Privacy and data handling

Collect less. State the purpose. Preserve the boundary. Delete on time.

FASO’s privacy position follows the same discipline as its evidence work: identity, purpose, authority, custody, access, retention and deletion must remain explicit and reviewable.

Policy statusVersion 1.0 was prepared on 27 July 2026 for this non-live public-release candidate. It takes effect when this version is published. The hosting and form-processor record must be verified against the final public deployment before publication.

Data controller

Project FASO is responsible for the personal information described here.

Project FASO is the independent founder-led Phase 0 initiative developing the proposed Frontier Alignment and Safety Observatory. The proposed future organisation does not yet exist and is not the current data controller. A later change of controller requires a separate, prominent notice and cannot silently alter the purposes described here.

To contact the controller, use the FASO contact route and begin the message with Data protection request. Do not send identity documents unless FASO asks for proportionate verification.

Scope

This notice covers the public website, enquiry forms and resulting correspondence.

It applies to website visitors, enquirers, prospective reviewers, developers, supporters, funders, media contacts and people whose information is included in related correspondence.

The public website and contact forms are separate from protected FASO system evidence and governed technical records. Do not submit confidential model evidence, credentials, security material or special-category information through a public form.

Information register

What FASO processes, why it processes it and exactly how long it keeps it.

FASO collects only what is required for a stated purpose. The retention period begins from the last event identified below, not from an undisclosed internal date.

01

Website delivery and security

Information
Internet Protocol address, request time, requested path, browser or user-agent information, response status and a security event where one occurs.
Purpose and lawful basis
Delivering and protecting the site; Project FASO’s legitimate interests in providing a secure public-information service.
Retention
Routine access and security records: no more than 30 days. Records isolated as evidence of a security incident: until the incident is closed, then 12 months.
02

General enquiries and correspondence

Information
Name, contact details, role, organisation where relevant, message, attachments, requested material, correspondence history and stated confidentiality, attribution or timing conditions.
Purpose and lawful basis
Responding, routing the enquiry and preserving an accurate authority record; legitimate interests, or steps requested before a possible agreement where applicable.
Retention
24 months after the last substantive exchange, unless the matter becomes an active relationship, contract, complaint, legal obligation or protected evidence record.
03

Reviewer and participation records

Information
Expertise, interests, availability, affiliation, relevant experience, declared conflicts, independence conditions, review scope, decisions and authorised attribution.
Purpose and lawful basis
Assessing suitability, independence, conflicts and safe participation; Project FASO’s legitimate interests in rigorous and accountable engagement.
Retention
If not progressed: 24 months after the final decision. If progressed: for the relationship and six years after it ends. Published attribution follows the separately authorised publication record.
04

Funding, diligence and formal relationships

Information
Identity, affiliation, proposal, diligence material, conflicts, correspondence, decisions, agreements, payment records and authority conditions.
Purpose and lawful basis
Assessing and administering a possible or actual relationship; legitimate interests, requested pre-contract steps, contract and legal obligations as applicable.
Retention
Unprogressed discussions: 24 months after the final decision. Agreements, financial records and material relationship records: six years after the relationship ends, or longer only where a specific legal duty requires it.
05

Rights, complaints and incidents

Information
The request or complaint, proportionate identity-verification evidence, correspondence, investigation material, decision, response and delivery proof.
Purpose and lawful basis
Meeting data-protection duties, protecting rights and demonstrating accountable handling; legal obligation and legitimate interests.
Retention
Six years after the request, complaint or incident is closed. Verification documents are deleted as soon as verification is complete unless required as evidence of a dispute.

Deletion rule. When a retention period ends, the record is deleted or irreversibly anonymised. Deletion reaches routine backups within 90 days. A documented legal hold may pause deletion only for the identified record and only until the relevant claim, investigation or legal duty ends.

Protected boundaries

Personal information does not acquire a new purpose merely because FASO holds it.

  • FASO does not sell or rent personal information.
  • FASO does not use personal information for behavioural advertising or profiling.
  • FASO does not place enquiries into public or general-purpose generative-artificial-intelligence services or use them to train artificial-intelligence models.
  • FASO does not publish a person’s name, organisation, correspondence or contribution without separate authority or another documented lawful basis.
  • FASO does not turn an enquiry into a mailing-list subscription. There is currently no public newsletter or marketing list.
  • FASO does not make solely automated decisions about people that produce legal or similarly significant effects.

Sources, sharing and processors

Access follows purpose, not convenience.

Most information comes directly from the person concerned. Where FASO receives information from an organisation, referrer or public source, it records the source and provides privacy information where required.

Who may receive information

Only bounded recipients with a defined need.

Information may be handled by website and form-hosting providers, email and secure-record providers, people authorised to administer the relevant enquiry, and professional legal, accounting, security or data-protection advisers. An independent reviewer receives identifiable information only where it is necessary and authorised; de-identification is preferred.

FASO may disclose information where law requires it, to protect a person from serious harm, or to establish, exercise or defend legal rights. It does not give funders, developers, supporters or prospective institutional partners an automatic right to another person’s information.

International processing

Location does not reduce the protection.

Where a technical provider processes personal information outside the United Kingdom, FASO requires a lawful transfer mechanism: United Kingdom adequacy regulations or United Kingdom-approved contractual safeguards supported by the required transfer-risk assessment.

The current processor categories and transfer basis are available through the data-protection contact route. No international transfer is authorised for advertising, data brokerage, profiling or artificial-intelligence training.

Your rights

A privacy request does not require technical language.

State what you want FASO to do and provide enough information to locate the relevant record. FASO responds without undue delay and normally within one month.

01

Access

Ask whether FASO holds your personal information and request a copy.

02

Correction

Ask FASO to correct inaccurate information or complete an incomplete record.

03

Erasure

Ask FASO to delete information where the right applies.

04

Restriction

Ask FASO to limit use of information while an issue is resolved.

05

Objection

Object to processing based on legitimate interests. FASO must stop unless it demonstrates an overriding lawful reason.

06

Portability and consent

Request portable information where the right applies, or withdraw consent without affecting earlier lawful processing.

Security and minimisation

Public contact is separated from protected system evidence.

Access is limited to people who need the information for the stated purpose. Contact records are not stored in the public website source or published page output. FASO uses proportionate access control, secure transmission and record separation, and investigates suspected loss, unauthorised access or disclosure.

FASO does not ask for children’s information and the participation routes are intended for people aged 18 or over. If information about a child is received unintentionally, it is restricted and deleted unless a clear safeguarding or legal duty requires a different action.

Complaints and questions

Use the privacy route first—or go directly to the regulator.

Use the FASO contact route and begin the message with Data protection request, Privacy question or Privacy complaint. FASO may ask for limited information to verify identity but will not require excessive identification.

You may complain to the United Kingdom Information Commissioner’s Office at any time. Visit Make a data-protection complaint to the Information Commissioner’s Office.

Version control

Material changes are visible and do not operate retrospectively.

Version
1.0
Prepared
27 July 2026
Effective
When this public-release version is published
Review
Before any new form, cookie, analytics service, processor, data purpose or organisational controller is introduced

A revised notice states what changed and when. A revision cannot retrospectively widen an earlier purpose, convert silence into consent or erase an existing confidentiality, independence, attribution or authority condition.