and enough information to verify identity. Do not send a password or full payment-card details.
RDC Unsaid aims to acknowledge grievances within 24 hours and resolve them within seven days where the matter is within its control.
Make a privacy request
State whether you seek access, correction, deletion, consent withdrawal, account closure or another remedy.
Email rdc@rdcunsaid.com · Legal hub · Confidentiality protocol