1) Who we are
Our website is https://secondlifeguide.com(“we”, “us”, “our”). We are the data controller for the personal data described in this notice.
Contact (privacy):
Email: message.secondlifeguide@gmail.com
2) What this notice covers
This notice explains how we collect and use personal data when you:
- browse our blog,
- create and use a membership account,
- purchase a subscription / pay for member content,
- comment or interact with the site,
- contact us (support, enquiries).
3) Personal data we collect
A) Account and membership data
- Name (if provided), username/display name
- Email address
- Password (stored as a secure hash — we don’t store your plain password)
- Membership status, subscription level, access entitlements
- Profile information you choose to add
B) Purchases and billing
- Purchase history (e.g., subscription plan)
- Transaction references/IDs
- Billing/contact details you provide
Note: card payments are usually handled by your payment provider (we typically do not store full card details).
C) Content you provide
- Comments, posts, messages, support requests
- Any information you choose to include in those communications
- When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
- An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
- If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
D) Technical and usage data
- Security and error logs (to keep the site working and prevent abuse)
- IP address, device/browser type, pages visited, timestamps
4) Why we use your data and our lawful bases (UK GDPR Article 6)
UK GDPR requires us to have a lawful basis for each purpose we process personal data.
A) To provide membership access and digital content
Purpose: Create/manage your account, let you access member content, provide customer support.
Lawful basis: Contract (necessary to provide the service you requested).
B) To process payments and keep records
Purpose: Take payment, manage subscriptions, maintain invoices/records.
Lawful basis: Contract and/or Legal obligation (where record-keeping is required).
C) To keep the site secure and prevent misuse
Purpose: Security monitoring, abuse prevention, troubleshooting, service integrity.
Lawful basis: Legitimate interests (running a secure, reliable website).
D) To send service messages
Purpose: Password resets, account notices, subscription confirmations, important service updates.
Lawful basis: Contract (necessary to provide the service).
E) Marketing communications (optional)
Purpose: Newsletters, new content updates, promotions (if you opt in or where permitted).
Lawful basis: Usually Consent (you can withdraw at any time).
F) If you choose to share health information in messages/comments
Purpose: To respond to what you send us and moderate site content.
Lawful basis (Article 6): Typically Legitimate interests or Contract (depending on context).
5) Cookies and similar technologies (PECR)
We use cookies for core site functionality (e.g., login/session cookies) and may use non-essential cookies (e.g., analytics/marketing) if you enable them.
- Non-essential cookies require consent and should not be set until you’ve made a choice.
- We provide cookie controls so you can accept/reject non-essential cookies.
- If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
- If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
- When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
- If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
6) Who we share data with
We share personal data only as needed to run the site, such as with:
- Web hosting provider(s)
- Email provider(s) (transactional emails/newsletter)
- Payment provider(s) (subscriptions/payments)
- Security, backup, and logging tools (if used)
- Professional advisers (e.g., accountant/legal) where necessary
These suppliers act as “processors” where applicable and are required to protect your data.
7) International transfers
If any of our suppliers process data outside the UK, we use appropriate safeguards (e.g., approved transfer mechanisms) and can provide more information on request.
8) How long we keep your data (retention)
We keep personal data only as long as necessary for the purposes above:
- Account data: for as long as your account is active, and for 3 years after closure (e.g., for support/security and recordkeeping)
- Purchase records: for 3 years (accounting/tax)
- Support messages: indefinitely
- Comments: until you delete them (where available) or we remove them under moderation rules
We will also explain retention periods (or the criteria we use) in a clear way.
9) Your rights
You have rights under UK GDPR, including:
- Access to your personal data (subject access)
- Rectification (fix inaccurate data)
- Erasure (delete data in certain cases)
- Restriction and objection (in certain cases)
- Data portability (in certain cases)
- Withdraw consent (where we rely on consent)
We aim to respond to valid access requests within one month, and can extend by up to two further months for complex requests (with notice).
You also have the right to complain to the Information Commissioner’s Office (ICO).
10) Security
We use appropriate technical and organisational measures to protect personal data (access controls, encryption in transit where applicable, secure administration, monitoring).
11) Children
This site is not intended for children.
12) Changes to this notice
We may update this notice from time to time. We will post the updated version here and change the “Last updated” date.
Embedded Content
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Custom Genetic Report Service
Because we process genetic information, which is “special category data” under UK GDPR, we apply additional safeguards and require your explicit consent before you upload any DNA data. The full policy can be read here.




