Privacy
Privacy notice
This notice explains what personal data What’s in the Vial? handles, why it is used, how long it is kept and the choices available to you.
Who is responsible for your data
Yianni Kiromitis is the data controller for What’s in the Vial?. The site is an independent, self-funded editorial publication. It does not sell products, provide a diagnostic service or offer personalised medical advice.
For privacy questions or requests, email info@whatsinthevial.com. Please do not include medical records, test results or other sensitive health information in an email to the publication.
Information we handle and why
Server and security logs
The hosting system may record an internet protocol address, browser and device information, requested pages, timestamps, referring pages and technical error or security information. We use these records to deliver the site, diagnose faults, protect it from abuse and maintain service security. The legal basis is our legitimate interest in operating a secure and reliable publication.
Email correspondence
If you contact us, we receive the information you choose to send, your email address and the correspondence history. We use it to answer the message, handle correction requests, respond to data-protection requests and keep an appropriate editorial or compliance record. Depending on the message, the legal basis is our legitimate interest in running the publication, taking steps at your request, or meeting a legal obligation.
Administrative accounts
Authorised editors and technical administrators may have private site accounts. We process the account name, contact details, permissions and security records to administer the publication. Public registration and public commenting are disabled.
We do not ask visitors to create accounts, and we do not use visitor data for personalised advertising, automated decision-making or profiling.
Cookies and similar technologies
The public site does not currently use advertising, personalisation or audience-measurement cookies. It does not currently connect Google Analytics. A page may still rely on storage that is strictly necessary for security, network management or an action you request. If we introduce non-essential cookies or similar technologies, we will update this notice and request consent where the law requires it before setting them.
You can control stored site data through your browser. Blocking essential storage may affect a security or administrative function, but ordinary public reading does not require an account.
Who receives information
Hosting, security, email and technical service providers may process limited data for us under appropriate instructions. We may also disclose information when the law requires it, to establish or defend legal rights, or to protect the security of the publication and its users.
We do not sell personal data. We do not share it with peptide sellers, clinics or advertisers for their own marketing.
International processing
A service provider may process data outside the United Kingdom. Where that happens, we use a lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations or approved contractual clauses, where required.
External links
Articles link to journals, regulators and other external sources. Those organisations control their own sites and privacy practices. Their notices apply when you visit them.
How long information is kept
- Routine email correspondence is normally kept for up to 24 months after the matter closes.
- Records of privacy requests and our response are normally kept for up to three years to demonstrate compliance.
- Routine server and security logs are normally kept for up to 90 days, unless a security incident, legal duty or active investigation requires a longer period.
- Editorial correction records may be kept for as long as the related publication remains available, because they document its accuracy history.
We may delete information earlier when it is no longer needed. We may retain it for longer where the law requires this or where it is necessary for a live dispute, investigation or security incident.
Your data-protection rights
UK data-protection law may give you the right to ask for access to your personal data, correction, deletion, restriction, an objection to processing, or a portable copy. The right that applies depends on the information and the reason it is used.
Send a request to info@whatsinthevial.com. We may ask for information needed to confirm your identity. We normally respond within one month, subject to the extensions and exemptions allowed by law. You will not usually pay a fee.
If you are dissatisfied, contact us first so we can investigate. You can also complain to the Information Commissioner’s Office, the UK data-protection regulator.
Changes to this notice
We review this notice when the site, its services or the law changes. The date at the top identifies the current version. A material change will be described clearly on this page before or when it takes effect.