Chancery

Privacy

How Chancery handles personal data. Last revised 11 September 2026.

Who is responsible

Chancery is run by ArcSystemsTechnology, a practice of ArcGabriel Ltd, which is the controller of the personal data described here. Questions and requests go to Philip Martin.

What is held, and why

Chancery holds the name and email address of each person who has been given a key to the office, when the key was given, when it was last used and whether it has been taken back, so that they can be signed in and the principal can see who has access. It holds nothing else of its own: the register of engagements and the practice's files live in the practice's own repository, which Chancery reads and writes to as commits. A change made in Chancery is recorded in that repository with the name of the person who made it.

All of this is held in the practice's legitimate interest in running its own office and keeping a record of who changed what.

Sign-in

There are no passwords at the door. Sign-in is by a link emailed to an address that holds a key; the link works once and lasts fifteen minutes. A request to sign in an address without a key sends nothing and records nothing about the request beyond a count used to limit abuse. Sessions are kept in a signed cookie for up to thirty days, and the office asks for a second factor after the link.

Who else handles it

Chancery runs on Railway, sends email through Resend, and reads and writes the register through GitHub. Each processes data only to provide that service. No data is sold and nothing is used for advertising.

The audit ledger

Chancery keeps a record that actions happened: a sign-in, an unlock, a gate item ticked, a status written, a key given or taken back. The ledger records the kind of event and an identifier, never the content, and it is not personal data, which is why it survives an erasure.

How long

A key holder's record is kept while they hold a key and, once revoked, until they erase their account. Spent sign-in links and rate-limit counts are swept within hours. What is in the repository stays in the repository under its own rules.

Your rights

You may ask for a copy of what is held about you, ask for it to be corrected, and ask for it to be erased. Any signed-in person can erase their own account in two clicks at /account/erase; the commits in the repository that carry your name remain, because they are the practice's record. For anything else, write to Philip Martin. You may also complain to the Information Commissioner's Office.