Skip to content

Privacy Policy

Last updated: 25 August 2026

This policy covers the Tula Networks blog at blog.tulanetworks.com — what it collects when you read it, leave a comment, or talk to us, why, and what you can ask us to do about it.

Our main website and customer services at tulanetworks.com are covered by a separate privacy policy at tulanetworks.com/privacy-policy. That one deals with accounts, licences, and billing. This one deals only with the blog. If you are a Tula Networks customer, both apply to you — in different places.

Who we are

The blog is operated by Tula Networks (“we”, “us”), the data controller for the personal data described here.

  • Legal entity: [Legal entity name — TBC]
  • Company number: [Company number — TBC] (registered in England and Wales)
  • Registered office: [Registered office address — TBC]
  • ICO registration: [ICO registration number — TBC]
  • Privacy contact: privacy@tulanetworks.com

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

What we collect, and why

If you only read

Reading the blog does not require an account and we do not ask you for anything. Our web server records standard access log entries — your IP address, the page requested, the time, the referring page, and your browser’s user agent string. We use these for security monitoring, spotting abuse, and diagnosing faults.

Lawful basis: legitimate interests — keeping the site available, secure, and working correctly.

If you leave a comment

The comment form asks for your name and email address, and optionally your website. When you submit a comment, WordPress also records your IP address and your browser’s user agent string alongside it, to help us identify and filter spam.

Your name, your website (if given), and the text of your comment are published on the site and are visible to anyone. Your email address and IP address are not published. Please don’t put anything in a comment that you would not want to be public and indexed by search engines.

Lawful basis: legitimate interests — hosting a public discussion on our articles and keeping it free of spam and abuse. You choose whether to comment; if you would rather not share these details, simply don’t use the form.

Cookies

Nothing that is not strictly necessary is set until you agree to it. When you first arrive you will see a consent banner. Until you accept, analytics cookies are not set. There is no advertising or cross-site marketing on this site at all.

Cookie Set when Purpose Roughly how long
Consent cookies You answer the consent banner Records what you agreed to, so you are not asked again on every page 1 year
_ga, _ga_* Only after you accept analytics in the consent banner Google Analytics: distinguishes one visitor from another so we can count readers and see which articles are useful 2 years
comment_author_*, comment_author_email_*, comment_author_url_* You leave a comment and tick “Save my name, email, and website in this browser” Pre-fills the comment form next time so you don’t retype your details Just under a year
wordpress_test_cookie You reach the login page Checks whether your browser accepts cookies End of session
wordpress_*, wordpress_logged_in_* You log in (staff and contributors only) Keeps you signed in 2 days, or 14 days if you tick “Remember Me”
wp-settings-*, wp-settings-time-* You log in (staff and contributors only) Remembers your admin screen preferences 1 year

Lawful basis: the analytics cookies rely on your consent, given via the banner. The comment cookies are set only if you tick the box, so we rely on your consent there too — leave it unticked and they are not set. The login and test cookies are strictly necessary for the sign-in process to function.

You can delete or block cookies at any time in your browser settings. Blocking them will not stop you reading the blog.

Third parties your browser contacts

Some parts of the page involve other companies’ services. Where your browser connects to them directly, they will see your IP address and user agent as a normal consequence of serving the request.

Google Analytics

We use Google Analytics 4 to understand how the blog is used — how many people read an article, which pages they arrive from, roughly where in the world they are, and what kind of device they use. It is installed through the Google Site Kit plugin.

It does not run unless you allow it. Analytics is consent-gated: before you answer the consent banner, no _ga cookie is created and no measurement takes place. If you decline, it stays that way. Only if you accept does Google Analytics begin measuring you.

Once enabled, Google Analytics sets the cookies listed above and receives your IP address, the pages you view, and technical details about your browser and device. Google processes this on our behalf and its infrastructure is largely outside the UK. We do not use it for advertising, and we have not enabled Google Signals or advertising features.

We use this to decide what to write about next, not to identify you personally. Google’s own description of how it handles this data is at policies.google.com/privacy — and Google’s account of how Analytics data is used by its services is at policies.google.com/technologies/partner-sites.

If you would rather not be measured, Google publishes an opt-out browser add-on, and most browsers’ tracking-protection settings will block it too.

Akismet

Comments submitted to the blog are checked for spam by Akismet, a service operated by Automattic. To do that, the comment text along with the commenter’s name, email address, IP address, and browser user agent are transmitted to Automattic’s servers for analysis. Automattic’s privacy policy is at automattic.com/privacy.

Lawful basis: legitimate interests — keeping the blog free of spam and abuse, without which a public comment form is unusable.

Gravatar

If avatars are shown next to comments, WordPress sends a hashed (one-way scrambled) version of the commenter’s email address to the Gravatar service, operated by Automattic, so it can return that person’s avatar image if they have one. Automattic receives the hash and your IP address. Gravatar’s own privacy policy is at automattic.com/privacy.

Lawful basis: legitimate interests — showing avatars alongside comments.

Embedded content from other sites

Articles may embed content hosted elsewhere — a video, a social media post, a map. Embedded content behaves exactly as if you had visited that other website directly. Those sites may collect data about you, set their own cookies, and track your interaction with the embedded item, including if you have an account and are logged in to them. We have no control over, and no visibility of, what they collect. Their privacy policies apply, not ours.

How we use AI

We use AI in two ways on this site, and we think you should know about both.

Writing the blog

Some of the writing on this blog is produced with the help of AI tools, reviewed and edited by us before publication. What matters for your privacy is what those tools are given when we write, and the answer is: only the article being written. Your comments, your email address, your IP address, and your browsing on this site are not part of it.

Chat and support

If you use a chat assistant on this site, or your question to us is handled with AI assistance, the content of the conversation is sent to a third-party AI provider to generate a reply — currently Anthropic (Claude) and/or OpenRouter, depending on configuration. These providers process the conversation content to return the answer; we do not use them to build advertising profiles, and your conversation is not linked to your browsing on this site.

Transcripts of chat conversations are stored so our team can review them for quality control and to improve the answers over time, and are cleared out on our normal housekeeping schedule — or immediately, if you ask us to delete yours. We may also use the same AI tools internally, for example to summarise or help draft a reply to a question you have sent us; in those cases only the content of your question is shared, and the same providers and safeguards apply.

Because these providers are based outside the UK/EEA, this involves an international transfer of the conversation content, made under their own standard contractual safeguards. Please don’t put anything in a chat that you wouldn’t put in an email to a supplier — and never passwords or payment details, which we will never ask for in chat. Anthropic’s privacy policy is at anthropic.com/legal/privacy and OpenRouter’s is at openrouter.ai/privacy.

Lawful basis: legitimate interests — answering the questions you choose to send us, and improving the quality of those answers. You choose whether to use chat; everything it can do is also available by email.

What we don’t do

  • We do not place advertising or marketing cookies, and we run no advertising on this blog.
  • Beyond the Google Analytics described above, we run no other measurement: no Meta Pixel, no heatmapping, no session recording.
  • We have not enabled Google Signals or Analytics advertising features, so your activity here is not fed into advertising audiences.
  • We do not sell your personal data, and we never have.
  • We do not add blog commenters to any mailing list. Commenting does not sign you up to anything.

How long we keep things

  • Server access logs — 90 days, then automatically purged.
  • Comments and their metadata — comments are retained indefinitely so that discussion threads on older articles stay intact and readable. If you want a comment of yours removed, ask us and we will delete it, along with the email address and IP address stored with it.
  • Comments marked as spam — deleted on our normal spam-clearing schedule and not published.
  • Chat transcripts — kept for quality review as described above, cleared on our normal housekeeping schedule, and deleted on request.

Your rights

Under the UK GDPR you have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — ask us to correct anything inaccurate or incomplete.
  • Erasure — ask us to delete your personal data, including your comments, chat transcripts, and the details stored with them.
  • Restriction — ask us to limit how we use your data in certain circumstances.
  • Portability — ask us to provide your data in a structured, commonly used, machine-readable format.
  • Object — object to processing we carry out on the basis of legitimate interests, including everything described in this policy. If you object, we will stop unless we have compelling grounds to continue.
  • Withdraw consent — where we rely on your consent, such as the analytics and comment-details cookies, you can withdraw it at any time. Withdrawing consent does not affect processing carried out before you withdrew it.

To exercise any of these, email privacy@tulanetworks.com. We will respond within one month. There is no charge. We may ask you to confirm the email address you used when commenting, so we can be sure we are acting for the right person.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first at privacy@tulanetworks.com — we would rather have the chance to put it right.

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113

Children

This blog is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has left a comment containing their personal details, contact us and we will remove it.

Changes to this policy

We will update this page when our practices change, and we will change the “last updated” date at the top when we do. If a change materially affects how we handle data you have already given us, we will say so prominently rather than quietly editing the text.


Questions about anything here: privacy@tulanetworks.com