Privacy Policy
1. Scope and controller
This policy explains how Krenova Health Ltd handles personal information collected through krenova.info, contact messages and newsletter subscriptions. The organisation is based at 14 Bold Street, Liverpool L1 1AA. Questions can be sent to [email protected].
2. Information collected
We may receive an email address when a visitor subscribes, plus a name and message when someone uses the contact form. Server logs can include IP address, browser type, requested page and timestamp. We do not ask readers to submit sensitive personal details through general forms.
3. Purpose and legal basis
We use information to answer enquiries, deliver requested newsletter material, maintain site security and understand aggregate page performance. Consent is used for optional newsletter messages and non-essential cookies. Legitimate interests may apply to security and basic service administration.
4. Retention periods
Contact correspondence is normally kept for 24 months after the last relevant exchange. Newsletter records remain until unsubscribe, then suppression data may be retained for 36 months to respect that choice. Security logs are normally retained for 90 days. Longer retention may apply where a legal obligation requires it.
5. Rights
UK residents may request access, correction, deletion, restriction, portability or objection where applicable. Consent can be withdrawn at any time. Write to [email protected] with enough detail to identify the request; we aim to respond within one month.
6. Processors
Hosting, email delivery, form handling and analytics suppliers may process limited information on our instructions. Suppliers are selected for appropriate safeguards and contractual commitments. We do not sell personal information.
7. Cookies
Session cookies may support site operation and expire when the browser closes. Preference cookies may last up to 180 days. Optional analytics cookies, where enabled, may use a 13-month setting. The cookie page explains categories and choices in more detail.
8. International transfers
Some suppliers may process information outside the United Kingdom. Where that occurs, Krenova uses an adequacy decision, appropriate contractual safeguards or another lawful transfer mechanism. Information is shared only as needed for the stated purpose.
9. Security
We use access controls, encrypted transport and limited administrator access. No online service can promise absolute security. If we identify a serious incident, we assess notification duties under applicable UK rules.
10. Complaints
Contact us first so the question can be reviewed. You may also contact the Information Commissioner’s Office in the United Kingdom. This policy was reviewed on 9 September 2026 and may be updated with a new date when processing changes.
7. Sub-processors and international transfers
Depending on the site feature used, service providers may include the hosting provider, an email delivery provider, a form-processing provider, an analytics provider and Google Maps for the embedded location map. These providers receive only the information needed for their stated function. Where information leaves the United Kingdom, Krenova relies on an adequacy decision, contractual safeguards or another lawful transfer mechanism and reviews the arrangement periodically.
- a. Hosting logs may be processed in the region selected by the hosting supplier.
- b. Newsletter data is shared with the delivery provider only after an optional subscription.
- c. Map content is loaded only when the contact page requests it.
8. Security and breach handling
We use access controls, encrypted connections and proportionate supplier checks to protect personal information. No online transmission can be described as completely secure. If a personal data breach creates a risk to individuals, Krenova will assess it promptly and, where required, notify the Information Commissioner's Office within 72 hours of becoming aware of it and communicate with affected people where the law requires.
Visitors should contact [email protected] if they believe information has been sent to the wrong address or exposed. We aim to acknowledge a report within five working days and provide an update within 20 working days, subject to the complexity of the investigation.
9. Children and automated decision-making
The site is intended for a general adult audience and is not designed to invite information from children. We do not intentionally collect children's personal information through ordinary forms. If a parent or guardian believes a child has submitted information, they can contact us so that we can review and delete it where appropriate.
Krenova does not use personal information to make solely automated decisions that produce legal or similarly significant effects. We may use aggregate statistics to understand page performance, but those reports are not used to assess an individual reader.
10. Change log
This policy was reviewed on 9 September 2026 to expand information about processors, transfers, security and children's data. Earlier versions were maintained as part of the site editorial record. Future material changes will be dated on this page or announced through the relevant site channel.
9. Data protection impact and risk review
Krenova considers the nature, amount and purpose of personal information before introducing a new collection method or supplier. A formal Data Protection Impact Assessment may be completed where a proposed activity is likely to create a high risk to people's rights and freedoms. The assessment considers necessity, proportionality, access controls, retention and alternatives. It is reviewed when the relevant processing changes materially.
- a. General contact messages are reviewed separately from optional newsletter records.
- b. Aggregate page statistics are designed to reduce direct identification.
- c. A supplier is checked for contractual safeguards before access is enabled.
10. Breach response and notification
Suspected personal data incidents are recorded, contained and assessed by the responsible team. Where a breach is likely to create a risk to individuals, Krenova will consider notification to the Information Commissioner's Office without undue delay and, where required, within 72 hours of becoming aware of it. People affected will be contacted without undue delay where the law requires clear communication. Affected visitors can report a concern to [email protected].
We aim to acknowledge a privacy incident report within one working day where possible and provide a progress update within five working days. The final response may depend on evidence supplied by a hosting, form or email supplier. Visitors should not send passwords or unnecessary private details in an incident report.
11. Children and automated decision-making
The site is intended for adults and is not designed to invite information from children. We do not knowingly create profiles of children or use personal information to make solely automated decisions with legal or similarly significant effects. Aggregate reports may help us understand page performance, but they are not used to assess an individual reader.
A parent or guardian who believes a child has submitted information can contact [email protected] and request a review. We may ask for enough information to identify the record while avoiding unnecessary identity documents. Any deletion request remains subject to legal retention duties and legitimate record-keeping needs.
12. Change log and supervisory contact
This policy was reviewed on 9 September 2026. The review added detail about impact assessment, breach response, children's data and automated decision-making. Future material changes will be dated on this page, and visitors may contact the Information Commissioner's Office if they remain concerned after contacting Krenova.
Rights requests should be sent to [email protected] with the subject of the request and enough detail to locate the relevant information. We aim to confirm receipt within five working days and respond within one month, unless an extension is permitted by law. Identity checks will be proportionate to the request.