Skip to main content
Trygg

Legal

Privacy notice

Two capacities, kept separate: what we decide about ourselves, and what we hold on a client's instructions. Which one applies decides where your request goes.

Effective 10 August 2026Version 1.0UK GDPR and Data Protection Act 2018

1Who we are, and the two roles

TRYGG HEALTH LTD is a private limited company registered in England and Wales, company number 17061747. "We", "us" and "our" mean that company; "you" means any individual whose personal data we handle.

We handle personal data in two capacities, and which one applies decides where a request should go.

Controller and processor
CapacityWhose dataWho decidesWhere a request goes
ControllerPeople who write to us, prospective and actual client contacts, visitors to this websiteUsDirectly to us
ProcessorData inside a client's system that we build, review or repairThe clientTo that client. We route it if you write to us by mistake

Where we act as a processor we handle a client's data on their documented instructions. We have no product built on it and no purpose of our own for it, and we cannot delete a record on a third party's say-so, because it is not ours to decide about.

2What we hold as controller

Personal data we decide about
CategoryFieldsLawful basisKept
CorrespondenceEmail address, message content and metadataArt. 6(1)(f) legitimate interests: answering a message someone chose to send24 months, or 6 years for a complaint
Client contactsName, work email, role, organisationArt. 6(1)(b) performance of a contract, or Art. 6(1)(f) for a prospective oneDuration of the engagement, then 6 years for the contract record
BillingOrganisation name, billing address, invoice historyArt. 6(1)(c) legal obligation: tax and accounting6 years
Website request logsIP address, timestamp, path, user agent, response code, held by the hosting providerArt. 6(1)(f) legitimate interests: delivering the page and blocking abuseProvider cycle, under 30 days

Not collected

No marketing list, no lead enrichment, no scraped contact data, and no visitor identification service that resolves an IP address to an organisation and puts it in a sales queue. That last practice is common on consultancy websites and it is worth naming rather than merely omitting.

Special category data

We do not seek and do not knowingly hold data concerning health, or any other special category under Article 9. Despite the company name, no engagement we take involves patient data. If special category data reaches us in an attachment, it is deleted and the sender told.

3Your rights

Under the UK GDPR you have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights in relation to automated decision making.

How to exercise them

Email [email protected] with "Data protection request" in the subject. We respond within one month, which Article 12(3) allows to be extended by two further months for a complex request; if we extend, we tell you within the first month and say why. There is no charge.

Objecting where we rely on legitimate interests

You may object at any time. We stop unless we can demonstrate compelling legitimate grounds that override your interests, and for correspondence we will not usually have any, so an objection in practice means deletion.

Automated decisions

We make none. Nothing we run produces a decision about a person with legal or similarly significant effect, so Article 22 is not engaged.

Complaints

If our answer does not satisfy you, complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. You may do so without contacting us first, though we would rather have the chance to fix it.

4Recipients, transfers and security

Who receives personal data
RecipientPurposeLocation
Cloudflare, Inc.Serving and protecting this websiteGlobal edge network, including the United Kingdom
Our email providerReceiving and storing correspondenceUnited Kingdom and the United States
Our accountantStatutory accounts and taxUnited Kingdom

International transfers

Where a recipient is outside the United Kingdom we rely on UK adequacy where it exists, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment. We do not transfer first and paper it afterwards.

Security, and what we do not have

Transport encryption on every connection, encryption at rest provided by the platform, multi-factor authentication on every administrative account, and access limited to those who need it. The most reliable control available to a practice this size is holding less, which is why the table above is short.

TRYGG HEALTH LTD holds no ISO/IEC 27001 certification, no SOC 2 report and no Cyber Essentials certification, has not commissioned a penetration test, and employs no full time security engineer. We will not represent otherwise until one of those is genuinely true.

Personal data breaches

Where a breach is likely to result in a risk to people's rights and freedoms we notify the ICO within 72 hours of becoming aware, as Article 33 requires, and where the risk is high we tell the affected individuals without undue delay under Article 34. Where we are the processor, we notify the client without undue delay so they can meet their own deadline.

5Cookies, changes and contact

This website sets no cookies of its own and runs no analytics. The detail, and the regulation 6 reasoning, are in the cookie statement.

Changes

The version in force is the one published here with the effective date at the top. Where a change materially affects how we handle your data, we will say so at the top of this page for at least 30 days rather than editing quietly.

Contact

TRYGG HEALTH LTD, company number 17061747, registered in England and Wales. Email [email protected].

We have not appointed a Data Protection Officer. Article 37 does not require one for a practice of this size and activity, and appointing a nominal one would be a title rather than a safeguard.

This is a professionally structured document. It is not legal advice.