Effective 5 October 2026

Privacy Policy

This policy explains how Evolve, 78 Regent Street, Manchester, Greater Manchester, M14 4GP, handles personal information when you read the site or contact us. It is written for UK readers and reflects UK GDPR principles.

1. Scope and controller

Evolve is responsible for the editorial website and contact correspondence. We do not provide diagnosis or clinical records. Questions about this policy can be sent to the address shown on our contact page.

2. Information collected

We may receive your name, email address and message when you contact us. Technical logs may include an IP address, browser type, device information and page requests. We do not ask for special category health information and request that you avoid including it.

3. Lawful basis

We use consent for optional analytics cookies and legitimate interests to operate, secure and improve the website. We use steps taken at your request to respond to messages. We do not use automated decision-making to make decisions about individuals.

4. Retention

Contact correspondence is normally retained for 24 months after the last interaction, unless a longer period is necessary to resolve a complaint. Security logs are generally retained for 90 days. Cookie choices remain until cleared or replaced by a later choice.

5. Sharing

We may use hosting, security, email and analytics providers acting under written instructions. Providers receive only information needed for their service. We do not sell personal information or share it with advertisers for individual targeting.

6. International transfers

Where a supplier processes information outside the UK, we assess the transfer and use an adequacy decision or appropriate safeguards such as UK International Data Transfer Agreements. Details can be requested from Evolve.

7. Your rights

You may request access, correction, deletion, restriction or portability where applicable, and object to certain processing. Contact us with enough detail to identify the request. We may verify identity proportionately and normally respond within one month.

8. Children

The site is intended for a general adult audience. We do not knowingly collect information from children. If you believe a child has sent personal information, contact us so we can review and remove it where appropriate.

9. Security

We use access controls, encrypted connections and limited administrative permissions. No internet service can be guaranteed completely secure, so please do not send confidential medical details through a general contact form.

10. Complaints

Contact Evolve first so we can investigate. You may also complain to the Information Commissioner’s Office through its UK website or helpline if you remain dissatisfied.

11. Changes

We reviewed this policy on 5 October 2026. Future changes will be dated on this page and will explain material adjustments in clear language.

Practical handling and examples

For clarity, a contact message may include your name, email address, the subject of your enquiry and the content you choose to send. Please avoid entering information about diagnoses, medicines or other sensitive circumstances unless it is necessary for your question. Messages are accessed by the small Evolve team and hosting or email providers acting under written instructions. We use the information only to answer the enquiry, maintain correspondence and address reasonable follow-up questions.

Our retention approach is reviewed against the purpose for which information was collected. A routine enquiry is normally deleted after 24 months from the last meaningful exchange, while a complaint may be retained for up to six years where this is needed to establish, exercise or defend a legal position. Access logs are rotated after 90 days unless a security investigation requires a documented extension. Backups may remain for a limited additional period before ordinary system deletion cycles remove them.

Rights and requests

You may ask for a copy of personal information, correction of inaccurate details, deletion where the law permits, restriction of processing, or an explanation of how a particular use is justified. You may also object to processing based on legitimate interests and withdraw consent for optional analytics at any time. Requests should include enough detail to identify the relevant correspondence, but should not contain unnecessary sensitive information.

We normally acknowledge a rights request within five working days and respond within one calendar month, subject to identity checks and any lawful extension. If a request is complex, we will explain the reason for an extension before the initial month ends. You can contact Evolve at 78 Regent Street, Manchester, Greater Manchester, M14 4GP, or by phone on 0161 748 6329. You may also complain to the Information Commissioner’s Office if you remain dissatisfied.

Processors and transfers

Website hosting, email delivery, security monitoring and consent management may be provided by specialist suppliers. Each supplier receives only the information needed for its service and is expected to maintain confidentiality, access controls and deletion procedures. Where a supplier processes information outside the UK, Evolve assesses the transfer and uses an adequacy decision, the UK International Data Transfer Agreement or another lawful safeguard where appropriate.

Review record

  • 5 October 2026 — policy reviewed for UK GDPR wording, contact details and retention periods.
  • 5 October 2026 — rights request and international transfer guidance clarified.

The scope of this policy includes information collected when you browse Evolve, contact the editorial team, submit an accessibility or correction request, or exercise a data protection right. It applies to the website, ordinary email correspondence and technical records created when pages are delivered. It does not govern third-party websites reached through an external link, even where that link is included for context. Those services should be reviewed under their own privacy notices before information is provided.

Technical data can include an IP address, browser type, operating system, requested page, referring page, approximate time of access and security events. We use these details for delivery, fault diagnosis, abuse prevention and aggregate service planning. We do not need to retain the complete browsing history of an individual reader for ordinary editorial access. Server logs are normally rotated within 90 days, while records relevant to a security incident may be preserved for up to 12 months with access limited to the people investigating it.

Our lawful basis depends on the activity. Responding to a message is generally based on taking steps at your request or on legitimate interests in operating the publication; essential security processing is based on legitimate interests and legal obligations where applicable. Optional analytics or non-essential cookies are used only after a valid consent choice. You can withdraw that consent without affecting access to the core reading experience.

Requests can be made without using a special form. We may ask for proportionate information to confirm identity where disclosure could otherwise expose another person’s information, and we will explain why that check is needed. A request may be refused or limited only where a lawful exemption applies, such as protecting another person’s confidentiality or preserving legal professional privilege. We aim to acknowledge requests within five working days and provide a substantive response within one calendar month.

Named categories of processors may include the website hosting provider, transactional email provider, security monitoring service, consent-management provider and analytics service. These suppliers are selected for the function they perform and are instructed not to use Evolve correspondence for their own unrelated purposes. Supplier access is reviewed when contracts change or a security concern is raised. Where information is processed outside the UK, we assess the destination and use an adequacy decision, UK International Data Transfer Agreement or other lawful safeguard as appropriate.