Traincestry — Genealogy Privacy Notice
_Last updated: 1 October 2026_
Traincestry is LopoRail's railway-history and genealogy programme. It
publishes historical records and the connections between them. This notice
explains how we handle personal data in that programme.
1. Whose data we hold
1.1 Most of what Traincestry holds is about people who have died, drawn
from public and historical sources. Data about the deceased is not subject
to data-protection law.
1.2 Records can also contain information about living people (for example,
a living person named in a recent record). That information is protected,
and we treat it very carefully.
2. How we handle living people
2.1 We redact living individuals by default. We publish only deceased and
public-domain records; living people are shown by default as initials or
relationships, without identifying detail.
2.2 We make a documented "reasonable expectation" assessment for each
dataset — how public-facing and recent the person is, the sensitivity of the
record, and the risk to living relatives — before anything is published.
2.3 If you are a living person named in our records, you can contact us at
[email protected] to see it, correct it, or ask us to remove it, and we
will act on verified requests (see §4).
3. Why we hold it, and how long
3.1 Our lawful bases are legitimate interests and, where applicable, the
archiving / historical-research conditions with safeguards (minimisation,
research-only use, technical controls).
3.2 We keep records for as long as needed for the programme and the sources'
own terms, then remove or anonymise them. Living people's data is minimised
and removed on request.
4. Your rights
4.1 Living people (and those authorised to act for them) may access,
correct, restrict or erase their data, and object to
processing, by contacting [email protected]. We respond under our
Account & Sign-in Data Use framework (UK GDPR,
Data Protection Act 2018, Australian Privacy Act) and the programme-specific
rules above.
4.2 We also provide a takedown route for any record that should not be
published.
5. Where the data comes from
5.1 Records are gathered from public and open sources, each logged with its
licence and attribution (see our Data Sources register and
the API Terms of Use for upstream licences).
5.2 We do not publish material we are not licensed to publish.