Privacy policy. Plainly explained.
1. Scope
This policy explains how Bralton Health Ltd, 2024/278451, handles information connected with Bralton.info. It applies to visitors, newsletter readers and people who contact the editorial team. Our address is 12 Colmore Row, Birmingham B3 2QT. Bralton Health Ltd acts as the data controller for the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018, meaning we decide how and why personal information connected with this website is processed. This policy covers every page under the bralton.info domain, including article pages, the newsletter sign-up form and the contact form, but does not extend to third-party websites a reader may reach through an external link. Where a visitor interacts with an embedded service, such as the map on our contact page, that service's own privacy terms apply to the information it collects, in addition to this policy. If Bralton were to change its trading name, ownership or company registration in the future, this policy would be updated to reflect the new controller details before any new processing began under that change. Any question about whether a specific activity falls within this policy can be directed to [email protected].
2. Information collected
We may receive an email address submitted to the newsletter form, a name and message sent through the contact form, and technical information such as browser type, approximate location and access time in server logs. We do not ask for special category information through ordinary forms. Server logs typically capture an IP address, the page requested, the date and time of the request and the referring page, and this information is generated automatically by our hosting infrastructure rather than typed in by the visitor. If a reader voluntarily includes further detail in the free-text message field of the contact form, such as a health-related question, that detail is processed only to answer the query and is not used for any other purpose. We do not use the newsletter or contact forms to build a marketing profile, and we do not knowingly collect special category data such as health records, racial or ethnic origin, or religious belief, even where a reader's message might touch on general wellbeing topics. Cookie-related information, including the stored consent choice described in section 7, is also collected as part of normal website operation.
- a) Newsletter form: email address only, no name required.
- b) Contact form: name, email address and free-text message.
- c) Server logs: IP address, browser type, approximate location, page requested and timestamp.
3. Legal basis
We use consent for optional newsletter messages and non-essential cookies. We use legitimate interests for security logs and to respond to correspondence. Where a legal obligation applies, processing is based on that obligation. Consent may be withdrawn by contacting [email protected]. For example, subscribing to the newsletter relies on freely given consent recorded at the point of sign-up, and that consent can be withdrawn at any time using the unsubscribe link in any newsletter email or by writing to us directly, without affecting the lawfulness of processing carried out before withdrawal. Responding to a message sent through the contact form relies on our legitimate interest in operating a functioning editorial correspondence channel, balanced against the reader's own interest in privacy; we consider this balance appropriate because the processing is limited to what is needed to answer the query. Security logging relies on a legitimate interest in protecting the website against abuse, unauthorised access and technical faults. Where UK tax, accounting or other statutory record-keeping obligations apply to correspondence or supplier records, processing continues under that legal obligation for as long as the obligation remains in force, independent of any consent given for other purposes.
4. Retention periods
Newsletter records are held until unsubscribe or 24 months after the last meaningful interaction. Contact messages are normally retained for 12 months after closure. Security logs are retained for up to 90 days. Consent records may be kept for 24 months to demonstrate the choice made. These periods are reviewed periodically and represent our standard practice rather than a fixed maximum in every case; for example, a contact message that leads to an ongoing correspondence may be retained for the duration of that correspondence plus 12 months from its closure. Where a message contains information relevant to a legal claim, regulatory request or dispute, we may retain it for as long as reasonably necessary to address that specific matter, even if this exceeds the standard period stated above. Backups of our systems may retain a copy of deleted information for a limited additional period, typically no more than 30 days, purely as a result of routine backup cycles rather than active use. At the end of the applicable retention period, personal information is deleted or anonymised so that it can no longer be attributed to an identifiable individual.
5. User rights
Under UK GDPR, people may request access, correction, deletion, restriction, portability or object to certain processing. Send a request to [email protected] with enough detail for us to identify the record. We normally respond within one month. In practice, a request for access might ask what email address we hold in connection with a newsletter subscription, while a request for deletion might ask us to remove a contact message once a query has been resolved; we handle each type of request according to the specific right being exercised. To confirm identity before disclosing personal information, we may ask a requester to verify the email address or details originally submitted, which helps prevent a third party from wrongly obtaining someone else's information. The one-month response period may be extended by a further two months for a complex or repeated request, in which case we will explain the reason for the delay within the first month. There is no charge for a standard request; a reasonable administrative fee may apply only where a request is manifestly unfounded, excessive or repetitive, as permitted under UK GDPR.
- a) Access: request a copy of the personal information we hold about you.
- b) Correction: ask us to fix inaccurate or incomplete information.
- c) Deletion or restriction: ask us to erase or limit use of your information, subject to any legal retention obligation.
- d) Portability and objection: request a portable copy of information you provided, or object to processing based on legitimate interests.
6. Processors
Hosting, email delivery, analytics and security suppliers may process limited information on our behalf. We select suppliers with appropriate contractual safeguards and require them to act only on documented instructions. Our website hosting and infrastructure supplier stores the files and server logs described in section 2, while a separate email delivery supplier is used to send newsletter messages and to handle unsubscribe requests. Where an analytics service is introduced in a future release, as noted in our cookie policy, that supplier would process browsing statistics under a data processing agreement compliant with UK GDPR Article 28 before activation. Each processor is contractually required to use personal information only for the purpose we specify, to apply appropriate technical and organisational security measures, and to delete or return the information at the end of the engagement. We periodically review our processor arrangements and will update this section if a new category of supplier is introduced or an existing one is replaced.
7. Cookies
Our cookie banner stores cookieChoice for up to 12 months in local browser storage. Session cookies may last until a browser closes; analytics cookies, where enabled, may last up to 13 months; preference cookies may last 12 months. The cookie policy gives further detail. The cookieChoice value records only whether a visitor accepted or rejected non-essential cookies; it does not contain a name, email address or reading history, and it can be cleared at any time by clearing browser storage or using the cookie settings control described in our cookie policy. Session records used for navigation and basic security do not require consent because the website could not function reliably without them, in line with the exemption for strictly necessary cookies under the Privacy and Electronic Communications Regulations. Any future analytics or preference cookie would be listed by name, purpose and lifespan in our cookie policy before it is activated, so that a returning visitor can review the update before it takes effect. Readers who reject non-essential cookies can still read every article on this website; rejecting cookies only affects optional convenience features, not access to editorial content.
8. International transfers
Some suppliers may process information outside the United Kingdom. Where that occurs, Bralton relies on an adequacy decision, UK International Data Transfer Agreement or another lawful safeguard, with access limited to the stated purpose. For example, a hosting or email delivery supplier may operate servers in the European Economic Area or another jurisdiction covered by a UK adequacy decision, in which case no additional safeguard beyond that decision is required. Where a supplier operates in a jurisdiction without an adequacy decision, we require a UK International Data Transfer Agreement, incorporating the International Data Transfer Addendum to the EU Standard Contractual Clauses, before any personal information is transferred. Access to transferred information is limited to personnel who need it to provide the service in question, such as technical support or delivery of newsletter emails, and is not used for unrelated purposes by the receiving party. A reader may request further detail about a specific transfer, including which safeguard applies to a named supplier, by writing to [email protected].
9. Security
We use access controls, encrypted transport and limited retention. No internet service can promise absolute security. If we become aware of a relevant incident, we will assess it and take action required by UK law. In practical terms, this includes serving the website over an encrypted HTTPS connection, restricting administrative access to the small number of editorial and technical staff who need it, and keeping the retention periods described in section 4 so that less information is held for less time. Passwords and administrative credentials are not shared by email and are changed if a member of staff who held access leaves the organisation. Where a personal data breach is likely to result in a risk to an affected individual's rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and we will notify affected individuals directly where the risk is high, as required under UK GDPR. We also review our technical safeguards periodically to reflect changes in our hosting arrangements or the services described in section 6.
10. Complaints
Contact us first at [email protected]. You may also contact the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, if you are unhappy with our response. When raising a complaint with us directly, please describe the processing you are concerned about and, where relevant, the request you previously made and the response you received; this helps our editorial team investigate the matter without further back-and-forth. We aim to acknowledge a complaint within five working days and to provide a substantive response within one month, consistent with the response period described in section 5. If you remain unsatisfied after our response, or if you would prefer to raise the matter independently, the Information Commissioner’s Office can be contacted by telephone on 0303 123 1113 or through its website at ico.org.uk, in addition to the postal address above. Raising a complaint with the ICO does not affect any other right you may have, including the right to seek a judicial remedy through the courts of England and Wales.
11. Children
Bralton is intended for adults. We do not knowingly request information from children. If a parent or guardian believes a child has contacted us, please write to the address above. Our editorial content is written for an adult UK readership and is not designed, marketed or adapted for use by children under the age of 18. The newsletter and contact forms do not ask for a date of birth and are not intended to be completed by a child; if we become aware that information has been submitted by a child without appropriate parental consent, we will delete that information promptly. A parent or guardian who believes their child has submitted information through this website can contact [email protected] or write to 12 Colmore Row, Birmingham B3 2QT, and we will investigate and respond, normally within the same timeframe described for other requests in section 5.
12. Change log
24 September 2026: policy wording reviewed, cookie periods clarified and contact details checked. Earlier versions may be requested from [email protected]. This change log is intended to give returning readers a quick way to see what has substantively changed since their last visit, rather than requiring a full re-read of the policy each time. Where a future revision changes the categories of information we collect, the purpose of processing, or a retention period, we will add a new dated entry describing the change in plain terms, in addition to updating the relevant numbered section above. Minor corrections, such as fixing a typographical error or updating a contact detail, may be made without a separate change log entry, but any change that affects how personal information is actually handled will always be logged here with its date. Readers who want to compare a current section against an earlier version can request the prior text by writing to [email protected], and we will retain at least the immediately preceding version for that purpose.