1. Scope

This policy explains how Krenvel Health Ltd handles information received through krenvel.info, email, forms and newsletter sign-up. It applies to visitors in the United Kingdom and elsewhere who use the editorial platform. Krenvel is the controller for information it decides how to use. The policy was reviewed on 24 September 2026.

For example, if a reader in Manchester subscribes to the newsletter and a reader in another country fills in the contact form, both interactions fall within the scope of this policy even though the two readers are in different jurisdictions. In practice, this means the same standards of transparency, retention and security apply regardless of where a visitor is browsing from, subject to any additional local rights described in section 8. An edge case worth noting is that this policy does not cover information handled by third-party websites linked from Krenvel articles, nor does it cover any separate service a reader might use independently of krenvel.info. Where UK GDPR and the Data Protection Act 2018 apply, Krenvel Health Ltd acts as the data controller registered in England and Wales, and this policy is drafted to reflect the transparency obligations set out in Article 13 of UK GDPR.

  • (a) This policy covers krenvel.info, its contact form, its newsletter sign-up and any direct email correspondence with the editorial team.
  • (b) It does not cover third-party websites linked from articles, which maintain their own separate privacy notices.
  • (c) It applies to visitors both inside and outside the United Kingdom, with UK GDPR as the primary legal framework.

2. Information collected

We may receive an email address when a reader subscribes, and name, email and message details when someone contacts the team. Basic technical information such as browser type, approximate location and page requests may appear in server logs. We do not ask readers to provide sensitive personal information through ordinary forms.

For example, submitting the newsletter form typically results in only an email address being stored, without any further profile information being requested or collected. In practice, the contact form additionally stores whatever a sender chooses to write in the message field, so readers are encouraged not to include sensitive details, such as specific health records, that are not necessary for us to answer their query. An edge case arises if a reader voluntarily includes sensitive information, such as details about a health condition, in a free-text message; in that situation we treat the message as confidential correspondence, use it only to respond to the enquiry, and delete it in line with the retention period in section 4 rather than repurposing it for any other reason. Server-level technical information, including IP address fragments and browser identifiers, is generated automatically by hosting infrastructure for security and delivery purposes and is not cross-referenced with newsletter or contact records.

  • (a) Newsletter sign-up: email address only.
  • (b) Contact form: name, email address and free-text message content.
  • (c) Server logs: browser type, approximate location derived from IP address, and page requests, retained for security purposes.

3. Legal basis

Newsletter processing relies on consent. Responding to an enquiry relies on steps requested by the sender and our legitimate interest in communication. Security logs rely on legitimate interests in keeping the platform available and secure. Consent can be withdrawn by contacting [email protected].

For example, ticking the newsletter checkbox and submitting an email address constitutes freely given, specific consent under Article 6(1)(a) UK GDPR, and no newsletter email is sent without that action having taken place first. In practice, responding to a contact form message relies on Article 6(1)(b), because the sender has taken a step to request a reply, combined with Article 6(1)(f) legitimate interests where a reply requires limited follow-up correspondence. An edge case is where a reader withdraws newsletter consent but has also previously sent a separate contact enquiry; withdrawing consent stops future newsletter emails but does not automatically delete an unrelated, already-answered contact record, which continues to be governed by the retention period in section 4. Security logging relies on legitimate interests under Article 6(1)(f), balanced against the reader's privacy expectations, and is limited to what is reasonably necessary to detect and prevent misuse of the platform.

  • (a) Newsletter emails: consent, withdrawable at any time via [email protected] or the unsubscribe link.
  • (b) Contact form replies: performance of a request plus legitimate interest in correspondence.
  • (c) Security and server logs: legitimate interest in maintaining availability and preventing misuse.

4. Retention

Newsletter records are kept until unsubscribed, then removed within 30 days. Contact messages are normally retained for 24 months after the last meaningful exchange. Security logs are usually retained for 90 days. Accounting records, where applicable, are kept for the period required by UK law.

For example, an email address added to the newsletter list in January 2026 that unsubscribes in June 2026 will normally be removed from active systems by early July 2026, allowing for the standard 30-day removal window. In practice, a contact message answered in March 2026 with no further correspondence is expected to be deleted from the support inbox by March 2028, unless a legal or accounting reason requires it to be kept longer. An edge case is an ongoing conversation thread that spans several months; the 24-month period restarts from the date of the last meaningful exchange, not from the date of the very first message, so an active back-and-forth does not expire mid-conversation. Where invoices or accounting records exist, for example relating to advertising partners, UK tax law under HMRC record-keeping requirements generally expects business records to be kept for at least six years, and Krenvel follows that period for any such financial documentation.

  • (a) Newsletter subscriber list: retained while subscribed, deleted within 30 days of unsubscribing.
  • (b) Contact form messages: retained for 24 months from the last meaningful exchange.
  • (c) Security and server logs: retained for approximately 90 days on a rolling basis.
  • (d) Accounting and financial records, where they exist: retained for at least six years in line with HMRC requirements.

5. Your rights

You may request access, correction, deletion, restriction or portability where the law provides those rights. You may object to processing based on legitimate interests. Send a request to [email protected] with enough detail for us to identify the record. We aim to respond within one calendar month.

For example, a reader who wants to know what information is held about them can email [email protected] with their name and the email address used, and we will search the newsletter list and contact archive for matching records before replying. In practice, a request to correct an email address on the newsletter list is normally actioned within a few working days, well inside the one-month statutory response window under Article 12(3) UK GDPR. An edge case arises where we cannot verify the identity of the person making a request, for example because the request comes from an email address that does not match any record on file; in that situation we may ask for reasonable additional information before acting, to avoid disclosing information to the wrong person. If a request is complex or we receive a high volume of requests at once, the one-month period may be extended by a further two months, and we will explain the reason for any such extension within the first month.

  • (a) Right of access: a copy of the personal information we hold about you.
  • (b) Right to rectification: correction of inaccurate or incomplete information.
  • (c) Right to erasure: deletion of information where there is no overriding reason to keep it.
  • (d) Right to restriction and right to object: limiting or challenging certain processing based on legitimate interests.
  • (e) Right to portability: receiving newsletter subscription data in a portable format, where technically feasible.

6. Processors

We may use hosting, email delivery, analytics and security providers acting on documented instructions. Providers receive only the information needed for their function. We do not sell subscriber lists.

For example, the website itself is hosted on infrastructure provided by a cloud hosting company, which processes server logs and page requests strictly to keep krenvel.info online and secure. In practice, newsletter emails are dispatched through a dedicated email delivery provider that receives subscriber email addresses solely to send the newsletter and record delivery status, and that provider is contractually restricted from using the list for its own marketing. An edge case is where an analytics tool is introduced in future to understand general readership patterns; such a tool would be added only after being named in this policy and, where required, only after visitor consent has been obtained through the cookie banner described in section 7. Each processor operates under a written data processing agreement consistent with Article 28 UK GDPR, limiting use of the information to the specific service being provided to Krenvel.

  • (a) Hosting and infrastructure provider: processes server logs and page requests for platform availability and security.
  • (b) Email delivery provider: processes newsletter subscriber addresses solely to send and track newsletter emails.
  • (c) Any future analytics or measurement tool: will be named here and enabled only where consent has been given.

7. Cookies

Session cookies may support basic navigation. The consent choice may be stored locally in a browser under cookieChoice. Optional analytics cookies, if enabled, are described in the cookie policy and have lifespans of up to 13 months.

For example, the cookieChoice value is written to the browser only after a visitor clicks Accept All or Reject on the cookie banner, and it is read on later visits so the banner does not reappear unnecessarily on every page. In practice, no analytics or advertising cookie is currently active on krenvel.info, so the only browser storage in routine use is this single consent record and any short-lived session identifier created by the hosting infrastructure. An edge case is a visitor who clears their browser storage between visits; in that case the cookieChoice value is removed along with it, and the consent banner will appear again on the next visit, requiring a fresh choice. Full detail on cookie names, categories and lifespans is set out in the dedicated cookie policy, which should be read alongside this section.

  • (a) cookieChoice: essential consent record, stored locally until cleared by the visitor.
  • (b) Session identifiers: short-lived, created by hosting infrastructure, expiring within 24 hours or at the end of the browsing session.
  • (c) Optional analytics cookies: not currently active; would carry a lifespan of up to 13 months if introduced with consent.

8. International transfers

Some technology providers may process information outside the UK. Where that occurs, Krenvel relies on an adequacy decision or appropriate contractual safeguards and records the relevant transfer basis.

For example, a hosting or email delivery provider may operate data centres in the European Economic Area or in the United States, meaning that a UK reader's email address could, in practice, be processed on servers located outside the UK. In that situation, transfers to the EEA are generally treated as adequate under the UK's own adequacy regulations, while transfers to other countries, including the United States, are supported by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or an equivalent recognised safeguard. An edge case is a provider that changes its hosting region after this policy is published; if that happens, Krenvel reviews the new arrangement and updates the transfer safeguard on file before the change takes effect wherever possible. We keep a short internal record of which providers process information outside the UK and which legal transfer mechanism applies to each, available on request via [email protected].

9. Children

The platform is intended for a general audience and is not designed to collect information from children. If a parent or guardian believes information was submitted, contact us so the record can be reviewed.

For example, the newsletter and contact forms do not ask for a date of birth and are not marketed towards children, so Krenvel does not knowingly build any profile of a child visitor. In practice, if a parent discovers that a child has subscribed to the newsletter using their own or a family email address, contacting [email protected] will result in that subscription being removed promptly. An edge case is a shared family email address used by both a parent and a child; because no age information is collected, Krenvel cannot always distinguish who submitted a form, so parents are encouraged to review household email activity and contact us directly if they have any concern. Where we become aware that information has been collected from a child without appropriate parental awareness, we will delete the relevant record without requiring extensive justification.

10. Complaints

Contact us first at [email protected]. You can also contact the Information Commissioner's Office through ico.org.uk if you believe your concern has not been addressed.

For example, a reader unhappy with how a deletion request was handled should first email [email protected] describing the issue, and we aim to acknowledge that complaint within five working days and provide a substantive response within one calendar month. In practice, most concerns raised this way relate to newsletter unsubscribe timing or requests to correct a stored email address, and these are usually resolved directly with the editorial team without needing further escalation. An edge case is where a reader remains unsatisfied after our response, or does not receive a response within the expected timeframe; in that situation, the Information Commissioner's Office, the UK's independent regulator for data protection, can be contacted through ico.org.uk or by telephone on 0303 123 1113. The ICO is based at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, and complaints to it are free of charge for members of the public.

11. Changes

24 September 2026: this version consolidates contact, newsletter and cookie explanations. Future material changes will be dated on this page. Continued use after an update means the revised wording is available for review.

For example, if Krenvel introduces a new analytics tool in future, this page will be updated with a new dated entry explaining what changed, and the cookie policy will be updated at the same time to name the new cookie and its lifespan. In practice, minor clarifications, such as fixing a typo or updating a contact detail, may not warrant a new dated entry, whereas changes to retention periods, legal basis or processors always will. An edge case is a change required urgently for legal compliance, for example following new guidance from the ICO; in that case the update will be applied promptly and the changelog entry will note both the original and revised wording where practical, so returning readers can see what changed. Readers who want to be notified of material changes can check this page periodically, since Krenvel does not currently operate a separate change notification email beyond the general newsletter.

  • 24 September 2026: initial consolidated version covering scope, retention, rights, processors and cookies.

12. Contact

Krenvel Health Ltd, 44 Deansgate, Manchester M2 4WB, 0161 946 0274, [email protected].

For example, postal correspondence relating to this policy can be sent to the Manchester address above, marked for the attention of the editorial and data protection contact point, while most privacy queries are handled faster by email. In practice, telephone enquiries on 0161 946 0274 are answered during the published hours of Monday to Friday, 9:00 AM to 5:00 PM GMT, and calls outside those hours can leave a message or follow up by email instead. An edge case is a request that combines a general editorial question with a formal data protection request; in that case, please state clearly in the message that it relates to personal information, so it can be routed and logged against the one-month statutory response period described in section 5. We aim to acknowledge every privacy-related email within five working days, even where the full response takes longer to prepare.