Privacy policy
This policy explains how Veridia handles personal information for visitors in the United Kingdom. It applies to the website, editorial correspondence and the contact form.
1. Controller and scope
Veridia, 78 Elmwood Gardens, Islington, London, N1 1AB, is responsible for the information described here. This policy applies to information supplied directly and limited technical information created when the site is visited. It does not cover third-party websites linked from our pages.
2. Information collected
We may receive your name, email address and message when you contact us. Server logs may include an IP address, browser type, requested page and time of access. Please do not send detailed medical records or sensitive health information through the form.
3. Lawful bases
We use contact details to respond to a request because doing so is necessary for that communication. Essential technical processing is based on legitimate interests in operating a secure website. Optional analytics cookies are used only where consent has been provided.
4. Editorial correspondence
Messages are reviewed by the editorial desk for correction, accessibility and general site enquiries. We retain ordinary correspondence for 24 months after the matter closes, unless a longer period is needed to document a published correction or resolve a complaint.
5. Retention
Security logs are normally retained for 30 days. Contact messages are retained for up to 24 months. Consent records for optional cookies are retained for 12 months so we can remember the choice and request it again appropriately.
6. Processors
Hosting, email delivery and analytics providers may process limited information on our instructions. Providers are selected for appropriate contractual and security controls. We do not sell personal information or use it to create medical profiles.
7. Cookies
The essential cookie named cookieChoice records an accept or reject choice for 12 months. If optional analytics is enabled, the provider may set an analytics identifier with a lifespan of up to 13 months. See the cookies page for purposes and controls.
8. International transfers
Some technology suppliers may process information outside the UK. Where that occurs, we use a lawful transfer mechanism such as UK adequacy regulations or approved contractual safeguards, and we limit the information shared.
9. Your rights
You may request access, correction, deletion, restriction or portability where applicable, and you may object to processing based on legitimate interests. Contact the editorial desk with enough detail to identify your request; we normally respond within one calendar month.
10. Complaints
Please contact Veridia first at the address above or on 020 7946 0958. You can also complain to the Information Commissioner’s Office if you remain dissatisfied. The ICO website provides current contact guidance for UK residents.
11. Security and changes
We use access controls, limited retention and secure transport as reasonable safeguards. No online system can guarantee absolute security. This policy was reviewed on 5 October 2026; material changes will be dated on this page.
For practical purposes, personal information means details that can identify or reasonably relate to a visitor, including contact details, correspondence and technical identifiers. We do not ask visitors to provide medical records, diagnoses or treatment histories. If such material is sent accidentally, we will restrict access to the message, use it only to handle the enquiry, and delete it from working systems within 30 days unless a longer period is required to resolve a security or legal issue.
Our usual retention periods are limited: contact enquiries are retained for 24 months after the last substantive exchange, consent records for up to 24 months after the relevant choice, and security logs for up to 90 days. Financial, legal or regulatory records, if created, may be retained for the period required by UK law. Backups can retain deleted information for up to 90 days while they rotate through normal recovery cycles.
Where we rely on consent, you may withdraw it at any time by contacting Veridia at 78 Elmwood Gardens, Islington, London, N1 1AB, or by using the contact page. You may ask for access, correction, deletion, restriction, portability or objection where those rights apply under the UK GDPR and Data Protection Act 2018. We normally acknowledge a request within five working days and respond within one calendar month, subject to identity checks and lawful extensions.
Routine service providers may include our hosting provider, form-delivery provider, email provider and analytics provider where optional analytics has been accepted. Each receives only information needed for its function and is expected to apply confidentiality, access controls and appropriate security. We do not sell contact details or use them to create advertising audiences based on health interests.
Some suppliers may process information outside the United Kingdom. Where that occurs, Veridia will use an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another lawful safeguard. Visitors may request a general description of relevant safeguards without asking us to disclose confidential security details.
If you are dissatisfied, please contact us first with the page, date, concern and preferred reply method. We aim to provide a substantive response within 10 working days. You may also complain to the Information Commissioner’s Office through ico.org.uk or its helpline; using that route does not affect any other legal right.
Change record: this policy was issued and reviewed on 5 October 2026. Earlier versions may be retained for governance, and material future changes will be dated on this page before or when they take effect.
The scope also includes accessibility reports, correction requests and routine security enquiries received through the contact channel. We use this information only to understand and answer the stated request, and we do not use it to build profiles about readers. A visitor can read the site without creating an account or submitting contact details. If a message includes information that is not needed, it may be redacted or removed from the working record.
Our processing purposes include operating pages, preventing abuse, maintaining availability, answering correspondence and keeping a defensible record of privacy choices. We use the minimum information reasonably needed for each purpose. For example, an editorial correction normally needs a page address and explanation, not a person’s full history. Where a supplier handles information, written instructions and access restrictions are used to limit its role.
Contact enquiries are normally retained for 24 months after the last substantive exchange, while consent records may be retained for up to 24 months after the relevant choice. Security and diagnostic logs are normally retained for up to 90 days, unless an incident requires preservation for investigation. Backups can contain deleted information for up to 90 days while ordinary rotation takes place. Statutory accounting or legal records, if created, are retained for the period required by UK law.
You may request access, correction, deletion, restriction, portability or objection where the UK GDPR provides that right. Requests can be sent to 78 Elmwood Gardens, Islington, London, N1 1AB, or through the contact page, and we may ask for proportionate identity information before disclosing records. We aim to acknowledge a request within five working days and respond within one calendar month. If a lawful extension applies, we will explain it before the original deadline expires.
Service providers may include the website host, form-delivery provider, email service, security monitoring provider and analytics provider where optional measurement has been accepted. Examples of processing include delivering a message, storing a page request or providing aggregated traffic reports. These providers are not authorised to use Veridia correspondence for their own marketing. We do not sell contact details or use them to infer a reader’s health status.
Some providers may process limited information outside the United Kingdom. Veridia will use an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum or another lawful transfer mechanism where required. A transfer assessment considers the type of information, the supplier’s role and the protections available in the destination. A general description of safeguards can be requested without requiring us to disclose confidential security arrangements.
If you believe we have not handled a request properly, contact us first with the relevant page, date and concern. We aim to provide a substantive complaint response within 10 working days, although complex matters can require longer investigation. You may also contact the Information Commissioner’s Office through ico.org.uk. Complaining to the ICO does not remove any other right available under UK data-protection law.
Change record: this policy was reviewed on 5 October 2026. Material future changes will show a new effective date and, where useful, a short explanation of what changed. Previous versions may be retained for governance and audit purposes even after a public version is replaced.