Data controller and privacy contact
Grenova Health Ltd is the data controller for personal information collected through grenova.info and related editorial correspondence. The company is responsible for deciding why information is used and for applying the safeguards described in this policy. Privacy questions can be sent to [email protected] or by post to 15 Clerkenwell Road, London EC1A 1BB.
The privacy lead for Grenova Health Ltd oversees requests, provider reviews and incident records. Grenova does not currently appoint a separate statutory Data Protection Officer because its processing activities do not require one under the applicable UK framework. The privacy lead can be contacted through the same email address and will route a matter appropriately.
1. Scope
This policy explains how Grenova Health Ltd handles information when visitors browse grenova.info, contact the editorial desk or subscribe to occasional reading notes. It applies to the public website and related correspondence. It does not govern external websites linked from our pages. The current version was reviewed on 9 September 2026.
2. Information collected
We may receive an email address when a visitor subscribes, along with the content of an enquiry and the name supplied in a contact form. Basic technical information may be recorded by hosting systems for security and delivery. We do not ask visitors to provide more information than a particular interaction needs.
3. Legal basis
We rely on consent for optional newsletter messages and legitimate interests for site security, response handling and basic administration. Consent can be withdrawn at any time using the contact details below. Withdrawal does not affect earlier processing carried out lawfully.
4. Retention
Newsletter details are retained until withdrawal or 24 months without engagement. General enquiries are usually retained for 12 months after closure. Security logs may remain for up to 90 days unless a longer period is needed for an incident review.
5. Service providers
Hosting, email delivery and security providers may process limited information on our behalf. They receive only the data needed for their service and operate under contractual safeguards. Grenova does not sell personal information.
6. International transfers
Some service providers may process data outside the UK. Where this occurs, Grenova uses an adequacy decision, approved contractual safeguards or another lawful transfer mechanism recognised under UK data protection law.
7. Your rights
Subject to legal limits, you may request access, correction, deletion, restriction or portability, and you may object to certain processing. Send a request to [email protected] with enough detail to identify the request. We may need to verify identity before responding.
8. Complaints
Please contact us first so we can review the concern. You can also contact the Information Commissioner’s Office in the United Kingdom. We aim to acknowledge requests within five working days and respond within one month where the law requires.
9. Children
The site is intended for adults and is not directed at children. We do not knowingly collect information from children. If you believe a child has supplied personal data, contact us so the matter can be reviewed.
10. Changes
Policy changes will be posted on this page with a new review date. Material changes may also be highlighted on the site. The change log records the 9 September 2026 review and the 1 January 2026 publication.
7. Your rights and requests
Depending on the circumstances, UK data protection law may give you rights to access, correct, erase or restrict the use of personal information, and to receive a portable copy of information you provided. You may also object to processing based on legitimate interests and withdraw consent for optional messages. We may need to verify your identity before completing a request so that information is not disclosed to the wrong person.
- Send requests to [email protected] with the subject “Data protection request”.
- Include the email address or correspondence reference connected with the request.
- We aim to acknowledge requests within five working days and respond within one calendar month.
8. Contact forms and correspondence
Information sent through a contact form is used to understand and answer the enquiry, maintain a reasonable correspondence record and protect the website from misuse. Contact messages are normally retained for 12 months after the matter closes, unless a longer period is needed to resolve a continuing issue or establish, exercise or defend a legal position.
Grenova does not use contact messages to create advertising audiences. If an enquiry is forwarded to a named service provider for technical handling, the transfer is limited to the information needed to answer or route the message.
9. Sub-processors and security
Our hosting provider may store website files, access logs and submitted form data. An email delivery provider may process newsletter addresses and message metadata, while a security provider may inspect technical request data to identify malicious traffic. Grenova reviews the role of these providers and requires appropriate confidentiality and security terms.
No internet transmission can be described as completely secure. We use access controls, limited retention and provider safeguards appropriate to the scale and nature of the site, and we investigate credible reports of unauthorised access.
10. Breach handling and complaints
If Grenova becomes aware of a personal data incident, we will assess its scope, contain it where possible and keep an internal record of the response. Where the law requires notification to the Information Commissioner’s Office, we aim to make that assessment promptly and within the applicable 72-hour reporting window. Affected people will be contacted where notification is legally required or otherwise appropriate.
Questions should first be sent to [email protected]. We aim to acknowledge a privacy complaint within five working days and provide a substantive response within 20 working days. You may also complain to the Information Commissioner’s Office if you remain dissatisfied.
11. Children and automated decisions
The website is intended for a general adult audience and is not directed at children. We do not knowingly request information from children for newsletter enrolment or promotional profiling. If a parent or guardian believes that a child has submitted information, they can contact us so that we can review and remove it where appropriate.
Grenova does not use personal information to make solely automated decisions that produce legal or similarly significant effects. Editorial publication decisions are made by people and are not presented as personalised assessments.
12. Changes and review log
This policy was reviewed on 9 September 2026. Changes may be made when the website, providers or applicable UK data protection guidance changes. A revised date will appear on this page and the new wording will apply from publication.
Review log: 9 September 2026 — scope, retention periods, rights handling and provider descriptions reviewed. Earlier versions may be requested where a legal or accountability reason exists.