Your information
Privacy Policy
1. Scope
This policy explains how Grenvol Health Ltd handles information connected with grenvol.info. It applies to visitors, newsletter subscribers and people who contact the editorial team. The controller is Grenvol Health Ltd at 56 Buchanan Street, Glasgow G1 1AA.
2. Information collected
We may receive an email address when someone subscribes, and name, email and message content when someone uses the contact form. Server logs may include an IP address, browser type, requested page and time. We do not ask for sensitive personal details through the website.
3. Legal basis
We rely on consent for optional newsletter messages and selected cookies. We rely on legitimate interests for security, basic operation and responding to enquiries. Where a legal obligation applies, processing is based on that obligation.
4. Retention
Newsletter details remain until unsubscribe or twelve months after the last meaningful interaction. Contact messages are normally retained for 24 months. Security logs are normally retained for 90 days. We may retain a limited record of a rights request for up to six years where needed to demonstrate compliance.
5. Your rights
You may request access, correction, deletion, restriction, portability or objection where the law provides. You may withdraw consent at any time. Write to [email protected] and include enough detail for us to locate your request; we aim to respond within one month.
6. Processors
We may use hosting, email delivery, security and analytics providers acting under written instructions. Providers receive only information needed for their service. We do not sell personal information.
7. International transfers
Some suppliers may process information outside the United Kingdom. Where that occurs, we use an adequacy decision or appropriate contractual safeguards where required, and we assess the transfer context.
8. Cookies
Session cookies support basic operation, analytics cookies help us understand visits where consent is provided, and preference cookies remember choices. Lifespans and purposes are described in the Cookie Policy.
9. Children
This website is written for adults and is not directed at children. If a young person has submitted information, a parent or guardian may contact us to discuss deletion.
10. Complaints
Please contact us first at [email protected]. You may also complain to the Information Commissioner’s Office in the UK if you believe your information rights have been infringed.
11. Security
We use access controls, encrypted connections and proportionate supplier checks. No online service can promise absolute security, so please avoid sending confidential details through general forms.
12. Changes
Revision history: 9 September 2026, policy reviewed; 1 January 2026, initial publication. The current version is always displayed on this page.
8. Data minimisation and accuracy
Grenvol collects information that is reasonably needed to operate the website, answer enquiries and manage optional communications. We do not ask visitors to provide unnecessary personal details in a contact message. Please tell us if your email address or other information changes so that our records can be kept accurate. We may ask for clarification before changing a record where the request is unclear.
- a) Provide only the information needed for the stated purpose.
- b) Avoid including confidential details in a general enquiry.
- c) Tell us which record or message needs correction.
9. Sub-processors and service providers
Service providers may include a web-hosting provider, an email delivery provider, a form-handling service, a security service and a privacy-conscious analytics provider where enabled. Their access is limited by contract, configuration and the task they perform for Grenvol. Provider names and functions may change as the site develops, and material changes will be reflected in this notice where appropriate. We do not authorise providers to use submitted information for their own unrelated marketing.
- a) Hosting providers store pages, logs or submitted messages needed to deliver the site.
- b) Email providers transmit newsletter messages and service correspondence.
- c) Security providers may process technical identifiers to identify abusive traffic.
10. International transfers
Some suppliers may process information outside the United Kingdom. Where this occurs, Grenvol expects the supplier to use an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful safeguard. The transfer mechanism depends on the service and the destination. Visitors may request general information about the safeguards used for a particular processing activity.
11. Data protection impact and risk review
We consider privacy risks when introducing a new form, measurement tool, embedded service or email workflow. A documented impact assessment may be used where a proposed activity could create a higher risk to individuals. The assessment considers purpose, necessity, data categories, access controls, retention and transfer arrangements. If risks cannot be reduced appropriately, the activity will not be introduced in its proposed form.
12. Breach response and complaints
Grenvol maintains a process for identifying, containing and reviewing suspected personal-data incidents. Where the law requires notification to the Information Commissioner’s Office, we aim to assess the matter without undue delay and within the applicable 72-hour period. People affected will be contacted where notification is required or appropriate. Privacy questions should be sent to [email protected]; we aim to acknowledge them within five working days and respond within one month, subject to lawful extensions.
If you remain dissatisfied, you may contact the Information Commissioner’s Office through its UK website or helpline. A complaint can be raised without first waiting for a response from Grenvol, although contacting us first may help resolve a factual issue quickly. We keep a limited record of the concern and outcome for up to six years where needed for accountability. This record is access-controlled and is not used for unrelated marketing.
13. Children and automated decisions
The website is intended for a general adult audience and is not designed to knowingly collect information from children. If a parent or guardian believes a child has submitted information, they may contact [email protected] so that the matter can be reviewed. Grenvol does not use personal information for solely automated decisions that produce legal or similarly significant effects. Any future change to that position would be explained before the relevant activity begins.
This policy was reviewed on 9 September 2026. Changes will be dated on this page and will explain the principal reason for the update. The previous version may be retained internally for governance purposes.
8. Data accuracy and minimisation
Grenvol seeks to collect only information reasonably needed to operate the website, answer correspondence and manage optional communications. Please avoid placing sensitive personal details in a general contact message. If an email address or other information changes, tell us so the record can be corrected. We may ask for clarification where a request relates to more than one record.
- a) Provide the minimum information needed for the stated purpose.
- b) Identify the page, form or message connected with a correction.
- c) Do not send another person’s information without a lawful reason.
9. Named service categories and processors
Depending on the features enabled, Grenvol may use a hosting provider, an email delivery provider, a form-handling service, a security provider and an analytics provider. These suppliers process information under instructions and are expected to apply appropriate confidentiality and security measures. Hosting may handle server logs, email services may transmit newsletter messages, and security services may review technical identifiers connected with abusive traffic. We do not authorise processors to use submitted information for unrelated marketing.
Provider names and configurations may change as the site develops. A request for general processor information can be sent to [email protected], and we will explain the relevant category and purpose where disclosure is appropriate. Supplier access is limited to the information needed for the contracted task. Public embedded services, such as maps, may process information under their own notices once loaded.
10. International transfers
Some suppliers may process information outside the United Kingdom. Where this occurs, Grenvol expects the supplier to rely on an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful safeguard. The mechanism depends on the service, destination and data involved. Visitors may ask for general information about the safeguards used for a particular processing activity.
11. Data protection impact reviews
Grenvol considers privacy risks before introducing a new form, tracking feature, embedded service or email workflow. A documented Data Protection Impact Assessment may be prepared where a proposed activity could create a higher risk to individuals. The review considers purpose, necessity, data categories, access permissions, retention, security and international transfers. If material risks cannot be reduced appropriately, the proposed activity will be redesigned or not introduced.
12. Security incidents and notification
Grenvol maintains a process for identifying, containing, recording and reviewing suspected personal-data incidents. Where the law requires notification to the Information Commissioner’s Office, we aim to assess the matter without undue delay and within the applicable 72-hour period. People affected will be contacted where notification is required or appropriate, using the contact details available to us. Technical logs relating to an incident may be retained for up to six years where needed to establish what happened and demonstrate accountability.
13. Minors and automated decision-making
The website is intended for a general adult audience and is not designed to knowingly collect information from children. If a parent or guardian believes that a child has submitted information, they may contact [email protected] so the matter can be reviewed and the information assessed for removal. Grenvol does not use personal information for solely automated decisions that produce legal or similarly significant effects. Any material change to that position would be described in an updated notice before the relevant activity begins.
14. Complaints and change log
Privacy questions should be sent to [email protected] or Grenvol Health Ltd, 56 Buchanan Street, Glasgow G1 1AA. We aim to acknowledge a request within five working days and respond within one month, subject to lawful extensions for complex or multiple requests. If a person remains dissatisfied, they may contact the Information Commissioner’s Office through its UK channels. This policy was reviewed on 9 September 2026, and future revisions will record the effective date, affected sections and principal reason for the change.