Last updated: 9 September 2026

Privacy Policy

1. Scope

This policy explains how Drentov Health Ltd handles information when you visit drentov.info, contact the editorial team or subscribe to updates. It applies to the website and its ordinary communications. It does not govern third-party websites linked from our pages. The responsible organisation is Drentov Health Ltd, 51 Granby Street, Leicester LE1 1AA.

2.1 Data controller and privacy contact

The data controller for ordinary website processing is Drentov Health Ltd, 51 Granby Street, Leicester LE1 1AA. Drentov has not appointed a statutory Data Protection Officer because the current processing does not require one; privacy enquiries are handled by the responsible organisation at [email protected]. This contact can explain a processing purpose, receive a rights request or record a concern about a service provider. It is not a substitute for an independent regulator.

2. Information collected

We may receive your name, email address and message when you use a contact form. A newsletter subscription records your email address and consent choice. Basic technical information such as browser type, approximate location and request time may appear in server logs. We do not ask for information about health circumstances through the website.

3. Lawful basis

We use consent for optional newsletter messages and non-essential cookies. We use legitimate interests to keep the site secure, answer correspondence and understand basic service reliability. We use contractual necessity where needed to respond to a request you make. You may withdraw consent at any time by contacting [email protected].

4. Retention

Contact correspondence is normally retained for 24 months after the last meaningful exchange. Newsletter records remain until you unsubscribe, after which suppression information may be retained for 36 months to respect the request. Security logs are normally retained for 90 days. We review retention periods annually and delete information that is no longer needed.

5. Your rights

UK data protection law may give you rights to access, correction, erasure, restriction, objection and portability, depending on the circumstances. To exercise a right, email [email protected] with your request and enough detail to locate the record. We aim to respond within one calendar month. We may request proportionate identity information before releasing personal data.

6. Processors

We use carefully selected hosting, form delivery, email and security providers. They act on documented instructions and receive only information needed for their service. Providers may change as the website develops. A current list can be requested by writing to the address above.

7. International transfers

Some service providers may process information outside the United Kingdom. Where this occurs, we use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism. You can ask for further information about safeguards by email. We do not intentionally publish personal correspondence.

8. Security

We use access controls, encrypted connections and limited retention to reduce avoidable exposure. No online transmission can be described as completely secure. If we become aware of a personal data incident, we will assess it promptly and take steps required by applicable law.

9. Children

The publication is intended for adults and is not directed at children. We do not knowingly collect children’s information. If a parent or guardian believes that information has been submitted, please contact us so that we can review and remove it where appropriate.

10. Complaints

Please contact us first at [email protected] so we can investigate. You may also complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. The ICO provides current contact routes at its official website.

11. Changes

We may revise this policy to reflect legal, technical or editorial changes. The current version is dated 9 September 2026. Previous material changes are recorded here: 1 January 2026, initial publication; 9 September 2026, retention and processor wording reviewed. Continued use after publication means the revised notice is available to read.

10. Data protection impact and safeguards

Drentov assesses privacy risks in proportion to the nature of the website and the information it handles. The site is designed not to invite health details through ordinary forms, which limits the sensitivity of routine correspondence. Access to submitted messages is restricted to people who need it for editorial or administrative work. Technical safeguards include access controls, secure hosting arrangements and periodic review of permissions.

  • a) New tools are reviewed before they receive personal information.
  • b) Higher-risk processing is assessed before it begins.
  • c) Unneeded fields are not requested through forms.

11. Processors and international transfers

Service providers may support hosting, form delivery, email distribution, analytics or embedded maps. Providers are selected according to their role, security information and contractual terms, and they may process limited technical or contact data on Drentov’s instructions. Where information leaves the UK, Drentov looks for an adequacy decision, appropriate contractual safeguards or another lawful transfer mechanism. A current provider list can be requested from [email protected].

  • a) Hosting and security providers may receive server and device information.
  • b) Newsletter providers may receive an email address and subscription status.
  • c) Map and analytics providers operate under their own notices when enabled.

12. Breach response and children’s information

Drentov maintains a proportionate process for identifying, containing and reviewing suspected personal data incidents. If a breach is likely to create a risk to individuals, the relevant authority may be notified within the applicable legal period, normally within 72 hours of awareness where required. Affected people will be contacted without undue delay where the legal threshold is met. The website is intended for adults, and we do not knowingly collect information from children for newsletter or contact purposes.

  • a) Incident records include the date, systems involved and action taken.
  • b) Messages containing unnecessary information are securely restricted and assessed.
  • c) A parent or guardian may contact us about information believed to concern a child.

13. Automated decisions and change history

Drentov does not use personal information to make solely automated decisions that produce legal or similarly significant effects. Basic technical data may support security monitoring, but it is not used to assess a person’s character or eligibility. This policy was reviewed on 9 September 2026 and may be updated when services or legal expectations change. The revision date and a short description of material changes will be shown on this page.

  • a) 9 September 2026 — retention, processor and incident wording reviewed.
  • b) Future changes will be recorded with their effective date.
  • c) You may request clarification about a processing activity by contacting us.

14. Lawful basis and information minimisation

Drentov uses personal information only where a lawful basis applies under UK data protection law. Responding to a message is generally based on taking steps at the person’s request or on legitimate interests in managing editorial correspondence, while optional communications rely on consent. We ask for the minimum information needed for the stated purpose and do not invite detailed personal health histories through ordinary forms. If a message contains information that is not needed, access is limited and the content is assessed for secure deletion.

  • a) Consent can be withdrawn by contacting [email protected].
  • b) Legitimate-interest processing is balanced against individual rights.
  • c) A request can be made without providing extra information beyond what is needed to identify it.

15. Retention schedule and deletion

Routine contact correspondence is normally retained for up to 24 months after the last meaningful exchange, unless a longer period is needed to resolve a matter or meet a legal obligation. Newsletter subscription records are retained while consent remains active and for up to 36 months after an unsubscribe request to maintain suppression records. Security logs are normally retained for up to 90 days, while aggregated statistics may be kept longer because they are not intended to identify individuals. At the end of the relevant period, information is deleted, anonymised or securely restricted.

  • a) Retention periods are reviewed when the purpose ends.
  • b) Legal holds may temporarily prevent deletion.
  • c) Paper correspondence is securely destroyed when no longer required.

16. Rights, complaints and change record

You may ask for access, correction, erasure, restriction, portability or objection where the law provides that right. Send a request to [email protected] or 51 Granby Street, Leicester LE1 1AA and describe the information involved. Drentov aims to acknowledge requests within five working days and respond within one month, subject to lawful extensions for complex requests. If you remain dissatisfied, you may contact the Information Commissioner’s Office, and this policy was reviewed on 9 September 2026 with material future changes dated on this page.

  • a) Identity checks are proportionate and protect against disclosure to the wrong person.
  • b) Requests are recorded so response date and outcome can be tracked.
  • c) 9 September 2026 — lawful basis, retention and rights wording reviewed.