madebyahuman.global

Privacy

We hold less about you than almost any service you have signed up to, because there is nothing to sign up to.

Last updated 25 August 2026

What we hold

There are no accounts here, so there is very little to collect. For an order we hold:

  • Your email address. To send your credentials link, tell you when sealing finishes, and reach you if something goes wrong. It is the only channel we have.
  • A postal address, if you chose a posted certificate. Deleted once the certificate has been delivered.
  • A payment reference from our payment provider. We never see or store your card details.
  • The file's name, size and type, its SHA-256 fingerprint, and the moment it was sealed.
  • Your encrypted file, which we cannot read.
  • A record of every visit to your file's page — the date and time, what happened (opened, wrong code, file downloaded, deletion requested), the IP address it came from and the browser it identified as. Not the access code, not your key, and nothing about the file's contents.

That last one is the only IP address we keep, and it is worth saying why we keep it. Your access code is printed on a card that travels through the post. If somebody copies it, the file does not change and there is no session for us to end — so this record is the only way you or we would ever find out. It is kept for 365 days and then deleted.

We do not hold a password, a profile, a history of what you have looked at, or a marketing list. There is no analytics on this site, no advertising, and nothing that follows you to other sites. One third-party script does load — our payment provider's, on the page where you upload and pay, so that your card details go to them and never through us. It sets two cookies, and both are listed under Cookies below.

Your file, specifically

Your file is encrypted with a key we do not keep. Before that encryption there is a short window — a single automated pass, in memory — where the plaintext exists on our server so it can be fingerprinted. No person sees it, nothing about the contents is examined or recorded, and the plaintext copy is deleted as soon as the encrypted one is confirmed stored. We do not know what is in your file, and we never have. Nothing reads it, nothing classifies it, and after that pass nothing could: what we hold is ciphertext we have no key to.

After that we cannot read your file. If it contains personal data — yours or anyone else's — we are storing ciphertext we have no ability to decrypt.

Who else touches it

This is the whole list, not a sample of it.

  • Our hosting provider — in two roles, both in London. They store your encrypted file, and they run the server itself. The database on that server is what holds your email address, your postal address while an order is open, and your decryption key for as long as we hold it.
  • Our server management provider — how we deploy and administer that machine. It holds none of your data itself, but it has administrative access to the machine that does.
  • Our payment provider — takes the payment and holds the card details we never see. Their script also runs on the page where you upload and pay: it sets two cookies and reads some detail about your browser, which is how they tell a real customer from a stolen card.
  • Our email provider — sees your email address and the contents of our emails to you. Never your key: we never send it by email.
  • A timestamping authority — receives your file's fingerprint, and nothing else. Not your name, not your email, not even the file's name. A fingerprint is a one-way hash; it cannot be turned back into your file.
  • A postcode lookup service — only for a posted certificate, and only your postcode, checked against Ordnance Survey data so that a certificate is not sent to an address that does not exist. Not the rest of your address, and not your name.

We have named what each one does rather than who each one is, because the providers may change and what they are trusted with should not. Ask us and we will tell you exactly who they are on the day you ask.

Printing and posting are done in-house, by us, and not by a third party. That is deliberate: a print vendor would hold a plaintext copy of every decryption key.

Where it goes

Your encrypted file and our database stay in London. Our payment and email providers are US companies, so your email address, your payment reference and the contents of our emails to you are processed outside the UK. The timestamping authority is in the EU, and receives nothing that identifies you. Where data does leave the UK, it goes under the standard contractual terms in each provider's data processing agreement, including the UK's International Data Transfer Addendum.

How long we keep it

  • The encrypted file — indefinitely, until you delete it.
  • Your decryption key — for a posted certificate, until delivery is confirmed or 14 days after posting, whichever comes first. For self-print, as soon as you confirm you have saved it, or 72 hours. Then destroyed, and at most 90 days in any case.
  • Your postal address — until the certificate has been delivered. It is kept until then, not until posting, because a letter that goes astray has to be sent again.
  • Your email address — while the file is stored, so we can reach you about it.
  • The seal record — the fingerprint, the timestamp and the certificate reference — for as long as the certificate should remain verifiable. Outliving us is the point of it.
  • The record of visits to your file's page — 365 days. This one outlives the file: deleting a file does not delete the record of who asked for it to be deleted, because that is the event most likely to be questioned afterwards. It says nothing about what the file was.

Why we are allowed to hold it

MADE BY A HUMAN LTD is the data controller for everything described on this page. We rely on one lawful basis and no others: performing our contract with you — sealing, storing, certifying and posting the thing you bought.

We ask for nothing that is not needed to do that. There is no consent to give and none to withdraw, because we do not process anything on that basis, and nothing here rests on legitimate interests.

Your rights

Under UK GDPR — and under EU GDPR if you are in the EU, because we sell there — you can ask for a copy of what we hold, ask us to correct it, ask us to erase it, ask us to restrict what we do with it, or ask for it in a portable form. There is nothing here to object to in the Article 21 sense, because we process nothing on legitimate interests. Email support@madebyahuman.global and we will respond within one month.

Erasure has a wrinkle worth understanding before you ask for it. Your file's page offers two options. "Remove the file" deletes the encrypted file and your contact details but keeps the seal record — so your certificate keeps working and still proves what it always proved. "Erase everything" also deletes the seal record, which makes your certificate unverifiable by anyone, forever. Both are available; we would rather you knew which one you were choosing.

There is a limit we cannot get around: we cannot edit, extract or delete part of your file, because we cannot read it.

Complaints

If we get this wrong, tell us first — but you can also complain to a regulator, and you do not have to come through us to do it.

  • In the UK, the Information Commissioner's Office at ico.org.uk.
  • In the EU, your own country's supervisory authority — the one where you live or work, not one of ours. The European Data Protection Board lists them at edpb.europa.eu.

Cookies

Four, and not one of them for tracking or advertising.

  • A session cookie. Keeps your place in an order you have not finished, so an interrupted upload can be picked up and a payment matched to the right order. It does not remember your access code or your key: your file's page asks for both every time it is opened and stores neither. It goes when the session does.
  • A security token that pairs with it. It is how we tell a form you submitted from one that another site submitted in your name.
  • Two set by our payment provider, on the page where you upload and pay. They are how a card payment is checked for fraud. We never read them, and they carry that provider's name — so you can see whose they are in your browser even though this page does not name them.

All four are needed for the thing you came here to do: to keep you inside your own order, to stop another site acting as you, and to take a payment safely. So there is no banner and nothing to opt in or out of. We would rather list four honestly than claim one.

Who we are

MADE BY A HUMAN LTD, registered in England and Wales, company number 17393678.
Birchett Road,Farnborough, Hampshire, UK

support@madebyahuman.global