In short
We ask for as little as we can get away with. There is no password, so we hold no password. There is no advertising, so we sell nothing about you to anyone. Analytics runs without cookies, which is why you are not asked to click a banner. What we do hold is your email address, what plan you are on, and the records that come with taking a payment.
That is the summary. The detail below is what actually governs.
1. Who is responsible for your data
Colibri Holdings Ltd is the controller of the personal data described in this policy.
- Registered in England and Wales, company number 09741137
- Registered office: 71 Queen Victoria Street, London EC4V 4BE, United Kingdom
- VAT GB271861001
- ICO registration: [ICO REGISTRATION NUMBER]
- Privacy contact: hello@axiom.vc
We have not appointed a Data Protection Officer; we are not required to. The person accountable for data protection is the director, and the address above reaches them.
[EU REPRESENTATIVE] We offer the Wire to people in the European Economic Area. Where Article 27 of the EU GDPR requires a representative in the EEA, ours is [NAME AND ADDRESS, or: we rely on the exemption in Article 27(2) because our processing is occasional, does not involve large-scale special category data, and is unlikely to result in a risk to rights and freedoms].
2. What we collect, why, and on what lawful basis
2.1 Your Account
| What | Why | Lawful basis |
|---|---|---|
| Email address | It is your identity on the Wire. Sign-in, access, receipts, service messages. | Performance of a contract |
| Plan, role, status, access period | To know what you are entitled to see | Performance of a contract |
| Stripe customer and subscription identifiers | To connect your Account to your payment record | Performance of a contract |
| A note field, used by us | To record why access was granted or changed | Legitimate interests — running a subscription business |
Stored in a Postgres database hosted by Supabase in the eu-west-1 region (Ireland).
2.2 Signing in
| What | Why | Lawful basis |
|---|---|---|
| A hash of the single-use sign-in link, with your email and an expiry | So the link can be checked once and then never again | Performance of a contract |
| A hash of your session, with your email, when it was created, when it was last used, when it expires, and the browser user-agent string | To keep you signed in for up to 90 days and to let you and us end a session | Performance of a contract; legitimate interests — account security |
We never store the link or the session token itself, only a hash of it. If our database were read by someone who should not have it, they could not sign in as you with what they found.
2.3 Paying
Payment is taken by Stripe. We do not receive, see or store your card number. Stripe gives us back the identifiers in 2.1, the outcome of the payment, and the billing information needed for a VAT-compliant invoice — typically your name, billing country, any VAT number you enter, and the last four digits and brand of your card.
We also store the webhook events Stripe sends us, as received, so that a billing dispute can be reconstructed. Those events contain the billing information above.
Lawful basis: performance of a contract; and legal obligation, for the tax and accounting records we must keep.
2.4 Asking for access, and being invited
If you fill in the access-request form we collect your name, email address, organisation (optional) and what you would use the Wire for (optional). A person reads it before anything is issued.
Lawful basis: steps taken at your request before entering into a contract.
Please note: access requests, invitations and bug reports are currently written to a file in our private source repository. Because that repository keeps its history, a record there cannot be fully erased by deleting it — see section 8.3, which explains what we do instead. We are moving these records into the database, which does not have this property.
2.5 Using the Wire
| What | Why | Lawful basis |
|---|---|---|
| Which source links are clicked, counted in aggregate per source per day — not per person | To know which publications readers actually go to | Legitimate interests — editorial and commercial insight |
| Your IP address, used momentarily to apply a rate limit, and not stored by us for that purpose | To stop abuse and denial of service | Legitimate interests — security |
| Server logs kept by our hosting provider, which include IP address, request, user-agent and timestamp | Operations, debugging, security | Legitimate interests — running the service securely |
| Your taste profile — the stories you upvote or hide | To order the wire the way you prefer | Legitimate interests — providing the service you asked for |
The taste profile stays in your browser. It is held in your own device's storage and is not sent to us, except where you are an editorial collaborator who has chosen to contribute votes, which is explained to you at the time.
2.6 Analytics
We use Google Analytics 4 with Consent Mode v2 set to denied by default. In that mode GA sends aggregated, cookieless measurements: no analytics cookies are set and no identifier is stored on your device. That is why there is no consent banner on the Wire. Analytics is also switched off entirely on any host that is not the live site.
Lawful basis: legitimate interests — understanding, in aggregate, whether the Wire is being read. See Cookies and Local Storage.
If we ever switch on cookie-based measurement, we will ask you first, and the banner will appear before any cookie is set.
2.7 Email you ask for
If you subscribe to a newsletter, we collect your email address and confirm it by double opt-in through beehiiv. Every message has a one-click unsubscribe.
Lawful basis: consent, which you may withdraw at any time. Withdrawing it does not affect what happened before.
Transactional email — sign-in links, receipts, renewal reminders, service notices — is sent through Resend on the basis of our contract with you and cannot be unsubscribed from while you have an Account, because it is how the service works. Open and click tracking are switched off, deliberately: a tracked sign-in link would route your credential through a third party's redirect.
2.8 Things you send us
Bug reports, corrections, event submissions and enquiries. We keep what you send, together with who sent it and, for a bug report, the page and browser you were on, so that we can reproduce the problem.
Lawful basis: legitimate interests — fixing and improving the service; performance of a contract where you are a subscriber.
2.9 What we do not do
- We do not sell personal data, and we never will.
- We do not run advertising, and there are no advertising or social-media trackers on the Wire.
- We do not build a profile of you across other websites.
- We do not make automated decisions with legal or similarly significant effects about you. The Wire ranks stories for you automatically, which affects the order you read them in and nothing else.
- We do not knowingly collect data about anyone under 18. The Wire is a professional service and is not directed at children.
3. People we write about
The Wire is a journalistic and business-information publication. It reports on companies and, inevitably, on the people who run them — executives, dealmakers, litigants, named parties to a transaction. It also maintains a register of companies compiled from public sources.
That is a separate kind of processing from everything in section 2, and it has its own notice: Annex B, below. If you have been named in the Wire, Annex B is the part to read.
4. Who we share data with
We share personal data only with the service providers we need to run the Wire, listed in Annex A, and in the situations below.
- Professional advisers — accountants, auditors and lawyers, under a duty of confidence.
- Authorities, where we are legally required to disclose, or to establish, exercise or defend a legal claim. We will tell you unless we are prohibited from doing so.
- A buyer, if the business or the Wire is sold or reorganised. You would be told before your data was transferred, and the buyer would be bound by this policy.
We do not share your data with any other subscriber, and we do not tell anyone who our subscribers are.
5. Where your data goes
The subscriber database (Supabase) and transactional mail (Resend) are in the EU, Ireland (eu-west-1).
Some of our providers are in, or are group companies of businesses in, the United States — see Annex A for which. Where personal data is transferred outside the UK or the EEA, we rely on:
- UK adequacy regulations and the EU adequacy decision, where they cover the recipient (including the UK Extension to the EU–US Data Privacy Framework and the EU–US Data Privacy Framework for certified recipients); or
- the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or the SCCs themselves for EEA transfers, together with a transfer risk assessment.
You may ask us for a copy of the mechanism relied on for any particular provider.
[CONFIRM: the hosting region. render.yaml declares no region, so our hosting provider's default applies, which is in the United States. If the site and relay are to be hosted in the EU, that is a one-line change and it removes a transfer.]
6. How long we keep things
The full schedule is in our internal retention policy. In summary:
| Record | Kept for |
|---|---|
| Account (email, plan, status) | While you have an Account, and 24 months after your last access, then deleted |
| Sign-in tokens | Until used or expired, then swept — never more than [7] days |
| Sessions | Until they expire (90 days) or you sign out, then swept |
| Payment and tax records | 6 years from the end of the financial year, because HMRC requires it |
| Stripe webhook events | [24] months |
| Access requests that were declined | [12] months |
| Bug reports and correspondence | [24] months |
| Aggregated click counts | Indefinitely — they contain no personal data |
| Server logs | As set by our hosting provider, [typically 30 days] |
| Newsletter subscription | Until you unsubscribe, plus a suppression record kept indefinitely so that we do not email you again |
| The published archive of the Wire | 365 days for the working archive; published journalism is kept as a record — see Annex B |
7. How we protect it
- No password exists to be stolen. Sign-in links and sessions are stored only as hashes.
- The database is reachable only by our relay, with row-level security on and no public policy; the anonymous key sees nothing.
- Card data never touches our systems.
- Transport is HTTPS with HSTS, a content security policy, and the usual response hardening.
- Access to production credentials is limited to the director.
The fuller picture is in Security Statement. If you believe you have found a vulnerability, that document tells you how to report it, and we will thank you rather than threaten you.
8. Your rights
Under the UK GDPR and the EU GDPR you have the right to:
- be told what we do with your data — this policy;
- get a copy of your data;
- correct it if it is wrong;
- have it erased in the circumstances the law provides;
- restrict what we do with it while a dispute is resolved;
- portability — receive the data you gave us in a machine-readable form;
- object to processing we base on legitimate interests, including profiling. If you object, we stop unless we can show compelling grounds that override your interests;
- withdraw consent at any time, where consent is the basis;
- complain to a regulator.
8.1 How to exercise them. Write to hello@axiom.vc. We answer within one month and will tell you if we need longer because the request is complex. We do not charge, unless a request is manifestly unfounded or excessive. We may ask you to confirm you control the email address on the Account — that is the check, and it is the only one we need.
8.2 Erasing your Account. Ask, and we delete the Account row, the sessions and the tokens. We must keep the payment and tax record for six years; that is a legal obligation and it is the one thing we cannot delete on request.
8.3 The limit we want you to know about. Some historical records — early access requests, invitations and bug reports — were written into our private source repository, whose history is append-only. Deleting the current file does not remove the earlier version. Where you ask us to erase such a record, we will delete it from the live file, stop using it, and record the erasure; and we will tell you honestly that a copy remains in a private version history that only we can read. We are moving this data into the database, where deletion is deletion.
8.4 Complaining. If we have not got it right, tell us first — Complaints Procedure. You can also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF), or, if you are in the EEA, to your national supervisory authority.
9. Changes to this policy
We will post a new version here and change the date at the top. If a change is material, we will email account holders before it takes effect.
Annex A — Sub-processors and service providers
Current as at 4 September 2026. We will keep this list current, and it is the list referred to in our Data Processing Addendum.
| Provider | What they do for us | Personal data involved | Where processed |
|---|---|---|---|
| Render Services, Inc. (US) | Hosts the website and the relay | Server logs: IP address, user-agent, request | [CONFIRM REGION — no region declared; provider default is US] |
| Supabase, Inc. (US company, EU region) | Subscriber database | Email, plan, status, session and token hashes, user-agent | Ireland (eu-west-1) |
| Stripe Payments UK, Ltd. and Stripe, Inc. | Payments, checkout, tax calculation, customer portal, invoices | Name, email, billing address and country, VAT number, card metadata, transaction records | UK, EEA and US |
Resend (eu-west-1) | Transactional email — sign-in links, receipts, reminders | Email address, message content | Ireland |
| beehiiv, Inc. (US) | Newsletter list and delivery | Email address, subscription status | US |
| Google LLC / Google Ireland Ltd | Google Analytics 4, cookieless mode | Aggregated measurement; IP address processed transiently for approximate geography and discarded | EU and US |
| GitHub, Inc. (Microsoft) | Private source repository, which currently also holds access requests, invitations and bug reports | Name, email, organisation, free text, user-agent | US |
| Formspree, Inc. (US) | Enterprise enquiry form | Name, email, organisation, message | US |
| Anthropic PBC (US) | AI models used for clustering, summarisation and extraction of published news content | Not subscriber data. Published articles, which may name individuals | US |
| cron-job.org | Triggers scheduled refreshes | None | Germany |
On Anthropic: the models are used on published source material to produce the Wire. Your Account data is not sent to them. Anthropic is not affiliated with, and does not endorse or sponsor, the Wire.
Changes. We will update this Annex before a new sub-processor starts handling personal data. Business customers under a Data Processing Addendum can ask to be notified of changes and may object on reasonable data-protection grounds.
Annex B — People named in the Wire, and the company register
This Annex is our notice under Article 14 of the UK GDPR and the EU GDPR — the notice owed to people whose data we obtained from somewhere other than themselves.
B1. What we publish about people
The Wire reports on the business of entertainment. In doing so it names people in their professional capacity: an executive who has been appointed or has left, a party to a transaction, a named litigant, an author of a quoted post, a person quoted in a report we summarise.
We take this material from already-published sources: the trade and financial press, company statements, regulatory filings, court and merger-register records, and public social posts. We do not obtain it from the people concerned, which is why this notice exists.
B2. The company register
The register behind the Wire — around 2,960 companies, most of them private — is compiled from public company registries (Companies House and the national registers of France, Sweden, Ireland, Finland, Norway, Denmark, Japan and others), from Wikipedia and Wikidata, and from company and press statements. It is a register of companies, and the fields we export and serve are company fields — name, jurisdiction, identifiers, sector, ownership — not personal contact details. Where a person's name appears in it, it is because they are named in the public record of a company.
B3. Our lawful basis, and the journalism exemption
We rely on legitimate interests (Article 6(1)(f)): informing a professional audience about the business of entertainment, which is a recognised interest and, for reporting on people acting in a public and professional capacity, one that is not overridden by their interests. Our assessment is recorded in a Legitimate Interests Assessment, which we will summarise on request.
Where we process personal data for the special purposes — that is, for journalism, with a view to publication, believing publication to be in the public interest — we also rely on the exemption in paragraph 26 of Schedule 2 to the Data Protection Act 2018 and the equivalent provisions in EEA law. That exemption disapplies certain obligations, including some of the transparency and subject-rights provisions, to the extent that complying with them would be incompatible with journalism. We invoke it narrowly: for the editorial record of what has been published, and not for anything to do with subscriber accounts, billing or marketing.
B4. Special category data
We do not seek to publish data revealing health, sexual life, political opinions, religious beliefs, trade union membership, or genetic or biometric data, and we do not build any dataset of it. Where such information appears incidentally because it is the substance of a published report — a criminal charge against a named executive, for example — we rely on the special purposes condition in paragraph 13 of Schedule 1 to the Data Protection Act 2018 (journalism in connection with unlawful acts and dishonesty) and on Article 9(2)(e) where the person has manifestly made the information public.
B5. Your rights if you are named
You can ask us to:
- see what we hold about you;
- correct anything that is wrong — we would rather know, and a correction is faster than a complaint;
- erase it, or object to us holding it.
Write to hello@axiom.vc or use the correction route in Editorial Standards and Corrections.
What we will do. We treat a request about a factual error as a correction request first and answer it on the merits, quickly. Where you object to publication itself, we will weigh your interests against the public interest in the reporting and tell you the outcome and the reason. Where we rely on the journalism exemption we will say so explicitly rather than simply declining.
What we will not do. We will not quietly rewrite the record. Where a published figure or claim changes, the row records what it said before. That is a deliberate feature of the ledger, and it is how a reader can tell a correction from a revision.
B6. Where it came from
If you ask, we will tell you which source a particular item came from. In almost every case the Wire already shows it: each story and each ledger claim carries the report and the sentence it was taken from.
B7. Retention
The working archive holds every story the Wire has looked at for 365 days. Published journalism — what actually appeared in the Wire — is kept as a record of what was published, which is a legitimate purpose in itself; we do not delete the archive of what we published in order to make the past tidier. Rows superseded by a correction keep the record of the correction.
End of Privacy Policy.