Legal
Privacy notice
Two capacities, kept separate: what we decide about ourselves, and what we hold on a client's instructions. Which one applies decides where your request goes.
Effective 10 August 2026Version 1.0UK GDPR and Data Protection Act 2018
1Who we are, and the two roles
TRYGG HEALTH LTD is a private limited company registered in England and Wales, company number 17061747. "We", "us" and "our" mean that company; "you" means any individual whose personal data we handle.
We handle personal data in two capacities, and which one applies decides where a request should go.
| Capacity | Whose data | Who decides | Where a request goes |
|---|---|---|---|
| Controller | People who write to us, prospective and actual client contacts, visitors to this website | Us | Directly to us |
| Processor | Data inside a client's system that we build, review or repair | The client | To that client. We route it if you write to us by mistake |
Where we act as a processor we handle a client's data on their documented instructions. We have no product built on it and no purpose of our own for it, and we cannot delete a record on a third party's say-so, because it is not ours to decide about.
2What we hold as controller
| Category | Fields | Lawful basis | Kept |
|---|---|---|---|
| Correspondence | Email address, message content and metadata | Art. 6(1)(f) legitimate interests: answering a message someone chose to send | 24 months, or 6 years for a complaint |
| Client contacts | Name, work email, role, organisation | Art. 6(1)(b) performance of a contract, or Art. 6(1)(f) for a prospective one | Duration of the engagement, then 6 years for the contract record |
| Billing | Organisation name, billing address, invoice history | Art. 6(1)(c) legal obligation: tax and accounting | 6 years |
| Website request logs | IP address, timestamp, path, user agent, response code, held by the hosting provider | Art. 6(1)(f) legitimate interests: delivering the page and blocking abuse | Provider cycle, under 30 days |
Not collected
No marketing list, no lead enrichment, no scraped contact data, and no visitor identification service that resolves an IP address to an organisation and puts it in a sales queue. That last practice is common on consultancy websites and it is worth naming rather than merely omitting.
Special category data
We do not seek and do not knowingly hold data concerning health, or any other special category under Article 9. Despite the company name, no engagement we take involves patient data. If special category data reaches us in an attachment, it is deleted and the sender told.
3Your rights
Under the UK GDPR you have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights in relation to automated decision making.
How to exercise them
Email [email protected] with "Data protection request" in the subject. We respond within one month, which Article 12(3) allows to be extended by two further months for a complex request; if we extend, we tell you within the first month and say why. There is no charge.
Objecting where we rely on legitimate interests
You may object at any time. We stop unless we can demonstrate compelling legitimate grounds that override your interests, and for correspondence we will not usually have any, so an objection in practice means deletion.
Automated decisions
We make none. Nothing we run produces a decision about a person with legal or similarly significant effect, so Article 22 is not engaged.
Complaints
If our answer does not satisfy you, complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. You may do so without contacting us first, though we would rather have the chance to fix it.
4Recipients, transfers and security
| Recipient | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Serving and protecting this website | Global edge network, including the United Kingdom |
| Our email provider | Receiving and storing correspondence | United Kingdom and the United States |
| Our accountant | Statutory accounts and tax | United Kingdom |
International transfers
Where a recipient is outside the United Kingdom we rely on UK adequacy where it exists, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment. We do not transfer first and paper it afterwards.
Security, and what we do not have
Transport encryption on every connection, encryption at rest provided by the platform, multi-factor authentication on every administrative account, and access limited to those who need it. The most reliable control available to a practice this size is holding less, which is why the table above is short.
TRYGG HEALTH LTD holds no ISO/IEC 27001 certification, no SOC 2 report and no Cyber Essentials certification, has not commissioned a penetration test, and employs no full time security engineer. We will not represent otherwise until one of those is genuinely true.
Personal data breaches
Where a breach is likely to result in a risk to people's rights and freedoms we notify the ICO within 72 hours of becoming aware, as Article 33 requires, and where the risk is high we tell the affected individuals without undue delay under Article 34. Where we are the processor, we notify the client without undue delay so they can meet their own deadline.
5Cookies, changes and contact
This website sets no cookies of its own and runs no analytics. The detail, and the regulation 6 reasoning, are in the cookie statement.
Changes
The version in force is the one published here with the effective date at the top. Where a change materially affects how we handle your data, we will say so at the top of this page for at least 30 days rather than editing quietly.
Contact
TRYGG HEALTH LTD, company number 17061747, registered in England and Wales. Email [email protected].
We have not appointed a Data Protection Officer. Article 37 does not require one for a practice of this size and activity, and appointing a nominal one would be a title rather than a safeguard.
This is a professionally structured document. It is not legal advice.