Food supplement. Not a medicine. Sold by Stornev Health Ltd, Bristol, United Kingdom. · Disclaimer
Editorial health information. Not a substitute for professional medical advice. | Stornev · Bristol, United Kingdom

Privacy

Privacy Policy

Published 9 September 2026 · Stornev Health Ltd

1. Scope

This policy explains how Stornev Health Ltd handles information when you visit stornev.info, contact the editorial desk or subscribe to updates. It applies to visitors in the United Kingdom and readers elsewhere who use the website. Stornev is the controller for information held for these purposes. Questions can be sent to [email protected].

2. Information collected

We may receive an email address when you subscribe, alongside the message details you choose to send through a contact form. Basic technical information such as browser type, device category, approximate location and pages requested may appear in server logs. We do not ask for sensitive personal stories through the newsletter form.

3. Lawful basis

We rely on consent for optional newsletter messages and non-essential cookies. We rely on legitimate interests for website security, basic service administration and responding to enquiries. Where a legal obligation applies, information may be retained to meet that obligation.

4. Use of information

Information is used to send requested updates, answer enquiries, maintain security, understand general website performance and improve editorial accessibility. We do not sell reader lists. We do not use newsletter addresses to create advertising profiles.

5. Retention

Newsletter details are retained until you unsubscribe, then removed from the active mailing list within 30 days. Enquiry correspondence is normally retained for 24 months after the last meaningful exchange. Security records may be kept for up to 90 days unless a longer period is needed to investigate misuse.

6. Processors

We may use hosting, email delivery, analytics and security providers acting under written instructions. Providers receive only the information needed for their service. We review contractual safeguards and expect processors to protect information appropriately.

7. International transfers

Some technology providers may process information outside the UK. Where this occurs, we use an adequacy decision, the UK International Data Transfer Agreement or another lawful safeguard. Details can be requested from the contact address.

8. Your rights

You may ask for access, correction, deletion, restriction, portability or objection where the UK GDPR provides that right. You may withdraw newsletter consent at any time through the unsubscribe link. To exercise a right, email [email protected] with enough detail for us to identify the request.

9. Verification and response

We may request reasonable information to protect another person’s privacy. We aim to respond within one calendar month, although complex requests may take a further two months with an explanation. There is no charge unless a request is manifestly unfounded or excessive.

10. Complaints

If you are unhappy with our handling of information, please contact us first so we can investigate. You may also contact the Information Commissioner’s Office in the United Kingdom through its public website or helpline. This does not remove any other legal right.

11. Children

The website is intended for a general adult readership and is not directed at children. We do not knowingly collect children’s information for newsletters. If a parent or guardian believes information has been submitted, they may contact us for review.

12. Changes

We review this policy annually. The current version was published on 9 September 2026. Previous material changes will be recorded here with their effective date, and the latest version will remain available on this page.

9. International transfers

Some service providers may process limited technical or subscription information outside the United Kingdom. Where this occurs, Stornev seeks an appropriate transfer mechanism, such as UK adequacy regulations or approved contractual protections, and limits the information shared to what the service requires.

10. Rights and requests

You may ask for access, correction, deletion, restriction or portability where the relevant UK GDPR conditions apply. You may also object to processing based on legitimate interests and withdraw consent for optional messages at any time. Requests should be sent to [email protected] with enough detail to identify the request, and we aim to acknowledge them within five working days and respond within one calendar month.

We may ask for proportionate information to protect against an unauthorised request. If a request is complex, the response period may be extended as permitted by law, and we will explain the reason before the original period ends.

11. Breach response, children and automated decisions

Stornev maintains a proportionate process for identifying, recording and assessing data incidents. If a breach is likely to create a risk to individuals, we will consider notification to the Information Commissioner’s Office without undue delay and, where required, within 72 hours of becoming aware of it. Where the risk is high, affected people will be informed as required by applicable law.

The site is intended for a general adult audience and is not designed to knowingly collect information from children. Stornev does not use the information covered by this policy for solely automated decisions that produce legal or similarly significant effects.

12. Complaints and policy history

Please contact Stornev Health Ltd at 66 Corn Street, Bristol BS1 1AA, by telephone on 0117 946 1010 or by email at [email protected] before escalating a concern. We aim to acknowledge complaints within five working days and provide a meaningful response within 20 working days where practicable. You can also complain to the UK Information Commissioner’s Office if you remain dissatisfied.

Version 1.0 was published on 9 September 2026. Material future changes will be dated on this page and will describe what has changed, why it changed and when the updated wording takes effect.

13. Data protection review

Stornev uses a proportionate review process when a new form, embedded service or publishing feature could affect personal information. The review considers the purpose of collection, the minimum information needed, access controls, retention and the effect on readers. A formal Data Protection Impact Assessment may be completed where the nature, scale or context of processing creates a higher level of privacy concern. The assessment is revisited when the feature changes or a supplier introduces a material change.

  • a. New collection fields are checked for necessity before publication.
  • b. Access is limited to people who need information to perform their role.
  • c. Risks and mitigations are recorded where a review is required.

14. Sub-processors and transfer safeguards

Technical hosting, email delivery, form handling, security monitoring and embedded map services may be provided by specialist suppliers. Examples include a hosting provider, an email delivery provider and Google Maps when the map is loaded on the contact page. Suppliers receive only the information needed for their stated function and are expected to provide appropriate contractual and organisational safeguards. A current supplier description can be requested from [email protected], although supplier arrangements may change as services are maintained.

Where processing takes place outside the United Kingdom, Stornev considers adequacy decisions, international data transfer agreements and supplementary safeguards as appropriate. A transfer is not treated as permission to share unrelated information or to retain it indefinitely.

15. Incidents, children and automated decisions

Stornev records suspected personal data incidents, assesses their likely effect and takes steps to contain and correct them. Where notification is required, the Information Commissioner’s Office will be contacted without undue delay and, where practicable, within 72 hours of awareness. People affected will be informed where the law requires communication because the risk is high. Incident records are retained for up to 24 months after closure unless a longer period is needed for legal or governance reasons.

The website is intended for adults and is not designed to knowingly collect children’s information. Stornev does not use submitted information for solely automated decisions producing legal or similarly significant effects. Questions about rights can be sent to [email protected]; identity checks will be proportionate, requests are acknowledged within five working days and a response is normally provided within one calendar month.