Legal information
Privacy Policy
This policy explains how Safer Fireworks currently processes information when you use the website, the Consultation Assistant and the optional MP email feature.
Who we are
Safer Fireworks is operated by the British Fireworks Association.
Privacy contact: info@britishfireworksassociation.co.uk
Information processed by the Consultation Assistant
The Consultation Assistant asks for information you choose to provide so it can prepare editable responses to the Government consultation.
- your role or relationship to fireworks
- selected views and concerns
- selected occasions
- optional free-text details
- optional personal experiences
- business-impact information where relevant
This information is used to create consultation answers that you can review, edit and copy into the official Government form.
OpenAI processing
Selected interview answers and relevant response context are sent securely to the OpenAI API to generate consultation responses and MP-email text.
- The website does not send the MP lookup address, postcode, surname or personal email address to OpenAI.
- The MP-email prompt may include the first name, MP name, constituency, selected views and generated consultation responses.
- User input sent through the API may be subject to OpenAI's API data-handling and abuse-monitoring retention terms.
- Data sent through the OpenAI API is not used to train OpenAI models by default unless the account holder has opted into sharing.
OpenAI states that API abuse-monitoring logs may be retained for up to 30 days by default, and that Zero Data Retention requires separate approval. See OpenAI API data controls.
Local browser storage
Interview progress and answers may be saved locally in your browser so you can move between questions and recover progress after a refresh.
- This information remains on your device unless you submit, clear or remove it.
- It is not a server database.
- You can clear it through browser controls.
- The assistant removes saved interview answers after successful consultation response generation.
The Consultation Assistant also includes a "Clear my saved consultation data" control that removes this site's consultation-related local storage from the current browser.
MP lookup data
The optional MP-email feature asks for first name, surname, address line 1, town or city, postcode and email address.
- The postcode is used server-side to identify your MP.
- Parliament's public Members API is used for the lookup.
- The address information is used to support the constituent context.
- The site does not automatically send the email.
- The details are not stored in a database.
- The information exists temporarily in the browser and request memory while the email text is prepared.
- These details must not be deliberately logged or sent to analytics.
Vercel hosting and analytics
The website is hosted by Vercel and Vercel Web Analytics is enabled. Vercel Web Analytics records anonymised or aggregated page and event information and is designed not to use analytics cookies.
Custom events contain only broad non-identifying categories and actions. Free-text consultation answers, addresses, postcodes, names and email content are not intentionally sent to analytics.
Hosting infrastructure may still process technical information needed to serve and secure the website. See Vercel Web Analytics privacy information.
Parliament Members API
The postcode is sent to Parliament's Members service to identify the relevant MP and retrieve published parliamentary contact information. The current implementation does not ask Parliament to verify the full address.
Mailto and email clients
"Open in my email app" uses a mailto link. Your browser or email software handles that action. The website does not send the message.
Copied email content is handled by your device clipboard and by whichever email provider you choose to use.
Legal basis
- providing the requested response-writing service: processing necessary to provide the service requested by the user
- optional MP lookup and email preparation: processing initiated at the user's request
- anonymous website analytics and site security: legitimate operational interests, subject to applicable data-protection law
- legal obligations where applicable
Retention
- No consultation-response database is intentionally maintained by the application.
- Browser-stored interview data remains until it is cleared, reset, removed by browser controls or removed after successful response generation.
- MP lookup details are not deliberately persisted by the application.
- Hosting and API providers may keep technical or abuse-monitoring records under their own terms.
- Vercel Analytics retains data according to the project plan and Vercel's published terms.
- OpenAI API abuse-monitoring logs may be retained for up to 30 days by default unless different approved data controls apply.
International transfers
Some service providers may process information outside the UK. Where this happens, those providers are expected to use their own contractual and data-transfer safeguards. This policy does not make guarantees that have not been independently verified.
Your rights
UK data-protection law may give you rights to access, correct, delete, restrict or object to certain processing of your personal data.
Because most consultation data is not stored in an identifiable BFA database, the BFA may not be able to retrieve browser-local data or anonymous analytics events.
You can complain to the UK Information Commissioner's Office. See the ICO website.
Children
This service is intended for people capable of understanding and responding to the Government consultation. Children should use it with a parent, guardian or responsible adult.
Changes
Last updated: 29 July 2026.
