Food supplement. Not a medicine. Sold by Drenvek Health Ltd, Leeds, United Kingdom. · Disclaimer

UK GDPR

Privacy Policy. Clear handling of information.

This policy explains how Drenvek Health Ltd handles information connected with drenvek.info.

1. Scope and controller

This policy applies to drenvek.info, its contact forms, newsletter sign-up and ordinary correspondence. The controller is Drenvek Health Ltd, 27 Albion Street, Leeds LS1 4DY. You can contact [email protected] with questions about personal information. The policy is written for UK GDPR requirements and related UK data law.

Drenvek Health Ltd is registered in England and Wales under company number 2024/092634 and is registered with the Information Commissioner's Office (ICO) as a data controller for the processing described in this policy. This policy does not apply to third-party websites we link to, even where an article references a public body such as the NHS, and readers should review the privacy notice of any external site before submitting information there. If we introduce a new feature that collects information not described here, for example a comments feature or a reader survey, we will update this policy before that feature goes live and will note the change in the revision log at the foot of this page. Where a reader is under eighteen, we ask that a parent or guardian assist with any correspondence, since our editorial content and forms are designed with an adult UK audience in mind.

2. Information collected

We may receive a name, email address and message when you use a form. Technical information such as browser type, approximate location, IP address and page requests may be recorded by hosting or security services. We do not ask readers to submit sensitive personal stories through a public form. Please keep messages proportionate.

For example, the contact form on our Contact page asks only for a name, an email address and a free-text message, and the newsletter sign-up form on the homepage asks only for an email address; neither form requests a postal address, date of birth or any special category of personal information under Article 9 of the UK GDPR. Technical logs such as IP address, browser type and page requests are retained by our hosting and security providers primarily to protect the website against abuse, such as automated form submissions, and are not used by Drenvek to build an individual profile of a reader's health interests. If a reader nonetheless includes sensitive information in a free-text message, for example details about a personal health condition, that information is treated with the same confidentiality as any other correspondence, retained only for the periods described below, and is not shared with any third party except where strictly necessary to respond to the message or where required by law.

3. Legal basis

We rely on consent for optional newsletter messages and cookie choices. We rely on legitimate interests for site security, basic administration and responding to correspondence. We may rely on a legal obligation where a record must be retained. We do not use personal information for automated decisions with legal or similarly significant effects.

Where consent is the legal basis, for example for the newsletter or for non-essential cookies, that consent can be withdrawn at any time without affecting the lawfulness of processing that took place before withdrawal; the newsletter unsubscribe link and the cookie settings panel are the two mechanisms provided for this. Where legitimate interests is the legal basis, for example keeping records of correspondence to answer a follow-up question, we have considered whether that interest is outweighed by a reader's own rights and freedoms and have concluded that routine administrative retention for the periods set out in Section 5 is proportionate. A legal obligation basis applies in limited circumstances, such as retaining certain financial or contractual records for statutory periods under UK company and tax law, which for company accounting records is normally six years from the end of the relevant financial year. Because we do not operate automated profiling or algorithmic decision-making on this website, no reader is subject to a decision produced solely by automated means that has a legal or similarly significant effect on them.

4. Newsletter

If you subscribe, your email is used to send Drenvek editorial updates. Each message includes an unsubscribe route. We retain the subscription record until you unsubscribe, after which suppression information may be retained to ensure your preference is respected. We do not sell subscriber lists.

Newsletter delivery is handled through a dedicated email service provider acting as our processor under a data processing agreement; the provider stores the subscriber's email address and delivery status (such as whether a message bounced) but does not use subscriber information for its own marketing purposes. A typical newsletter is sent no more than twice per month, and no reader is added to the list without completing the sign-up form themselves; we do not purchase or import third-party marketing lists. If a subscriber's email address bounces repeatedly, for example because the mailbox no longer exists, we may suspend delivery to that address without further notice. A minimal suppression record, limited to the email address and the date it was unsubscribed, is retained after opt-out for up to twenty-four months so that the address is not accidentally re-added to the list, after which the suppression record is deleted unless a re-subscription occurs in the meantime.

5. Retention

Routine contact messages are normally retained for 12 months after the last exchange. Newsletter records are retained while subscribed and for up to 24 months after unsubscribing for suppression purposes. Server and security logs are typically retained for up to 90 days before automatic deletion. Financial or statutory records, where they exist, are retained for the periods required by UK law, which is typically six years for company accounting records.

These periods are reviewed periodically and may be shortened where a shorter period is sufficient for the purpose the information was collected for. For example, if a contact form enquiry is resolved within a single exchange and no further correspondence follows, the record may be deleted before the twelve-month period ends, particularly if the reader has asked us to do so. Where information is retained for a statutory reason, such as a record connected to a regulatory enquiry, the retention period is set by the relevant law rather than by this policy, and we will inform a reader if this applies to information they have provided. At the end of any retention period, information is deleted or anonymised using the deletion tools provided by our hosting and email service providers, and we do not retain offline or paper backups of routine reader correspondence beyond the periods described here.

6. Your rights

Under the UK GDPR, you have the right to request access to the personal information we hold about you, to request that inaccurate information be corrected, and to request erasure of information where there is no lawful reason for us to continue holding it. You also have the right to object to processing based on legitimate interests, to request that processing be restricted in certain circumstances, and to request a portable copy of information you have provided to us, where the processing is based on consent and carried out by automated means.

To exercise any of these rights, contact [email protected] with a description of the request and enough detail, such as the email address used, for us to locate the relevant record. We aim to acknowledge a rights request within five working days and to provide a full response within one calendar month, as required by the UK GDPR, extending this by up to two further months for a complex or repeated request, in which case we will explain the reason for the extension. We do not charge a fee for a straightforward request, although a reasonable administrative fee may apply to a manifestly unfounded, excessive or repetitive request, in accordance with the UK GDPR. If we are unable to fulfil a request, for example because a statutory retention obligation applies, we will explain the reason in our response.

7. Third parties and processors

We use a small number of third-party service providers to operate this website, each acting as a data processor under a written agreement rather than as an independent controller of reader information. These typically include a website hosting provider, an email delivery provider for the newsletter and contact form notifications, and, where enabled, a privacy-conscious analytics provider used to understand aggregate page traffic.

None of these providers are permitted to use reader information for their own advertising purposes, and none receive more information than is necessary to perform their specific function; for example, our hosting provider processes technical request logs to serve pages, and our email provider processes subscriber addresses solely to deliver newsletter messages. We do not sell, rent or otherwise disclose personal information to third parties for marketing purposes, and we do not share reader information with advertising networks. Where a service provider is located outside the United Kingdom, the safeguards described in Section 8 apply. If we engage a new processor that materially changes how information is handled, we will update this section and note the change in the revision log below.

8. International transfers

Some of our service providers, including elements of our website hosting infrastructure, may process information on servers located outside the United Kingdom, including in the United States or the European Economic Area. Where this occurs, we rely on the UK's International Data Transfer Agreement (IDTA), an EU Commission adequacy decision extended to the UK context, or equivalent standard contractual clauses approved for use under the UK GDPR, to ensure that transferred information receives a comparable standard of protection to that required within the UK.

We select service providers that have their own publicly available data protection commitments and, where relevant, certifications such as ISO 27001 or an equivalent security framework, and we review these arrangements periodically rather than assuming a one-off assessment remains valid indefinitely. If a reader would like more detail about a specific international transfer relevant to their own information, for example which country a particular backup is stored in, they may ask at [email protected] and we will provide what detail we reasonably can without disclosing commercially sensitive provider information.

9. Complaints

If you are unhappy with how we have handled your personal information, please contact us first at [email protected] so that we can try to resolve the concern directly; we aim to respond to a complaint within five working days and to reach a substantive resolution within one calendar month.

If you remain unsatisfied after contacting us, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent regulator for data protection, at ico.org.uk or by calling 0303 123 1113. You are not required to contact us before contacting the ICO, although we would welcome the opportunity to address a concern directly. We keep a short internal record of complaints received, limited to the nature of the concern and how it was resolved, for up to twenty-four months, so that we can identify and address any recurring issue with our own data handling practices.

10. Changes to this policy

We may update this policy from time to time to reflect changes in the law, our service providers or the way the website operates. Material changes will be reflected on this page with an updated date, and we encourage readers to review this policy periodically.

This policy was last reviewed on 24 September 2026. Where a change is significant, for example a new category of information being collected or a new international transfer being introduced, we will also note the change in a short revision line at the foot of this page rather than only updating the date silently. Continued use of drenvek.info after a policy update constitutes acknowledgement of the revised policy, although for any use of information based on consent, such as the newsletter, we will always seek fresh consent if the purpose of that processing changes materially.

Revision log — 24 September 2026: initial publication of this policy alongside the launch of drenvek.info.