1. Scope

This policy explains how Kreltov Health Ltd handles information connected with kreltov.info, enquiries and newsletter requests. It applies to visitors in the United Kingdom and to people contacting our Portsmouth office. It does not govern websites reached through external links. We aim to collect only what is reasonably needed for the stated purpose.

2. Information collected

We may receive an email address when a reader subscribes, and a name, email address and message when someone uses the contact form. Server logs can include an IP address, browser type, requested page and timestamp. We do not ask for special-category details through ordinary forms. Please avoid sending sensitive personal information in a message.

3. Legal basis

We rely on consent for optional newsletter messages and on legitimate interests for security and basic site operation. We use contractual steps where needed to respond to a direct enquiry. Consent can be withdrawn at any time by using the contact channel below, without affecting earlier processing.

4. Retention

Newsletter records are retained until withdrawal or 24 months after the last meaningful engagement. Enquiry messages are normally retained for 12 months after closure. Security logs are retained for up to 90 days. Accounting records, where relevant, are retained for the period required by UK rules, commonly six years after the relevant financial year.

5. Rights

Subject to legal limits, you can request access, correction, deletion, restriction, portability or objection. You can withdraw consent for optional messages. Send a clear request to [email protected], including enough detail to locate the record; we aim to reply within one calendar month.

6. Processors

Hosting, email delivery, security and analytics providers may process limited information on our behalf. They receive only the data needed for their service and are expected to maintain suitable safeguards. We do not sell reader information or publish contact lists.

7. Cookies

Session cookies may last until a browser closes; preference cookies may last up to 12 months; analytics cookies, where enabled with consent, may last up to 13 months. Cookie names and settings can change as tools are reviewed. The separate Cookie Policy explains categories and choices.

8. International transfers

Some service providers may process information outside the UK. Where that occurs, Kreltov seeks a lawful transfer mechanism such as UK adequacy regulations or suitable contractual safeguards. Provider locations and safeguards are reviewed during supplier checks. Further details are available on request.

9. Security

We use access controls, encrypted transport and restricted administrative access appropriate to a small editorial website. No internet transmission is completely risk-free. If we identify a personal-data incident, we assess it promptly and follow applicable UK notification duties.

10. Complaints

Contact us first at [email protected] so we can investigate. You may also contact the Information Commissioner’s Office through its official UK channels. We do not penalise anyone for raising a genuine privacy concern.

11. Children

The site is written for adults over 40 and is not intentionally directed at children. We do not knowingly request children’s personal information. If a parent or guardian believes a child has submitted details, please contact us so we can review and remove them where appropriate.

12. Changes

Edition 9 September 2026: clarified retention periods, cookie lifespans and transfer wording. Earlier versions may be requested for transparency. Material changes will be signposted on the site where practical.

Data minimisation and accuracy

We use information for the purpose for which it was provided and limit access to people who need it for site administration, editorial correspondence or security. We do not ask ordinary forms to collect health histories, identity documents or payment details.

  • Contact details are checked for obvious errors when a message is received.
  • Duplicate newsletter entries may be combined or removed.
  • Requests for correction are recorded with the date received.

Service providers and international transfers

Hosting, email delivery, form handling, analytics and embedded map services may be supplied by carefully selected processors. Examples include the website host, Google Maps for the map embed, Google Fonts for typography and a newsletter delivery provider if the newsletter is enabled. Each provider receives only the information needed for its function.

Some providers may process information outside the United Kingdom. Where that occurs, Kreltov will use an adequacy decision, the UK International Data Transfer Agreement or another lawful safeguard, together with appropriate contractual and security measures.

Requests, complaints and review history

To exercise a right, email [email protected] with the request and enough detail to locate the relevant record. We aim to acknowledge a request within five working days and respond within one calendar month, subject to lawful extensions for complex requests. We may ask for proportionate identity information before disclosing personal data.

If you remain dissatisfied, you can contact the Information Commissioner’s Office. This policy was reviewed on 9 September 2026 and will be reviewed again when processing activities or applicable UK data rules materially change.

Children and automated decisions

The site is intended for a general adult audience and is not knowingly directed at children. We do not use personal data from ordinary site forms to make solely automated decisions that produce legal or similarly significant effects. If a parent or guardian believes a child has submitted information, they may contact us so the matter can be assessed and the record removed where appropriate.

12. Data protection review

We assess new collection or sharing arrangements before they are introduced. The assessment considers the purpose, categories of information, retention period, access controls and likely impact on readers. A formal Data Protection Impact Assessment may be prepared where a proposed activity could create a high risk to people’s rights and freedoms. The assessment is kept as an internal governance record and is reviewed when the activity changes.

Examples include adding a new newsletter provider, introducing a new form field or enabling a new analytics feature. We seek to avoid collecting information that is not necessary for the stated function. Where a risk cannot be sufficiently reduced, we will reconsider the proposed processing before launch.

13. Sub-processors and access controls

Service providers may process information on our behalf for hosting, email delivery, form handling, security, analytics or embedded content. Current examples may include the hosting provider, Google Maps for an optional map embed, Google Fonts for typography and a newsletter provider if subscription delivery is enabled. We review provider privacy terms and contractual safeguards before relying on a service.

Access is limited by role and is removed when it is no longer needed. Providers are expected to use information only for documented services and to apply suitable technical and organisational safeguards. A material change to a processor or processing purpose will be considered during the next policy review and reflected here where appropriate.

14. Security incidents and notification

We maintain reasonable measures designed to protect information against accidental loss, unauthorised access and inappropriate disclosure. If a personal data incident occurs, we will assess its scope, contain it, preserve relevant records and record the decision taken. Where UK data protection law requires notification to the Information Commissioner’s Office, we aim to notify without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach.

People affected by a serious incident will be contacted where the law requires or where communication is appropriate to help them take protective steps. Reports about a suspected incident should be sent promptly to [email protected]. We do not ask people to include unnecessary sensitive details in an incident report.

15. Young readers and automated processing

The website is written for adults and is not knowingly directed at children. We do not use ordinary newsletter or contact-form information to make solely automated decisions with legal or similarly significant effects. If a parent or guardian believes that a child has supplied information, they may contact us with enough detail to locate the record. We will assess the request and apply the relevant UK data protection rules.