Skip to the main content
LarkfieldHealth Library

Privacy policy

What is collected when you visit, why it is collected, and what you can do about it.

The whole policy in five lines

There is nothing to register for, nothing to buy, and no health information collected about you. Every page can be read without supplying a single personal detail. What does get processed is the technical information your browser sends, aggregate visit counts once you have agreed to them, and anything you choose to put in an email to us. No advertising runs on this site, so there is no ad network here to hand anything to.

1. Who is responsible

This website is operated by Larkfield Health Library (“we”, “us”), which is the data controller for the processing described below.

The library is run online only. There is no office to visit and no telephone line, and a single mailbox handles everything covered by this policy: [email protected]. Write “privacy” in the subject line and your message is routed accordingly.

2. What is collected

a. What your browser sends automatically

As with every web server, ours logs technical data each time a page is requested: IP address, date and time, the page requested, the HTTP status, the referring page, and browser and operating system identifiers. This is used to deliver the site, keep it secure, diagnose faults and detect abuse.

b. Aggregate usage statistics

We may use a web analytics service to see which pages get read and how people move through the site, so that we know what to improve and what to write next. Analytics data is looked at in aggregate. We do not use it to build profiles of identified individuals and we make no attempt to work out who you are.

c. What you send us

If you email us we receive your address, your message and anything else you put in it. That is used only to reply and to keep a record of the correspondence. Please do not send medical details, test results or other sensitive personal information: we cannot give medical advice, and email is not a secure channel. If you send it anyway, we will not act on it clinically and will delete it once the exchange is closed.

d. What is never collected

  • Health data, diagnoses, symptoms or medical records about you.
  • Payment details — nothing is sold here.
  • Account credentials — there are no accounts.
  • Anything knowingly collected from children under 16.

3. Cookies and similar technologies

Cookies are small files your browser stores. On this site they fall into two groups, and that is the whole list.

Cookie categories used on this site
TypePurposeConsent needed?
Strictly necessaryServing the pages, security, and remembering your cookie choiceNo — the site cannot work without them
AnalyticsAggregate counts of which pages are readYes, where local law requires it

There is no third category. No advertising is shown on these pages, so no advertising cookie, pixel, device identifier or similar marker is set by us or by anyone on our behalf, and nothing here is used to target you with advertising elsewhere.

Where the law of your location requires consent — the EU and the UK among others — analytics cookies are set only after you have given it, and you can change or withdraw that choice at any time using the “Cookie choices” control at the foot of every page, or by clearing cookies in your browser. Most browsers also let you block or delete cookies outright; blocking the strictly necessary ones may affect how the site behaves.

4. Legal bases for processing

Where the EU General Data Protection Regulation, the UK GDPR or a comparable regime applies to processing described here, the bases we rely on are:

  • Legitimate interests — operating and securing the site, replying to your correspondence, and keeping basic server logs.
  • Consent — analytics cookies and similar technologies, withdrawable at any time.
  • Legal obligation — where we are required to retain or disclose data to comply with applicable law.

Where more than one of those regimes reaches the same processing, we apply whichever of them gives you the stronger protection.

5. Sharing and international transfers

We neither sell personal data nor share it for anybody's commercial benefit, and several US state laws use “sale” and “sharing” in a wide sense that we still fall outside of, because there is no advertising here to feed. Data may be processed on our behalf by service providers: hosting and content delivery, analytics, and email. Each is permitted to process data only as far as is needed to provide its service.

Some of those providers are located outside your country, including in the United States. Where personal data leaves the EEA or the UK, we rely on an adequacy decision or on standard contractual clauses with appropriate safeguards. We may also disclose data where the law requires it, or to protect the security and legal rights of the site and its readers.

6. How long anything is kept

  • Server logs: a short period, of the order of weeks to months, for security and diagnostics, then deleted or anonymised.
  • Aggregate analytics: kept in aggregate form for trend analysis.
  • Email correspondence: kept only as long as needed to deal with the matter and hold a reasonable record, then deleted.
  • Cookies: until the expiry shown in the cookie control, or until you delete them in your browser, whichever comes first.

7. Your rights

Which rights you hold depends on where you live. Where they apply, you can ask us to:

  • confirm what personal data we hold about you, and let you have a copy of it;
  • correct anything inaccurate, or erase it altogether;
  • halt or narrow a particular use of it;
  • hand it over in a portable form;
  • treat a consent you gave earlier as withdrawn from now on;
  • record that your data is not to be sold or shared in whatever sense your local law gives those words — a request we can honour on the spot, since we do neither.

Asking costs you nothing and changes nothing about what the site gives you in return. Write to [email protected]; we answer inside whatever deadline the law sets, and we may have to ask for enough information to be sure the request is really yours. If our answer does not satisfy you, a data protection authority will hear a complaint. Readers in the EEA may take one to the supervisory authority of the country where they live or work, and readers in the United Kingdom to the Information Commissioner's Office.

8. Security

Pages are served over HTTPS only, and the small amount of data we handle is protected by technical and organisational measures proportionate to it. Treat that as an honest best effort rather than a guarantee: nothing sent across the internet and nothing stored anywhere is perfectly safe. It is also the reason we keep asking you not to put health information in an email to us.

9. Children

What is written here is written for adults, and the site is neither aimed at nor promoted to children. We knowingly collect no personal data from anyone under 16. If you have reason to think a child has sent us some, tell us and it will be deleted.

10. Do Not Track and Global Privacy Control

Browser Do Not Track signals have no agreed standard behind them, and we do not respond to them. Where the law requires it, we honour recognised opt-out preference signals such as Global Privacy Control.

11. Changes to this policy

We may update this policy to reflect a change in our practices or in the law. The “last updated” date at the top always identifies the current version, and material changes will be flagged on this page.

12. Contact

Privacy requests, editorial corrections and everything else go to the same place: [email protected]. The contact page says a little more about what to include.

Key points

  • Nothing to sign up for and nothing to pay
  • Your symptoms and diagnoses are never recorded here
  • Personal data is not sold to anybody
  • No adverts, so no advertising cookies at all
  • Visit statistics wait for your consent where the law says they must