Privacy Policy

Last Updated: June 8, 2026

1. Introduction

Boon & Moil ("we", "us", or "our") operates the Council Tax Reviewer waitlist registry. We are fully committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) and other applicable UK and EU data protection legislation.

This policy explains how we collect, process, protect, and store your personal data when you submit your email address to join our early access waitlist.

2. Data Collection and Purpose

We only collect one type of personal data:

  • Email Address: Necessary to register your place on our private beta waitlist, notify you when your cohort is ready, and provide product updates.

The legal basis for processing this data under the GDPR is your explicit consent, which you grant us when checking the consent box upon registration.

3. Security & Application-Level Encryption

We employ state-of-the-art security measures to protect your personal data. Unlike traditional databases that store information in plain text:

Cryptographic Safeguard

Your email address is encrypted at the application level using AES-256-GCM (Advanced Encryption Standard with Galois/Counter Mode) before it is written to the database. Additionally, we generate a one-way cryptographic hash of the email address using SHA-256 to enforce waitlist uniqueness without exposing the underlying plain text email address in lookup logs.

This means that even in the highly unlikely event of a database compromise, your plain text email address cannot be decrypted without our securely isolated master encryption key.

4. Hosting & Infrastructure (Scaleway)

Our databases and servers are hosted using Scaleway cloud infrastructure inside the European Union (EU). This hosting location ensures that your data never leaves the EU and benefits from the stringent protection rules mandated by the GDPR.

5. Your Rights Under GDPR

Under GDPR guidelines, you possess the following rights regarding your personal data:

  • Right of Access: You can request confirmation of whether we process your email address.
  • Right to Rectification: You can update or correct your email address.
  • Right to Erasure (Be Forgotten): You can request that we permanently delete your email address from our database.
  • Right to Restrict or Object: You can withdraw your consent at any time, halting any further processing.
  • Right to Portability: You can request a machine-readable copy of the data you provided.

To exercise any of these rights, simply email us at dpo@boonandmoil.com. We will honor your request within 30 days free of charge.

6. Data Retention

We only retain your email address for as long as necessary to fulfill the waitlist and beta-testing notification functions. Once Boon & Moil launches its public services, or if you request deletion, your encrypted email address and hash will be immediately and permanently purged from our database records.