Privacy & Cookies
Last updated: 8 October 2026
Island Graph is a research-grade directory of Guernsey’s businesses. This page explains how the site handles personal data, why some individuals are named, and what we collect when you visit. We aim to keep it short and honest rather than legalistic.
Who we are
Island Graph is operated by Island Graph Limited, a company incorporated in Guernsey (registration no. CMP78596), whose registered office is at Ashridge, Ruette De La Croix, Castel, GY5 7NN, Guernsey. Island Graph Limited is the data controller for the personal data described on this page. The company was founded and is run by Niki Wiles. Questions, corrections and data requests can be sent to hello@island.gg.
The applicable framework is The Data Protection (Bailiwick of Guernsey) Law, 2017, supervised by the Office of the Data Protection Authority (ODPA). The Law is GDPR-equivalent, which is why Guernsey holds adequacy status with the EU and the UK. Island Graph Limited is registered with the ODPA as a data controller under registration number DPA11733.
Personal data and named individuals
Island Graph is a directory of businesses, not of people. However, some named individuals appear on the site because they are publicly associated with those businesses — typically directors, partners, principals, owner-operators, or named professionals (e.g. a sole-trader plumber whose business trades under their own name).
Where the information comes from
Names and roles published on Island Graph are drawn from information that is already in the public domain. Typical sources include:
- the public register maintained by the Guernsey Registry (company name, registration number, status, registered office, and named officers);
- regulatory registers operated by the GFSC and similar bodies;
- business websites, “About” / “Team” pages, and other materials the business itself publishes;
- press releases, news articles, and public business profiles and directory listings (for example a Google Business Profile or an island directory) where the individual has chosen to associate themselves with the business publicly. We do not read LinkedIn, by crawler or by hand, and on 4 September 2026 we retired the facts we had once recorded from it.
We collect these pages with our own crawler. It identifies itself as IslandGraphBot, reads public pages only, and honours robots.txt. What it reads and how to block it are set out on the crawler page.
We do not publish personal information unrelated to a person’s public business role. For a small business, the phone number, email or address the business gives out is often the owner’s own, so the contact details we show are the ones the business itself publishes. We make every reasonable effort not to publish a home address unless the business invites customers to it, and we will remove one on request.
Lawful basis
For the publication of names tied to public business roles, we rely on legitimate interests under section 7 of, and Schedule 2, Part I, paragraph 4 to, the Guernsey Law (the equivalent of Article 6(1)(f) of the GDPR): namely, the public interest in a navigable, evidence-linked directory of the island’s businesses, balanced against the limited privacy impact of republishing information that a data subject has already chosen to make public in a professional capacity. Where a record incidentally includes information that goes beyond what is reasonably necessary for that purpose, we will remove or redact it on request.
Your rights
If you are named on the site, you have the right to:
- see what we hold about you and where each fact came from (every claim on Island Graph is linked to its source);
- correct anything that is wrong or out of date;
- object to your name being published, and ask for it to be removed or redacted;
- complain to the ODPA if you are not satisfied with how we have handled your request — details at odpa.gg.
To exercise any of these, email hello@island.gg. We aim to respond within a few working days and, in any event, within the statutory one-month window.
Hosting, AI processing and data flows
The site is served from a server hosted with Amazon Web Services in its London region (the closest to Guernsey), with data stored on Neon, a managed database service, in the same region. Delivering a page necessarily involves your IP address and standard request headers.
Our web server keeps a standard access log of each request it serves: your IP address, the URL you asked for, the page you came from, your browser string, the response status and size, how long it took, and basic connection details such as the encryption version your browser negotiated. Two things are deliberately left out before a line is written. Any search or question text is stripped from the logged URL, so the anonymity of search queries described above holds in this log too; and cookie, authorisation and language headers are dropped. Log lines are kept for 14 days and then deleted automatically — the deletion is enforced by the web server itself, not by someone remembering to run a cleanup. They stay on that machine, are not sent to any third-party logging service, and are used for one purpose: diagnosing abuse and automated crawling that the rate limits below do not catch. Since 26 August 2026 those requests reach that server through Cloudflare, which keeps its own short-term record of the traffic it handles for us, under its retention periods rather than ours; on our plan we receive only aggregate traffic and security statistics from it, never request-by-request records.
To protect the site from abuse, we enforce per-visitor rate limits using Upstash, a managed Redis service, also hosted in the London region. This holds short-lived request counters keyed by IP address; the counters expire within minutes and are not used for any other purpose.
Island Graph is built by software agents that read public webpages and structured registers, extract factual claims, and link each claim back to its source. Large language models are used in that extraction pipeline, but they operate on already-public material and they do not receive any data about you as a visitor.
Cloudflare sits in front of this site
Cloudflare already appears above, as the processor behind our cookieless analytics beacon. Since 26 August 2026 its role here is much wider: every request to island.gg passes through Cloudflare before it reaches us. Cloudflare is a content-delivery and security network — your browser connects to whichever of its data centres is nearest you, London for most visitors, and Cloudflare forwards the request on to the single London server described above.
Cloudflare handles your traffic in the clear. The connection is encrypted from your browser to Cloudflare, and encrypted again from Cloudflare to our server, but Cloudflare decrypts it in between in order to route and filter it. In practice that means Cloudflare sees everything you send us: your IP address, the page you asked for, your browser string, and anything you type into the site, including the search box. We spell this out because it is a wider disclosure than anything above, and because it was not true before 26 August 2026 — until then, traffic went straight to our own server.
Why we did it. This is precautionary, not a response to an incident. A single large crawler sweep on 25 August 2026 showed how much traffic one machine has to absorb before anyone notices, and load of that kind cannot be recognised and turned away one address at a time. Cloudflare can absorb it; a single server cannot. As with the server logs above, our basis for this is a legitimate interest in keeping the site available and secure.
What we have deliberately left switched off. Island Graph is meant to be readable by search engines, AI assistants and automated agents, so Cloudflare’s bot-fighting products are off, its “under attack” mode is off, and we do not put CAPTCHAs in front of ordinary visitors. We also do not use Cloudflare to cache pages: every page you read is still generated by our own server. Cloudflare’s baseline reputation filter does stay on, so an address with a bad reputation may occasionally be shown a one-off browser check — that check is the one thing here that would set a short-lived Cloudflare security cookie, which is why the statement above is strictly-necessary cookies only rather than none at all.
Cloudflare’s role. Cloudflare processes this traffic on our behalf as our service provider, under its own terms and privacy policy; it is not free to use it to profile or advertise to you. Cloudflare, Inc. is a US company operating a worldwide network, so a request may be handled at a data centre outside the UK. You can read Cloudflare’s privacy policy for what it does with data it handles for sites like ours.
Two smaller consequences. Static files such as images, fonts and scripts may now be served to you from a Cloudflare cache rather than from our server; the pages themselves are not cached there. And Cloudflare asks browsers to report failed connections back to it — a standard network-error report naming the address you tried to reach and why it failed — which is used to diagnose outages.
Children
The site is aimed at an adult, business-and-research audience. It is not directed at children, and we do not knowingly collect information about children.
Changes to this notice
If we change how the site handles personal data or analytics, this page will be updated and the “last updated” date at the top will change. Material changes will be flagged on the homepage for a reasonable period.