Skip to main content
Trygg

Information governance

Privacy notice

Written in the form this practice uses for its own governance documents: purpose, scope, who is answerable, which records exist, when each one is destroyed, and what happens when one of them goes wrong.

Version 2.0, issued 14 August 2026Review due August 2027UK GDPR and Data Protection Act 2018

1Purpose and status

This notice states how TRYGG HEALTH LTD handles information that identifies a living person. It follows the shape of a governance document rather than a marketing page, because that shape is auditable: purpose, then scope, then who answers for what, then the records themselves, then the procedure that runs when one of them is put at risk.

Read end to end, it should tell you which records exist, why each one exists, the date each one is destroyed, and where to take an answer that does not satisfy you. If it does not do that, it has failed at its own standard and the address in section 16 is the place to say so.

Two limits on what this document is. It is not a contract, and nothing written here reduces a right the law gives you. Where this notice and the law point in different directions, the law governs.

The company behind it is TRYGG HEALTH LTD, registered in England and Wales, number 17061747. Throughout, the practice means that company, and you means any person whose information it handles, client or not.

2Scope

This notice governs information the practice decides about for its own purposes. Information sitting inside a client's system is governed by section 8, where the decisions belong to the client and the practice works to instruction.

Inside the scope of this notice

  • Correspondence to and from [email protected].
  • Contact records for clients, and for organisations that have asked about work.
  • Engagement paperwork: statements of work, invoices, expenses and the accounting entries behind them.
  • The request log generated by the provider that serves this website.
  • An incident record, on the occasions when one is opened. Section 12 gives the trigger.

Outside it

  • Records inside a client's system, which section 8 covers.
  • Anything held on your device by this website. The cookie statement deals with that in full.
  • The company filing held by the registrar. Companies House maintains that record under its own statutory duties and this notice has no bearing on it.

3Roles and responsibilities

Data protection allocates duties by role, not by job title, and the two capacities below carry different obligations. Which one applies decides who can act on a request.

Allocation of responsibility
FunctionHeld byCovers
ControllerTRYGG HEALTH LTDPurposes and means for every record listed in section 5
ProcessorTRYGG HEALTH LTD, under written instructionRecords inside a client's system, for that client's purposes only
Approval of this noticeThe directorsThe notice, the retention schedule, and any amendment to either
Day-to-day handlingWhoever is working the engagementApplying the schedule, opening an incident record, routing a request
Requests and complaintsThe published addressOne route in, with no separate mailbox to discover

Data Protection Officer

None is appointed, and Article 37 does not call for one here. That Article bites on a public authority, on an organisation whose core activity is regular and systematic monitoring of people at scale, and on one whose core activity is large-scale handling of special category or criminal offence data. A two-person software practice holding correspondence, contracts and invoices sits outside all three. Data protection correspondence is therefore read by a director rather than routed to a function.

4The framework applied

Three instruments govern what follows.

  • The UK General Data Protection Regulation. Sets the principles, the lawful bases, the rights and the notification duties.
  • The Data Protection Act 2018. Supplements the Regulation, carries the exemptions, and supplies the conditions that Article 9 and Article 10 handling must satisfy in this jurisdiction.
  • The Privacy and Electronic Communications (EC Directive) Regulations 2003. Govern storage on your device and unsolicited electronic marketing. The first is dealt with in the cookie statement; the second is not something this practice sends.

Engagements import a further layer. A client working under sector record-keeping duties is bound by them whatever a supplier writes, so the engagement schedule names those duties at the start. A retention rule drafted without them is a rule the client cannot lawfully follow, which is a failure of the work rather than a detail.

5Records held as controller

This is the whole register. If a record is not on it, the practice does not keep it.

Register of records held by the practice
RecordContentsWhy it existsLawful basis
Enquiry correspondenceYour address, your name where you give one, the message and its headersTo answer you, and to keep the thread readable if the matter comes backArticle 6(1)(f), legitimate interests
Client contact recordName, work address, role, organisationTo run an engagement and reach the right person inside itArticle 6(1)(b) where you are the counterparty; Article 6(1)(f) where the contract is with your employer
Engagement and accounting recordsStatements of work, invoices, payments, expensesTo perform the contract and to evidence it for tax and statutory accountsArticles 6(1)(b) and 6(1)(c)
Website request logNetwork address, time, path, browser string, response code, held by the providerTo deliver a page and to keep abusive traffic off the siteArticle 6(1)(f), legitimate interests
Incident recordWhat happened, when it was noticed, who was affected, what was doneTo contain an incident and to evidence the response afterwardsArticle 6(1)(f), with 6(1)(c) where a report is required

Where it comes from

All of it reaches the practice from you or from the organisation you work for. The one exception is the request log, which the hosting provider generates automatically the moment a browser asks for a page. Nothing is purchased, and no third-party source is used to fill in a field you left blank.

The balancing test, recorded rather than assumed

Legitimate interests carry four of the entries above, so the balance is written down. The interest is the ordinary operation of a working practice: answering people who write in, keeping a website available to read, and being able to reconstruct later what was agreed and when. Each purpose is served by the fields named and by no further field. None of it feeds a profile, a score, or an approach about something you never raised. Somebody writing to a company about a piece of work reasonably expects the company to keep the exchange, and that expectation is why the balance falls where it does. Section 13 sets out how to object, and an objection to correspondence will ordinarily end with the thread being removed.

6Retention and disposal

Every record on the register has a period, a start point and a disposal method. Retention is a decision taken once and then executed, which is the same discipline this practice sells to clients.

Retention schedule
RecordPeriodCounted fromDisposal
Enquiry correspondence24 monthsThe last message in the thread, not the firstRemoved from the mailbox; provider backups age out on their own cycle
Client contact recordThe engagement, then 6 yearsThe final invoiceRemoved with the engagement file
Engagement and accounting records6 yearsThe end of the accounting period they fall inRemoved once the tax position for that period is closed
Website request logUnder 30 daysThe request itselfOverwritten on the provider's rolling cycle
Incident record6 yearsClosure of the incidentRemoved, with the closure entry removed alongside it

How disposal is actually carried out

A period nobody executes is a period on paper. The schedule is worked through on a fixed date each quarter: anything past its period goes, the disposal is recorded against the category rather than against you individually, and anything held back is held back for a reason written down on the day. Deletion of data reaches provider backups on their cycle rather than the same afternoon, which is a genuine limit and is stated here instead of being smoothed over.

You may ask the practice to delete your data ahead of the schedule. Unless a statutory period is still running the answer is yes and it is done. Where a period is still running, the reply names the period, the obligation behind it, and the date it ends.

7Health information and Article 9

Information about a person's physical or mental health is special category data under Article 9(1). It cannot travel on an Article 6 basis alone: a condition in Article 9(2) has to apply as well, and the conditions that matter in practice carry a further requirement in Schedule 1 of the Data Protection Act 2018. Given the company name, the position deserves stating precisely rather than in one line.

What the practice holds itself

None of it. Nothing in the section 5 register requires it: an invoice, an enquiry and a request log disclose nothing about anybody's health, and no field exists in which to put it. The practice does not ask for it and has no purpose that would carry it.

It occasionally arrives unbidden, attached to an email that nobody solicited. The attachment is then deleted, the deleted items folder is emptied of it, and the sender is told what arrived and what became of it. It is not filed, quoted, forwarded, or allowed to inform the work.

Inside a client's system

This is where health records genuinely arise, and the honest description is that the practice designs for them without taking custody of them.

The Article 9 condition belongs to the client, who is the controller. Most often it is Article 9(2)(h), health or social care purposes, which the Data Protection Act 2018 ties to paragraph 2 of Schedule 1 and to section 11(1), so that the handling sits under the responsibility of somebody owing a duty of confidentiality. Sometimes it is Article 9(2)(g) or 9(2)(i) with the matching Schedule 1 condition. Occasionally it is explicit consent under Article 9(2)(a), which is only worth relying on where refusing is genuinely open to the person being asked. Where a client relies on a Schedule 1 condition, Part 4 of that Schedule obliges it to keep an appropriate policy document, and the practice asks to see that document at the start rather than after a deliverable has been built on an assumption about it.

The work itself is kept at arm's length from live records. A schema, a retention rule, an export routine and a set of handover notes can all be built and exercised against synthetic or masked records, and that is the default position of every engagement. Where a task genuinely cannot be completed without sight of real records, three conditions apply together: the access is named and time-limited, the client logs it at their end, and it falls under the processing schedule described in section 8. Nothing is copied onto the practice's own systems, and a live health record is never used as development or test material.

The practice does not perform clinical safety work, hold the clinical safety officer role, or give a clinical opinion on a record or a system. Those are regulated activities and they sit with people who hold the qualifications for them.

Criminal offence data

Article 10 data is treated on the same footing: not sought, not held by the practice as controller, and encountered inside a client's system only under a Schedule 1 condition the client has identified and recorded.

8Records held for a client

Where the practice works inside a client's system it acts as processor. The client decides why the records exist and what becomes of them; the practice does what the engagement instructs and stops there.

A written schedule satisfying Article 28(3) forms part of any engagement of that kind, and it fixes the following before work starts.

  • What the handling covers, how long it runs, its nature and its purpose, and which categories of person and record it touches.
  • That the practice acts on documented instructions only, and says so where an instruction looks unlawful rather than carrying it out and noting a reservation.
  • That everyone with access is under a duty of confidence which outlasts the engagement.
  • The Article 32 measures, named individually rather than summarised as appropriate.
  • That no sub-processor is engaged without written authorisation, and that an authorised one takes the same terms it was authorised under.
  • The assistance owed on rights requests, on security, on breach notification and on an impact assessment where one is required.
  • What happens at the end: records returned or destroyed on the client's instruction, with written confirmation of which was done.
  • The information and access the client needs in order to satisfy itself that all of the above is true.

If your record sits in a client's system and you write here

The practice cannot answer for a controller and will not give the impression that it can. You will be told which organisation holds the record, and where the engagement permits it your message is passed on with a note of when it reached us. A request to correct or remove something is decided by the client.

What never happens to client records

They are not used to build anything the practice owns, not kept as a sample, not written up as a case study, and not retained past the end of the engagement except where the client instructs it or a law requires it.

9Who else sees any of it

Recipients, and what reaches each one
RecipientFunctionWhat reaches themWhere
Cloudflare, Inc.Delivers and shields this websiteRequest metadata: address, time, path, browser stringEdge network, the United Kingdom included
Mail and document providerMailbox and file storageCorrespondence and anything attached to itUnited Kingdom and United States
AccountantStatutory accounts and tax filingsInvoices and payment recordsUnited Kingdom
HMRC and Companies HouseStatutory filingWhatever the filing itself requiresUnited Kingdom
Professional advisersAdvice on a dispute, if one ever arisesOnly the material the matter turns onUnited Kingdom

That table is exhaustive. Nothing is sold, rented, or handed to an advertising network, and there is no arrangement under which an outside service adds information from elsewhere to a record held here. Change a supplier and this notice changes with it.

Disclosure to a public authority happens only where the law compels it. Where the practice is permitted to tell you that such a disclosure was made, it will.

10Transfers out of the United Kingdom

Two recipients above operate outside the United Kingdom. Before anything reaches them, one of these has to be in place.

  • Adequacy regulations covering the destination, which remove the need for a further safeguard.
  • The International Data Transfer Agreement issued by the Commissioner, the IDTA.
  • The Addendum that fits the EU standard contractual clauses to this jurisdiction.

Where the second or third is relied on, a transfer risk assessment is completed beforehand and filed with the supplier record. It considers the law of the destination, what a public authority there could compel, and whether the safeguard would survive contact with either. The assessment is redone when the supplier changes what it does or where it does it.

Inside a client's system, the client decides where records live. The practice does not move a client's records across a border on its own initiative, and where a proposed hosting change would have that effect it is put in writing before anything is migrated.

11Security controls

Controls are listed so they can be checked. An adjective cannot be audited.

  • Accounts are individual and named. Nothing is shared, and every administrative account carries a second factor.
  • Access follows the engagement: granted for the work, scoped to what the work needs, withdrawn on the day the work ends rather than at the next review.
  • Traffic to this site is encrypted in transit, and stored records are encrypted at rest by the platform holding them.
  • Practice records and client environments are kept apart. Client material is not held on a personal device and is not copied into the practice's own storage for convenience.
  • Backups are the providers' and a restore is exercised rather than assumed, which is the standard the practice applies to a client's export path and would be difficult to justify skipping for its own.
  • Suppliers in section 9 are reviewed at renewal. One that will not answer a straight security question is replaced.

Volume is a control in its own right. The register in section 5 is short deliberately: a record that was never created cannot be disclosed, cannot be lost, and cannot be misused years later by somebody who found it.

12Incident handling

An incident is any event that puts a record at risk: a message sent to the wrong address, a device out of the practice's control, an account used by somebody who should not have it, a deletion that ran when it should not have. The procedure starts on suspicion and does not wait for certainty.

  1. Open the record. Time noticed, who noticed it, what is known and what is only suspected. The record opens before the cause is understood, because a reconstruction written afterwards is worth less than a note written at the time.
  2. Contain. Credentials rotated, sessions ended, access revoked, and where a message went astray the recipient is asked to delete it and to confirm that they have.
  3. Assess. Which records, how many people, and what could follow for them. The measure is what the event could do to a person, not how awkward it is for the practice.
  4. Report. Where the assessment finds a risk to people's rights and freedoms, the Commissioner is told. The deadline is 72 hours measured from the point the practice became aware, and a report filed later than that carries the reason for the delay.
  5. Tell the people affected. Where the risk to them is high they hear directly, without waiting for the investigation to close: what happened, what it means for them, what has been done, and what they can usefully do themselves.
  6. Where the practice is processor, the client is told without undue delay and ahead of anything else, because the notification clock that matters is theirs and it starts when they know.
  7. Close and review. What allowed it, what was changed as a result, and whether that change actually shipped. The entry is kept for six years and the review is part of it.

A near miss goes on the same form as an incident. A practice that only writes down the failures it could not conceal learns nothing from the ones it caught in time.

13Rights, and how a request runs

The UK GDPR gives you the rights below. They are restated here because a right nobody can locate is not much of a right.

  • To be informed. Served by this document.
  • Of access. A copy of what is held about you, with the purposes, the recipients and the retention period for each.
  • To rectification. Correction of anything inaccurate, and completion of anything misleading by omission.
  • To erasure. Removal where the record is no longer needed for the purpose it was created for, or where an objection succeeds.
  • To restriction. Handling paused while an accuracy dispute or an objection is worked out.
  • To portability. A machine-readable copy of what you supplied, where the basis is consent or contract and the handling is automated.
  • To object. Against anything resting on legitimate interests, at any time and without giving a reason.
  • Against solely automated decisions producing a legal or similarly significant effect. Nothing here produces one, so this right has nothing to bite on.

Making a request

Send it to [email protected]. Put Data protection request at the front of the subject line, which is what causes it to be routed as a request instead of read as an enquiry. Then say what you want in your own words: naming an Article is neither required nor expected, and asking for the wrong one costs you nothing.

What then happens, in order

  1. The request is logged on the working day it arrives, together with the date the statutory period starts.
  2. Identity is checked in proportion to the risk. Writing from the address that holds the correspondence is itself the check, and nothing further is asked for. Identity documents are requested only where answering the wrong person would disclose somebody else's information.
  3. The answer goes out inside one month. Article 12(3) permits two further months for a complex request or several made together; where that extension is used you are told inside the first month and given the reason for it.
  4. Nothing is charged. A fee is possible only for a request that is manifestly unfounded or excessive, and in that situation the practical alternative is a refusal with reasons.
  5. A refusal, whole or partial, arrives with the reason, the exemption relied on, and the route for challenging it.

Where the records in question belong to a client, the request cannot be answered here at all. Section 8 sets out what happens instead, and it happens whether or not you ask for it.

14Children and young people

The practice sells to organisations. No part of this website is directed at a child and nothing on it collects information from a visitor. A message that proves to have been sent by a child is removed rather than kept on file, and no reply is sent beyond one telling them so.

Client systems are a different matter, and they are where this practice's subject and data protection meet most directly. A record made about a child may have to stay legible for decades. A childhood health record is the clearest case: the person it describes may need it as an adult, long after the service that created it has been reorganised, renamed or absorbed into something else, and long after everyone who wrote in it has moved on.

Retention for those records is the client's decision and is usually fixed by statute or by a national schedule. What the practice contributes is design. That the record can be read by somebody who was not present when it was made. That its retention period travels attached to the record instead of living in a policy document nobody migrates. That an export produces something the person the record is about could actually use on the day they finally ask for it, rather than a file that technically satisfies a portability duty.

15Concerns and complaints

Raise it here first if you are willing to. Write to [email protected] with Data protection complaint in the subject line. A director looks into it, and the answer arrives in writing inside one month with the reasons behind it and a note of anything that has changed as a result. Where the conclusion is that nothing went wrong, the answer says so directly and sets out why.

You are entitled to take the matter to the supervisory authority instead, or as well, and nothing obliges you to come here first. The supervisory authority for the United Kingdom is the Information Commissioner.

Supervisory authority
DetailEntry
AuthorityInformation Commissioner's Office
PostWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone0303 123 1113
Onlineico.org.uk

A complaint made there costs you nothing to bring, and the office can examine it without any participation from the practice.

16Document control

Version and review
FieldEntry
DocumentPrivacy notice, TRYGG HEALTH LTD
Version2.0
Issued14 August 2026
SupersedesVersion 1.0, issued 10 August 2026
ReviewAugust 2027, or earlier if the handling changes
Approved byThe directors of the company
CompanyTRYGG HEALTH LTD, company number 17061747, England and Wales
Address for this notice[email protected]

A change affecting how information about you is handled is not made quietly. The version number moves, the issue date moves, and a note at the head of this page records what changed and stays there for at least thirty days. Fixing a typographical error or a broken link warrants neither.

This is a working governance document, written by the practice for the practice and published because the people it describes are entitled to read it. It is not legal advice to anyone.