Privacy
Privacy notice
How the Centre for Youth Voice uses information about you on this website and in the CYV Evidence Library, and what you can do about it.
Last updated 27 September 2026
In short
- You can read everything on this website and search the Evidence Library without giving us any details.
- We only collect personal information when you send it to us: by booking an event, through the contact form, by submitting a report to the library, or by typing a question to the library's AI assistant.
- Event bookings are taken by Eventbrite on our behalf. Its booking form only loads on our pages when you press "Book your place".
- We count visits to the website and the Evidence Library with Umami, which uses no cookies and does not identify you. We do not use advertising or tracking cookies, and we never sell your information.
- Once the library's AI assistant opens, questions typed into it will be sent to two AI companies (OpenAI and Anthropic) to produce an answer, and deleted after 30 days. Please do not type personal details into it.
- If you have a question or want to use your rights, email matthew.walsham@cityoflondon.gov.uk.
Who we are
The Centre for Youth Voice (CYV) is a programme hosted by the Network of Regional Youth Work Units, which is why you see the Network's name in the footer of every page. For data protection law, the organisation responsible for your information (the "data controller") is Partnership for Young London, the charity that holds the contracts for this website and the Evidence Library. PYL is itself hosted by the City of London Corporation.
- Data controller
- Partnership for Young London (registered charity 1062226, company 3334117)
- Address
- Guildhall, London EC2V 7HH
- Email for anything about your data
- matthew.walsham@cityoflondon.gov.uk
- Hosted by
- City of London Corporation. If a question needs the Corporation's data protection team, we will pass it on and tell you.
This notice covers two places: this website at centreforyouthvoice.org, and the CYV Evidence Library at evidence.centreforyouthvoice.org, which is built and hosted separately. Where the two work differently, we say so.
This website
Most of centreforyouthvoice.org is just pages to read. This is what happens with your information, feature by feature.
Reading pages
We count visits with Umami, a privacy-friendly statistics service. It records which pages are viewed, the website that referred you, your browser and device type, and your approximate location (country, region and city), so we can see how the site is used and report to our funder. It sets no cookies, does not store your IP address, and does not follow you across other websites or build a profile of you. The same count covers the Evidence Library, so a visit to both is treated as one. We do not set any cookies of our own. The company that hosts the site, Cloudflare, sees the standard technical information every website receives when you open a page (your IP address, browser type and the pages requested) and keeps short-lived logs to keep the site running and stop attacks. Our page fonts come from Google Fonts, so your browser also sends your IP address to Google to fetch them.
The contact form
When you use the form on the About page, we receive your name, email address and message so that we can reply. The form is delivered to us by a service called Web3Forms, which also runs the message through spam filters. We use your details only to reply and to keep track of the conversation. We do not add you to any list.
Recorded seminars
Recordings on our Training & Events pages are played through YouTube (in its privacy-enhanced mode, which does not set cookies until you press play) or Vimeo. Once you play a video, that provider may set its own cookies and collect viewing data under its own privacy policy.
Booking events
Our events are booked through Eventbrite. Each event has its own page on this website, and the booking form appears on that page when you press "Book your place". The form is Eventbrite's, shown inside our page. Nothing from Eventbrite loads, and no Eventbrite cookies are set, until you press the button. You can also book on Eventbrite's own website; the same applies there.
| What | Details |
|---|---|
| What you give us | Your name and email address, which ticket you choose (for example practitioner or young person), and your answers to our booking questions: your organisation, where in the UK you are based, and, if you choose to tell us, any access needs. The access question is optional. |
| What we use it for | Running the event: confirming your place, sending the joining link and reminders, making access arrangements, managing the waitlist, sending the recording and slides afterwards, and counting attendance for our funder (as totals only, never names). |
| Eventbrite's role | For your booking, Eventbrite acts on our behalf and on our instructions (as our "data processor"), under a data processing agreement that forms part of its terms with us. If you have or create an Eventbrite account, Eventbrite also uses your account details for its own purposes, as a separate data controller, under Eventbrite's privacy policy. |
| Emails | We only email you about the event you booked. We will not add you to a mailing list unless you tick a box asking for news from us. Eventbrite may send you its own emails about other events; you can unsubscribe using the link in any of them or in your Eventbrite account settings. |
| Cookies | Once you open the booking form, Eventbrite may set cookies, as described in its cookie statement. Until then, none are set. |
| Where it is stored | On Eventbrite's systems, mainly in the USA. See Data outside the UK. We download attendee lists only when we need them to run an event. |
| How long we keep it | 24 months after the event, then we delete it from Eventbrite and from anything we downloaded. |
| Young people | Our events are for people aged 16 and over. If you are 16 or 17 you can book in your own right and have the same rights over your information as an adult. |
If you cannot or would rather not use Eventbrite, email matthew.walsham@cityoflondon.gov.uk and we will book a place for you.
Following us
Our LinkedIn page is run by LinkedIn and is covered by LinkedIn's privacy notice, not this one. If we add a newsletter, you will only be signed up if you tick a box asking for it, and you will be able to unsubscribe from every email.
People named on the site
Our Voices pages name the Youth Voice Ambassadors, blog authors and the people quoted in case studies. Everyone named has agreed to appear. If you are named and want something changed or removed, email us and we will do it.
The CYV Evidence Library
The Evidence Library is a searchable collection of research reports about young people aged 16 to 25. You can search it and read every summary without an account and without giving us any details. Personal information comes in through four routes.
| What you do | What we collect | Where it goes | Kept for |
|---|---|---|---|
| Search and read reports | Nothing from you. Standard hosting logs (IP address, browser) and the words you search for. | Vercel (hosting), Algolia (search) | Provider defaults; short-lived logs |
| Ask the AI assistant | The questions you type. Your IP address is stored only as a scrambled code (a "salted hash") so we can limit how many questions each person can ask. | OpenAI and Anthropic (to produce the answer); Supabase, London (to store the conversation) | 30 days, then deleted automatically |
| Submit a report | The report link and your notes, plus your name and email address if you give them so we can tell you what happened. | Supabase, London; email replies via Resend once live | Until we decide on the report, then up to 12 months |
| Admin log-in (staff and interns only) | Work email address and password | Supabase | While the person needs access |
| Visitor statistics | Nothing that identifies you. Umami counts visits without cookies and without storing IP addresses, as on the rest of this website. | Umami | Up to 6 months, as totals only |
There are no public accounts on the Evidence Library, so you never need to sign up.
Report authors
Report records usually name the organisation that published them, but some also name the authors. We take these names from the published report itself or from the publisher's website. We show them because authors expect to be credited, and it helps readers find related work. If you are an author and a record is wrong, or you would rather not be named, email us and we will correct or remove it within a month. See For publishers and authors.
The AI assistant Beta
The assistant is not yet open to the public. This section describes how it will work when it is.
Please do not type personal details into the assistant, about yourself or anyone else. It is built to answer questions about research, not about people. If you do type something personal, it is stored with the conversation for 30 days and then deleted. It is never used to build a profile of anyone.
How it works
- Your question is sent to OpenAI, which turns it into a set of numbers used to find matching passages in the library's reports.
- The matching passages and your question are sent to Anthropic, whose Claude model writes an answer using only those passages, and cites the reports it used.
- Automatic checks then remove any citation or number that does not actually appear in the reports it was given.
- The conversation is saved in our database in London so you can carry on the conversation, and is deleted after 30 days.
What it will not do
It will not give advice about your personal situation and will not answer from general knowledge. If the reports in the library do not cover your question, it says so. It cannot list or count reports; use search for that.
Known limits
The assistant can make mistakes, so check the cited report before relying on an answer. Coverage is uneven: some reports have little text, and the assistant sometimes plays safe and gives a shorter answer. Most reports are UK-wide, national or London-focused, so the English regions are less well covered.
What OpenAI and Anthropic do with your questions
Both companies process your question only to produce the answer, under our contracts with them. We are asking both to confirm in writing how long they keep questions and that they are not used to train their models, and we will update this notice when we have that confirmation.
Limits on use
There is a limit on how many questions each person can ask per session and per day. This keeps the service free and fair for everyone; every question costs us money. The scrambled IP code described above is what makes the limit work.
Reports left out of the assistant
Publishers can ask for their reports to be left out of the assistant. Those reports stay listed and searchable but are never used to write answers.
Why we use your information
UK data protection law says we need a reason (a "lawful basis") for each use of personal information. These are ours.
| Use | Lawful basis | Why |
|---|---|---|
| Running the website and the library securely | Legitimate interests | We cannot run a website without hosting logs, and we need them to stop abuse. |
| Counting visits (Umami) | Legitimate interests | We need to know how the site and library are used, to improve them and report to our funder; nothing identifies you. |
| Answering your questions through the assistant | Legitimate interests | You asked a question and expect an answer; the processing is limited to producing it. |
| Limiting how many questions each person can ask | Legitimate interests | Keeps the free service available to everyone. |
| Replying to contact-form messages and report submissions | Legitimate interests | You contacted us and expect a reply. |
| Running events you book (joining link, reminders, waitlist, recording, attendance totals) | Legitimate interests | You asked for a place and expect us to run the event and follow it up. |
| Access needs you tell us about when booking | Explicit consent | Access needs can include information about health or disability, which the law treats as especially sensitive. You choose whether to tell us, we use it only to make arrangements for that event, and you can ask us to delete it at any time. |
| Naming report authors in library records | Legitimate interests | Authors expect credit and readers need to find related work; the names are already public. |
| Staff and intern admin log-ins | Legitimate interests | Only the people who look after the library can change it. |
| Anything optional we add later, such as a newsletter | Consent | You choose to opt in and can withdraw at any time. |
Where we rely on legitimate interests we have weighed our reasons against your rights, and we keep a record of that assessment. You can object to any of these uses; see Your rights.
No automated decisions. Nothing on this website or in the Evidence Library makes decisions about you with legal or similarly important effects.
Who we share it with
We use a small number of companies to run the website and the library. They act on our instructions and can only use your information to provide their service to us. We do not sell your information and do not use it for advertising.
| Company | What it does for us | Where it processes data |
|---|---|---|
| Cloudflare | Hosts this website | Global network; UK and EU data centres |
| Google Fonts | Serves the typefaces on this website | Global (USA) |
| Web3Forms | Delivers contact-form messages to our inbox and filters spam | India, with servers in the USA and EU |
| YouTube and Vimeo | Play recorded seminars | USA |
| Eventbrite | Takes event bookings on our behalf, and sends confirmations, reminders and messages from us about the event | USA and EU |
| Vercel | Hosts the Evidence Library | Global (USA) |
| Supabase | The library's database and admin log-ins | London, UK |
| Algolia | Runs the library's search | Global (USA and EU) |
| OpenAI | Turns assistant questions into search numbers | USA |
| Anthropic | Writes the assistant's answers (Claude) | USA |
| Resend (planned) | Sends email replies about submitted reports | USA and EU |
| Umami | Counts visits to this website and the Evidence Library without cookies | See Umami's privacy policy |
We would also share information if the law required it, for example to comply with a court order.
Data outside the UK
Some of the companies above process data outside the UK, mainly in the United States. When that happens, the transfer is protected by one of the safeguards UK law allows: the UK's adequacy regulations for the country concerned, the UK–US Data Bridge for companies certified under it, or the ICO's International Data Transfer Addendum built into our contract with the company. For example, Eventbrite is certified under the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge) and also signs standard contractual clauses. Email us if you would like to know which safeguard applies to a particular company.
How long we keep it
| Information | Kept for |
|---|---|
| Assistant conversations and scrambled IP codes | 30 days, then deleted automatically every night |
| Contact-form messages and our replies | 12 months after we last reply, unless you ask us to delete them sooner |
| Event bookings (attendee lists), including any access needs | 24 months after the event, then deleted. Access needs are deleted sooner if you ask. |
| Report submissions and the submitter's details | Until we have decided whether to list the report, then 12 months |
| Visitor statistics (Umami) | Up to 6 months. They contain no information that identifies you; we may keep the monthly totals for reporting. |
| Hosting logs | The provider's default, normally days to a few weeks |
| Admin log-ins | Deleted when the person no longer needs access |
| Author names in library records | While the report is listed, or until the author asks for the name to be removed |
Your rights
You have the right to:
- see the information we hold about you (a "subject access request")
- correct anything that is wrong
- have it deleted
- limit how we use it while a question is sorted out
- object to any use based on legitimate interests
- receive a copy of information you gave us in a form you can move elsewhere, where this applies
- withdraw consent at any time for anything you opted into.
To use any of these, email matthew.walsham@cityoflondon.gov.uk. Tell us which right you want to use and what the information relates to (for example, "the message I sent through the contact form on 3 March"), so we can find it. We may ask you to confirm who you are. We will reply within one month. It is free, unless a request is clearly unfounded or excessive.
If you are under 18 you have exactly the same rights, and you can ask a parent, carer or trusted adult to help you if you like.
How to complain
If you are unhappy with how we have used your information, please tell us first. Email matthew.walsham@cityoflondon.gov.uk with "data protection complaint" in the subject line, or write to us at Guildhall, London EC2V 7HH. We will acknowledge your complaint within 30 days, look into it, and tell you what we found and what we are doing about it.
If you are not satisfied with our answer, or would rather not come to us, you can complain to the Information Commissioner's Office (ICO), the UK's data protection regulator: ico.org.uk/make-a-complaint, telephone 0303 123 1113.
Cookies and storage
This website sets no cookies of its own and uses no advertising trackers. Our visitor statistics (Umami) work without cookies or any other storage on your device. The only cookies you may get come from YouTube or Vimeo when you play a recording (see Recorded seminars), and from Eventbrite when you open a booking form (see Booking events).
The Evidence Library uses only strictly necessary browser storage: a token that keeps staff logged in to the admin area, and a small marker that lets the assistant apply its question limit to your session. Umami statistics work without cookies. Because none of this is used for tracking or advertising, no cookie banner is needed.
For publishers and authors
The Evidence Library lists research reports published by other organisations. This is what we do with them and how to ask for changes.
What we do with reports
Each record links to the original report on the publisher's website. We keep an archive copy so the link keeps working if the original moves, and may also save a copy to the Internet Archive's Wayback Machine. We use the text of the report so the assistant can answer questions from it. Report pages show a small image of the report's front cover to help you recognise it. We also keep a private archive copy of each report, which is only shown if the original link stops working and the publisher has agreed. If you would rather your covers were not shown, email us and we will remove them.
Why we can use the text
The assistant's use of report text is non-commercial text and data mining for research, which is permitted under section 29A of the Copyright, Designs and Patents Act 1988. The library is free, and answers always cite and link to the source report. Publishers have been, or will be, notified that their reports are included.
Opting out of the assistant
If you would rather the assistant did not use your reports, email matthew.walsham@cityoflondon.gov.uk with the report titles or your organisation's name. We will confirm within 10 working days. Your reports stay listed and searchable, but the assistant will never use them to write answers.
Corrections and removal
Email us if a record has wrong details, a dead link, or you want a report removed altogether. Corrections and dead links are fixed within 10 working days; removal requests are acted on within a month, usually much sooner.
Suggesting a report
Anyone can submit a report for the library. The submission page explains what we include.
Changes to this notice
We review this notice at least once a year, and whenever we add a new service or provider. The date at the top shows when it was last changed. If a change affects how we use information you have already given us, we will say so on this page and, where we can, tell you directly.
Last updated 27 September 2026. Next review by September 2027.