Legal
Privacy Policy
Last updated 25 August 2026
Rail Industry Magazine (railindustry.co.uk) is published by TADGT Digital Solutions Limited, a company registered in England and Wales. TADGT Digital Solutions Limited is the data controller for personal data processed through this website, our newsletters and our commercial services.
1. Who we are and how to contact us
Controller: TADGT Digital Solutions Limited (“TADGT”, “we”, “us”), trading as Rail Industry Magazine. Data protection enquiries, access requests and complaints should be sent to our privacy contact via the contact page. We aim to acknowledge all requests within five working days and to respond substantively within one month, as required by UK GDPR.
2. Personal data we collect
- Newsletter subscribers: email address, optional first and last name, job title, company, and the sectors or briefings you choose to receive.
- Enquiries and partnerships: name, email address, telephone number, organisation and the content of the message you send us through contact, advertising or work-with-us forms.
- Account holders and contributors: email address, display name, author biography, profile image and role permissions where you have editorial access to the newsroom.
- Technical and usage data: IP address (processed transiently), browser and device type, referring page, pages viewed, aggregate article view counts, and approximate country-level location.
- Cookie and similar technology data: as set out in our Cookie Policy.
We do not deliberately collect special category data (such as health, political opinions or biometric data) and ask that you do not send it to us. We do not knowingly collect data from children under 16.
3. How we collect it
Directly from you when you subscribe, submit a form, create an account or correspond with us; automatically through your use of the website and essential cookies; and occasionally from publicly available business sources (for example a company website or press office) where we contact organisations about editorial or commercial matters.
4. Purposes and lawful bases
- Sending newsletters and briefings — consent (UK GDPR Art. 6(1)(a)) and, for existing business contacts, legitimate interests under PECR soft opt-in.
- Responding to enquiries and delivering commercial services — performance of a contract or steps prior to a contract (Art. 6(1)(b)).
- Operating, securing and improving the website — legitimate interests (Art. 6(1)(f)) in running a reliable, fraud-resistant publication.
- Editorial and journalistic activity — legitimate interests, with the journalism exemption in Schedule 2 of the Data Protection Act 2018 applied where relevant.
- Complying with legal obligations — legal obligation (Art. 6(1)(c)), for example accounting and record-keeping.
5. Marketing communications
We only send email marketing where you have opted in or where the soft opt-in applies to a business contact. Every message contains a one-click unsubscribe link, and you can also ask us to stop at any time. Withdrawing consent does not affect processing carried out before withdrawal.
6. Sharing your data
We do not sell personal data and we do not share your details with advertisers for their own marketing. We use a small number of processors acting on our documented instructions:
- hosting, database and authentication providers that run the website and store subscriber records;
- email delivery providers used to send newsletters and transactional messages;
- privacy-conscious analytics used to measure aggregate readership;
- professional advisers, and regulators or law enforcement where we are legally required to disclose.
7. International transfers
Some providers process data outside the UK. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical safeguards such as encryption in transit and at rest.
8. Retention
- Newsletter records: kept while your subscription is active and for 24 months after unsubscribing, to honour suppression.
- Enquiry and partnership correspondence: up to 24 months after the matter closes.
- Account and contributor records: for the life of the account plus 12 months.
- Financial records: six years, as required by UK tax law.
- Aggregate analytics: retained in non-identifying form.
9. Your rights
You have the right to be informed, and to request access, rectification, erasure, restriction, portability and objection, including objecting to processing based on legitimate interests and to direct marketing at any time. You can also withdraw consent where processing relies on it. To exercise a right, contact us using the details in section 1. We may ask for information to verify your identity.
10. Security
Access to subscriber and account data is restricted by role-based permissions and row-level database security, traffic is encrypted with TLS, and administrative access requires authentication. No system is perfectly secure, but we review our controls regularly and will notify you and the ICO of a qualifying breach within the statutory timescales.
11. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects or similarly significant effects on you.
12. Complaints
Please raise any concern with us first. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113).
13. Changes to this policy
We may update this notice to reflect changes in our services or the law. The date at the top shows when it was last revised, and material changes will be highlighted on the website.
