Skip to main content
ScotNet Cloud Hub
• Self-hosted services
• Synology-inspired control
13°C Cloudy

ScotNet Privacy & Operating Principles

Collect less, keep it private, publish only what people actually need.

UK GDPR • Policy v3.2 • 4 August 2026
No advertising No behavioural tracking Limited security logs

ScotNet is privately operated infrastructure for personal, family and limited trusted use. It is not built to monetise attention, construct user profiles or resell activity data.

Operator and scope

ScotNet is operated privately by an individual in the United Kingdom. Where UK data-protection law applies, the operator is the data controller for information processed by the services described here.

This policy covers the main ScotNet site and the shared operating principles used across related ScotNet services. A specialist service may publish additional terms where its function requires them.

What ScotNet does not do

Browser storage

The main public site does not use tracking cookies. The theme and Gizmo interface may use local browser storage to remember display preferences and limited on-device interaction state.

Operational and security logging

Public services may record limited connection and security metadata needed to diagnose faults, enforce rate limits, investigate abuse and protect systems.

Contact forms and messages

When you contact ScotNet, the details you choose to submit are processed so the message can be delivered and answered. Limited technical metadata may also be used to detect automated abuse.

Weather and weather history

Station observations, forecasts and detailed weather history are collected by private scheduled jobs. Raw cache files and the history database are stored outside the public website document root.

Status and external monitoring

The public status page is generated from a private monitoring cache. It publishes simplified service states, confirmed recent history and selected aggregate Miko external-monitor statistics.

DNS and DNSBL services

ScotNet Secure DNS is intended for trusted use and is operated without advertising identifiers or commercial DNS profiling. Short-lived operational data may exist when required for reliability and abuse control.

bl.scott.ovh records network reputation and security decisions about IP addresses. A listing represents observed network behaviour, not a conclusion about a person. Public transparency is intentionally limited to self-checks, published reason text and process information rather than a scrapeable ledger.

BackToYou and other services

BackToYou and other ScotNet services publish only the information needed for their stated purpose. Where a user controls public content, the service is designed to expose only the fields intentionally selected for publication.

Lawful basis

Your rights

Requests need enough information to identify the relevant service or message without requiring ScotNet to collect additional unnecessary identity data.

Policy changes

This page is updated when ScotNet’s infrastructure, retention rules or public data boundaries materially change. Release-level changes are recorded in the ScotNet version history.

Use the main-site contact route for privacy questions.

Contact messages

When you use the ScotNet contact form, the message and reply address are stored privately in encrypted form so they can be reviewed and deleted from the Contact Centre. Delivery copies are sent only to the operator-enabled destinations, which can be Synology Chat, email, both or neither.

Anti-spam controls use short-lived signed form tokens, bounded rate state and keyed one-way hashes rather than retaining the sender's raw IP address in the message record. The sender address may be checked against the ScotNet DNSBL and any additional DNSBLs explicitly enabled by the operator; those checks use the normal DNSBL lookup form derived from the sender IP.

If live chat is enabled, the accepted message can open an encrypted temporary chat transcript. The visitor receives an in-memory/session-tab bearer token for that conversation; Synology Chat replies are accepted only through the configured outgoing webhook token and conversation code. Live transcripts expire automatically and can be closed or deleted by the operator.

Stored contact messages are subject to the configured retention period (180 days by default) and can be deleted earlier by the operator.