1. Scope and controller

Stolvek Health Ltd, 47 Lister Gate, Nottingham NG1 6JR, is responsible for the site information described here. This policy covers browsing, contact messages and newsletter requests. It does not govern websites linked from Stolvek.

Stolvek Health Ltd (company number 2024/589341, VAT registration GB589341724) acts as the data controller for the purposes of the UK GDPR and the Data Protection Act 2018, meaning we determine why and how information connected with this website is used. This policy applies to every page under the stolvek.info domain, including the homepage, the six editorial articles, the about, contact and disclaimer pages, and any newsletter sign-up form embedded on them. A practical example: if a reader submits the contact form on contact.php, that submission is governed by this policy from the moment it is received, whereas clicking through to an external NHS page referenced in an article moves the reader outside our control and into that third party's own privacy practices. The consequence of this defined scope is that Stolvek cannot be held responsible for the data practices of any site reached via an outbound link, and readers are encouraged to review the privacy policy of any external destination separately. An edge case worth flagging is that if Stolvek ever introduces a distinct sub-service (for example, a dedicated newsletter platform hosted on a different domain), a supplementary notice specific to that service would be published and linked from this page before it goes live.

2. Information received

We may receive an email address and name when a reader uses a form. Server logs can include an IP address, browser type, time and requested page. We do not ask for sensitive personal details through editorial forms.

In practical terms, the contact form on contact.php collects a name, an email address and a free-text message, while the newsletter form on the homepage collects only an email address. Server-level logging, generated automatically by our hosting infrastructure, can capture the requesting IP address, user agent string, referring page, timestamp and the specific URL requested, in line with standard web server operation rather than any deliberate profiling activity. The practical consequence is that Stolvek does not build a behavioural profile of individual readers from ordinary browsing; server logs exist primarily to assess faults, detect abuse and maintain service security. An edge case arises if a reader voluntarily includes sensitive information (for example, details about a specific health condition) in the free-text field of the contact form; while we do not request this, if it is submitted we will handle it with the same confidentiality as any other message and will not use it beyond responding to the specific enquiry raised, consistent with the special category data safeguards in Article 9 UK GDPR.

  • a) Contact form fields: name, email address, message body — collected only when voluntarily submitted.
  • b) Newsletter form field: email address only — no name or additional profiling data is requested.
  • c) Passive server logs: IP address, browser/user agent, timestamp, requested page — retained for security and diagnostic purposes as described in Section 4.

3. Lawful basis

We use information to respond to a message, based on steps requested by the sender. Optional newsletter communication is based on consent. Security logs are handled on the basis of legitimate interests in operating a reliable website.

Under Article 6(1)(b) UK GDPR, replying to a contact enquiry is treated as a step taken at the sender's request prior to or in the course of that exchange, meaning we do not need a separate consent tick-box to send a direct reply to a message the reader initiated. Newsletter communication instead relies on Article 6(1)(a) consent, obtained through the explicit act of submitting an email address into the newsletter form and confirming subscription; a reader who never ticks or submits that form receives no newsletter correspondence. The practical consequence of this dual basis is that withdrawing newsletter consent has no effect on our ability to respond to a distinct contact enquiry, and vice versa — the two data flows are legally and operationally separate. Security and diagnostic logging is instead justified under Article 6(1)(f) legitimate interests, following a proportionality assessment that weighs our interest in preventing abuse and maintaining uptime against a reader's ordinary expectation of privacy while browsing a public website. An edge case: if we ever wished to use a contact message for a purpose beyond replying to it (for example, internal editorial research), we would seek a separate, clearly worded consent before doing so.

4. Retention

Contact correspondence is normally retained for 12 months after the last meaningful exchange. Newsletter records remain until consent is withdrawn or the list is closed. Security logs are normally retained for 30 days.

The 12-month retention period for contact correspondence reflects a balance between being able to refer back to a recent exchange (for example, if a reader follows up on an earlier question) and the storage limitation principle in Article 5(1)(e) UK GDPR, which requires that personal data not be kept longer than necessary. A concrete example: if a reader emails in March 2026 and there is no further exchange, that correspondence would ordinarily be deleted or anonymised by March 2027 unless a legal or regulatory reason required longer retention. Newsletter subscriber records are kept only for as long as a subscription remains active, and an unsubscribe request is actioned within a reasonable period, typically within five working days, after which the associated email address is removed from active sending lists (some residual suppression-list data may be kept indefinitely solely to ensure a reader who unsubscribed is not re-contacted by mistake). Security and access logs generated by our hosting and security infrastructure are retained for approximately 30 days, which is a common industry window for detecting and investigating suspicious activity, after which they are automatically purged as part of routine log rotation. An edge case: if a security incident is under active investigation at the point a retention period would otherwise expire, the specific logs relevant to that investigation may be retained for longer, solely for that purpose, consistent with our legitimate interest in resolving the incident.

5. Rights

Under UK GDPR, a person may request access, correction, deletion, restriction or portability where applicable, and may object to certain processing. Requests can be sent to [email protected]. We may need reasonable identity confirmation.

In practice, a subject access request is normally acknowledged within five working days and substantively responded to within one calendar month of receipt, in line with the statutory timescale under Article 12(3) UK GDPR; this period may be extended by a further two months for a complex or high-volume request, with the reader informed of the extension and the reason for it. A concrete example of exercising a right: a former newsletter subscriber who wishes to confirm what information Stolvek still holds about them can email [email protected] requesting access, and will typically receive a summary of any retained contact or subscription records within that one-month window. The practical consequence of the identity confirmation requirement is that we may ask a requester to confirm the email address associated with their enquiry before releasing details, to avoid disclosing personal information to the wrong person. An edge case concerns a deletion request made while a related contact exchange is still active or unresolved; in that situation we will explain why limited retention may continue briefly (for example, to finish addressing an open enquiry) before full erasure, consistent with Article 17(3) exceptions to the right to erasure.

  • a) Right of access — a copy of personal data held, provided within one month of a verified request.
  • b) Right to rectification — correction of inaccurate contact or subscription details.
  • c) Right to erasure and restriction — removal or limitation of processing where no overriding legal ground applies.

6. Processors

Hosting, email delivery and security suppliers may process limited information under written arrangements. They may act only on documented instructions and must maintain suitable safeguards.

Concretely, this includes a web hosting and infrastructure provider that stores the website's files and server logs, a transactional email delivery service used to send newsletter confirmations and contact-form acknowledgements, and a security or content-delivery provider that helps filter automated abuse before it reaches our server. Each of these suppliers operates under a written data processing agreement consistent with Article 28 UK GDPR, which restricts them to acting only on Stolvek's documented instructions and prohibits them from using reader information for their own independent purposes such as advertising. The practical consequence is that no processor is permitted to sell, share or repurpose contact or newsletter data beyond the specific technical function it performs for Stolvek. An edge case arises if Stolvek introduces a new supplier in the future (for example, a dedicated email marketing platform); this policy will be updated to reflect that addition, and the change log in Section 10 will record the date of that update, before the new processor begins handling any reader data.

7. Transfers

If a supplier processes information outside the UK, Stolvek seeks an adequacy decision or suitable contractual safeguards. A reader may ask for more information about the relevant protection.

In practice, our current hosting and email infrastructure primarily stores data within the United Kingdom and the European Economic Area, both of which benefit from adequacy recognition that permits data to flow without additional safeguards being layered on top. Where a specific supplier processes data in a jurisdiction without an adequacy decision (for example, the United States under certain service arrangements), Stolvek relies on the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment, before that arrangement is used. A concrete example: if our email delivery supplier operates infrastructure in more than one region, the applicable safeguard is documented in our internal supplier register, a summary of which can be requested by emailing [email protected]. The practical consequence of this approach is that a reader's information is not moved outside the UK without an equivalent standard of protection being contractually secured first. An edge case: should a relevant adequacy decision be withdrawn or amended by the UK government in the future, Stolvek would review affected transfers and, if necessary, pause a supplier relationship until an alternative safeguard is confirmed.

8. Complaints

We ask readers to contact us first so that an issue can be reviewed. A complaint may also be made to the Information Commissioner's Office at ico.org.uk.

Where a reader raises a concern directly with Stolvek, we aim to acknowledge it within five working days and to provide a substantive response within 20 working days, reflecting good practice even though this internal timescale is not itself a statutory requirement. A concrete example: a reader who believes an email address was retained longer than described in Section 4 can raise this by emailing [email protected], and we will review the specific record and correct the position if an error is confirmed. The practical consequence of encouraging readers to contact us first is that many concerns can be resolved directly and quickly, without the additional time a formal regulatory complaint can take. An edge case: if a reader is not satisfied with our response, or prefers to raise the matter independently, the Information Commissioner's Office can be contacted at ico.org.uk or by telephone on 0303 123 1113; making a complaint to the ICO does not require having contacted Stolvek first, though we would welcome the opportunity to resolve a concern directly wherever possible.

9. Children

The site is not directed at children and contact forms should not be used to submit a child's personal information. If such information is received, contact us so it can be reviewed.

Stolvek's editorial content concerns adult men's health topics such as hormonal balance and vitality after 30, and the site is not designed, marketed or age-gated for use by children under 13, the age threshold that generally applies to information society services consent under UK data protection law. A concrete example: if a parent or guardian submits a contact form on behalf of a minor, that submission is treated the same as any other message under Section 2, but Stolvek will not knowingly retain a child's personal information beyond what is necessary to close out that specific enquiry. The practical consequence is that no part of this website knowingly collects data from a child for marketing, newsletter or profiling purposes. An edge case: if we become aware that a child's personal information has been submitted without appropriate parental involvement, we will delete the relevant record promptly upon becoming aware of it, and a parent or guardian can request this directly by emailing [email protected].

10. Changes

This policy was reviewed on 24 September 2026. Future revisions will show a new date and will apply from publication. Material changes may be signposted on the site.

A concrete example of how updates are handled: if Stolvek begins using an analytics service in the future, as anticipated in our Cookie Policy, this Privacy Policy would be revised on or before that change takes effect, with the new review date replacing 24 September 2026 at the top of this section. The practical consequence of dating each revision is that a returning reader can quickly confirm whether the policy has changed since their last visit by comparing the stated date against their own records. An edge case: where a change is minor and clarificatory (for example, correcting a typographical error) rather than material, the review date may still be updated for transparency, but no additional on-site notice will necessarily be posted, whereas a material change — such as a new category of data collected or a new processor — will be flagged with a visible notice on the homepage for a reasonable period following publication.