Privacy Policy.
This page explains how Delvorn Health Ltd handles information connected with delvorn.info.
Data protection responsibility
Delvorn Health Ltd is the controller for personal information collected through delvorn.info. The designated contact for data protection matters is the Privacy Lead, who can be reached at [email protected] or 42 Deansgate, Manchester M1 1AA.
1. Scope
This policy applies to visitors, newsletter subscribers and people who contact the editorial desk. It covers information collected through this website and messages sent to our published email address.
2. Information collected
We may receive an email address when a visitor subscribes, plus the name and message details supplied through the contact form. Basic technical information such as browser type, approximate region and pages viewed may be recorded by hosting or security systems.
3. Lawful basis
We use consent for optional newsletter communication and necessary interests for security, site operation and responding to enquiries. Visitors can withdraw optional consent at any time.
4. Retention
Contact correspondence is normally retained for up to 24 months after the last meaningful exchange. Newsletter records remain until a person unsubscribes, after which suppression data may be kept for up to 36 months to respect that request.
5. Your rights
You may request access, correction, deletion, restriction or a copy of relevant personal information. Email [email protected] with the nature of the request and enough detail to locate the record.
6. Processors
Hosting, email delivery and security providers may process limited information on our behalf. They are expected to use appropriate safeguards and only act for the services requested.
7. International transfers
Some providers may operate outside the UK. Where this occurs, Delvorn seeks an adequacy decision, approved safeguards or another lawful transfer mechanism.
8. Children
The website is written for adults and is not directed at children. We do not knowingly collect information from children.
9. Complaints
Please contact us first so we can investigate. You may also contact the Information Commissioner’s Office in the United Kingdom.
10. Changes
This policy was last reviewed on 9 September 2026. We may revise it when the website, providers or legal requirements change, and the revised date will be shown here.
8. Sources and sharing
Information is shared only where it is needed to operate the website, answer a message, send an opted-in newsletter or meet a legal obligation. Delvorn does not sell visitor information or make it available for unrelated marketing. A hosting provider may see technical logs, while an email provider may see the address and delivery status needed for a message.
- Hosting and security logs are limited to operational and protection purposes.
- Newsletter delivery data is used to send, suppress and measure delivery of requested messages.
- Contact details are shared internally only with people who need them to respond.
9. Named service categories
Delvorn may use a web host, a domain and security provider, an email delivery provider and a form or mailbox service. The exact provider can change as the site develops, and this page will be updated when a change materially affects personal information. Each provider is expected to maintain confidentiality, use suitable security measures and process information only for documented services.
At present, no advertising profile is required to read the editorial pages. If a new service introduces optional measurement or personalisation, Delvorn will explain its purpose and request consent where required before activating it.
10. Security and data incidents
Reasonable technical and organisational measures are used to limit unauthorised access, alteration, loss or disclosure. No online transmission can be described as completely secure, so visitors should avoid including sensitive details in ordinary email or contact forms. If a personal data incident occurs, Delvorn will assess it promptly and notify the Information Commissioner’s Office within the applicable legal period where notification is required.
Where an incident is likely to create a high risk to affected people, Delvorn will communicate relevant information without undue delay and explain practical steps available to them. Records of the assessment, decisions and remedial work will be retained for accountability.
11. Children and young people
This website is written for an adult audience and is not directed at children. Delvorn does not knowingly invite children to submit newsletter or contact information. If a parent, guardian or young person believes information has been submitted inappropriately, they can contact [email protected] so the record can be reviewed and removed where appropriate.
12. Automated decision-making
Delvorn does not use personal information to make decisions that produce legal or similarly significant effects through solely automated processing. Editorial pages are selected for general publication rather than personalised assessment. Basic technical systems may identify suspicious traffic or repeated requests, but those controls are operational safeguards and not decisions about a person’s rights or eligibility.
13. Requests and complaints
Requests are normally acknowledged within five working days and answered within one month, subject to identity checks and the complexity of the request. Delvorn may ask for additional information where a record cannot be located safely from the details supplied. A request can be sent to [email protected] or to 42 Deansgate, Manchester M1 1AA.
If a visitor remains concerned, they may contact the Information Commissioner’s Office in the United Kingdom. Delvorn welcomes the opportunity to review a concern first and will keep a record of the issue, response and any agreed follow-up.
14. Review history
This policy was reviewed on 9 September 2026. The review considered newsletter handling, contact correspondence, technical logs, international service arrangements and the rights available under UK data protection law.
Future revisions will show a new review date and a short explanation of material changes. The previous version will not be treated as silently amended; visitors should check this page when they submit a new enquiry or subscribe.
15. Data protection assessments
Delvorn considers whether a Data Protection Impact Assessment is appropriate when a proposed change could create a higher privacy risk. This includes new analytics, substantial profiling, large-scale monitoring or a service that handles sensitive information. The current editorial website is designed around limited collection and does not intentionally create health profiles about readers.
Where an assessment is needed, it records the purpose, information involved, risks, safeguards and review owner. The assessment is revisited when the processing changes materially or a new risk becomes known.
16. Sub-processors and service changes
Operational providers may use carefully selected sub-processors for hosting, security, email delivery or infrastructure. Delvorn expects contractual confidentiality, access controls and deletion or return procedures when a service ends. A material change in provider or processing purpose will be reflected in this policy before it is introduced where practical.
- Service providers receive only the fields needed for their defined task.
- Access is limited to authorised personnel and monitored where appropriate.
- Provider changes are reviewed for location, safeguards and retention.
17. Breach response and version history
If Delvorn becomes aware of a suspected personal data breach, it will contain and assess the event promptly. Where the law requires, the Information Commissioner’s Office will be notified within 72 hours of becoming aware of a reportable breach. People affected by a high-risk incident will be informed without undue delay with practical guidance.
This policy was reviewed on 9 September 2026. The next review will consider provider changes, retention periods, international transfer safeguards, children’s information and any guidance issued by the Information Commissioner’s Office.