5. Retention periods

Contact messages are normally retained for up to 12 months after the last substantive exchange, unless a longer period is needed to resolve a complaint or maintain an audit record. Newsletter subscription records are retained while consent remains active and for up to 12 months after unsubscribe to prevent accidental re-enrolment. Security records are generally retained for up to 90 days, subject to hosting requirements and an active investigation.

At the end of the relevant period, information is deleted, anonymised or securely restricted from ordinary use. Backups may retain limited copies for a further cycle, normally no longer than 90 days, before routine replacement. We review retention periods periodically and reduce them where the information no longer serves the stated purpose.

6. Processors and international transfers

Operational providers may process limited information on our behalf, including Vercel hosting, Google Analytics, Google Maps, email delivery, form handling, security monitoring and Mailchimp newsletter administration. Providers are selected for appropriate contractual safeguards and are instructed to use information only for the service they provide. A current provider list can be requested by emailing [email protected].

Some providers may process information outside the United Kingdom. Where that occurs, we use an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful safeguard where applicable. We do not intentionally publish contact details or transfer them to unrelated advertisers.

7. Rights, complaints and review times

People may ask for access, correction, deletion, restriction, portability or objection where the relevant legal conditions apply. Requests should include the email address used for contact and a clear description of the request so we can locate the correct record. We aim to acknowledge a request within five working days and provide a substantive response within one calendar month, subject to lawful extensions for complex requests.

If a request cannot be fulfilled, we will explain the reason and identify any available complaint route. A person may contact the Information Commissioner's Office if they remain concerned about the handling of their information. Policy changes are recorded with the date of publication; the current version takes effect when posted on this page.

1. Scope

This policy explains how Draltov Health Ltd handles information submitted through draltov.info. It applies to visitors, newsletter subscribers and people who contact the editorial team.

It covers the public website, forms, newsletter administration and ordinary communications connected with the site. It does not replace a separate notice supplied by a third-party website reached through an external link. The responsible organisation is Draltov Health Ltd, 31 Above Bar Street, Southampton SO14 1AA.

  • a. Browsing alone normally does not require an account.
  • b. Forms should contain only information needed to respond.
  • c. This notice is written for people in the United Kingdom.

2. Information received

We may receive an email address, name and message when a visitor uses a form. Basic technical records may include browser type, approximate location and access time.

Technical records can also include an IP address, referring page, requested URL and error details generated by hosting security logs. We do not ask visitors to provide special-category information through ordinary forms. If such information is sent voluntarily, it will be handled only where necessary to deal with the message and then removed according to the retention schedule.

3. Purpose

Information is used to respond to enquiries, send requested reading updates and maintain site security. We do not sell personal information.

Our usual legal bases are legitimate interests for operating and securing the site, and consent where a person asks to receive optional newsletter messages. A person can withdraw newsletter consent at any time using the unsubscribe route or by contacting us. Withdrawal does not affect processing already completed lawfully before the request.

4. Retention

Enquiry messages are normally retained for 12 months. Newsletter records remain until a person unsubscribes, after which suppression details may be kept for up to 24 months.

Security logs are normally retained for up to 90 days, unless a longer period is reasonably needed to investigate misuse or meet a legal obligation. Routine form attachments are not requested and should not be sent. At the end of a period, information is deleted, anonymised or securely restricted from routine use.

5. Rights

UK residents may request access, correction, deletion or restriction by emailing [email protected]. We aim to respond within one calendar month.

Requests should include the email address used and a description of the right being exercised. We may ask for proportionate information to confirm identity before disclosing personal data. Where a request is complex, we may explain an extension permitted by applicable law.

  • a. Access: receive a copy of relevant personal information.
  • b. Correction: ask us to fix inaccurate or incomplete information.
  • c. Deletion or restriction: ask us to remove or pause processing where the legal conditions apply.
  • d. Objection: object to processing based on legitimate interests.

6. Processors

Hosting, email delivery and analytics providers may process limited information under contractual safeguards. We select providers with appropriate security commitments.

Typical categories include website hosting, transactional email, consent management, spam protection and technical monitoring. Current providers are engaged only for the service required, receive the minimum information reasonably needed and must protect it under written terms. Provider names and material changes can be requested from [email protected].

7. Transfers

Where information is processed outside the UK, we use an adequacy decision or suitable contractual safeguards where required.

Before a relevant transfer, we consider the destination, the service, the type of information and available safeguards. Some providers may process support data in the UK or European Economic Area, while others may use approved international arrangements. A transfer request can be raised with the privacy contact.

8. Security

We use access controls, encrypted transport and limited retention. No online service can promise absolute security.

Access is limited to people who need it for editorial, technical or administrative work. We review permissions, use strong account controls and investigate unusual activity where appropriate. Visitors should use current browsers and avoid placing confidential details in open contact forms.

9. Complaints

Contact us first so we can investigate. You may also contact the Information Commissioner’s Office through its official website.

We aim to acknowledge a privacy complaint within five working days and provide an initial outcome within 20 working days, although complex matters may take longer. A complaint should include the relevant date, communication channel and requested remedy. Contacting the ICO does not prevent a person from asking us to correct the issue directly.

10. Changes

This policy was reviewed on 9 September 2026. Earlier versions may be requested by email.

Material changes will be shown on this page with a new review date. The change record will explain whether the update concerns a new service, provider, legal requirement or retention practice. Visitors should check this page periodically if they continue to use forms or subscriptions.

11. Data protection impact assessment

Before introducing a processing activity likely to create a higher privacy risk, Draltov will consider whether a Data Protection Impact Assessment is appropriate. The review may examine necessity, proportionality, access controls, retention and the effect on individuals. It may result in a narrower form, a shorter retention period or additional safeguards. A summary can be requested where disclosure would not expose security-sensitive information.

12. Minors and automated decision-making

The site is intended for a general adult audience and is not designed to knowingly collect information from children. Parents or guardians who believe a child has submitted information may contact us so it can be assessed and removed where appropriate. Draltov does not use personal information for solely automated decisions that produce legal or similarly significant effects. Newsletter selection is administrative and does not score or rank individuals.

13. Breach response and revision log

If we identify a personal data breach, we will contain it, assess the likely risk and keep an internal record of the response. Where applicable, we will notify the ICO without undue delay and within the statutory timeframe, and will contact affected people when the law requires clear communication. The privacy contact is [email protected]. This expanded policy entry was recorded on 9 September 2026.