Privacy, explained plainly.
Last updated 9 September 2026.
1. Scope
This policy describes how Drelvon Health Ltd handles information when visitors use drelvon.info, contact the editorial team or subscribe to updates. It applies to readers in the United Kingdom and visitors elsewhere. The site is intended for adults and does not seek sensitive personal details. We review this policy when our pages, suppliers or legal duties change.
2. Information collected
We may receive an email address when a reader subscribes, plus the name and message supplied through the contact form. Basic technical information such as browser type, approximate region and pages viewed may be processed through hosting logs. We do not ask for special-category information through ordinary forms.
3. Lawful basis
We rely on consent for optional newsletter messages and non-essential cookies. We rely on legitimate interests for security, site operation and answering enquiries. Where a legal duty applies, processing is based on that duty. Consent can be withdrawn at any time without affecting earlier processing.
4. Retention
Newsletter details remain until unsubscribe, or for 24 months after the last meaningful interaction. Contact messages are normally retained for 12 months after closure. Security logs are generally kept for up to 90 days. Records needed for legal accounting duties may remain for six years.
5. Your rights
You may request access, correction, deletion, restriction, portability or objection where applicable. To exercise a right, email [email protected] with enough detail to identify the request. We may ask for proportionate verification and aim to respond within one calendar month.
6. Processors
Hosting, email delivery, analytics and security suppliers may process information on our behalf. They receive only the information needed for their task and must protect it under written arrangements. We do not sell reader information or use it for unrelated advertising lists.
7. Cookies
Session cookies may last until the browser closes. Preference cookies may last up to 12 months. Optional analytics cookies, where enabled, may last up to 13 months. The cookie policy explains categories and controls, and browser settings can remove stored values.
8. International transfers
Some suppliers may operate outside the United Kingdom. Where information leaves the UK, we use an adequacy decision or suitable contractual safeguards where required. Supplier locations and safeguards are reviewed as part of our service checks.
9. Security
We use access controls, encrypted transport and limited administrative access. No internet transmission is entirely risk-free, so readers should avoid placing sensitive personal details in general messages. Suspected security issues should be reported promptly to [email protected].
10. Children
Drelvon is designed for adults and does not knowingly collect information from children. If a parent or guardian believes a child has supplied details, contact us so the record can be reviewed and removed where appropriate.
11. Complaints
We encourage readers to contact us first so we can investigate. UK residents may also contact the Information Commissioner’s Office. A complaint will not affect any other legal right or remedy available to you.
12. Changes
Revision history: 9 September 2026, first published for the Drelvon editorial site. Future changes will show a new date at the top of this page. Material changes may also be signposted on the homepage.
9. Processors and service providers
Drelvon may use carefully selected providers for hosting, email delivery, security monitoring, form handling and website measurement. Current categories include the site host, an email distribution provider, Google Maps on the contact page and analytics tools only where optional consent has been recorded. Each provider receives only the information needed for its stated service.
We do not sell reader information or use newsletter details to create a separate advertising audience. Providers are required to handle information under contractual terms and to assist with security, deletion and rights requests where applicable.
- a) Hosting and security logs: retained for up to 90 days unless a longer period is needed for an incident.
- b) Newsletter provider: email address and delivery preferences until unsubscribe or the retention period in section 4.
- c) Embedded map service: browser connection data may be processed when the map is loaded, subject to that provider’s policy.
10. International transfers and safeguards
Some service providers may process limited information outside the United Kingdom. Where that occurs, Drelvon considers the adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, as appropriate. We also consider access controls, encryption and the provider’s security information before appointment.
Readers may ask which transfer safeguard applies to a particular processing activity by contacting [email protected]. A response will normally be provided within one calendar month, subject to lawful extensions for complex requests.
- a) Transfers are limited to the service purpose described in this policy.
- b) Access is restricted to authorised provider personnel and systems.
- c) Safeguards are reviewed when a supplier or processing purpose changes.
11. Impact assessments, incidents and contact procedure
For a new activity that could create a higher privacy risk, Drelvon will consider whether a Data Protection Impact Assessment is appropriate before the activity begins. We record the purpose, data categories, access arrangements, retention period and safeguards. If a personal data incident occurs, we will assess its nature and document the response.
Where the law requires notification to the Information Commissioner’s Office, we aim to make that notification without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach. If affected individuals face a high risk, we will communicate relevant information without undue delay. Privacy questions can be sent to [email protected]; we aim to acknowledge them within five working days.
- a) Incident assessment considers what data was involved and who may be affected.
- b) Containment, recovery and lessons learned are recorded where proportionate.
- c) Requests for access or deletion are normally answered within one calendar month.
12. Minors, automated decisions and changes
The site is designed for adults and is not directed at children. If we learn that a child has submitted personal information unnecessarily, we will take reasonable steps to remove it. Drelvon does not make decisions about readers using solely automated processing that produce legal or similarly significant effects.
This policy was reviewed on 9 September 2026. Earlier versions may have described fewer service categories; the current version adds detail about processors, transfers and incident handling. Any material change will be shown by updating the date at the top of this page.
- a) First published: 9 September 2026.
- b) Current review: 9 September 2026.
- c) Next routine review target: September 2027.
9. Named processors and service categories
Drelvon may share limited information with service providers that support hosting, security, email delivery, contact forms, mapping and optional measurement. Google Maps may process technical browser information when its map is loaded on the contact page. An email provider may process an address and subscription status so that requested updates can be delivered and unsubscribes can be respected.
Providers receive information only for the relevant service and are expected to apply suitable security controls. Drelvon does not sell subscriber details or use them to create a separate advertising audience. The current supplier list can be requested from [email protected], subject to reasonable security checks.
- a) Hosting and security logs: generally retained for up to 90 days.
- b) Newsletter records: retained until unsubscribe or the period in section 4.
- c) Contact records: generally retained for 12 months after closure.
10. International transfers
Some providers may process limited information outside the United Kingdom. Before using such a provider, Drelvon considers whether an adequacy decision, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses is appropriate. We also consider access controls, encryption, retention and the provider’s security documentation.
Readers may ask which safeguard applies to a particular processing activity by writing to [email protected]. We aim to answer that question within one calendar month, although complex requests may require a lawful extension. International processing does not change the reader’s rights under applicable UK data protection law.
- a) Transfers are limited to defined service purposes.
- b) Access is restricted to authorised personnel and systems.
- c) Safeguards are reviewed when suppliers or purposes change.
11. Impact assessments and incident response
For a new activity that could create a higher privacy risk, Drelvon will consider whether a Data Protection Impact Assessment is appropriate. The assessment may record the purpose, data categories, access controls, retention period, risks and safeguards. We will also consider whether a less intrusive method could achieve the same editorial or operational purpose.
If a personal data incident occurs, we will assess what happened, what information was involved and who may be affected. Where notification to the Information Commissioner’s Office is legally required, we aim to notify without undue delay and, where feasible, within 72 hours of becoming aware of the reportable incident. Where a high risk to individuals is identified, we will communicate relevant information without undue delay.
- a) Containment and recovery actions are recorded where proportionate.
- b) Supplier incidents are escalated through the relevant contract contact.
- c) Affected people can contact [email protected] for incident questions.
12. Minors, automated processing and policy changes
The site is designed for adults and does not intentionally seek information from children. If we learn that a child has submitted unnecessary personal information, we will take reasonable steps to remove it. Drelvon does not make decisions about readers using solely automated processing that produce legal or similarly significant effects.
This policy was reviewed on 9 September 2026. The current review adds detail about processors, transfers, impact assessments, incidents and minors while preserving the existing policy text. Material changes will be reflected in the date at the top of this page and may be announced through the site where appropriate.
- a) First published: 9 September 2026.
- b) Current review: 9 September 2026.
- c) Next routine review: September 2027.