Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions app/privacy-policy.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
---
layout: page
caption:
title: Privacy policy
---

This privacy policy explains how NHS England uses information when you visit the Digital Prevention Services Portfolio (DPSP) website.

## Information we collect

When you visit this website, we collect your IP address, user agent, page URL and title, referring page, language and screen information. A user agent is information about the browser and operating system you use to access a website.

We use this information to understand how the website is being used and to improve it. We do not use it to identify you directly.

## How we store information

We use your IP address and user agent to create a pseudonymous identifier for analytics. Pseudonymised information is still personal data under data protection law.

We keep this identifier for up to 2 months, after which it is deleted. We keep the other analytics data, excluding your IP address, for up to 2 years. Once the identifier is deleted, the remaining data is anonymised.

## Our legal obligations

We have obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our lawful basis for processing this information is **public task**. This means we process it because it is necessary for us to carry out a task in the public interest or in the exercise of official authority.

## Your rights

You have rights over your personal information, including the right to ask for a copy of it, to have inaccurate information corrected and, in some circumstances, to ask for it to be deleted or for its use to be restricted.

## Contacting us

If you have questions about this privacy policy or how we use information, email [england.dpsp-front-door@nhs.net](mailto:england.dpsp-front-door@nhs.net). You can also contact the NHS England Data Protection Officer through the [NHS England privacy notice](https://www.england.nhs.uk/contact-us/privacy-notice/).

You can read more about how NHS England handles personal information and your data protection rights in the [NHS England privacy notice](https://www.england.nhs.uk/contact-us/privacy-notice/).
50 changes: 50 additions & 0 deletions eleventy.config.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,23 @@ import yaml from 'js-yaml'

const serviceName = 'Digital prevention services (DPSP)'

// The host serving the Umami script and receiving analytics events.
const analyticsHost = 'https://analytics.digital-prevention-services.nhs.uk'

// The Umami website ID, available in the website's Umami settings.
const analyticsWebsiteId = '046780c9-3684-4ded-a9d2-bdf361faf561'

// Hash of the exact inline script emitted by the NHS plugin, used by the CSP.
// If that script changes, hash its contents with the command below,
// replacing '<script contents>' with the JavaScript between the <script> tags
// in the generated HTML body (currently: document.body.className += ' js-enabled' + ('noModule' in HTMLScriptElement.prototype ? ' nhsuk-frontend-supported' : '');).
// Do not use the external Umami <script defer src="..."> tag for this hash.
// That external script is allowed by the CSP separately by script-src via analyticsHost.
// printf '%s' "<script contents>" | openssl dgst -sha256 -binary | openssl base64 -A
// Prefix the result with 'sha256-' and update this value.
const cspInlineScriptHash =
'sha256-tDOvXJi1PXbg0CWjLCCYSNHRXtps26K4JXkE3M6u/c0='

export default function (eleventyConfig) {
eleventyConfig.addPlugin(nhsukEleventyPlugin, {
titleSuffix: `NHS ${serviceName}`,
Expand Down Expand Up @@ -54,12 +71,45 @@ export default function (eleventyConfig) {
{
text: 'About us',
href: '/about'
},
{
text: 'Privacy policy',
href: '/privacy-policy'
}
]
}
}
})

// The NHS plugin does not provide a way to add a script to the <head>, so use this approach instead
eleventyConfig.addTransform('analytics-script', (content) => {
if (!content.includes('<head>')) return content

return content.replace(
'<head>',
// GitHub Pages cannot set response headers, so enforce the basic CSP in the document head.
// Keep the analytics host in both script-src and connect-src: Umami loads its script and sends events there.
`<head>
<meta http-equiv="Content-Security-Policy" content="default-src 'self';
script-src 'self' ${analyticsHost} '${cspInlineScriptHash}';
connect-src 'self' ${analyticsHost};
style-src 'self';
img-src 'self' data:;
font-src 'self' https://assets.nhs.uk;
object-src 'none';
base-uri 'self';
form-action 'self';
frame-src 'none';">
` +
// Load Umami asynchronously for analytics.
// The host and website ID are configured in the variables above.
`<script defer src="${analyticsHost}/script.js"
data-website-id="${analyticsWebsiteId}"
data-host-url="${analyticsHost}"
data-domains="www.digital-prevention-services.nhs.uk"></script>`
)
})

// Allow YAML to be used for data
eleventyConfig.addDataExtension('yaml', (contents) => yaml.load(contents))

Expand Down
Loading