1. Scope
This policy explains how Brelvan Health Ltd handles information collected through brelvan.info, newsletter forms and direct correspondence. It applies to visitors in the United Kingdom and readers elsewhere who choose to contact us.
Brelvan Health Ltd (company number 2024/134708, VAT number GB134708562, registered office at 22 Bold Street, Liverpool L1 8DQ) is the data controller for the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018. This policy covers the homepage, the six published articles, the about, contact and disclaimer pages, and the newsletter sign-up form, together with any correspondence sent to [email protected] or 0151 946 0763. It does not cover third-party websites linked from our articles, each of which publishes its own separate privacy notice. Readers based outside the United Kingdom, including those in the European Union, are welcome to contact us and are treated under the same standards described here, since Brelvan does not currently operate country-specific policies. Where this policy refers to "we", "us" or "Brelvan", it means Brelvan Health Ltd acting through its editorial team based in Liverpool.
- (a) This policy sits alongside, and should be read together with, the separate Cookie Policy and the Disclaimer published on this website.
- (b) Where a reader contacts us from outside the UK, we still apply UK GDPR standards as a matter of consistent practice, even where local law may differ.
- (c) Any future addition of new forms, analytics tools or newsletter providers will be reflected in a revised version of this page before it takes effect.
2. Information collected
We may receive an email address, name and message when a reader submits a form. Standard server records may include an IP address, browser type, requested page and timestamp.
For the newsletter form, the only field collected is an email address, submitted through the form described on the homepage; no name, date of birth or other personal detail is requested at sign-up. For the contact form, we ask for a name, an email address and a free-text message, which is used solely to respond to the enquiry raised. Server-level logs generated automatically by our hosting infrastructure typically include the visiting IP address, browser and operating system identifiers, the page requested, the date and time of the request, and the referring page where applicable; these are standard web server records rather than information a reader actively submits. We do not knowingly collect any special category data, such as information about health conditions, and we ask readers not to include such detail in a contact form message beyond what is necessary to describe a general query about an article. Brelvan does not operate any checkout, account login or payment system, so no payment card or financial account information is collected through this website.
- (a) Newsletter data collected: email address only, plus the date of sign-up and the current subscription status (subscribed or unsubscribed).
- (b) Contact form data collected: name, email address, message text and the date the message was sent.
- (c) Automated server records: IP address, browser and device identifiers, requested URL and timestamp, retained under the schedule described in Section 4.
3. Legal basis
We rely on consent for optional newsletter messages, contract-related necessity for correspondence you request, and legitimate interests for site security and basic service administration.
Consent under Article 6(1)(a) UK GDPR is the basis for newsletter emails; a reader who signs up can withdraw that consent at any time by using the unsubscribe link included in every newsletter issue, and doing so stops future messages without affecting messages already sent. Where a reader submits the contact form to ask a question, we rely on legitimate interests under Article 6(1)(f) to read and reply to that message, since responding to a query that has been voluntarily raised is a reasonable and proportionate use of the information supplied. Legitimate interests also cover basic server security logging, since detecting and preventing misuse of the website protects both Brelvan and its readers. Where a legal obligation applies, for example a request from a UK regulatory authority made through the proper legal channel, we may rely on Article 6(1)(c) to the extent strictly necessary. We do not use profiling or automated decision-making that produces a legal or similarly significant effect on any reader.
- (a) Consent (newsletter): withdrawable at any time via the unsubscribe link or by emailing [email protected].
- (b) Legitimate interests (contact form replies and security logging): balanced against reader privacy and limited to what is proportionate.
- (c) Legal obligation: used only where a lawful request from a UK authority requires disclosure of specific records.
4. Retention
Newsletter records remain until unsubscribe. General enquiries are normally retained for 24 months. Security records are normally retained for 90 days unless a longer period is required to investigate misuse.
In practical terms, an email address supplied for the newsletter is kept for as long as the subscription remains active, and is deleted from our active mailing list within 30 days of an unsubscribe request being processed, subject to a short suppression record kept to honour the opt-out itself. A contact form message and any reply thread connected to it is normally deleted or anonymised 24 months after the last exchange, unless a shorter period is requested by the reader or a longer period is required to respond to a related follow-up query. Server-level security logs are retained for approximately 90 days on a rolling basis, which is a period consistent with common UK hosting security practice, extended only where a specific investigation into misuse, such as attempted unauthorised access, is ongoing. Once a retention period expires, records are deleted or irreversibly anonymised rather than archived indefinitely. Where a reader asks us to delete information earlier than these default periods, we will do so unless a legal reason, such as an ongoing complaint investigation, requires the information to be kept.
- (a) Newsletter: retained while subscribed, deleted within 30 days of unsubscribe, subject to a minimal suppression record.
- (b) Contact enquiries: retained for approximately 24 months from the last message in the thread.
- (c) Security logs: retained for approximately 90 days, extended only for an active misuse investigation.
5. Your rights
You may ask for access, correction, deletion, restriction or a portable copy where applicable. Email [email protected] and include enough detail for us to understand your request.
Under the UK GDPR, readers also have the right to object to processing based on legitimate interests, and the right to withdraw consent at any time where consent is the basis being used, such as the newsletter. To protect readers, we may ask for reasonable information to confirm identity before acting on a request, for example confirming the email address associated with a newsletter subscription. We aim to respond to a rights request within one calendar month of receiving it, as required by the UK GDPR, and will explain if a complex request needs up to two further months, in which case we will tell the requester why within the first month. There is normally no charge for a straightforward request; a reasonable administrative fee may apply only for a manifestly unfounded, excessive or repeat request, which is expected to be rare in practice. If a request cannot be fulfilled, for example because a message needs to be kept to demonstrate that a prior complaint was resolved, we will explain the specific reason in our reply.
- (a) Access and portability: a copy of the personal information we hold, provided in a common electronic format on request.
- (b) Correction and deletion: inaccurate information can be corrected, and information no longer needed for the purpose collected can be deleted.
- (c) Restriction and objection: processing can be paused while a dispute is resolved, or objected to where based on legitimate interests.
6. Processors
Hosting, email delivery and analytics suppliers may process limited information on our behalf under contractual safeguards. We do not sell reader information.
Our website hosting provider stores the files that make up brelvan.info and generates the server-level logs described in Section 2, under a data processing agreement that limits its use of that information to providing the hosting service itself. A separate email delivery service is used to send newsletter issues to subscribers who have opted in, and that provider processes only the email address supplied at sign-up, together with basic delivery status information such as whether a message bounced. At present no third-party analytics platform is active on this website, consistent with the position described in the Cookie Policy; if that changes, this policy and the Cookie Policy will be updated before any such tool is switched on. Each processor we use is required by contract to process information only on our instructions, to apply appropriate security measures, and to delete or return information once the relationship ends. None of our processors are permitted to use reader information for their own independent marketing purposes, and Brelvan does not sell, rent or otherwise trade reader information to any third party for commercial gain.
- (a) Hosting provider: stores website files and server logs under a written data processing agreement.
- (b) Email delivery provider: sends newsletter issues and processes subscriber email addresses solely for that purpose.
- (c) Analytics: not currently active; any future analytics provider will be named here before deployment.
7. Cookies
Our consent banner records a cookieChoice preference. Session and analytics technologies are described in the Cookie Policy and are used only where their stated conditions apply.
The cookieChoice preference cookie is stored for up to 180 days and simply records whether a reader selected Accept All or Reject in the banner, so that the banner does not need to reappear on every visit; it does not identify a specific individual. A separate session-level record may be created by our hosting infrastructure to support secure page delivery, and this typically expires within 24 hours or when the browser session ends, whichever comes first. As set out in the Cookie Policy, no optional analytics cookies are currently active on brelvan.info, and none will be activated without first updating both that policy and this section to name the provider, purpose and retention period involved. Readers can withdraw cookie consent at any time by clearing cookies in their browser settings or by selecting Reject in the banner on a future visit, which may cause preference cookies to be reset. Full detail on each cookie category, including names and approximate lifespans, is maintained in the standalone Cookie Policy rather than duplicated here, to avoid the two documents falling out of step with one another.
- (a) cookieChoice: up to 180 days, records Accept All or Reject only, no personal identifier attached.
- (b) Session cookie: expires within 24 hours or at the end of the browser session.
- (c) Analytics cookies: none currently active; see the Cookie Policy for the current position.
8. International transfers
Some suppliers may operate outside the UK. Where this occurs, we use an adequacy decision, approved contractual clauses or another lawful safeguard before information leaves the UK.
Where a hosting or email delivery provider stores information on servers located outside the United Kingdom, for example within the European Economic Area or in a country covered by a UK adequacy regulation, we rely on that adequacy status where it applies, since the UK government has recognised the EEA as providing an adequate level of protection. Where a transfer is made to a country without a UK adequacy decision, we require the receiving processor to sign the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, which impose contractual obligations equivalent to UK GDPR protections on the recipient. We review the location of our processors periodically as part of routine supplier management, and any material change to where information is stored will be reflected in an update to this section. No reader information is knowingly transferred to a jurisdiction with materially weaker data protection standards without one of these safeguards in place. Readers who would like more detail on the specific safeguard used for a particular processor can request this by emailing [email protected].
- (a) EEA-based processors: covered by the UK's adequacy regulations for the European Economic Area.
- (b) Other jurisdictions: covered by the IDTA or the UK Addendum to the EU Standard Contractual Clauses.
- (c) Supplier locations are reviewed periodically, with this section updated to reflect any material change.
9. Complaints
If you are unhappy with how your information has been handled, contact [email protected] first so we can try to resolve the matter directly. You may also lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent regulator for data protection.
When a complaint is raised with us directly, we aim to acknowledge it within five working days and to provide a substantive response within 28 days, which allows time to investigate the specific handling concern raised. Most concerns can be resolved at this stage, for example by correcting a record, confirming that a deletion request has been actioned, or clarifying why a particular retention period applies to a given case. Where a reader remains unsatisfied after contacting us, or prefers to raise the matter independently, the ICO can be contacted at ico.org.uk, by telephone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. There is no requirement to contact Brelvan before contacting the ICO, although doing so first often allows a quicker resolution for straightforward issues. We keep an internal record of complaints received about data handling, separate from ordinary contact enquiries, so that recurring issues can be identified and addressed through a change to our practices where appropriate.
- (a) Direct complaint to Brelvan: acknowledged within five working days, substantive response within 28 days.
- (b) ICO complaint: can be raised at any time, independently of whether Brelvan has already responded.
- (c) Recurring issues identified through complaint records may lead to a change in this policy, reflected in a future dated revision.
10. Changes
This policy was last reviewed on 24 September 2026 and may be updated as the platform or applicable law changes. Material changes will be reflected on this page with an updated review date.
We expect to review this policy at least annually, or sooner where a change to UK data protection law, a new supplier, or a new feature on the website makes an update necessary. Where a change is minor, such as a correction to a phone number format, the review date is updated without a separate announcement. Where a change is material, for example the introduction of an analytics tool or a change to a retention period described in Section 4, we will note the nature of the change in the page itself and, where practical, highlight it on the homepage or in a newsletter issue so that regular readers are aware. A reader who wants to understand what changed between two versions of this policy can email [email protected], and we will describe the substantive differences between the version they read previously and the current version. The version currently displayed on brelvan.info always takes precedence over any earlier printed or saved copy.
- (a) Routine review cadence: at least once every 12 months, or sooner if required by a change in law or practice.
- (b) Minor changes: reflected by an updated review date without separate notice.
- (c) Material changes: flagged where practical via the homepage or newsletter, with an explanation available on request.