NOOFA

Privacy Notice

At a glance

1. Who we are

NOOFA is operated by John Kennedy, a sole trader trading as NOOFA. John Kennedy is the controller of the personal information described in this notice.

You can contact the privacy lead and exercise data-protection rights at tkmax@mac.com. Correspondence address: 88–90 Hatton Garden, London, United Kingdom, EC1N 8PG.

NOOFA will keep its ICO data-protection fee and registration position under review and complete any registration or fee requirement that applies.

2. What this notice covers

This notice covers NOOFA’s public Home, Browse, Find and Public Object Profile routes; invitation-only Account functions; Profile Control and Private Object Profiles; private authoring, media and Preview; objective public-profile preparation; exact Public preview; Make public; public delivery; private edits and Update public profile; Make private; and later re-publication.

It does not make public Account signup, public personal profiles, paid services, behavioural advertising, a marketplace, seller contact, buyer lists, transaction execution or unrelated AI training current capabilities. Homepage editorial selection is separate and not activated by this notice.

The controlled phase uses Accounts for people aged 18 or over. Public pages may still be accessed by children. NOOFA therefore keeps public processing proportionate, does not provide behavioural advertising or profiling in the controlled phase, and asks Profile Holders to avoid unnecessary identifying or location information about children.

It also covers private Object Identifiers, their optional deliberate public expression, exact Public-Identifier Find and the limited comparison, rate-control and security records needed for those functions. Describing a capability here does not activate it; public Identifier release remains a separate NOOFA decision.

3. Personal information we use

Account and invitationEmail, Auth identifier, Account state, timestampsPrivate
Authentication/sessionVerification state, provider-held credential state, session/recovery eventsPrivate / provider
Policy evidencePolicy identifier, document hash, accepted/acknowledged event, presentation surface, timePrivate
Profile ControlAccount-to-profile authority relationship and historyPrivate; not ownership proof
Self-declared relationshipPrivate controlled response and limited Other textPrivate; not verification
Object Profile sourceTitle, category, identity answers, Story, Details, Appearance, Maintenance, Update, NotePrivate by default; selected eligible material may later become Public
Private record supportPrivate text about supporting external recordsAlways private
Private imagesOriginal, filename, dimensions, security state, rights/source, description, creditOriginal remains private
Prepared derivativesRestricted resized/reformatted copies, version, technical metadataRestricted before publication
Exact Public previewProposed public-safe content and authorised preview locatorsProfile Holder only
Public profile/versionProfile Reference, selected public fields, public image copies, public state/version timestampsPublic while active, except restricted operational history
FollowAccount-to-profile Follow statePrivate
Reports/complaintsReport, contact, rights request, triage, restriction evidenceRestricted
Security/diagnosticsIP address, browser/device data, request times, errors, security eventsRestricted
Object Identifier sourceHolder-entered display value; type; issuing jurisdiction where relevant; current/previous status; source confirmation and catalogue/normalisation versionPrivate by default. Only eligible holder-selected published values and safe context become Public.
Identifier selectionPer-record choice for a proposed Public version; selection version and timePrivate product state; not publication
Identifier comparison / public retrievalDerived comparison key, normalisation rule/version and active public-version linkageRestricted matching data; public lookup uses only active Public-Identifier records
Find requestsSubmitted search wording, which may include a number concerning a public, private or absent objectService input, not public content; URL/provider handling subject to section 9.2
Search safeguardsNetwork/browser-derived caller bucket, short-lived query token, request times/counters, throttle or unusual-query eventsRestricted security data; not product analytics or a public search history

NOOFA is not designed for identity documents, medical records, criminal records or unnecessary special-category information. Do not add such information unless there is a genuinely necessary, lawful and proportionate reason and the service expressly permits it.

4. Where information comes from

A Profile Holder may provide information about another person, including a person shown in an image, mentioned in an object story, represented by the holder or otherwise connected with an object. If information about you appears in a Public Object Profile and you did not provide it, contact tkmax@mac.com.

Identifiers come from the Profile Holder’s entry or correction; NOOFA derives comparison keys from that entry under the applicable formatting rules. Search wording comes from the person using Find. Network/browser request information may be used to group requests for abuse prevention. ID-02 does not obtain Identifier facts from a VIN/serial decoder, external register or AI service.

5. Why we use information and our lawful bases

We use personal information only for identified purposes and on an appropriate lawful basis. Acceptance of the Terms, “Include in public profile”, Make public and Privacy acknowledgement are product/contract actions; they are not blanket data-protection consent.

Account invitation/authenticationCreate and operate the Account; security/service messagesContract; legitimate interests/legal obligation for security18+ invitation-only; no public personal profile
Private Object ProfileCreate, edit, save and retrieve Private profile/originalsContract; legitimate interests for resilience/securityAccess-controlled; private by default
Profile ControlAuthorise profile management; resolve conflicts; preserve key evidenceContract + legitimate interestsNot ownership or permission proof
Private relationship responseIntegrity, misuse deterrence and accountabilityLegitimate interests, subject to LIAPrivate, minimal free text, no public badge
Prepared derivatives / exact previewCreate public-safe candidate images and show exact previewContract; legitimate interests for security/accessibilityRestricted; no anonymous pre-public access
Make public / public deliveryProvide the deliberate Public profile requested by the holderContract for holder instruction; legitimate interests for service operation/discoveryExact preview; objective gate; public consequences explained
Browse and FindMake deliberately Public profiles ordinarily discoverableLegitimate interestsPublic-only projection; no private fallback
Security/fraud/abuseProtect people, objects, Accounts and systemsLegitimate interests; legal obligation where applicableMinimisation, least privilege, audit
Rights/complaints/moderationHandle rights, complaints, legal/safety issuesLegal obligation and legitimate interestsNeed-to-know access; procedural controls
Policy/audit recordsProve important policy/publication actionsLegal obligation / legitimate interestsAppend-only evidence; limited retention

Where we rely on legitimate interests, our interests include operating a trustworthy object-profile service, preventing misuse, keeping the service secure, making deliberately Public profiles ordinarily discoverable, responding to rights/safety concerns and maintaining limited evidence of important actions. You can object at tkmax@mac.com and ask for more information about our balancing assessments.

Any special-category or criminal-offence processing requires an appropriate lawful condition and is not justified merely by contract or ordinary legitimate interests.

5.1 Object Identifier processing

The following distinguishes the person using the service from another person who may be identified by an object number. A contract with a holder is not, by itself, a lawful basis for processing somebody else’s personal information. Where an Identifier does not relate to an identifiable person it may be object data rather than personal data, but the same product access controls still apply.

Private Identifier and comparison keyRecord and retrieve the particular object information requested by the holderContract where necessary to provide the service to that data subject; legitimate interests for necessary third-party data and integrityPrivate access; no external decoding; context-specific assessment
Selection, exact preview and deliberate public displayCarry out the holder’s requested public expression of selected informationContract for necessary holder-service processing; legitimate interests for proportionate third-party publication, subject to balancingItem-level choice; exact preview; no automatic publication
Exact public Find and public comparison indexLet a person who knows a full public Identifier retrieve the corresponding Public profileLegitimate interests in purposeful retrieval of deliberately published profilesActive-public-only lookup; conservative exact matching; private matches undisclosed
Caller/rate token and short-lived query tokenLimit abusive queries and distinguish repeated searching from attempts to enumerate recordsLegitimate interests in security and preventing misuseRestricted pseudonymous data; purpose limitation; short retention
Security eventsInvestigate throttling, unusual queries or incidentsLegitimate interests; legal obligation only where a specific duty appliesNeed-to-know access; limited incident evidence
Identifier rights and complaintsInvestigate accuracy/privacy concerns and meet applicable rights dutiesLegal obligation and legitimate interests as applicableProportionate verification; prompt restriction where required

Public inclusion, Make public, Terms acceptance and Privacy acknowledgement are not blanket data-protection consent. Legitimate interests do not remove your right to object or NOOFA’s responsibility to assess necessity, proportionality and the rights of other people. ID-02 does not use Identifier numbers to infer ownership, authenticity, manufacture date, theft status or a legally significant automated decision.

6. Profile Holder and relationship privacy

Profile Control identifies the Account authorised to manage a profile inside NOOFA. It is private and does not prove ownership, possession, permission, authenticity, provenance, condition, value or right to sell.

Before first publication, NOOFA may collect one private self-declared response describing the holder’s connection to the object. We use it for integrity, misuse deterrence, accountability and dispute handling. It is not shown publicly and is not used as automated proof. Access is limited to the holder and need-to-know authorised operations.

The “Another connection” text is deliberately short. Do not include sensitive personal information or another person’s name unless genuinely necessary. The response is included in appropriate rights searches and is kept only for as long as needed for its purpose, legal obligations, security and dispute handling.

7. Private source, public selection and exact preview

Private source content stays access-controlled. Ordinary Save does not publish. Selecting “Include in public profile” records what the holder wants included in a future deliberate public action; the selection itself remains private product state.

Before Make public or Update public profile, NOOFA assembles the exact proposed public-safe output. Prepared image derivatives used in that preview remain restricted and are delivered to the authorised holder through short-lived access. Opening the preview does not create public image objects or make the profile public.

A new Identifier is private. You may select an eligible Identifier while adding it or later editing it. If the private save succeeds but selection fails, the Identifier remains privately saved and is not represented as selected. Selecting an Identifier gives neither public access nor a Find match. Unselected records, private confirmation/audit information and Account identity stay out of the proposed public output.

Before Make public or Update public profile, the exact preview shows each eligible selected Identifier in full, with its type and necessary issuing-country or Previous context. There is no separate searchable choice. A previous Identifier is included only where its type supports that use and you select it individually.

8. Public information, Browse, Find and external copies

When the Profile Holder deliberately chooses Make public, selected public-safe information becomes available to anyone through the canonical Public Object Profile and may appear in Browse and Find. NOOFA may also make it technically discoverable to ordinary search engines and crawlers where appropriate.

Once information is Public, other people or services may link, index, cache, copy, quote, download or screenshot it. NOOFA cannot control independent copies made outside its systems.

Make private stops NOOFA’s active public route, Browse/Find exposure and NOOFA-controlled public image delivery. It does not guarantee erasure from third-party caches, search engines, screenshots or independent copies.

Once you deliberately activate a Public version containing an Identifier, the displayed value can retrieve that Public profile through exact Find. Matching may ignore only formatting differences allowed by its type, such as presentation spaces in a UK Registration; it does not use partial, fuzzy, prefix, wildcard or range Identifier matching. A public match is not proof of ownership, authenticity, uniqueness or theft/loss status.

Private or unselected source records do not contribute matches. However, an Identifier already included in the active Public version remains publicly displayed and retrievable if you later edit, deselect or remove its private source, until you Update public profile or public delivery ends through Make private or authorised restriction. A no-result response does not reveal whether a private match exists.

NOOFA’s exact-only rule applies to NOOFA Find, not to external search engines or copies. Other people or services may provide broader search or retain public values after NOOFA withdraws them. There is no Identifier bulk register, listing or browse facet in this service.

9. Images, public media and technical metadata

Private originals are stored separately and remain access-controlled. NOOFA creates resized/reformatted derivatives for responsive display, accessibility, security and public-profile preparation. Before publication, prepared derivatives remain restricted.

The holder-only exact Public preview uses the prepared derivative version. When the holder deliberately publishes or updates, NOOFA copies/promotes the exact approved derivatives into separate public delivery. On Make private, NOOFA removes the public-delivery copies it controls; valid restricted prepared derivatives may remain for later re-publication subject to current source/version checks.

NOOFA strips or normalises embedded metadata from public/preview copies where technically appropriate, including metadata that could reveal location or device information. Operational logs must not contain private image bytes, full signed URLs, tokens or unnecessary original filenames.

9.1 Service-provider path

NOOFA uses service providers for application hosting and execution, authentication/database/storage, image processing, email, security/monitoring and public web delivery. A narrow Google Cloud Run image-processing worker in London is used for derivative generation. Provider access is limited to what is needed for the relevant service function and remains subject to NOOFA’s provider governance.

9.2 Find requests, security records and request logs

Find processes the wording you submit, which can itself be personal information even when no public profile matches. NOOFA’s application design excludes raw Identifier search terms from general product analytics and ordinary diagnostic messages. It uses restricted derived tokens and counters for exact-search safeguards rather than a general search-history feature.

Where a Find query is carried in a page address, it may remain in your browser history or a copied link, and hosting or edge services may record the request address. An indexing instruction does not prevent logging, browser storage or all onward disclosure.

Find is submitted as a page address, so the wording you type forms part of the request address. Services in NOOFA’s provider path — application hosting and execution, the authentication/database/storage platform, public web delivery and security monitoring — may record request addresses, including that wording, in their own operational and security logs, alongside technical details such as an IP address, a timestamp and a user agent. Those provider records exist to run, protect and debug the service; NOOFA does not treat them as a search-history feature and does not use them for profiling, advertising or marketing.

NOOFA cannot promise that a raw search term never appears in provider infrastructure logs, and does not claim that a different submission method would remove that possibility. What NOOFA does control it minimises: raw Identifier search terms are excluded from NOOFA’s own product analytics and ordinary diagnostic messages, exact-search safeguards use short-lived derived tokens and counters rather than stored queries, and access to provider logs is limited to the people and processes needed to operate and protect the service. Provider log retention follows each provider’s own operational and security schedule, and verified provider-specific periods and backup treatment are recorded in the retention schedule as they are confirmed.

10. Information about other people

Object Profile content may concern people other than the Account holder. The Profile Holder must have a lawful and proportionate reason to include that information and must respect privacy, confidentiality, copyright, image rights and other applicable rights.

NOOFA relies on legitimate interests for proportionate third-party information needed to operate deliberately Public object profiles, subject to balancing and safeguards. If information about you appears in a Public Object Profile, you can contact tkmax@mac.com to challenge it, ask for information about the processing or exercise applicable rights.

Do not publish home addresses, access codes, precise storage locations, sensitive routines or unnecessary special-category/criminal-offence information. Content involving children requires particular care and the holder must have an appropriate lawful basis and authority to share it.

A Registration may identify a current or previous keeper, owner or another person when combined with other information. VINs, chassis numbers and watch or guitar numbers may also be personal information in context. The fact that a number is visible elsewhere does not remove NOOFA’s privacy responsibilities.

Before making a number public, consider the effect on others and whether sharing it is lawful and proportionate. This applies to inherited, entrusted or managed objects as well as objects a holder owns. Do not publish another person’s name, location or sensitive routine merely to explain a number. NOOFA does not require ownership proof simply to record the object information.

If we receive personal information about you indirectly, we will provide the required privacy information within the applicable timetable unless a lawful exception applies. We assess any exception rather than assume that publication of this notice or public availability of the number alone is sufficient. Contact the privacy lead to ask about a record or raise a concern.

11. Cookies and browser storage

NOOFA uses browser/storage technologies that are necessary for authentication, session security and core service operation. NOOFA does not currently use behavioural advertising. Any non-essential analytics or similar technology will use the appropriate notice and consent mechanism where required.

Identifier safeguards use limited request information to group activity for security, not to create a marketing profile or track people across services. Any storage or access to information on a device must have the notice and legal treatment applicable to the actual technology. ID-02 does not authorise behavioural advertising or a new persistent tracking cookie.

12. Who receives information

NOOFA shares personal information only where necessary and subject to appropriate contractual, confidentiality, security and data-protection arrangements. Recipient categories include service providers for application hosting/execution, authentication/database/storage, image processing, email, security/monitoring and public web delivery; professional advisers; regulators/courts/law enforcement where required; and the public where a Profile Holder deliberately makes content Public.

NOOFA does not sell personal information or provide personal information to third parties for behavioural advertising in the controlled phase.

For Identifiers this includes the service providers actually used for application/database/search delivery and restricted security monitoring, and the public only for values deliberately included in an active Public version. Search request data and security tokens are not part of public profile content. ID-02 does not send numbers to an external decoder or AI model. Provider access to request logs is described in section 9.2 once the final disposition is complete.

13. International transfers

Some providers may process or make personal information accessible outside the United Kingdom, including through support, telemetry, subprocessors or global web-delivery infrastructure. NOOFA will rely only on a lawful UK transfer route that applies to the actual recipient and transfer, such as an adequacy regulation or appropriate contractual safeguards with the required assessment and supplementary measures.

14. How long we keep information

NOOFA keeps personal information only for as long as needed for the relevant purpose, legal obligations, security, dispute handling and a proportionate recovery/backup period. Retention depends on the data category, purpose, legal requirements and applicable provider backup cycles. You can contact tkmax@mac.com for more information about the criteria used for particular information.

Account/invitationWhile active; then prompt operational deletion with limited legal/security evidence for a period justified by legal, security and dispute-handling needs.
Private profile/originalsWhile retained by the holder; after deletion/Account closure, subject to short recovery/backup window and legal holds.
Prepared derivativesOnly while current/useful for preview/publication; remove when stale, replaced, failed or after the current cleanup rule.
Public derivativesWhile part of an active Public version; delete/verify on Make private or superseded-media withdrawal.
Policy/publication evidenceFor the period justified by legal, limitation and audit needs; exact text/hash/event provenance retained.
Security logsShortest period justified by security/incident needs and provider capabilities.
Rights/complaints/moderationFor the period needed to handle the matter and defend/meet legal obligations.
Provider backupsAccording to each provider’s own deletion and backup cycle; an individual backup period is set by the provider, not by a single request.
Private Identifier source and comparison keyWhile retained for the holder’s profile; removal ends ordinary holder display. Restricted history, correction/removal audit, recovery copies and legal holds remain only for their justified purpose under the applicable schedule.
Active public Identifier and Find keyOnly while expressed in the active Public version. Withdraw or replace with a successful public update, Make private or authorised restriction. Private removal alone does not update the active version.
Identifier history in publication/audit evidenceRestricted only after public withdrawal; no public lookup. Retention follows the documented legal, dispute and accountability criteria, not an indefinite “immutable” exception.
Short-lived query tokenMaximum 60 minutes from collection, for the exact-search safeguard only. Deletion is automatic on a five-minute schedule and is recorded.
Rate-control counter / bucketMaximum 24 hours from collection of the relevant window record. Deletion is automatic on the same five-minute schedule and is recorded.
Identifier-security eventMaximum 30 days from event collection, deleted automatically on the same schedule. A necessary incident extract may be retained separately under a documented, reviewed hold.
Find provider/access logsHeld by the provider under its own operational and security log schedule and not controlled by an individual request. NOOFA keeps no copy of raw Identifier search terms in its own records; verified provider-specific periods and backup treatment are recorded in the retention schedule as they are confirmed.

The short periods above are the operative limits for the security records NOOFA controls, and scheduled automatic deletion enforces them. They apply to ordinary operational security records, not to every justified legal record or independent public copy. No blanket indefinite retention is permitted. Recovery and provider-backup periods follow the applicable provider cycles recorded in the retention schedule.

15. Security

NOOFA uses layered controls including authentication, profile-specific authority, restricted source schemas/storage, least-privilege trusted operations, short-lived signed capabilities, public-safe projections, separate restricted/public media storage, version guards and fail-closed public reads. Providers may add infrastructure and security controls under their own governed roles.

No security system is perfect. If a personal data breach or security incident occurs, NOOFA will assess it, take proportionate steps to contain and investigate it, and make any notifications required by law. We do not publish sensitive technical details that would weaken security.

Identifier safeguards separate private source from the active public search projection, use profile-scoped trusted operations and version checks, restrict direct table access, and control exact-query volume. Comparison keys are not shown as authority. Caller and query tokens are treated as potentially personal, pseudonymous security information; hashing does not make them anonymous or justify wider reuse.

16. Children and Account age

Accounts in the controlled phase are limited to people aged 18 or over. NOOFA does not currently provide child Accounts.

Public Object Profiles, Browse and Find may be accessed by children even though NOOFA does not provide child Accounts. NOOFA does not use behavioural advertising or profiling in the controlled phase. Profile Holders should avoid unnecessary identifying, location or routine information about children and use particular care when deciding whether such information should be Public.

A Profile Holder who includes information or images concerning a child remains responsible for having an appropriate lawful basis, permission/authority where required, and for avoiding unnecessary identifying or location information.

17. Your data-protection rights

Depending on the circumstances, you may have rights to access, correct, erase or restrict personal information, object to processing based on legitimate interests, obtain portable information, and complain about how personal information is used. Some rights have legal limits.

Send a request to tkmax@mac.com. NOOFA may need proportionate information to confirm identity and scope. The policy-update gate must not prevent access to statutory privacy requests or support needed to reduce exposure.

You can raise an Identifier correction, objection, erasure or restriction request whether or not you have an Account. Tell us enough to locate the issue and explain your concern; we may request proportionate evidence through a suitable channel. Knowing a number does not itself prove ownership or give access to private records.

Ordinary holder editing and public updating do not replace statutory rights handling. We will use the appropriate restriction or depublication route where needed while investigating a privacy, accuracy or safety issue, rather than wait for another holder’s voluntary update. We respond within the applicable legal timescales and explain any lawful refusal or extension.

18. Data-protection complaints and the ICO

If you have a privacy concern, contact NOOFA first at tkmax@mac.com so we can investigate.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data-protection regulator.

You may complain by email or post using the contact details below, without an Account or a new Terms acceptance. We will acknowledge a data-protection complaint within 30 days, make appropriate enquiries, keep you informed and tell you the outcome without undue delay. You may also exercise the applicable rights described above; a complaint acknowledgement does not replace an information-rights response.

19. Changes to this notice

NOOFA may update this notice when processing, providers, public/private boundaries, legal obligations or the controller change. Material changes use a controlled new policy version and a prospective effective date. Existing Accounts may be required to acknowledge the updated notice. A privacy acknowledgement records that the notice was presented/read; it is not blanket consent.

20. Contact us

Controller: John Kennedy, a sole trader trading as NOOFA.

Correspondence address: 88–90 Hatton Garden, London, United Kingdom, EC1N 8PG.

Privacy, rights, privacy complaints and controlled-phase support: tkmax@mac.com.

Do not send passwords, recovery links, invitation links, access tokens or refresh tokens by email.