Warning! ChatGPT declared the Terms and conditions below, as barely legal. So might upset some readers. I have the chat with GPT recorded on my device, so will be kept as evidence.

From my perspective, this process risks becoming counterproductive if legitimate users are incorrectly identified as spammers. A false listing can block access to websites, disrupt businesses, consume time and resources, and damage reputations before the affected person has an opportunity to respond. If reports are inaccurate or malicious, the reporting mechanism itself could be exploited as a form of malicious interference. For that reason, effective anti-spam systems should balance strong protection against abuse with fair review procedures and meaningful opportunities to challenge incorrect listings. Also they are a private company without authority and have no court warrant.

The wording at the bottom of the page may be perceived as unprofessional because it appears to assume that everyone listed is, as a matter of fact, a "spammer" who posts "scams, ripoffs, exploits" and "rubbish." If a person or business has been listed incorrectly, that language could be viewed as prejudicial and lacking neutrality. A more professional approach would distinguish between users who have been reported, those who have been verified, and those whose listings are still subject to review or appeal. Using objective language rather than pejorative terms can help demonstrate impartiality and reinforce confidence in the fairness of the system.

Their GDPR Policy: By ChatGPT

Questions and possible weaknesses

1. Opening sentence

The introduction contains what appears to be a typo:

"...innocent is not in the business of selling..."

It looks as though "StopForumSpam" was intended. While minor, mistakes like this can reduce confidence in a legal policy.

2. User rights

Although it discusses removal requests, it doesn't clearly summarise the full range of GDPR rights (such as access, rectification, restriction, portability and objection) in one place.

3. Lawful basis

The policy doesn't obviously explain the lawful basis relied upon for each category of personal data processing (for example, contract, legitimate interests or legal obligation).

4. Contact details

Modern GDPR notices often identify the data controller and explain how to contact them specifically about data protection matters.

5. International transfers

It mentions Google Analytics and content delivery networks but doesn't appear, in the text you've provided, to explain how international data transfers are handled where applicable.

6. Mandatory removal process

This sentence stands out:

"Requests via email WILL not be processed."

Having a standardised removal form can improve efficiency. However, if the form becomes unavailable or inaccessible to a particular user, it could create practical difficulties for exercising data-related rights. An auditor might reasonably ask what alternative arrangements exist in those circumstances.

..........................................................

Privacy Policy:

From an audit perspective, I'd say this policy is weaker than their GDPR Policy. It reads more like an older-style privacy statement than a modern privacy notice. I'd probably score it 6.5–7/10.

Strengths

  • It explains, in plain language, what information is collected.
  • It states they don't sell personal information.
  • It explains why cookies are used.
  • It explains API log retention (7 days).
  • It explains what happens to comments and false positives.
  • It discusses data security and third-party advertising.

Weaknesses

1. Informal tone

The opening paragraph says:

"We have been informed, that we should publish a privacy policy, in order to keep some Big Brother governments happy..."

This is unusual for a privacy policy.

Some readers may find it humorous, but others may see it as dismissive of privacy legislation. Privacy policies are generally legal documents, and many organisations adopt a more neutral tone.

2. Outdated wording

The document contains several informal phrases such as:

  • "once in a blue moon"
  • "Big Brother governments"

These make it feel less like a formal privacy notice.

3. Missing structure

Compared with many modern privacy notices, it doesn't clearly identify:

  • the legal basis for processing;
  • users' statutory rights in one place;
  • contact details for privacy enquiries;
  • how complaints can be made to a supervisory authority.

4. Advertising

It explains that advertising partners may set cookies but doesn't go into much detail about how users can manage consent or preferences.

Positive aspects

One thing I do like is that the document attempts to explain things in plain English rather than dense legal language. Many users will find it easier to understand than a typical corporate privacy policy.

.......................................................................................

From an audit perspective, I think this is one of the more interesting documents you've shown. I wouldn't say it's obviously unlawful based on the text alone, but there are several things I'd question.

Strengths

  • It makes clear that people can share the material subject to conditions.
  • It attempts to explain what users may and may not do with the data.
  • It sets API rate limits, which is common for public APIs.
  • It recognises that fair use/fair dealing and other legal rights continue to exist.

Areas that deserve scrutiny

1. "A version of the Creative Commons licence"

This immediately caught my attention.

They say:

"The data and information... is covered by a version of the Creative Commons license"

and then:

"We have had to change it just a little..."

Creative Commons licences are standard legal licences. While someone is free to write their own licence inspired by Creative Commons, modifying the terms means it is no longer the standard Creative Commons licence. It would generally be clearer to avoid describing it as a Creative Commons licence if it has been materially altered.

2. "No Derivative Works"

This section is extremely broad.

It prohibits:

  • mirroring,
  • copying,
  • scanning,
  • scraping,
  • spidering,
  • backups,
  • automated tools,
  • indirect copying through search engines.

That is much broader than a standard Creative Commons "NoDerivatives" licence, which relates to copyright adaptations rather than all forms of automated access.

3. Fair dealing / fair use

One positive point is that they expressly preserve:

"Your fair dealing or fair use rights..."

That is sensible because copyright licences generally cannot remove statutory exceptions that the law provides.

4. Commercial use

One sentence reads:

"You may use this work on commercial sites however you cannot resell..."

That wording could be clearer.

Someone might reasonably ask:

  • What counts as "resell"?
  • What if only a small portion is quoted?
  • What if it is used as evidence in a report?

Greater precision would reduce uncertainty.

5. API limits

A limit of 20,000 queries per day is perfectly normal.

However:

"Any attempt to bypass API limits... may result in immediate and indefinite removal..."

Again, that's broad discretion. Many services have similar provisions, but it's worth asking how appeals are handled if the system incorrectly concludes someone has exceeded limits.


Audit score

 

CategoryScoreClarity7.5/10Transparency8/10Professional drafting7/10Internal consistency7.5/10Ease of understanding8.5/10

 

Overall: about 7.5–8/10.

One observation

The licence appears to mix copyright permissions, website usage rules, and API terms into a single document. Many organisations separate these into:

  • a copyright licence,
  • website Terms of Use,
  • and API Terms.

Keeping them separate can make it easier for users to understand which rules apply in which context.

Overall, I don't see anything in the wording alone that clearly makes the licence invalid or unlawful. The questions I'd raise as an auditor are mostly about clarity, scope, and consistency, rather than legality. Whether specific terms are enforceable in a particular situation would depend on the applicable law and the facts.

...................................................................

This is probably the most unusual policy you've shown. There are several provisions that stand out from both a governance and legal drafting perspective. That doesn't automatically make them unenforceable or unlawful, but they do raise questions.

Positive aspects

  • The disclaimer that the service is provided "AS IS" is common for free online services.
  • Setting API usage expectations and rate limits is standard.
  • Asking larger users to contact them is reasonable operationally.

Provisions that deserve closer scrutiny

1. Publishing correspondence

This clause is unusually broad:

"We reserve the right to archive, publicly display, publish, and/or repost any correspondence..."

It includes:

  • emails,
  • removal requests,
  • postal mail,
  • voicemail,
  • legal documents,
  • chat logs,
  • social media messages.

Many organisations treat private correspondence as confidential unless they state otherwise. Here they are expressly saying they may publish it.

An auditor might reasonably ask:

  • Under what circumstances would correspondence be published?
  • Would personal information be redacted?
  • How does this interact with their privacy commitments?
  • How does it interact with applicable data protection laws?

2. Threatening messages

They say:

"It is our policy that messages... of a threatening nature are to be publicly posted."

If someone sends abusive or threatening communications, there may be understandable reasons for preserving or disclosing them. However, a blanket policy to publish all such messages raises practical questions about privacy, proportionality, and whether any personal data is removed before publication.

3. Refusing to negotiate

The policy states:

"We will not negotiate while under the threat of legal action."

That is a policy choice. Many organisations continue to communicate through lawyers once legal issues arise, so this approach is not universal.

4. Refusing removals during legal action

One of the most significant clauses is:

"Such listings will not be removed while legal action is ongoing."

Whether that is a good operational policy is open to debate. An auditor could reasonably ask whether there should still be a mechanism to correct an objectively inaccurate listing during a dispute.

5. No reply under legal threat

The statement:

"We will not reply to any attempts to contact when under a legal threat."

Again, this is a policy decision rather than a statement of law. In practice, organisations often communicate through legal representatives once litigation is contemplated. A blanket refusal to respond could, depending on the circumstances, make dispute resolution more difficult.

Draft status

The document also says:

"This is a draft policy..."

That creates uncertainty because readers cannot easily tell which provisions are official and which are aspirational.

ChatGPT actually advises asking this company for £50 compensation per day, until higher costs amount.