Privacy

Plain-English UK GDPR notice · last updated 21 April 2026 · v1
The short version. RiDraw Ltd publishes Sovereign Meridian. There are two ways your data reaches us. First: you make contact via WhatsApp or email. We hold what you told us (typically name, role, organisation, and a contact channel) and reply manually. Second: you pay for a Canvas subscription. Stripe holds your card or bank-mandate details and we hold your name, billing address, email, and phone number. In both cases, the data is used to do the thing you asked for and nothing else. You can ask for access, correction, or deletion at any time. Full details below.

Who we are

Data controller: RiDraw Ltd, a UK-incorporated limited company. Registered office and company number available on request via email. Santosh R. Dubey is the founder-director and the person who reads every email to santosh@ridraw.com.

What we hold, why, and for how long

DataWhyLawful basisRetention
Contact details (lead capture via WhatsApp or email) To reply to your message and follow up on what you asked for Consent: you sent the first message Two years from last contact, or until you ask us to delete
Email address (Sovereign Meridian weekly issue list) To deliver the weekly publication. Subscribers are added by hand on request; we do not auto-enrol from contact forms or lead capture. Consent: explicit request to be added to the list Until you unsubscribe; 30 days after unsubscribe for confirmation records
Name, billing address, phone, email (Canvas subscribers) To manage the paid subscription, send the welcome pack, issue invoices, and provide customer support Contract performance Duration of subscription + 6 years post-termination (HMRC statutory)
Payment card or Bacs Direct Debit mandate To process recurring payments Contract performance Held by Stripe (payment processor). RiDraw does not store card or bank data
WhatsApp contact save (if you save the RiDraw number) To receive the broadcast message that follows each issue Consent: saving the number is the consent act Until you delete the contact or leave the broadcast list
Email replies + correspondence To respond to you and preserve the editorial record Legitimate interest (publication integrity) Duration of subscription + 2 years post-termination

No patient data, no classified material, no biometric data. The editorial content of Sovereign Meridian does not ingest, process, or publish personal clinical data under any circumstance. Individuals are not named in public artefacts without explicit written consent (standing editorial rule; applies to Issues, Canvas packs, LinkedIn articles, and all public pages).

Processors we use

Sovereign Meridian is operated on a small, transparent stack. Each processor below is a Data Processor acting on RiDraw's behalf; contracts and Data Processing Addenda are in place or on standard vendor terms.

ProcessorRoleJurisdiction
StripePayment processing (card and Bacs Direct Debit) for Canvas subscriptions, including Stripe Tax for VATUS parent · Irish entity for EU/UK customers
Cloudflareinsights.ridraw.com hosting (Cloudflare Pages) and the Stripe webhook function; UK-edge deliveryUS HQ · UK edge
ResendTransactional email: the welcome pack sent to a Canvas subscriber within minutes of payment, and any follow-up team emailsUS
BeehiivWeekly issue delivery to the curated subscriber list. Beehiiv is no longer the consent point for sign-up; it is the email-sending tool onlyUS
WhatsApp (Meta)Broadcast messages and inbound contact (if you save our number or message us)US (Meta)
NotionInternal subscriber records and editorial pipelineUS

Our operational stack is documented internally with vendor jurisdictions, the rationale for current use, and the migration plan to UK-resident or EU-resident alternatives triggered at first ICS licence. If you have a specific sovereignty question about a vendor we use, email santosh@ridraw.com.

Your rights under UK GDPR

You have the following rights at any time, exercisable by emailing santosh@ridraw.com:

Unsubscribing from the publication is always available via the footer of every email we send, or by replying "unsubscribe" to any RiDraw email or WhatsApp message.

Cookies

insights.ridraw.com uses minimal cookies. Cloudflare sets a small number of technical cookies to deliver pages and manage sessions; these are necessary for the site to function and do not track you across other sites. The Observatory and Library pages use browser localStorage (not cookies) to remember that you have entered the access code so you do not have to enter it on every page. No advertising cookies. No third-party trackers. No Google Analytics.

Content exclusions (hard-coded)

RiDraw Sovereign Meridian does not publish, offer, or accept requests for:

These exclusions apply to every artefact we publish and every engagement we take on. They are part of the Subscription Service Agreement for Canvas subscribers.

Changes to this policy

We will publish material changes to this policy at least 30 days before they take effect, via the weekly Sovereign Meridian issue and via a WhatsApp broadcast to every saved contact. Historical versions are retained on request.

Questions or requests about your data: email santosh@ridraw.com or WhatsApp +44 7428 435688. The RiDraw team reads every message and responds within 48 hours on weekdays.