1. Scope

This policy applies to visitors, newsletter subscribers and people who contact Trenvol through the website. It covers information collected through forms, essential hosting logs and optional cookies. It does not govern third-party websites linked from our pages. For example, an outbound link to an NHS guidance page or a research abstract on an external journal site is governed entirely by that destination's own privacy notice, and Trenvol has no visibility into how that separate organisation handles a reader's information once they leave trenvol.info. This policy applies equally regardless of the device used to reach the site, so the same protections and retention periods described below apply whether a reader visits from a desktop browser, a mobile device or a tablet. Trenvol Health Ltd, registered under company number 2024/467523 with its registered office at 38 Surrey Street, Sheffield S1 2GU, acts as the data controller for the personal information described in this policy, meaning it decides how and why that information is processed rather than merely processing it on behalf of another organisation.

2. Information collected

We may receive a name, email address and message when a reader uses the contact form. A newsletter request may include an email address. Hosting systems may record an IP address, browser details, requested page and timestamp for security and reliability. In practical terms, the contact form does not request or require a postal address, date of birth or any special category of information such as health data, and readers are asked in the Disclaimer not to volunteer sensitive personal details through the form. An edge case involves a reader who includes unsolicited additional information, such as a description of a personal health concern, in a free-text message field; where this happens, that information is treated with the same security safeguards as any other message content but is not used for any purpose beyond responding to the enquiry, and it is deleted according to the same retention period as the rest of the correspondence. Hosting-level logs, including IP address and browser user-agent string, are generated automatically by the underlying server infrastructure rather than deliberately collected for marketing purposes, and they are used chiefly to detect abuse, prevent unauthorised access and assess technical faults.

3. Legal basis

We use consent for optional newsletter communication and non-essential cookies. We rely on legitimate interests for basic security, site operation and handling an editorial enquiry. Where a law requires another basis, we will identify it at the relevant point. For newsletter communication specifically, consent is captured at the point a reader submits their email address through the sign-up form, and that consent can be withdrawn at any time using the unsubscribe link included in every newsletter message, without needing to state a reason. Our legitimate interest in basic security processing has been balanced against the reader's own interest in privacy through an internal assessment, and we consider this processing proportionate because it is limited to information already generated by ordinary browser activity rather than additional tracking. Where UK GDPR would instead require explicit consent, such as for certain categories of special category data, we do not currently process any such data through this website and have no plan to introduce a feature that would require it without first updating this policy and obtaining that consent.

4. Retention

Editorial enquiries are normally retained for 12 months after closure. Newsletter records remain until a person unsubscribes, followed by deletion within 30 days, except for a suppression record needed to honour that request. Security logs are normally retained for 30 days. The twelve-month period for closed editorial enquiries allows our team to refer back to a previous exchange if a reader follows up on the same topic, after which the message content is permanently deleted from our systems rather than merely archived. The suppression record kept after an unsubscribe request contains only the minimum information needed to prevent that email address being added to the newsletter list again by mistake, such as the address itself and the date of the request, and it does not include any other content from the original subscription. A practical consequence of the 30-day retention period for security logs is that, beyond that window, we cannot retrospectively investigate an access event unless it was already flagged and escalated during that period, which is consistent with common UK hosting industry practice for a small editorial website of this kind.

5. Service providers

Hosting, email delivery, analytics and security providers may process limited information on our behalf. They receive only what is needed for their task and are expected to protect it through contractual and technical safeguards. Our website hosting and infrastructure is provided by a UK or EU-based hosting provider operating under a written data processing agreement, and outbound newsletter and contact-form email delivery is handled by a reputable transactional email provider that processes message content solely to deliver it and does not use it for its own marketing purposes. Where an analytics provider is introduced in the future, as described further in the Cookie Policy, that provider will be bound by an equivalent data processing agreement before any analytics cookie is permitted to load. Each provider is contractually restricted to processing personal information only on our documented instructions, and we review our list of active service providers periodically to confirm that each one remains necessary and appropriately safeguarded.

6. Cookies

The site uses a cookie-choice item named cookieChoice for up to 12 months. Session cookies may support basic operation and expire when a browsing session ends. Optional analytics cookies are used only after consent and may last up to 13 months. Details are in the Cookie Policy. The cookieChoice item stores only the reader's selection of Accept All or Reject, not any other personal information, and it is read by the site purely to decide whether to display the cookie banner again on a later visit. Session cookies of this kind are classed as strictly necessary under the Privacy and Electronic Communications Regulations and do not require separate consent, which is why they may be set before a reader interacts with the cookie banner. Should an optional analytics cookie be introduced, it will not be set until the reader actively selects Accept All, and the Cookie Policy will be updated in advance to name the specific provider, cookie names and exact expiry periods that would apply.

7. International transfers

Some service providers may process information outside the UK. Where that occurs, Trenvol relies on an adequacy decision, UK-approved contractual safeguards or another lawful transfer mechanism, with proportionate protections. In practice this means that before any personal information is transferred to a provider based outside the UK, we confirm whether the destination country benefits from a UK adequacy regulation; where it does not, we require the receiving provider to sign the UK's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, whichever is appropriate to that provider's own contractual framework. An example of this in practice is a cloud-based email delivery provider with infrastructure located in more than one region; in that case, the safeguards described above apply to the specific processing location used for Trenvol's account rather than to the provider's business as a whole. We keep a record of which providers, if any, process personal information outside the UK, and a reader can request a summary of that record using the contact details in section 11.

8. Your rights

Under UK GDPR you may request access, correction, deletion, restriction or portability, and you may object to certain processing. Consent can be withdrawn at any time. Write to [email protected] and include enough detail for us to identify the request. For example, a subject access request should include the email address or name used when contacting the site, along with a description of the records sought, so that we can locate the correct correspondence without needing to search unrelated records. A request for deletion will normally be actioned within the response times described in section 9 below, except where we are required to retain a limited record, such as the suppression entry described in section 4, to comply with another reader's own request or a legal obligation. An edge case involves a request for portability of newsletter subscription data; because that data consists only of an email address and a subscription date, portability in practice means providing that same information in a simple exportable format such as a plain text or CSV file, since there is no more complex profile to transfer.

9. Identity checks

We may ask for reasonable information to confirm identity before releasing personal information. We aim to respond within one month. Complex requests may take a further two months, and we will explain why. A reasonable identity check for a request made from the same email address already on file might be as simple as confirming that address by reply; a request made from a different address, or one alleging that an account was used without the requester's knowledge, will require additional verification before any information is released, in line with the Information Commissioner's Office's own guidance on identity verification. Where a request is unusually complex, for example because it spans several years of correspondence or touches on information held by more than one service provider, we will notify the reader within the first month that an extension is needed and give a clear explanation of the reason and the revised timeline. We do not charge a fee for a straightforward request, though a manifestly unfounded, excessive or repetitive request may be met with a reasonable administrative charge or a polite refusal, as permitted under UK GDPR.

10. Children

Trenvol is intended for adults and does not knowingly collect information from children. If a parent or guardian believes a child has sent information, contact us so the record can be reviewed. Because the subject matter of this site concerns adult men's bone and joint wellbeing, we do not direct any marketing or newsletter sign-up messaging at readers under the age of eighteen, and the contact and newsletter forms do not ask for or record an age or date of birth. Where we become aware that a message or subscription appears to have come from a child, our practice is to delete the associated record promptly rather than retain it under the standard retention periods described in section 4, and we will confirm that deletion to the parent or guardian who raised the concern. This approach reflects the age-appropriate design expectations set out in the Information Commissioner's Office's Children's Code, even though the site is not primarily aimed at, or targeted towards, a younger audience.

11. Complaints

Contact us first so we can investigate. You can also complain to the Information Commissioner's Office at ico.org.uk. This does not remove any legal rights. We would ask that a complaint sent to us directly include the same level of detail as a rights request, such as the date of the original enquiry and the email address used, so that our team can review the relevant record without unnecessary delay; we aim to provide a substantive response to a complaint within the same one-month period described in section 9. The Information Commissioner's Office can also be reached by telephone on 0303 123 1113 or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, and a reader is free to raise a concern with the ICO at any time, whether or not they have first contacted Trenvol. Raising a complaint, whether with us or with the ICO, does not affect any other legal right or remedy a reader may have, including the right to seek a judicial remedy through the courts of England and Wales.

12. Changes

Reviewed 24 September 2026. We may update this policy when services, law or site features change. The latest date will appear on this page. Prior to this review, the policy was last checked in the first quarter of 2026 to confirm that the retention periods described in section 4 remained accurate following a routine internal audit of our contact-form and newsletter records, and no material change was required at that time. Where a future update introduces a new category of processing, such as an analytics provider or a new third-party integration, we will revise the relevant section above rather than publishing a separate notice, and the review date at the top of this section will be updated accordingly so that a returning reader can see at a glance whether the policy has changed since their last visit. We encourage readers who have previously exercised a right under section 8 to check this page periodically, particularly if they continue to receive the newsletter or maintain other ongoing contact with Trenvol.