Privacy & Cookies

Last updated: 8 October 2026

Island Graph is a research-grade directory of Guernsey’s businesses. This page explains how the site handles personal data, why some individuals are named, and what we collect when you visit. We aim to keep it short and honest rather than legalistic.

Who we are

Island Graph is operated by Island Graph Limited, a company incorporated in Guernsey (registration no. CMP78596), whose registered office is at Ashridge, Ruette De La Croix, Castel, GY5 7NN, Guernsey. Island Graph Limited is the data controller for the personal data described on this page. The company was founded and is run by Niki Wiles. Questions, corrections and data requests can be sent to hello@island.gg.

The applicable framework is The Data Protection (Bailiwick of Guernsey) Law, 2017, supervised by the Office of the Data Protection Authority (ODPA). The Law is GDPR-equivalent, which is why Guernsey holds adequacy status with the EU and the UK. Island Graph Limited is registered with the ODPA as a data controller under registration number DPA11733.

Personal data and named individuals

Island Graph is a directory of businesses, not of people. However, some named individuals appear on the site because they are publicly associated with those businesses — typically directors, partners, principals, owner-operators, or named professionals (e.g. a sole-trader plumber whose business trades under their own name).

Where the information comes from

Names and roles published on Island Graph are drawn from information that is already in the public domain. Typical sources include:

  • the public register maintained by the Guernsey Registry (company name, registration number, status, registered office, and named officers);
  • regulatory registers operated by the GFSC and similar bodies;
  • business websites, “About” / “Team” pages, and other materials the business itself publishes;
  • press releases, news articles, and public business profiles and directory listings (for example a Google Business Profile or an island directory) where the individual has chosen to associate themselves with the business publicly. We do not read LinkedIn, by crawler or by hand, and on 4 September 2026 we retired the facts we had once recorded from it.

We collect these pages with our own crawler. It identifies itself as IslandGraphBot, reads public pages only, and honours robots.txt. What it reads and how to block it are set out on the crawler page.

We do not publish personal information unrelated to a person’s public business role. For a small business, the phone number, email or address the business gives out is often the owner’s own, so the contact details we show are the ones the business itself publishes. We make every reasonable effort not to publish a home address unless the business invites customers to it, and we will remove one on request.

Lawful basis

For the publication of names tied to public business roles, we rely on legitimate interests under section 7 of, and Schedule 2, Part I, paragraph 4 to, the Guernsey Law (the equivalent of Article 6(1)(f) of the GDPR): namely, the public interest in a navigable, evidence-linked directory of the island’s businesses, balanced against the limited privacy impact of republishing information that a data subject has already chosen to make public in a professional capacity. Where a record incidentally includes information that goes beyond what is reasonably necessary for that purpose, we will remove or redact it on request.

Your rights

If you are named on the site, you have the right to:

  • see what we hold about you and where each fact came from (every claim on Island Graph is linked to its source);
  • correct anything that is wrong or out of date;
  • object to your name being published, and ask for it to be removed or redacted;
  • complain to the ODPA if you are not satisfied with how we have handled your request — details at odpa.gg.

To exercise any of these, email hello@island.gg. We aim to respond within a few working days and, in any event, within the statutory one-month window.

Cookies and analytics

Island Graph does not show a cookie banner. It also does not set marketing, advertising, or cross-site tracking cookies, and it does not sell or share visitor data with any third party for advertising.

What we use, and what we don’t

  • No advertising cookies. We do not run ads and we do not use ad-tech tracking.
  • No third-party social trackers. No Facebook pixel, no LinkedIn Insight tag, no TikTok pixel, nothing of that kind.
  • No account, no logins. The site has no user accounts, so there is nothing to associate a visit with a person.
  • Search queries are recorded anonymously. What you type into the search box is kept as the bare phrase, how many results it found, where it was typed (the suggestions box, the search page, or our public API), what was chosen from the suggestions (a category, a business, a specialism, or nothing), whether the request came from a browser or a program, and a timestamp — with no IP address, session, cookie, user-agent string, or any other identifier attached, so a query cannot be traced to a person. We use these aggregates for one purpose: finding the businesses people look for that we don’t yet list. Queries are truncated to 200 characters and are deleted after 12 months.
  • Shortlist use is counted, never tracked. When a card is ticked into a shortlist, a shortlist is seeded, or the comparison workspace is opened, we add one to a daily count for that page and that business. The count carries no identifier and no copy of your shortlist, which lives only in your browser’s address bar. Businesses may one day see these counts; nobody ever sees who.
  • Strictly-necessary cookies only, plus aggregate analytics. The site may set small functional cookies needed to make pages work (for example, to remember a UI preference within a session). These are exempt from consent requirements.

Analytics — Cloudflare Web Analytics

For aggregate visit counts we use Cloudflare Web Analytics, chosen specifically because it is the lightest-touch option short of having no analytics at all:

  • No cookies, no stored identifiers of any kind. The measurement script sets no cookies and writes nothing to your browser — no localStorage, no fingerprinting.
  • No cross-site or cross-device tracking. It cannot stitch your visit here to anything else, because it assigns you no identifier to stitch with.
  • Aggregate only. What we see is page views, referrers, countries, and page-performance timings — counts, not people. We cannot look up an individual visitor, and neither can Cloudflare on our behalf.
  • Internal use only. The numbers tell us which parts of the directory are useful. Nothing is shared with advertisers — there are no advertisers.

Cloudflare, Inc. processes the measurement requests on our behalf as a data processor. Because the script is cookieless and stores nothing on your device, it sits within the Guernsey ePrivacy Ordinance’s consent exemptions — which is why there is no banner. If you would still prefer not to be counted, any browser content blocker will block the script (served from static.cloudflareinsights.com) without affecting the site in any way. Cloudflare has a second and much wider role on this site since 26 August 2026 — see Cloudflare sits in front of this site below.

Hosting, AI processing and data flows

The site is served from a server hosted with Amazon Web Services in its London region (the closest to Guernsey), with data stored on Neon, a managed database service, in the same region. Delivering a page necessarily involves your IP address and standard request headers.

Our web server keeps a standard access log of each request it serves: your IP address, the URL you asked for, the page you came from, your browser string, the response status and size, how long it took, and basic connection details such as the encryption version your browser negotiated. Two things are deliberately left out before a line is written. Any search or question text is stripped from the logged URL, so the anonymity of search queries described above holds in this log too; and cookie, authorisation and language headers are dropped. Log lines are kept for 14 days and then deleted automatically — the deletion is enforced by the web server itself, not by someone remembering to run a cleanup. They stay on that machine, are not sent to any third-party logging service, and are used for one purpose: diagnosing abuse and automated crawling that the rate limits below do not catch. Since 26 August 2026 those requests reach that server through Cloudflare, which keeps its own short-term record of the traffic it handles for us, under its retention periods rather than ours; on our plan we receive only aggregate traffic and security statistics from it, never request-by-request records.

To protect the site from abuse, we enforce per-visitor rate limits using Upstash, a managed Redis service, also hosted in the London region. This holds short-lived request counters keyed by IP address; the counters expire within minutes and are not used for any other purpose.

Island Graph is built by software agents that read public webpages and structured registers, extract factual claims, and link each claim back to its source. Large language models are used in that extraction pipeline, but they operate on already-public material and they do not receive any data about you as a visitor.

Cloudflare sits in front of this site

Cloudflare already appears above, as the processor behind our cookieless analytics beacon. Since 26 August 2026 its role here is much wider: every request to island.gg passes through Cloudflare before it reaches us. Cloudflare is a content-delivery and security network — your browser connects to whichever of its data centres is nearest you, London for most visitors, and Cloudflare forwards the request on to the single London server described above.

Cloudflare handles your traffic in the clear. The connection is encrypted from your browser to Cloudflare, and encrypted again from Cloudflare to our server, but Cloudflare decrypts it in between in order to route and filter it. In practice that means Cloudflare sees everything you send us: your IP address, the page you asked for, your browser string, and anything you type into the site, including the search box. We spell this out because it is a wider disclosure than anything above, and because it was not true before 26 August 2026 — until then, traffic went straight to our own server.

Why we did it. This is precautionary, not a response to an incident. A single large crawler sweep on 25 August 2026 showed how much traffic one machine has to absorb before anyone notices, and load of that kind cannot be recognised and turned away one address at a time. Cloudflare can absorb it; a single server cannot. As with the server logs above, our basis for this is a legitimate interest in keeping the site available and secure.

What we have deliberately left switched off. Island Graph is meant to be readable by search engines, AI assistants and automated agents, so Cloudflare’s bot-fighting products are off, its “under attack” mode is off, and we do not put CAPTCHAs in front of ordinary visitors. We also do not use Cloudflare to cache pages: every page you read is still generated by our own server. Cloudflare’s baseline reputation filter does stay on, so an address with a bad reputation may occasionally be shown a one-off browser check — that check is the one thing here that would set a short-lived Cloudflare security cookie, which is why the statement above is strictly-necessary cookies only rather than none at all.

Cloudflare’s role. Cloudflare processes this traffic on our behalf as our service provider, under its own terms and privacy policy; it is not free to use it to profile or advertise to you. Cloudflare, Inc. is a US company operating a worldwide network, so a request may be handled at a data centre outside the UK. You can read Cloudflare’s privacy policy for what it does with data it handles for sites like ours.

Two smaller consequences. Static files such as images, fonts and scripts may now be served to you from a Cloudflare cache rather than from our server; the pages themselves are not cached there. And Cloudflare asks browsers to report failed connections back to it — a standard network-error report naming the address you tried to reach and why it failed — which is used to diagnose outages.

Children

The site is aimed at an adult, business-and-research audience. It is not directed at children, and we do not knowingly collect information about children.

Changes to this notice

If we change how the site handles personal data or analytics, this page will be updated and the “last updated” date at the top will change. Material changes will be flagged on the homepage for a reasonable period.