Privacy Policy. Clear data notes.
This policy explains how Drenval Health Ltd handles information connected with drenval.info.
1. Scope
This policy applies to the public website, reader correspondence and subscription forms operated by Drenval Health Ltd, 18 Scrutton Street, London EC2A 1NT. It describes the information collected, why it is used and the choices available to visitors. It applies to visitors in the United Kingdom and readers elsewhere who contact the platform.
a) The policy also extends to any reader who submits a comment, correction request or media enquiry through the contact channels listed on this website, even where no newsletter subscription is created. b) Where a reader accesses the site from outside the United Kingdom, the same core principles apply, though certain rights described in section 9 are specific to UK data protection law and may not have an identical equivalent in every country. c) This policy does not cover the practices of third-party websites linked from our articles, or of any social media platform a reader may use to share our content; those services maintain their own separate privacy notices. For clarity, Drenval Health Ltd is the data controller for the personal information described in this policy, and can be contacted using the details in section 9 below.
2. Information collected
We may receive an email address when a reader subscribes, a name and message when a reader uses the contact form, and technical information such as browser type, approximate location and page requests supplied by a server. We do not request special-category information through ordinary forms. Please do not send sensitive personal details by email.
For example, a newsletter subscription typically involves only an email address and the date of subscription, without any further profiling of the subscriber. A contact form submission may include a name, an email address and the text of a message, plus the date and time it was sent, so that a reply can be matched to the original enquiry. Server-level technical information, such as an IP address truncated for logging purposes, browser type and the pages requested, is collected automatically by hosting infrastructure to keep the website secure and functioning correctly. a) We do not use the contact form or newsletter sign-up to collect payment details, since no products are sold on this website. b) We do not knowingly collect information from children, and the website is intended for a general adult readership. c) If a reader includes unnecessary personal detail in a free-text message, that detail is stored only as part of the message thread and is handled with the same care as the rest of the correspondence, then deleted according to the retention period in section 5.
3. Legal basis
We rely on consent for optional newsletter messages and non-essential cookies. We rely on legitimate interests for site security, basic analytics where enabled and responding to correspondence. We rely on legal obligations where a record must be kept. Consent can be withdrawn through the contact details below.
In practice, this means a newsletter subscription is only created after a reader actively submits their email address, and that action can be withdrawn at any time by using the unsubscribe link included in each newsletter message. a) Legitimate interests are only relied upon after weighing the reader's expectations and privacy interests against the operational need, for example keeping logs long enough to investigate suspicious traffic. b) Where legitimate interests are relied upon for basic analytics, a reader may still object to that processing using the contact details in section 9, and we will assess the objection individually. c) Legal obligations may require limited retention of financial records connected with hosting or service invoices, even after a business relationship with a supplier ends, in line with standard UK record-keeping requirements for limited companies.
4. Use
Information is used to deliver requested messages, answer questions, maintain security, understand broad readership and keep our records accurate. We do not sell reader details or use them to make automated decisions with legal or similarly significant effects.
a) Aggregated, anonymised statistics about overall readership, such as which article categories are most read, may be used internally to plan future editorial topics, but this analysis does not identify any individual reader. b) We do not share reader email addresses with advertisers, and the website does not run personalised advertising based on newsletter or contact-form data. c) Where a reader reports a factual correction, their message may be referenced internally when the article is reviewed, but their name is not published alongside the correction unless they specifically request public attribution.
5. Retention
Newsletter records are retained until unsubscribe or two years after the last meaningful interaction. Contact messages are normally retained for 24 months after closure. Security logs are normally retained for 90 days. Accounting records, where applicable, are kept for the period required by UK law.
a) Where a subscriber unsubscribes, their email address is removed from the active mailing list within a reasonable operational period, typically within 30 days, though a suppression record may be kept briefly to ensure they are not re-added by mistake. b) Contact messages that lead to a published correction may have the substance of the correction retained for editorial reference beyond the 24-month period, while personally identifying details such as the sender's email address are still deleted on the normal schedule. c) Security logs are kept only long enough to investigate abuse or technical faults and are not used for any secondary purpose; a 90-day window reflects common practice for a website of this size and is reviewed periodically to confirm it remains proportionate.
6. Processors
Service providers may host the website, deliver email, process form submissions or provide aggregated measurement. They receive only the information needed for their task and operate under contractual safeguards. A current provider list can be requested from [email protected].
a) Typical categories of processor include a web hosting provider, an email delivery service for newsletter distribution, and, where enabled, a privacy-conscious analytics provider; none of these processors are authorised to use reader data for their own independent purposes. b) Each processor is engaged under a written agreement that limits their use of data to the services provided to Drenval, consistent with UK GDPR requirements for processor contracts. c) Where a processor is replaced, historical data held by the outgoing provider is deleted or securely returned in line with the retention periods described in section 5, rather than being retained indefinitely by a former supplier.
7. Cookies
The cookie banner stores a local preference named cookieChoice for up to 12 months. Session cookies may be used for essential operation and expire when the browser session ends. Optional analytics cookies, if enabled, are configured with a maximum lifespan of 13 months and can be refused.
a) The cookieChoice preference is stored using the browser's local storage rather than a traditional cookie file, but is described here for clarity since it performs the same consent-recording function. b) Where session cookies are used by the hosting or security provider, they typically do not persist after the browser is closed and are not used to build a profile of the visitor across multiple visits. c) Full detail on cookie categories, specific names where applicable, and expiry periods is provided in the separate Cookie Policy, which forms part of this Privacy Policy by reference and should be read alongside it.
8. International transfers
Some technology providers may process data outside the UK. Where this occurs, Drenval seeks a UK adequacy decision, an approved transfer mechanism or another lawful safeguard. Details can be requested from the contact address.
a) Where a hosting or email provider operates servers outside the UK, for example within the European Economic Area or the United States, Drenval relies on the provider's participation in a recognised transfer framework or on UK-approved standard contractual clauses. b) We periodically review the location of our processors as part of routine supplier management, and will update this section if a material change occurs. c) A reader who would like more detail about a specific transfer, including the safeguard relied upon, may request this information from [email protected] and can expect a substantive response within one calendar month.
9. Your rights
Subject to legal limits, you may request access, correction, deletion, restriction, portability or objection. You may withdraw consent at any time. Send a request to [email protected] with enough detail for us to locate the record.
a) An access request allows a reader to ask what personal information, if any, is held about them; a correction request allows factual inaccuracies in that information to be fixed. b) A deletion request will normally be honoured unless a legal obligation, such as a financial record-keeping rule, requires continued retention for a defined period. c) A portability request applies only to information provided directly by the reader, such as a newsletter email address, and can be supplied in a common electronic format such as a spreadsheet file on request. Requests are verified using reasonable means, such as replying from the same email address originally used, to prevent a third party from impersonating the reader.
10. Complaints
We welcome the opportunity to address a concern first. You may also contact the Information Commissioner’s Office at ico.org.uk. We aim to acknowledge requests within five working days and respond within one calendar month.
a) When contacting Drenval directly, please describe the concern clearly and include any reference number from previous correspondence, if applicable, so the request can be located quickly. b) More complex requests may take longer to resolve fully, in which case we will explain the delay and provide an expected timeframe. c) A reader is not required to contact Drenval before approaching the Information Commissioner's Office, though doing so first often resolves a concern more quickly, since the editorial team can review the specific page or record involved directly.
11. Security
We use access controls, encrypted connections and limited retention. No internet service can promise absolute security. If we identify a data incident, we assess it and communicate with affected people and regulators where required.
a) Access to systems that store reader correspondence and subscription records is limited to personnel who need it to operate the website, and is protected by authentication controls appropriate to the size of the operation. b) Connections to the website are served over an encrypted connection, and forms are configured to reduce the risk of common web vulnerabilities such as unauthorised script injection. c) In the unlikely event of a data breach that poses a risk to individuals, Drenval will assess the incident and, where required by UK GDPR, notify the Information Commissioner's Office within 72 hours of becoming aware, and inform affected individuals without undue delay where the risk is high.
12. Changes
Version dated 24 September 2026 records the current approach. Earlier versions may be requested. Material changes will be highlighted on this page, with the effective date shown near the heading.
a) A summary of material changes, where applicable, will be added near the top of this page so that a returning reader can quickly identify what has changed since their last review. b) Minor edits, such as correcting a typographical error or updating a contact detail, do not necessarily change the effective date shown in the page header. c) A reader who would like to see how this policy read at an earlier date may request an archived copy from [email protected]; we retain prior versions for reference purposes.