1. Scope
This policy covers stalvel.info, correspondence and ordinary website interactions. Stalvel Health Ltd is based at 15 St Mary Street, Cardiff CF24 3AB. It is written for readers in the United Kingdom and reflects UK GDPR principles.
This policy therefore applies to every page on stalvel.info, to emails sent to [email protected], and to any newsletter subscription a reader chooses to start, but it does not extend to third-party websites that may be linked from an article. For example, if a reader follows a source link to a government website or a research publisher, that external site has its own separate privacy practices which this policy does not cover. Stalvel Health Ltd is registered in England and Wales under company number 2024/318962 and is registered for VAT under number GB318962841, and it acts as the data controller for the personal information described in this policy. Because the company is based in Cardiff and serves a UK readership, this policy is written primarily with UK GDPR and the Data Protection Act 2018 in mind, though the same practical safeguards apply to any reader regardless of location. A practical consequence of this scope is that a reader based in another country can still contact the team using the same address and expect the same handling standards described below.
- a) This policy covers the public pages of stalvel.info; it does not cover services operated by third parties, such as an external analytics provider's own website.
- b) Where an article links to an external source, that source is outside the scope of this policy and readers should check the destination site's own privacy notice.
- c) The registered company details above can be used to verify Stalvel Health Ltd with Companies House if a reader wishes to confirm the identity of the data controller.
2. Information collected
We may receive a name, email address and message when a reader contacts the team. Server logs can include an IP address, browser type, requested page and timestamp. Newsletter details are collected only when a reader submits the subscription field.
For example, a reader who uses the contact form will typically provide their name, an email address for a reply, and a short message describing their query, and no further personal details are requested beyond what is needed to respond. Server logs of this kind are generated automatically by standard web hosting infrastructure and are mainly used to keep the site secure and to assess technical problems, such as an unusually high number of requests from a single source. The IP address recorded in these logs is not combined with a reader's name or email address to build an individual browsing profile. In practice, no financial information, payment card details or government identification numbers are collected anywhere on stalvel.info, since the site does not process orders or payments. An edge case worth noting is a reader who includes extra personal information voluntarily in a free-text message; that information is treated with the same confidentiality as the rest of the message and is not used for any purpose beyond answering the query.
- a) Contact form data: name, email address, message content, and the date and time of submission.
- b) Automatic technical data: IP address, browser type and version, device type, referring page and requested URL, retained within standard hosting logs.
- c) Newsletter data: email address only, collected solely when a reader actively completes the subscription field described on the homepage.
3. Lawful basis
Correspondence is handled on the basis of legitimate interests or steps requested by the reader. Optional newsletter delivery relies on consent. Necessary technical storage is used to provide a secure, functioning website.
For example, when a reader emails a question about an article, Stalvel relies on its legitimate interest in operating a functioning editorial contact channel, balanced against the reader's own interest in receiving a reply, and no further use of that message is made beyond answering it. Where newsletter delivery is concerned, the lawful basis is consent under UK GDPR Article 6(1)(a), which means a reader can withdraw that consent at any time without needing to give a reason, and doing so does not affect the lawfulness of any processing carried out before withdrawal. Necessary technical storage, such as the cookie that remembers a reader's cookie-banner choice, is processed under the strictly necessary exemption in the Privacy and Electronic Communications Regulations 2003, which does not require separate consent. A practical consequence of this structure is that different categories of personal information are processed on different legal grounds, and a reader who objects to one basis, such as legitimate interests, can raise that objection without it automatically affecting a separate basis, such as consent for the newsletter.
- a) Legitimate interests: used for handling contact-form enquiries and maintaining basic website security logs.
- b) Consent: used only for the optional newsletter subscription, and withdrawable at any time using the unsubscribe link or by emailing [email protected].
- c) Strictly necessary processing: used for the cookie-consent record described in the Cookie Policy, which does not require a separate consent step.
4. Retention
General enquiries are normally retained for 12 months. Editorial correction records may be retained for 24 months. Subscription records remain until withdrawal, then are removed within 30 days, subject to a minimal suppression record.
For example, an email asking a general question about an article is normally deleted from the team's inbox and any related record around twelve months after the last reply, unless a shorter or longer period is needed for a specific reason such as an ongoing correction discussion. Editorial correction records, such as a note that a particular figure in an article was updated following reader feedback, are kept for up to twenty-four months so the editorial team can track how a page has changed over time. A practical consequence of the newsletter retention approach is that a reader's email address is removed from the active mailing list within thirty days of unsubscribing, but a small suppression record, containing only the email address and the date it opted out, may be kept indefinitely to make sure that address is not re-added by mistake. Server logs containing IP addresses are typically rotated automatically by the hosting provider and are not normally kept beyond 90 days. These periods are reviewed from time to time and may be shortened where a longer period is found not to be necessary.
- a) Contact-form enquiries: approximately 12 months from the last message in the thread.
- b) Editorial correction and fact-check notes: approximately 24 months from the date of the correction.
- c) Newsletter subscription: active for the duration of the subscription, removed from the live list within 30 days of unsubscribing, with a minimal suppression record kept to honour the opt-out.
5. Rights
Readers can request access, correction, deletion, restriction, portability or objection. Requests can be sent to [email protected] with enough detail to locate the relevant record.
For example, a reader who wants to know what information Stalvel holds about them can send a request to [email protected], describing roughly when they last contacted the site so the relevant record can be located efficiently. The team aims to acknowledge a rights request within 5 working days and to provide a full response within one calendar month, as set out under UK GDPR, extendable by a further two months for a complex request, in which case the reader will be told the reason for the extension. A practical consequence of the right to object is that a reader who does not want their contact-form message used even for the limited purpose described in section 3 can ask for it to be deleted, and the team will do so unless it needs to keep a minimal record for a legal reason. If a reader is not satisfied with how a request has been handled, they have the right to complain to the Information Commissioner's Office, the UK's independent data protection regulator, at ico.org.uk, in addition to raising the matter directly with Stalvel first. An edge case worth noting is a request that cannot be verified, for example an email address that does not match any record on file; in that situation the team may ask for reasonable additional information before acting, purely to avoid disclosing information to the wrong person.
- a) Access and portability requests: acknowledged within 5 working days, completed within 1 calendar month where possible.
- b) Correction and deletion requests: actioned as soon as reasonably practicable once the relevant record is confirmed.
- c) Complaints that cannot be resolved directly with Stalvel may be referred to the Information Commissioner's Office (ICO) as the supervisory authority for the United Kingdom.
6. Processors
Hosting, email delivery and security providers may process limited information on our instructions. They receive only what is needed for the stated service and are expected to maintain appropriate safeguards.
For example, the website is hosted using infrastructure provided by a mainstream cloud hosting provider, outbound email from the contact form and newsletter is delivered through a standard transactional email service, and basic security filtering is provided by the hosting stack's own protection tools; none of these providers are permitted to use reader information for their own marketing purposes. Where a processor stores or transfers information outside the United Kingdom or the European Economic Area, for example where a hosting provider operates data centres in the United States, Stalvel relies on that provider's Standard Contractual Clauses or an equivalent UK-recognised safeguard to keep the transfer lawful under UK GDPR's international transfer rules. A practical consequence of using established third-party processors is that Stalvel does not build or maintain its own servers, which reduces certain risks but means the team depends on each provider's own security certifications and incident-notification procedures. Each processor is engaged under a data processing agreement that limits its use of information strictly to providing the contracted service, such as delivering an email or serving a web page, and prohibits it from retaining that information for longer than necessary to do so. If a processor changes materially, for example if the hosting provider is replaced, this policy will be updated to reflect the new arrangement.
- a) Hosting and infrastructure providers process technical logs and page-delivery data only.
- b) Email delivery providers process the reader's email address and message content solely to send a reply or a newsletter issue.
- c) Any transfer of information outside the UK or EEA is only made where a recognised safeguard, such as Standard Contractual Clauses, is in place.
7. Cookies
Session storage supports basic preferences. The consent choice may be retained for 12 months. Optional analytics, if enabled in the future, would only load after a reader actively accepts it, and this page together with the Cookie Policy would then name the specific tool and its retention period before it is used.
For example, the cookieChoice value described on the Cookie Policy page does not identify a reader by name; it simply records whether the cookie banner was accepted or rejected, so the banner does not need to be shown again on every visit. No advertising or cross-site tracking cookies are set by stalvel.info at this time, and if that were to change, this policy and the Cookie Policy would both be updated in advance and reader consent would be requested through the same banner mechanism. A practical consequence of this approach is that a reader who rejects cookies can still read every article on the site; the only effect of rejecting is that the consent prompt may reappear on a later visit. Full detail on individual cookie names, purposes and lifespans is maintained on the separate Cookie Policy page, which forms part of this overall privacy approach. This Privacy Policy was last reviewed on 24 September 2026; any future revision affecting the categories of information described above will be reflected in an updated review date on this page and, where the change is significant, readers will be notified through a notice on the homepage.