Privacy Policy
Stalvon Health Ltd respects the privacy of visitors to stalvon.info. This policy explains what information may be collected, why it is used and how readers can contact us about their rights. It applies to pages, forms, newsletter requests and correspondence. Stalvon Health Ltd (company number 678) is the data controller for the purposes of this policy and is responsible for deciding how and why personal information collected through this website is used. This policy is written to reflect UK data protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018, and it sits alongside our Cookie Policy, which covers browser-based technologies in more detail.
1. Information received
We may receive an email address when a reader joins the newsletter and a name, email address or message when someone contacts us. Server logs may include an IP address, browser type, requested page and timestamp for security and service administration. We do not ask readers to submit health information, financial details or other special category data through our forms, and we ask that contact messages avoid including such information where possible. If a message is received that contains such information despite this request, we handle it with the same security precautions applied to other personal information and delete it once it is no longer needed for the purpose of responding to that message.
a) Newsletter sign-up: email address only, submitted voluntarily through the homepage form.
b) Contact form: name, email address and the content of the message, submitted voluntarily.
c) Server and security logs: IP address, browser and device type, referring page, requested URL and timestamp, collected automatically for every visit.
2. Lawful basis
We use information where it is needed to respond to a request, provide a subscription requested by the reader, meet a legal obligation or pursue a legitimate interest in keeping the website secure and usable. Where consent is the relevant basis, for example for optional analytics cookies described in our Cookie Policy, that consent can be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
a) Consent — for the newsletter subscription and for optional cookies.
b) Contract or request — to respond to a message sent through the contact form.
c) Legal obligation — for example, retaining certain records where required by law.
d) Legitimate interest — for basic security logging and preventing misuse of the site.
3. Newsletter
Newsletter messages are sent only where a reader has requested them. Each message includes a clear unsubscribe route. Mailing preferences are retained until withdrawal and suppression records may be kept to respect that request. For example, if a reader unsubscribes, we keep a minimal suppression record of the email address so that the address is not accidentally re-added to the mailing list at a later date, rather than to contact the reader again.
4. Retention
Routine correspondence is normally retained for up to 24 months after the last exchange. Newsletter records are retained while subscribed and for up to 24 months after unsubscribing. Security logs are normally retained for 90 days unless needed to investigate misuse. These periods are reviewed periodically and may be shortened where a shorter period is sufficient for the stated purpose.
a) Contact form messages: up to 24 months from the date of the last reply.
b) Newsletter subscriber list: for the duration of the subscription, plus up to 24 months of suppression records after unsubscribing.
c) Server security logs: 90 days as standard, extended only where an investigation into misuse is ongoing.
d) Accounting records connected to the operation of the company: retained in line with UK company record-keeping requirements, generally six years.
5. Service providers
Hosting, analytics and mailing suppliers may process limited information on our behalf. They receive only what is needed for the stated service and are expected to protect it through contractual and technical safeguards. We enter into data processing arrangements with these suppliers that reflect the requirements of UK data protection law, and we review our list of suppliers periodically to confirm that each one remains necessary.
a) Website hosting and infrastructure providers, who process server logs and site content.
b) Email delivery providers, who process newsletter subscriber addresses to send requested messages.
c) Analytics providers, where enabled, who process aggregated visit data as described in our Cookie Policy.
6. International transfers
Some suppliers may process data outside the United Kingdom. Where that occurs, Stalvon seeks a lawful transfer mechanism and appropriate contractual protection, such as the UK's International Data Transfer Agreement or a recognised adequacy decision covering the destination country. We take reasonable steps to confirm that any supplier processing data outside the UK maintains a standard of protection broadly equivalent to that required under UK data protection law before engaging them.
7. Your rights
Subject to applicable law, you may ask for access, correction, deletion, restriction, portability or objection. Contact [email protected] with enough detail for us to identify the request, without sending unnecessary sensitive information. We aim to acknowledge a rights request within five working days and to provide a full response within one calendar month, as required by UK data protection law, extending this by up to two further months for complex requests where we will explain the reason for the extension. There is normally no charge for making a request of this kind; a reasonable administrative fee may only be considered where a request is manifestly unfounded, excessive, or repeated shortly after an identical earlier request has already been answered in full.
a) Right of access — a copy of the personal information we hold about you.
b) Right to rectification — correction of inaccurate or incomplete information.
c) Right to erasure — deletion of information where there is no lawful reason for us to continue holding it.
d) Right to restriction and objection — limiting or objecting to certain processing, such as newsletter analytics.
e) Right to portability — receiving certain information in a portable format where technically feasible.
8. Verification
We may need to verify an identity request before releasing information. This protects readers from unauthorised access and we will ask only for proportionate evidence, such as confirming the email address associated with a newsletter subscription or a previous contact form message. We will not ask for a copy of formal identification documents unless the nature of the request makes this genuinely necessary.
9. Complaints
Please contact us first so we can review the concern. You may also contact the UK Information Commissioner's Office if you remain dissatisfied. The Information Commissioner's Office can be reached at ico.org.uk or by writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We take complaints about how we handle personal information seriously and will treat any concern raised through our contact channels with the same response times described in section 7.
10. Changes
Published 9 September 2026. We may revise this page to reflect changes in the site, suppliers or law. The latest date will appear here. A short log of substantive changes is kept below.
9 September 2026 — initial publication of this policy alongside the launch of the Stalvon editorial website.
11. Contact details
Stalvon Health Ltd, 21 Surrey Street, Sheffield S1 1AA. Email [email protected]. Phone 0114 946 0606.
12. Data breach notification
Stalvon maintains a basic internal process for identifying and responding to any incident that may affect the security of personal information collected through this website. Where a breach is identified that poses a genuine risk to the rights and freedoms of affected readers, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by UK data protection law. Where a breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly using the contact details we hold for them, explaining what happened, what information was involved and what steps we recommend. We review our hosting and mailing suppliers periodically to confirm that they maintain reasonable technical safeguards intended to reduce the likelihood of such incidents occurring in the first place.
13. Children's information
This website is an editorial resource intended for adults, and content is written with adults over 40 in mind. We do not knowingly collect personal information from children, and the newsletter and contact form are not directed at or designed for use by children. If we become aware that we have inadvertently collected information from a child without appropriate consent, we will delete that information promptly. A parent or guardian who believes their child has provided personal information through this website should contact us using the details in section 11 so that we can address the matter.
14. Automated decision-making
Stalvon does not use personal information collected through this website to make automated decisions that produce legal effects or otherwise significantly affect readers. Newsletter sends and basic analytics, where enabled, are administrative in nature and do not involve profiling used to make decisions about individual readers. If this were to change in the future, this policy would be updated in advance to explain the logic involved, the significance of the processing and the choices available to readers before any such feature was introduced.
15. Sub-processors
Our hosting, email delivery and analytics suppliers may in turn rely on their own infrastructure and support providers to deliver their service to us, and these are generally referred to as sub-processors. We select suppliers who maintain a published list of their own sub-processors and who commit contractually to imposing data protection obligations on those parties equivalent to the obligations they owe to us. We do not disclose personal information to a sub-processor for any purpose beyond what is needed to provide hosting, email delivery or analytics functionality to Stalvon, and we periodically review the categories of sub-processor engaged by our suppliers as part of our ongoing supplier oversight. A reader who would like general information about the categories of sub-processor involved in operating this website may contact us using the details in section 11, and we will provide what context we reasonably can.
16. Dispute resolution
If a reader believes that Stalvon has not handled their personal information appropriately, we encourage them to raise the concern with us directly in the first instance using the contact details in section 11, so that we have the opportunity to investigate and respond before the matter is escalated further. Most concerns of this kind can be resolved through direct correspondence, for example by correcting an inaccurate record, honouring an erasure request that was not actioned promptly, or clarifying a point of confusion about how a particular piece of information is used. Where a reader remains dissatisfied after raising a concern with us, they retain the right to complain to the Information Commissioner's Office as described in section 9, and nothing in this policy is intended to limit or discourage the exercise of that right. Any dispute concerning this policy that proceeds to formal proceedings would be subject to the law of England and Wales, consistent with the governing law provisions in our Terms of Service.
17. Data Protection Impact Assessments
Before introducing a new feature that involves a materially different or larger-scale use of personal information than described in this policy, we consider whether a Data Protection Impact Assessment is appropriate, in line with UK data protection law. Given the limited categories of information currently collected through this website, described in section 1, we do not currently carry out large-scale or systematic profiling of readers, and no such assessment has been required to date. If our processing activities change in a way that increases risk to readers, for example through the introduction of a more detailed analytics or personalisation feature, we would carry out an appropriate assessment before launch and update this policy to reflect the outcome and any resulting safeguards.