1. Scope
This policy explains how Kaltvel Health Ltd, 33 Corn Street, Bristol BS1 4ER, handles information when you visit kaltvel.info, contact the editorial team or subscribe to the newsletter. It applies to visitors in the United Kingdom and describes our approach under the UK GDPR and the Data Protection Act 2018. It covers every page on the domain, including article pages, the contact form and the newsletter sign-up box, and it applies regardless of the device or browser used to access the site. This policy does not cover third-party websites that Kaltvel may link to for editorial context, since those services operate under their own separate privacy terms. If you access kaltvel.info from outside the United Kingdom, the same standards apply to your visit, and we do not offer a region-specific version of this policy. Where this policy refers to "we", "us" or "Kaltvel", it means Kaltvel Health Ltd, registered at the Bristol address above, acting as the data controller for the purposes described in this document.
- a) This policy applies to casual browsing of articles as well as to active use of the contact form or newsletter sign-up.
- b) It does not apply to information you may voluntarily share with us through channels not operated by Kaltvel, such as a third-party social media platform.
- c) Where local law in a reader's country provides additional protections beyond the UK GDPR, this policy does not attempt to override those protections.
2. Information collected
We may receive an email address when you subscribe, plus your name, email and message when you use the contact form. Technical logs may include IP address, browser type, device information and requested pages. We do not ask readers to submit private health details. For example, if a reader includes a personal health detail voluntarily within a contact form message, that detail is treated with the same confidentiality as the rest of the message, but we do not request or expect readers to share such information with us. Technical logs are generated automatically by standard web server software and are primarily used to detect and prevent abuse, such as automated spam submissions through the contact form. We do not use hidden tracking pixels, browser fingerprinting or third-party advertising identifiers to build a profile of individual readers.
- a) Newsletter sign-up collects only an email address, unless a reader chooses to add further detail in an optional field.
- b) Contact form submissions collect a name, an email address and the message content typed by the reader.
- c) Server logs, including IP address and browser type, are retained separately from newsletter and contact records and are not merged with them.
3. Legal bases
We rely on consent for optional newsletters and non-essential cookies, contractual necessity for responding to a requested service, and legitimate interests for security and basic site administration. You may withdraw consent at any time by contacting [email protected]. Where consent is the legal basis, for example for the newsletter, withdrawing it does not affect the lawfulness of any processing carried out before the withdrawal. Where legitimate interest is the basis, such as maintaining basic security logs, we have considered that this processing is proportionate and does not override a reader's own privacy interests, and readers may object to this processing by contacting us with their specific concern. Contractual necessity applies narrowly, for instance when a reader asks a question through the contact form and we need their email address to reply; we do not treat browsing the site itself as creating a contract.
- a) Consent-based processing: newsletter sign-up and any non-essential cookie set only after the cookie banner is accepted.
- b) Contract-based processing: replying to a specific question or request submitted through the contact form.
- c) Legitimate interest processing: server security logs, fraud prevention and basic site administration, always balanced against reader privacy.
4. Retention periods
Newsletter records are retained until you unsubscribe, then removed within 30 days. Contact messages are normally retained for 12 months after the last exchange. Security logs are retained for up to 90 days. Accounting records, where applicable, are retained for the period required by UK law. In practice, this means a reader who unsubscribes from the newsletter today will have their email address removed from the active mailing list within 30 days, subject to a short technical delay while the change propagates through our email delivery provider. Contact messages are kept for 12 months so the editorial team can refer back to a previous conversation if a reader writes again about the same topic, after which they are permanently deleted from our systems. Where UK tax or company law requires records to be kept for longer, such as invoices connected to any commercial activity, those records are retained for the statutory period, which is typically six years under UK tax legislation, and are kept separately from general marketing or contact data.
- a) Newsletter data: retained while subscribed, deleted within 30 days of unsubscribing.
- b) Contact form data: retained for 12 months after the last message in a conversation, then deleted.
- c) Security and server logs: retained for a rolling 90-day window and then automatically purged.
- d) Statutory financial records, where they exist: retained for the period required by UK law, typically up to six years.
5. Your rights
You may ask for access, correction, erasure, restriction, portability or objection. Send a clear request to [email protected] or 33 Corn Street, Bristol BS1 4ER. We may request reasonable identity confirmation and aim to respond within one calendar month. If a request is particularly complex, or if we receive several requests from the same reader in a short period, we may extend our response time by a further two months, and we will explain the reason for any extension within the first month. Identity confirmation may involve asking a reader to confirm the email address or details previously used to contact us, so that we do not disclose information to the wrong person. There is normally no fee for a straightforward request, although UK GDPR permits a reasonable administrative fee for requests that are manifestly unfounded, excessive or repetitive.
- a) Right of access: request a copy of the personal data we hold about you.
- b) Right to rectification: ask us to correct inaccurate or incomplete information.
- c) Right to erasure: ask us to delete your data where there is no lawful reason to keep it.
- d) Right to restriction, portability and objection: available in specific circumstances set out in the UK GDPR, and we will explain which apply when you contact us.
6. Processors
We use hosting, email delivery, analytics and security providers where needed to operate the site. Providers receive only information necessary for their service and are expected to protect it through appropriate contractual measures. For example, our hosting provider processes server logs and page requests to keep the site online, while our email delivery provider processes newsletter and contact addresses solely to send the messages a reader has requested. We enter into data processing agreements with each provider that require them to use the information only for the agreed purpose, to apply appropriate technical and organisational security measures, and to delete or return data at the end of the arrangement. We periodically review the providers we use to confirm they remain appropriate for the volume and sensitivity of information involved, and we do not sell or rent reader information to any third party for their own marketing purposes.
- a) Hosting and infrastructure providers process server logs and technical data needed to deliver the website.
- b) Email delivery providers process newsletter and contact addresses solely to send requested communications.
- c) Security providers, where used, process technical data to detect and prevent abuse such as automated form submissions.
7. International transfers
Some providers may process information outside the United Kingdom. Where this occurs, Kaltvel relies on an adequacy decision, the UK International Data Transfer Agreement or another lawful safeguard. For example, where a provider is based in a country that the UK government has formally recognised as offering an adequate level of protection, no additional safeguard is required beyond that adequacy finding. Where a provider is based in a country without an adequacy decision, we require a signed International Data Transfer Agreement, or an equivalent recognised mechanism, before any information is transferred there. We review the safeguards in place with each processor periodically and will update this section if the providers we use, or their location, change materially.
8. Security
We use access controls, encrypted connections and limited retention. No online service can promise absolute security, so readers should avoid placing sensitive personal details in open forms. In practical terms, this means the site is served over an encrypted HTTPS connection, administrative access to backend systems is restricted to a small number of authorised individuals, and passwords or credentials used to manage the site are not shared over unencrypted channels. If we become aware of a security incident that is likely to result in a risk to readers' rights and freedoms, we will assess whether it must be reported to the Information Commissioner's Office within 72 hours, as required by the UK GDPR, and will notify affected individuals directly where the risk is high.
9. Children
The site is intended for adults and general readers. We do not knowingly collect information from children. If a parent or guardian believes information has been submitted, contact us for review. Kaltvel does not knowingly permit children to subscribe to the newsletter or submit the contact form, and any such submission identified as coming from a child will be removed once we become aware of it. Parents or guardians who believe a child has provided personal information through the site can request its removal at any time using the contact details in this policy, and we will act on that request promptly without requiring extensive justification.
10. Complaints
Please contact us first so we can investigate. You may also complain to the Information Commissioner's Office, the UK supervisory authority, through ico.org.uk. We aim to acknowledge a complaint within five working days and to provide a substantive response within one calendar month, in line with the timescales we apply to other rights requests under this policy. If a reader remains unsatisfied after our internal review, they are free to escalate the matter to the ICO at any time, and doing so does not require our permission or prior sign-off. We treat every complaint about how personal information is handled as an opportunity to review and, where appropriate, improve our internal processes.
11. Changes
This policy was reviewed on 24 September 2026. Earlier versions may be requested by email. Material changes will be shown on this page with a new review date. Minor edits, such as correcting a typographical error or updating a contact detail, may be made without changing the review date shown at the top of the page, while substantive changes to how information is collected, used or retained will always be accompanied by an updated date and, where appropriate, a brief summary of what has changed. Readers who want to compare an earlier version of this policy against the current one can request a copy of the previous version by writing to [email protected], and we retain at least the immediately preceding version for this purpose.