Privacy Policy

Grelvon Health Ltd respects the privacy of visitors to grelvon.info. This policy explains what information may be collected, why it is used and how questions can be raised.

1. Scope

This policy covers the website, newsletter form and contact enquiries. It does not cover websites reached through an external link.

2. Information collected

We may receive an email address when a visitor subscribes, together with the content of a voluntary enquiry. Basic technical logs may include browser type, date and approximate location.

3. Legal basis

We rely on consent for optional newsletters and non-essential cookies, and legitimate interests for security, basic operation and responding to messages.

4. Retention

Newsletter records remain until unsubscribe or 24 months of inactivity. Contact messages are retained for 24 months. Security logs are normally deleted after 90 days.

5. Your rights

UK residents may request access, correction, deletion, restriction or portability where applicable. Email [email protected] with enough detail to identify the request.

6. Processors

We may use hosting, email delivery and analytics providers acting under written instructions. They may process only the information needed for their service.

Current processor categories include Vercel for hosting, Google Maps for the consent-gated map embed, and an email delivery provider if the newsletter is activated. The person responsible for data protection enquiries is the Privacy Contact at Grelvon Health Ltd, reachable at [email protected] and 55 Pilgrim Street, Newcastle NE1 1AA.

7. Cookies

Session cookies expire when the browser closes. Preference cookies may last up to 12 months. Analytics cookies, where enabled with consent, may last up to 13 months.

8. International transfers

Some suppliers may process information outside the UK. Where this occurs, we use appropriate safeguards such as contractual protections or recognised adequacy arrangements.

9. Children

The publication is intended for adults and is not knowingly directed to children. Please contact us if a child has submitted personal information.

10. Complaints

Contact us first so we can investigate. You may also contact the Information Commissioner’s Office in the United Kingdom.

11. Security

We use access controls, encrypted transport and limited retention. No internet transmission can be guaranteed completely secure.

12. Changes

Version 1.0 published 9 September 2026. Material revisions will be dated on this page.

10. Contact procedure and response times

Privacy questions and rights requests can be sent to [email protected] or posted to 55 Pilgrim Street, Newcastle NE1 1AA. We aim to acknowledge a request within five working days and respond within one calendar month, subject to any lawful extension for complex or repeated requests. We may ask for proportionate information to confirm identity before disclosing or changing personal data.

  • Include the email address or enquiry reference connected with the request.
  • State the right you wish to exercise and the outcome you are seeking.
  • Tell us if the request concerns a newsletter, contact form, cookie choice or technical log.

11. Breach management

If we become aware of a personal data breach, we will assess its scope, record the relevant facts and take reasonable steps to contain it. Where UK data protection law requires notification to the Information Commissioner’s Office, we aim to make that notification within 72 hours of becoming aware of the breach. If the breach is likely to create a high risk to individuals, affected people will be informed without undue delay where required.

Visitors who believe their information has been exposed should contact [email protected] promptly and avoid sending passwords or other unnecessary sensitive details. We will provide a practical update where the facts can be verified.

12. Review and change log

This policy was published on 9 September 2026. A review is planned at least annually and sooner when a supplier, cookie, form or legal requirement changes. The current record is Version 1.0, published 9 September 2026; later material amendments will be dated at the point of publication.

We do not use personal data for solely automated decisions that produce legal or similarly significant effects. We may use ordinary operational filtering to reduce spam or route messages, but a person can review a genuine enquiry.