Wildio is an editorial site. The desk does not run games, does not run a player wallet and does not ask readers to register an account on the site. The desk reads the questions readers send in by mail and the figures the desk publishes alongside them. The rest of this page spells out what is collected, what is not, and how to ask the desk for a copy or a deletion.
What the desk collects from a reader visit
- Standard web logs. The hosting provider records the request path, response code, browser user-agent string, referrer if any, IP address and timestamp. Logs are kept for 30 days for security and abuse-handling, then deleted.
- Aggregated analytics. The site runs a privacy-respecting analytics tool that records page paths and rough geographic region (city-level at the most granular). The tool does not record the reader's IP address, device fingerprint or behaviour across other sites. The aggregated data is retained for 13 months.
- Reader mail. Messages the reader sends to the desk. Stored in the desk's mailbox, kept as long as the desk considers it useful for editorial reference. The reader can ask for a copy or a deletion at any time.
What the desk does not collect
- The desk does not set tracking cookies for advertising. There are no cross-site trackers on the site.
- The desk does not ask for, store or process payment information. The site has no deposit form, no signup form and no user-content form.
- The desk does not collect the reader's PAN, Aadhaar, address, phone number, photograph or biometric data.
- The desk does not sell reader data and does not share reader mail with any platform the desk reviews.
Where the data sits
Web logs sit on the hosting provider's infrastructure, protected by TLS in transit and access controls at rest. Reader mail sits on the desk's mail provider, also TLS-protected. The desk does not export reader data to any other processor. If the desk partners with a translation service or a fact-checking service in the future, the privacy policy will be amended before any reader data is shared with them.
Retention
| Data | Retention | Reason |
|---|---|---|
| Web logs | 30 days | Security, abuse handling |
| Aggregated analytics | 13 months | Editorial planning |
| Reader mail | While useful for editorial reference | Editorial continuity |
| Correction log | Permanent | Editorial record |
Reader rights and how to exercise them
The desk honours the rights a reader has under applicable Indian law and the EU GDPR, in plain terms:
- Access. The reader can ask for a copy of the reader mail the desk holds under the reader's name or address. The desk answers within 30 days.
- Deletion. The reader can ask the desk to delete the reader's mail. The desk deletes within 30 days and confirms in writing. The correction log keeps the fact of a correction but no personal data.
- Correction. The reader can ask the desk to correct a fact that names the reader. The desk corrects within 30 days.
- Complaint. The reader can complain to a data protection authority. The relevant authority in India is the Data Protection Board under the Digital Personal Data Protection Act 2023.
Cookies and similar technologies
The site uses no advertising cookies. The site uses no cross-site trackers. The site's analytics tool sets a single first-party cookie that records a session identifier and expires at the end of the reader's session. The cookie is necessary for the analytics tool to distinguish new readers from returning readers. The site uses no third-party fonts that ship tracking pixels; the site loads the chosen serif and sans-serif fonts from the open Google Fonts endpoint with the `display=swap` parameter to keep the rendering honest.
Where a reader clears the cookie, the next visit is treated as a new visit. The aggregation window is 13 months, and the rolled-up data is not rebuilt from the erased cookie. The reader can also use the browser's privacy mode to read the site without leaving a footprint; the analytics tool respects the privacy-mode flag and skips the session write.
Linked sites and the responsibility boundary
The site links to a small set of platform pages and to a small set of external resources (support lines, regulator pages, the published method notes). The linked sites are not operated by the desk. The desk does not control the cookies, the data collection or the privacy practices of the linked sites. The reader's relationship with a linked site is governed by the linked site's own privacy policy, not by this one. Where the desk links to a platform, the link is marked as a commercial referral and the platform's policy is named in the platform's review page.
Cross-border data movement
Web logs originate on the hosting provider's edge network and may be cached at intermediate points for performance. The hosting provider's edge covers multiple jurisdictions; the cached logs are deleted on the cache's eviction policy, which is sooner than the 30-day retention window. Reader mail is stored on the desk's mail provider, which sits in a single jurisdiction named in the provider's published policy. The desk does not move reader mail to a third processor.
Children
The site is for adult readers. The desk does not knowingly collect data from a reader under 18. If the desk learns that it has inadvertently done so, the desk deletes the data on receipt of the notice.
Changes to this page
When this page changes materially, the desk publishes a dated note on the editorial desk. The desk does not silently expand the data it collects; if a change would broaden collection, the desk announces it before the change takes effect.
Sub-processors and onward sharing
The desk uses a small number of sub-processors to operate the site. The desk publishes the list of sub-processors on this page and updates the list within seven days of any addition. The desk does not share reader data with a sub-processor for a purpose other than the purpose the reader's data was collected for, and the desk's contract with each sub-processor binds the sub-processor to the desk's published retention window.
The current sub-processors are: the hosting provider, which serves the site and retains web logs; the analytics provider, which records the rough geographic region of a reader visit; the mail provider, which stores reader mail; the font provider, which serves the chosen serif and sans-serif fonts to the reader's browser. The desk does not use a marketing sub-processor; the desk does not use a third-party email newsletter; the desk does not use a third-party chat widget. The desk does not transfer reader data to a processor outside this list.
Automated decisions on the site
The site does not perform automated decisions on the reader. The site does not use an automated content filter on incoming reader mail. The site does not use an automated comment-moderation system. The site does not use behavioural advertising; the site has no advertising. The desk reads the reader's mail by an editor, and the desk replies by an editor. The desk does not run a chat bot on the contact page because the desk would rather answer a clear question than read a chat bot's reply.
Where the desk adds a new automated feature in the future, the desk will amend the privacy policy before the feature goes live. The desk will not silently introduce an automated decision that affects the reader's reading experience, and the desk will publish the date the feature went live on the editorial desk.
Lawful bases for processing
The desk processes reader data under the lawful basis of legitimate interest for the site operation (hosting, security, abuse handling) and under the lawful basis of consent for analytics that record the rough geographic region. The desk processes reader mail under the lawful basis of consent (the reader has chosen to write to the desk) and the desk's further use of the mail for editorial reference is a legitimate interest, balanced against the reader's right to ask for a deletion at any time.
Where the desk is required to disclose reader data to a court or regulator, the desk publishes the disclosure on the editorial desk within seven days of the disclosure, named in plain text. The desk does not voluntarily disclose reader data to a commercial third party.
Reading the privacy policy in practice
The privacy policy is a working document. The desk reads the policy before the desk publishes a new feature on the site. The desk reads the policy when a reader asks for a copy of the reader's data. The desk reads the policy when the desk considers a new sub-processor. The desk reads the policy when the desk considers a change to the data-retention window. The reading is the practice; the practice is the reading. The two are not separate.
A reader who reads the privacy policy and the reader's notes on the policy will recognise the desk's habit. The desk writes the policy in plain English because the desk would rather answer a clear question than read a lawyer's letter. The desk writes the policy to be read once and understood, then referred back to when it needs to be. The policy is not a legal document; the policy is a description of what the desk does, written for the reader's benefit.
Where the desk considers a change to the policy, the desk publishes the proposed change on the editorial desk before the change takes effect. The proposed change is open for reader comment for fourteen days. The reader who wants to comment on the proposed change can write to the privacy address on this page. The desk reads the comments and the desk responds to the comments on the editorial desk before the change takes effect.
Reach the desk on a privacy matter
Address: [email protected]. The desk answers within five working days and resolves within 30 days.