From ef38964db9e6fd47cce4c231fa20f8bcf6ec756a Mon Sep 17 00:00:00 2001 From: sjlegg Date: Wed, 30 Sep 2026 12:26:29 +0100 Subject: [PATCH] Update Umami analytics host --- app/privacy-policy.md | 33 ++++++++++++++++++++++++++++ eleventy.config.mjs | 50 +++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 83 insertions(+) create mode 100644 app/privacy-policy.md diff --git a/app/privacy-policy.md b/app/privacy-policy.md new file mode 100644 index 0000000..1d538c7 --- /dev/null +++ b/app/privacy-policy.md @@ -0,0 +1,33 @@ +--- +layout: page +caption: +title: Privacy policy +--- + +This privacy policy explains how NHS England uses information when you visit the Digital Prevention Services Portfolio (DPSP) website. + +## Information we collect + +When you visit this website, we collect your IP address, user agent, page URL and title, referring page, language and screen information. A user agent is information about the browser and operating system you use to access a website. + +We use this information to understand how the website is being used and to improve it. We do not use it to identify you directly. + +## How we store information + +We use your IP address and user agent to create a pseudonymous identifier for analytics. Pseudonymised information is still personal data under data protection law. + +We keep this identifier for up to 2 months, after which it is deleted. We keep the other analytics data, excluding your IP address, for up to 2 years. Once the identifier is deleted, the remaining data is anonymised. + +## Our legal obligations + +We have obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our lawful basis for processing this information is **public task**. This means we process it because it is necessary for us to carry out a task in the public interest or in the exercise of official authority. + +## Your rights + +You have rights over your personal information, including the right to ask for a copy of it, to have inaccurate information corrected and, in some circumstances, to ask for it to be deleted or for its use to be restricted. + +## Contacting us + +If you have questions about this privacy policy or how we use information, email [england.dpsp-front-door@nhs.net](mailto:england.dpsp-front-door@nhs.net). You can also contact the NHS England Data Protection Officer through the [NHS England privacy notice](https://www.england.nhs.uk/contact-us/privacy-notice/). + +You can read more about how NHS England handles personal information and your data protection rights in the [NHS England privacy notice](https://www.england.nhs.uk/contact-us/privacy-notice/). diff --git a/eleventy.config.mjs b/eleventy.config.mjs index 393d872..10d0d4c 100644 --- a/eleventy.config.mjs +++ b/eleventy.config.mjs @@ -3,6 +3,23 @@ import yaml from 'js-yaml' const serviceName = 'Digital prevention services (DPSP)' +// The host serving the Umami script and receiving analytics events. +const analyticsHost = 'https://analytics.digital-prevention-services.nhs.uk' + +// The Umami website ID, available in the website's Umami settings. +const analyticsWebsiteId = '046780c9-3684-4ded-a9d2-bdf361faf561' + +// Hash of the exact inline script emitted by the NHS plugin, used by the CSP. +// If that script changes, hash its contents with the command below, +// replacing '` + ) + }) + // Allow YAML to be used for data eleventyConfig.addDataExtension('yaml', (contents) => yaml.load(contents))