Privacy Policy

Last updated: 25 July 2026

True Observer Media Ltd. (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard information when you interact with our website, chat tools, intake forms, volunteer academy, and services.


1. Who We Are

True Observer Media Ltd.
Registered in England & Wales
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company Number: 16688440
Email: info@trueobservermedia.com

For data protection purposes, True Observer Media Ltd. is the controller of personal data collected through this website and our services, unless we clearly state otherwise.


2. What Data We Collect

We may collect the following categories of data:

  • Contact Information: name, email address, phone number, company details, role, and communication preferences.
  • Service Data: information you provide when requesting reports, monitoring, reputation support, evidence preservation, training, academy access, or other services.
  • Chat and Intake Data: messages, conversation history, uploaded or pasted links, page context, urgency, requested outcome, and any details you choose to provide through TOBI, web chat, forms, or similar intake tools.
  • Case and Evidence Data: URLs, screenshots, timestamps, usernames, platform identifiers, public posts, reviews, allegations, incident descriptions, and supporting material needed to assess or deliver a requested service.
  • Account and Academy Data: registration details, course enrolments, lesson progress, quiz attempts, certificates, volunteer assignments, reviews, and related training records.
  • Payment and Transaction Data: billing details, purchase history, invoice records, payment status, and transaction references. Payment card details are normally processed by our payment providers and are not stored by us in full.
  • Technical Data: IP address, browser type, device information, approximate location, referral URL, pages visited, security logs, cookie identifiers, and similar technical information.

Some information you provide may include special category data or sensitive information, for example where a case involves health, harassment, political views, legal allegations, criminal allegations, children, or vulnerable individuals. We ask you to share only what is necessary. Where sensitive information is necessary for a requested service, we process it with additional care and only where we have a lawful basis to do so.


3. How We Use Your Data

We process personal data only for specific and legitimate purposes, such as:

  • Responding to enquiries and providing requested services.
  • Operating TOBI, web chat, contact forms, service-finder tools, and intake workflows.
  • Routing enquiries to the appropriate True Observer team member, agent, adviser, or vetted volunteer.
  • Preparing and delivering monitoring, reputation, evidence, OSINT, training, academy, or analysis services.
  • Preserving evidence, preparing reports, creating case chronologies, and supporting platform, adviser, or client handovers where requested.
  • Managing academy enrolments, volunteer training, course progress, quiz attempts, certificates, reviews, and related records.
  • Processing payments, issuing invoices, and maintaining accounting records.
  • Improving our website, tools, services, security, and user experience.
  • Preventing abuse, spam, fraud, unauthorised access, or misuse of our systems.
  • Meeting legal, regulatory, accounting, insurance, and governance obligations.

4. AI-Assisted Chat, TOBI, and OpenAI Processing

We use AI-assisted tools, including TOBI and OpenAI-powered processing, to help with intake, triage, drafting, summarisation, routing, and first-response support. These tools may process the messages and information you provide through chat, forms, service-finder journeys, or related workflows.

AI-assisted tools are used to support our team; they do not replace human responsibility for case handling, professional judgement, or final decisions. Where a matter may require legal, safeguarding, emergency, medical, financial, or other regulated advice, we may signpost you to an appropriate professional or authority.

When you use TOBI, web chat, or an AI-assisted intake tool:

  • your message and relevant context may be sent to an AI service provider, including OpenAI, so that a response, summary, classification, or routing recommendation can be generated;
  • chat transcripts may be stored so our team can follow up, maintain continuity, audit decisions, and improve service quality;
  • you should avoid sending unnecessary sensitive information, passwords, payment card details, private keys, or information about third parties unless it is necessary for your request;
  • we may review AI-assisted outputs before relying on them for operational decisions; and
  • we may use conversation data to improve our own workflows, quality control, and safety processes, but we do not sell chat content.

Where we use OpenAI business or API services, OpenAI processes the submitted content to provide the service. OpenAI states that, by default, it does not train its models on business/API inputs and outputs unless an organisation explicitly opts in. OpenAI may process data in the United States and other locations through its approved infrastructure and subprocessors. We rely on appropriate contractual and transfer safeguards where required.


5. Legal Basis for Processing (UK GDPR / GDPR)

We rely on one or more of the following legal grounds:

  • Contractual necessity: when processing is needed to provide services you requested, manage subscriptions, enrol you in training, process purchases, or deliver reports.
  • Legitimate interests: to respond to enquiries, protect our systems, operate chat and intake tools, improve services, preserve evidence at your request, manage client relationships, and communicate relevant updates, provided your rights do not override those interests.
  • Consent: where you explicitly agree, such as for some cookies, marketing communications, optional analytics, or where consent is the most appropriate basis for a specific activity.
  • Legal obligations: to comply with applicable law, tax, accounting, court, regulatory, or law-enforcement requirements.
  • Special category conditions: where sensitive data is necessary, we rely on an appropriate UK GDPR / GDPR condition, such as explicit consent, establishment or defence of legal claims, substantial public interest where applicable, or another lawful condition relevant to the service requested.

6. Data Sharing

We do not sell or trade your personal data.

We may share limited data with:

  • service providers who support hosting, security, email, forms, CRM, analytics, payments, chat, automation, AI processing, cloud storage, academy delivery, and operational systems;
  • Raiola Networks, S.L. and its authorised hosting subprocessors, including OVH Hispano, S.L.U. where applicable, for website hosting, storage, backups, server security, and related infrastructure services;
  • OpenAI and other AI or automation providers where needed to operate TOBI, chat, intake, routing, summarisation, or analysis functions;
  • Firebase / Google Cloud or similar infrastructure providers where used to support real-time chat, messaging state, notifications, storage, or operational workflows;
  • OPserver.app or related True Observer operational systems where you submit a reputation check, incident report, academy workflow, or case-routing request;
  • payment providers, banks, accountants, auditors, and professional advisers where necessary;
  • vetted volunteers, contractors, agents, or partner specialists where they need access to help deliver the service, subject to confidentiality and access controls;
  • platforms, publishers, legal advisers, insurers, regulators, or authorities where you ask us to prepare or submit evidence, reports, notices, or handover materials; and
  • legal authorities where required by law or where disclosure is necessary to protect rights, safety, or security.

We limit access to what is necessary for the relevant purpose and use contractual, technical, and organisational safeguards where appropriate.


7. International Transfers

Some providers we use, including cloud, analytics, AI, payment, and communications providers, may process data outside the UK or European Economic Area. Where personal data is transferred internationally, we use appropriate safeguards where required, such as adequacy regulations, Standard Contractual Clauses, the UK International Data Transfer Addendum, data processing agreements, transfer risk assessments, or equivalent measures.

Our hosting provider, Raiola Networks, S.L., is based in Spain. Its data processing terms state that international transfers outside the European Union will not be made without prior written authorisation, except where required by applicable law.


8. Cookies & Tracking

Our website uses cookies and similar technologies to:

  • enable basic functionality, including security, consent management, language preferences, logins, chat availability, session management, academy access, and shopping or checkout features;
  • measure and improve website performance and content;
  • support advertising and campaign measurement; and
  • help us understand how visitors interact with forms, chat, service-finder tools, and key pages.

TOBI, Web Chat, and Messaging Tools

Our chat tools may use cookies, local storage, session identifiers, Firebase, WordPress REST API endpoints, or similar technologies to open the chat widget, remember conversation state, send and receive messages, route enquiries, prevent abuse, and notify our team. If you send a message, we process the message and contact details you provide so we can respond to your enquiry.

Matomo Analytics (self-hosted)

We use Matomo Analytics to understand how visitors interact with our content and to improve user experience. Matomo is an open-source, privacy-focused analytics platform that runs entirely on our own servers. Depending on your consent preferences, Matomo may set a small number of first-party cookies to generate anonymous usage statistics and recognise returning visits. The information collected includes anonymised IP address, pages visited, device type, operating system, and approximate location.

Google Ads / Google Tag (gtag.js)

We also use Google Ads, including the Google tag (gtag.js), to measure the effectiveness of our advertising campaigns and, where applicable, to show relevant ads on Google services and the Google Display Network. When you consent to marketing/analytics cookies, Google may set cookies and collect information such as your IP address, browser and device information, pages visited, and conversion events. This information may be processed by Google LLC in the United States and other countries. Google may act as an independent controller for this data.

You can manage your cookie preferences at any time using the cookie banner on this website or through your browser settings. If you disable non-essential cookies, certain analytics, advertising, chat, or convenience features may not function as intended.


9. Data Retention

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • General enquiries and chat transcripts: normally retained for up to 24 months after the last interaction unless they become part of a client, volunteer, safeguarding, legal, or operational case file.
  • Client case, evidence, monitoring, and report records: normally retained for up to 6 years after closure, unless a longer period is needed for legal, insurance, contractual, safeguarding, dispute, or evidential reasons.
  • Academy and volunteer records: retained while your account, enrolment, certification, or volunteer relationship remains active, and for a reasonable period afterwards for audit, safeguarding, verification, and governance purposes.
  • Payment, invoice, and accounting records: normally retained for at least 6 years to meet tax and accounting obligations.
  • Analytics and cookie data: retained according to the settings of the relevant analytics or consent tool.
  • Marketing records: retained until you unsubscribe or object, plus a suppression record where needed to respect your choice.

We may delete, anonymise, or archive information earlier where it is no longer needed.


10. Your Rights

Under UK GDPR / GDPR and applicable data protection law, you may have the right to:

  • access your personal data;
  • request correction or deletion;
  • restrict or object to processing;
  • request data portability;
  • withdraw consent where processing is based on consent;
  • object to direct marketing; and
  • ask for information about automated decision-making, where applicable.

To exercise your rights, contact us at: privacy@trueobservermedia.com.

We may need to verify your identity before responding. Some rights may be limited where information is needed for legal claims, security, safeguarding, evidence preservation, regulatory obligations, or the rights of others.


11. Security

We take appropriate technical and organisational measures to protect personal data from loss, misuse, and unauthorised access. These measures may include access controls, role-based permissions, encryption in transit, security monitoring, backups, audit trails, confidentiality obligations, and limiting access to people who need the information for an authorised purpose.

Our hosting arrangements include measures described by Raiola Networks, S.L., such as controlled data centre access, monitoring, fire detection and suppression, redundant connectivity and power, backups, firewall protections, brute-force mitigation, malware analysis, and infrastructure monitoring, depending on the hosting service used.

If we become aware of a personal data breach, we will assess it promptly and take appropriate action, including notifying affected individuals, regulators, clients, or processors where required by law.

No online service can be guaranteed to be completely secure. Please do not send passwords, payment card details, private keys, or unnecessary sensitive information through chat or forms.


12. Children and Vulnerable People

Our services are not directed at children. If a matter involves a child, young person, or vulnerable person, only provide information that is necessary for the requested support. We may take additional steps where safeguarding, legal, or safety concerns arise.


13. Automated Processing and Human Review

Our service-finder tools, reputation checks, chat routing, and AI-assisted features may help classify enquiries, generate summaries, estimate risk, or recommend a starting route. These tools support intake and triage. They do not make legally binding decisions about you, and a human member of our team can review the information where a service, report, or case action is requested.


14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with the “last updated” date.


15. Contact Us

If you have any questions about this Privacy Policy or your personal data, please contact:

Data Protection Officer
True Observer Media Ltd.
Email: privacy@trueobservermedia.com

If you are not satisfied, you may also contact the UK Information Commissioner’s Office (ICO) or your local data protection authority.