Important Notices
Privacy Policy
How we collect, use, share, and protect your personal information
Last updated: [LAST UPDATED DATE]. Effective: [LAST UPDATED DATE].
1. Who we are and how to contact us
This Privacy Policy explains how SirenMold (“we,” “us,” “our”), the operator of SirenMold.com (the “Site”), collects, uses, shares, and protects personal information about visitors, newsletter subscribers, and commenters.
Controller (data controller / “business”): SirenMold, [POSTAL ADDRESS], California.
General contact: hello@sirenmold.com. Privacy contact / requests: privacy@sirenmold.com.
EU representative (Article 27 GDPR), if applicable: [EU REPRESENTATIVE NAME, ADDRESS, EMAIL]. UK representative (Article 27 UK GDPR), if applicable: [UK REPRESENTATIVE NAME, ADDRESS, EMAIL]. Brazilian representative (LGPD Art. 23), if applicable: [BRAZILIAN REPRESENTATIVE].
Data Protection Officer: We have determined that a DPO is not mandatory under GDPR Article 37 because our core activities do not consist of large-scale, regular, systematic monitoring of data subjects or large-scale processing of special category data. We nonetheless maintain a privacy contact at the address above.
2. Scope and what this policy covers
This Policy applies to personal information we collect through the Site, our newsletter, our comment and community features, and any related communications. It does not apply to third-party websites we link to.
Important health-topic notice. SirenMold publishes general health, wellness, and science information. We are not a HIPAA “covered entity” or “business associate” as defined at 45 C.F.R. § 160.103. Information you submit to us is not “protected health information” (PHI) under HIPAA. Separate state, federal, and international laws — described below — may nevertheless apply, and we handle sensitive information accordingly. See also our separate Medical Disclaimer.
3. Information we collect
3.1 Information you give us directly. Newsletter signup: email address; optionally first name; any topic preferences you voluntarily select (we offer only general topics — we do not ask for specific conditions or diagnoses). Comments and community features: the name or pseudonym you choose, the email address you submit (not displayed publicly), any website URL, the contents of your comment, your IP address and browser user-agent at the time of submission (for spam prevention). Contact and support messages: your name, email address, and the contents of your message. Account registration (if offered): username, email, hashed password, and any optional profile fields.
3.2 Information collected automatically. Device and connection data: IP address (approximate geolocation, usually city-level), browser type, operating system, device identifiers, referring URL, pages visited, timestamps, language, and user-agent. Cookies and similar technologies: strictly necessary cookies, and — only with your consent where required — analytics, advertising, affiliate, and preference cookies, pixels, local storage, and SDKs. Analytics events: pageviews, scrolls, clicks, outbound link clicks, form interactions.
3.3 Information we infer. We may infer approximate location from IP address and broad audience interests from pages you view. We do not construct profiles by specific health condition, and we do not tag subscribers by health topic.
4. How we use information and legal bases
We use information to: operate, maintain, and secure the Site; send the newsletter and respond to inquiries; display and moderate comments; analyze audience for editorial planning; and comply with legal obligations. Under GDPR, our legal bases are: consent (newsletter, analytics, advertising), legitimate interest (secure operation, community moderation), and contract/pre-contract (direct inquiries). Under LGPD, we rely on consent, legitimate interest, and contract as applicable.
Special category (health) data under GDPR Article 9. We do not intentionally process health data. Where you voluntarily disclose health information (e.g., in a comment or contact message), we rely on your explicit consent under Article 9(2)(a) (for comments also Article 9(2)(e) where information is manifestly made public). We ask you not to post personal health details in public comments. If you do, you can request removal at any time.
5. Cookies, pixels, and similar tracking technologies
We use first-party and third-party cookies, pixels, and similar technologies. Non-essential cookies and trackers are set only after you grant consent through our cookie banner (EEA, UK, Switzerland, Brazil, and certain US states).
Categories: Strictly necessary (session, CSRF, consent-record, load balancer — no consent required). Preferences (language, theme — consent required in EU/UK). Analytics (Google Analytics 4 — consent required). Advertising (if applicable — consent required). Affiliate (if applicable — consent required).
A complete, live list of cookies is available at [SITE URL]/cookie-policy. You can change cookie preferences at any time through the “Cookie settings” link in the footer. We honor Global Privacy Control (see § 10).
6. Third-party services and data sharing
We do not sell personal information for money. We disclose personal information to service providers acting as processors under data processing agreements: hosting provider, CDN/security (Cloudflare), analytics (Google Analytics 4), newsletter platform (Mailchimp), comment platform, spam filtering (Akismet), and email delivery service. A current list of sub-processors is available at [SITE URL]/subprocessors.
7. International data transfers
Our servers and several processors are located in the United States. Transfers from the EEA and Switzerland rely on: (i) the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), where the recipient is self-certified; and/or (ii) the 2021 Standard Contractual Clauses with supplementary measures. Transfers from the UK rely on the UK-US Data Bridge or the UK Addendum to EU SCCs. Transfers from Brazil comply with LGPD Article 33. You may request a copy of the safeguards by writing to privacy@sirenmold.com.
8. Data retention
Server logs: up to 14 days. Analytics data: up to 14 months at event level; aggregated metrics longer. Newsletter: for as long as you remain subscribed, plus up to 24 months after unsubscribe for suppression and compliance. Comments: retained while published; IP associated with a comment is deleted after 12 months. Contact messages: 24 months. Accounts: duration of account plus 90 days after closure. Breach and security records: 24 months.
9. Data security
We use TLS encryption in transit, encrypted storage, role-based access controls, hardened admin authentication (MFA), vendor due diligence, and routine backups. No online service can guarantee perfect security; we commit to acting in good faith if an incident occurs.
10. Your privacy rights
Regardless of where you live, you may contact us at privacy@sirenmold.com to ask about your data. We will respond within the statutory deadline that applies to you (generally 30-45 days).
EEA, UK, and Switzerland (GDPR / UK GDPR): rights of access, rectification, erasure, restriction, portability, objection (including absolute right to object to direct marketing), and rights concerning automated decision-making. You may withdraw consent at any time. You may lodge a complaint with your national supervisory authority.
California (CCPA/CPRA): right to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination. Use our “Your California Privacy Choices” link or email privacy@sirenmold.com. We recognize and honor Global Privacy Control as a valid opt-out request.
Other US states: Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and any additional state whose law becomes effective after this Policy’s date, have rights to confirm, access, correct, delete, obtain portable copies, opt out of targeted advertising, opt out of sale, and opt out of profiling. We honor Global Privacy Control in all states that require it.
Washington, Nevada, and Connecticut — Consumer Health Data: See our separate Consumer Health Data Privacy Policy at [SITE URL]/consumer-health-data-privacy. We do not sell consumer health data and do not operate geofences around healthcare facilities.
Canada (PIPEDA and Quebec Law 25): You may access and correct your personal information, withdraw consent, and file a complaint with the OPC (priv.gc.ca). Quebec residents have additional rights under Law 25 including portability and de-indexation.
Brazil (LGPD): Rights under LGPD Art. 18 including confirmation, access, correction, anonymization/blocking/deletion, portability, deletion of consent-based data, information about sharing, revocation of consent, and review of automated decisions. Complaints to the ANPD (gov.br/anpd).
Australia: Australian Privacy Principles apply. You may access and correct information, complain to us, and lodge a complaint with the OAIC (oaic.gov.au).
11. Children’s privacy
SirenMold is a general-audience website intended for adults. The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13 within the meaning of COPPA. If we become aware that a child under 13 has provided personal information, we will delete it promptly. Parents or guardians may contact privacy@sirenmold.com.
12. Breach notification
If we discover a personal data breach affecting your information, we will notify the relevant supervisory authority within 72 hours where required (GDPR Art. 33; UK GDPR Art. 33; LGPD Art. 48), and affected individuals without undue delay where there is a high risk. In Canada, we report to the OPC and maintain breach records for 24 months.
13. Do Not Sell or Share My Personal Information
We do not sell personal information for money. If we use advertising networks that constitute “sharing” under CCPA, we disclose that here and provide opt-out at [SITE URL]/do-not-sell-or-share or via Global Privacy Control.
14. Community, comments, and user-generated content
Comments you post are public. Do not post personal health information, contact details, or anything you want to keep private. We moderate for spam, abuse, and content that appears to reveal a third party’s sensitive information. Community rules are in our Terms of Use.
15. Newsletter and email
We send the newsletter only to email addresses that have completed opt-in. Every email includes a one-click unsubscribe link and our postal address, as required by CAN-SPAM, CASL, and ePrivacy Directive Art. 13.
16. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects about you using solely automated processing. We use basic analytics-derived audience segments for editorial planning, which is not automated decision-making within the meaning of GDPR Art. 22.
17. Do we rely on HIPAA? No.
For clarity: we make no claim of HIPAA compliance. We do not offer a HIPAA “covered entity” or “business associate” service. Information you submit to us is not protected health information under HIPAA.
18. Changes to this Policy
We may update this Policy to reflect changes in law, our services, or our practices. Material changes will be highlighted at the top of this page and recorded in the /changelog. The “Last updated” date always reflects the current version.
19. Contact
Email: privacy@sirenmold.com
Post: SirenMold, [POSTAL ADDRESS]
EU representative: [EU REPRESENTATIVE CONTACT]
UK representative: [UK REPRESENTATIVE CONTACT]
Brazilian representative: [BRAZILIAN REPRESENTATIVE CONTACT]
Who we are
Suggested text: Our website address is: https://sirenmold.com.
Comments
Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Who we share your data with
Suggested text: If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where your data is sent
Suggested text: Visitor comments may be checked through an automated spam detection service.
Privacy policy package for a global health information website (2026)
This package contains four deployable documents for a globally accessible health information website with newsletter, comments, analytics, advertising/tracking pixels, affiliate marketing, and a global audience. It is drafted to satisfy the dominant privacy regimes as of April 2026: EU GDPR (Regulation 2016/679) + ePrivacy Directive 2002/58/EC; UK GDPR + Data Protection Act 2018 + PECR, as amended by the Data (Use and Access) Act 2025; CCPA/CPRA as amended by the CPPA regulations effective 1 January 2026; the 20 other US state comprehensive privacy laws in force as of April 2026; Washington My Health My Data Act (RCW Ch. 19.373), Nevada SB 370, and the Connecticut CTDPA consumer health data amendments; PIPEDA and Quebec Law 25; the Australia Privacy Act 1988 as amended by the Privacy and Other Legislation Amendment Act 2024; Brazil LGPD; COPPA under the FTC’s final amended rule (compliance deadline 22 April 2026); and FTC Endorsement Guides (16 CFR Part 255) and Health Breach Notification Rule (16 CFR Part 318, effective 29 July 2024).
How to use this package. Replace every bracketed placeholder. Have counsel licensed in your home jurisdiction review before publication, particularly if you (i) target EU/UK readers and need an Article 27 representative, (ii) are subject to Washington MHMDA (which has a private right of action), or (iii) produce content about medical tourism, therapeutic peptides, GLP-1 drugs, or other regulated substances.
PART A — Privacy policy
[SITE NAME] Privacy Policy Last updated: [LAST UPDATED DATE] Effective: [LAST UPDATED DATE]
1. Who we are and how to contact us
This Privacy Policy explains how [COMPANY NAME] (“we,” “us,” “our”), the operator of [SITE NAME] (the “Site”) located at [SITE URL], collects, uses, shares, and protects personal information about visitors, newsletter subscribers, and commenters.
- Controller (data controller / “business”): [COMPANY NAME], [POSTAL ADDRESS], [JURISDICTION].
- General contact: [CONTACT EMAIL].
- Privacy contact / requests: [PRIVACY EMAIL or CONTACT EMAIL].
- EU representative (Article 27 GDPR), if applicable: [EU REPRESENTATIVE NAME, ADDRESS, EMAIL — e.g., EDPO, Prighter, DP-Dock]. (Required for non-EU operators that target EU readers and whose processing is not “occasional” — most active blogs with EU newsletter subscribers or EU analytics/ad tracking must appoint one.)
- UK representative (Article 27 UK GDPR), if applicable: [UK REPRESENTATIVE NAME, ADDRESS, EMAIL].
- Brazilian representative (LGPD Art. 23), if applicable: [BRAZILIAN REPRESENTATIVE].
- Data Protection Officer: [DPO CONTACT if applicable, otherwise delete this line]. (We have determined that a DPO is not mandatory under GDPR Article 37 because our core activities do not consist of large-scale, regular, systematic monitoring of data subjects or large-scale processing of special category data. We nonetheless maintain a privacy contact at the address above.)
2. Scope and what this policy covers
This Policy applies to personal information we collect through the Site, our newsletter, our comment and community features, and any related communications. It does not apply to third-party websites we link to, including affiliate merchant pages.
Important health-topic notice. [SITE NAME] publishes general health, wellness, and science information. We are not a HIPAA “covered entity” or “business associate” as defined at 45 C.F.R. § 160.103. Information you submit to us is not “protected health information” (PHI) under HIPAA. Separate state, federal, and international laws — described below — may nevertheless apply, and we handle sensitive information accordingly. See also our separate Medical Disclaimer (Part C).
3. Information we collect
3.1 Information you give us directly
- Newsletter signup: email address; optionally first name; any topic preferences you voluntarily select (we offer only general topics such as “weekly roundup” — we do not ask for specific conditions or diagnoses).
- Comments and community features: the name or pseudonym you choose to display; the email address you submit (not displayed publicly); any website URL you submit; the contents of your comment; your IP address and browser user-agent at the time of submission (for spam prevention).
- Contact and support messages: your name, email address, and the contents of your message.
- Account registration (if offered): username, email, hashed password, and any optional profile fields.
- Payments or donations (if offered): processed by our payment processor (see § 6); we do not store full card numbers.
3.2 Information collected automatically
When you browse the Site, we and our service providers automatically collect:
- Device and connection data: IP address (approximate geolocation derived from it, usually city-level), browser type, operating system, device identifiers, referring URL, pages visited, timestamps, language, and user-agent.
- Cookies and similar technologies: strictly necessary cookies, and — only with your consent where required — analytics, advertising, affiliate, and preference cookies, pixels, local storage, and SDKs. See § 7.
- Analytics events: pageviews, scrolls, clicks, outbound link clicks, form interactions, and custom events.
3.3 Information we infer
We may infer approximate location from IP address and broad audience interests from pages you view. We do not construct profiles by specific health condition, and we do not tag subscribers by health topic.
3.4 Categories of personal information under the CCPA/CPRA
Within the last 12 months we have collected the following categories of personal information listed in Cal. Civ. Code § 1798.140(v)(1): (A) identifiers (name, email, IP, account name); (B) customer records (§ 1798.80(e)); (D) commercial information (for donations/purchases, if any); (F) internet or other electronic network activity; (G) coarse geolocation (city-level from IP); and (K) inferences drawn from the above to create a consumer profile reflecting general content preferences. In limited circumstances we may collect sensitive personal information (SPI) under § 1798.140(ae) — specifically, (1) account login credentials (if you create an account) and, voluntarily and only when you submit it, (8) personal information concerning health disclosed within a comment, contact message, or email reply. We do not use or disclose SPI for purposes other than those permitted by § 1798.121(a) and 11 C.C.R. § 7027(m), and we honor your right to limit the use of SPI (see § 11).
4. How we use information and legal bases (GDPR Art. 6 and Art. 9; LGPD Art. 7/11; PIPEDA Principle 3)
| Purpose | Data used | GDPR Art. 6 basis | LGPD Art. 7 basis |
|---|---|---|---|
| Operate, maintain, and secure the Site | Log data, IP, cookies strictly necessary | Art. 6(1)(f) legitimate interest (secure operation; Recital 49) | Art. 7(IX) legitimate interest |
| Send the newsletter and respond to inquiries | Email, name, message content | Art. 6(1)(a) consent (newsletter); Art. 6(1)(b) contract / pre-contract (direct inquiries) | Art. 7(I) consent; Art. 7(V) contract |
| Display and moderate comments | Display name, comment text, email, IP | Art. 6(1)(f) legitimate interest in running a community + Art. 6(1)(a) where a consent checkbox is used | Art. 7(IX) legitimate interest |
| Analytics | Cookies, event data, device info | Art. 6(1)(a) consent (ePrivacy Art. 5(3)) | Art. 7(I) consent |
| Advertising and affiliate tracking | Cookies, pixels, click IDs | Art. 6(1)(a) consent | Art. 7(I) consent |
| Comply with legal obligations / exercise legal rights | As required | Art. 6(1)(c); Art. 6(1)(f) | Art. 7(II); Art. 7(VI) |
Special category (health) data under GDPR Article 9. We do not intentionally process health data. Where you voluntarily disclose health information to us (for example, by describing a condition in a comment, contact message, or email reply), we rely on your explicit consent under Article 9(2)(a) (for comments, we also rely on Article 9(2)(e) where the information is manifestly made public by you). We ask you not to post personal health details in public comments. If you do, you can request removal at any time. Under Brazil LGPD Article 11, we rely on the equivalent highlighted specific consent where sensitive data is processed.
Legitimate interest balancing. Where we rely on legitimate interest (EDPB Guidelines 1/2024), we have documented a balancing assessment that considers the reasonable expectations of the average reader and the minimal intrusiveness of the processing.
5. Cookies, pixels, and similar tracking technologies
5.1 What we set and when
We use first-party and third-party cookies, pixels, SDKs, and similar technologies. Non-essential cookies and trackers are set only after you grant consent through our cookie banner (EEA, UK, Switzerland, Brazil, and certain US states). In other regions we rely on your ability to refuse or withdraw via the same banner at any time.
| Category | Examples | Purpose | Lifetime | Consent required |
|---|---|---|---|---|
| Strictly necessary | Session cookie, CSRF token, consent-record cookie, load balancer | Site functionality and security | Session to 12 months | No |
| Preferences | Language, theme | Remember your choices | Up to 12 months | Yes (UK), Yes (EU) |
| Analytics | Google Analytics 4 (_ga, _ga_*) | Audience measurement | 2–14 months | Yes |
| Advertising | Google Ads, Meta Pixel _fbp, fr | Ad measurement and, where you consent, personalization | Up to 13 months | Yes |
| Affiliate | [NETWORK] click/conversion cookies | Attribute referrals to partner merchants | Up to 90 days | Yes |
A complete, live list of cookies and trackers is available at [SITE URL]/cookie-policy.
5.2 Google Consent Mode v2 (effective 6 March 2024)
For visitors in the EEA, UK, and Switzerland we implement Google Consent Mode v2 via a Google-certified Consent Management Platform and IAB TCF v2.2/2.3 where applicable. We pass four signals — ad_storage, analytics_storage, ad_user_data, ad_personalization — reflecting your choices. We operate in [Basic / Advanced] consent mode. [If Advanced: When you refuse consent, Google tags still send cookieless, anonymous pings for conversion modeling; we disclose this so your choice is informed.]
5.3 Changing your choices
You can change cookie preferences at any time through the “Cookie settings” link in the footer. Withdrawing consent is as easy as granting it (GDPR Art. 7(3)). Browser “Do Not Track” signals are not consistent; we honor Global Privacy Control (see § 11).
6. Third-party services and data sharing
We do not sell personal information for money. We disclose personal information to the following categories of recipients, each acting as a processor under a data processing agreement unless stated otherwise. Sharing that supports cross-context behavioral advertising is treated as “sharing” (CCPA) or “sale” (several states) and is disclosed accordingly.
| Service | Provider / role | Data involved | EU→US transfer mechanism |
|---|---|---|---|
| Hosting | [HOSTING PROVIDER, e.g., Amazon Web Services, Inc.] (processor) | Server logs, request metadata | EU-US Data Privacy Framework + 2021 SCCs fallback |
| CDN / security | Cloudflare, Inc. (processor) | IP, request metadata, TLS headers, bot signals | EU-US DPF + SCCs |
| Analytics | Google Analytics 4 — Google Ireland Ltd. / Google LLC (processor; joint controller for aggregated benchmarking) | Pseudonymous event data, approximate geolocation, device info | EU-US DPF |
| Advertising | Google Ads / AdSense (Google); Meta Pixel / Conversions API (Meta Platforms Ireland Ltd.); [OTHER NETWORKS] (independent controllers for advertising) | Cookies, pixel events, IP, user-agent, Meta cookies _fbp/fr; no Advanced Matching of health terms | EU-US DPF |
| Newsletter | [Mailchimp / Kit / Substack / Beehiiv] (processor) | Email, name, subscription events | EU-US DPF and/or 2021 SCCs |
| Comments | [Native WordPress / Disqus / Hyvor Talk / Giscus] | Display name, email, IP, comment text | EU-US DPF or intra-EEA as applicable |
| Payments (if used) | Stripe, Inc. (processor) | Tokenized card data, billing address, email, IP | EU-US DPF + SCCs |
| Spam filtering | Akismet (Automattic) | Comment metadata, IP | EU-US DPF |
| Email delivery | [Postmark / SendGrid / SES] (processor) | Email, message content, engagement | EU-US DPF + SCCs |
A current list of sub-processors is available at [SITE URL]/subprocessors and is updated when changes occur.
7. International data transfers (GDPR Chapter V; UK IDTA; LGPD Art. 33)
Our servers and several processors are located in the United States and other countries outside the EEA, UK, Switzerland, and Brazil. Transfers from the EEA and Switzerland to the US rely on: (i) the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), where the recipient is self-certified; and/or (ii) the 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with supplementary measures and a Transfer Impact Assessment.
Transfers from the UK rely on the UK-US Data Bridge (operative 12 October 2023) for DPF-certified recipients, or on the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs. Transfers from Brazil comply with LGPD Article 33 using SCCs or equivalent safeguards. You may request a copy of the safeguards by writing to [CONTACT EMAIL].
We note that the Latombe challenge to the EU-US DPF was dismissed by the EU General Court on 3 September 2025 (Case T-553/23); an appeal is pending before the CJEU. If the DPF is invalidated, we will promptly transition to SCCs with supplementary measures.
8. Data retention
We retain personal information only as long as reasonably necessary for the purposes described above, after which we delete, anonymize, or archive in encrypted form.
- Server logs: up to 14 days.
- Analytics data: up to [2 / 14] months at Google’s event level; we retain aggregated, non-identifying metrics longer.
- Newsletter: for as long as you remain subscribed, plus up to 24 months after unsubscribe for suppression and compliance records. You may request deletion earlier.
- Comments: retained while published; edits and deletions processed promptly on request. The IP associated with a comment is deleted after 12 months.
- Contact messages: 24 months.
- Accounts: duration of the account plus 90 days after closure, longer only as legally required.
- Payment records: 7 years (tax/accounting).
- Breach and security records: 24 months (Canada PIPEDA Breach Regulations s. 6).
9. Data security
We use TLS encryption in transit, encrypted storage, role-based access controls, hardened admin authentication (MFA), vendor due diligence, and routine backups. No online service can guarantee perfect security; we commit to acting in good faith if an incident occurs (see § 13).
10. Your privacy rights
Regardless of where you live, you may contact us at [PRIVACY EMAIL] to ask about your data. We will respond within the statutory deadline that applies to you (generally 30–45 days). We will verify your identity in a manner proportionate to the sensitivity of the request.
10.1 EEA, United Kingdom, and Switzerland (GDPR / UK GDPR Articles 15–22 and 77)
You have the rights of access (Art. 15), rectification (Art. 16), erasure / “right to be forgotten” (Art. 17), restriction (Art. 18), portability (Art. 20, where processing is based on consent or contract and carried out by automated means), objection (Art. 21, including an absolute right to object to direct marketing under Art. 21(2)), and rights concerning solely automated decision-making and profiling (Art. 22). You may withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3)). You have the right to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in Ireland, the Data Protection Commission (dataprotection.ie); in France, the CNIL; or with your local DPA. Under the UK Data (Use and Access) Act 2025, you also have a statutory right to complain directly to us (effective 19 June 2026); we will acknowledge within 30 days and respond without undue delay.
10.2 California (CCPA/CPRA)
You have the right to know what we collect and how we use and share it (§§ 1798.100, 1798.110, 1798.115); the right to delete (§ 1798.105); the right to correct (§ 1798.106); the right to opt out of the sale or sharing of personal information, including for cross-context behavioral advertising (§ 1798.120); the right to limit the use and disclosure of sensitive personal information (§ 1798.121); the right to non-discrimination (§ 1798.125); and, as of the CPPA regulations effective 1 January 2026, rights with respect to automated decision-making technology in certain circumstances (phased in by 1 January 2027).
To exercise these rights, use our “Your California Privacy Choices” link at [SITE URL]/do-not-sell-or-share or the “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” links in the footer, or email [PRIVACY EMAIL]. You may designate an authorized agent.
Global Privacy Control. We recognize and honor the Global Privacy Control browser signal as a valid request to opt out of sale/sharing for the browser sending it, consistent with 11 C.C.R. § 7025. When we detect a GPC signal from a California visitor, we display a visible confirmation on-page.
Categories of personal information and SPI we collected, disclosed for a business purpose, and “shared” for cross-context behavioral advertising in the last 12 months are listed in § 3.4 and § 6.
10.3 Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island (and any additional state whose comprehensive privacy law becomes effective after this Policy’s date) have rights to confirm processing and access, correct, delete, obtain a portable copy, opt out of targeted advertising, opt out of the sale of personal data, and opt out of profiling producing legal or similarly significant effects, subject to each statute’s thresholds and exceptions. Sensitive data, including health information, is processed only with your opt-in consent (Utah and Iowa: on notice, with an opt-out). You may appeal a denied request to [PRIVACY EMAIL]; if unsatisfied, you may contact your state Attorney General.
Universal opt-out. We honor Global Privacy Control in California, Colorado, Connecticut, Texas, Montana, Nebraska, Oregon, Delaware, New Hampshire, New Jersey, Maryland, and Minnesota, consistent with each state’s regulations.
Maryland Online Data Privacy Act note. We do not sell sensitive data (including consumer health data), and we collect and process sensitive data only as strictly necessary to provide a product or service you request, as required by Md. Code Ann., Com. Law § 14-4607.
10.4 Washington, Nevada, and Connecticut — Consumer Health Data
Washington residents and persons whose consumer health data is collected in Washington: see our separate Consumer Health Data Privacy Policy at [SITE URL]/consumer-health-data-privacy (required by RCW 19.373.020). It discloses the categories of consumer health data we collect, the purposes, the categories of sources, the categories of third parties and specific affiliates with which we share, and how to exercise your MHMDA rights (to confirm, access, withdraw consent, and delete, including from backups and downstream recipients). Nevada (NRS Ch. 603A) and Connecticut (Public Act 23-56) residents have similar rights, which we honor. We do not sell consumer health data, and we do not operate geofences around healthcare facilities as prohibited by these laws.
10.5 Canada — PIPEDA and Quebec Law 25
You may access and correct your personal information, withdraw consent, and file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec residents have additional rights under the Act respecting the protection of personal information in the private sector (Law 25): access, rectification, portability (since 22 September 2024), de-indexation/erasure, objection to use in an automated decision, and the right to submit observations. Our privacy officer for Quebec Law 25 purposes is [PRIVACY OFFICER NAME — often defaults to the person with highest authority in the enterprise], reachable at [PRIVACY EMAIL]. Quebec complainants may contact the Commission d’accès à l’information (cai.gouv.qc.ca).
10.6 Brazil — LGPD
Data subjects in Brazil have the rights listed in LGPD Art. 18: confirmation, access, correction, anonymization/blocking/deletion of unnecessary or excessive data, portability, deletion of data processed on consent, information about data sharing, information about refusing consent and its consequences, revocation of consent, and review of solely automated decisions (Art. 20). Complaints may be directed to the Autoridade Nacional de Proteção de Dados (ANPD), gov.br/anpd. Our Brazilian representative, if applicable, is identified in § 1.
10.7 Australia
Australian Privacy Principles apply. You may access and correct personal information, complain to us, and — if unresolved — lodge a complaint with the Office of the Australian Information Commissioner (OAIC), oaic.gov.au. We comply with applicable amendments introduced by the Privacy and Other Legislation Amendment Act 2024, including the statutory tort for serious invasions of privacy (effective 10 June 2025) and automated decision-making transparency (effective 10 December 2026, where applicable).
10.8 Other jurisdictions
We respond to lawful requests from residents of other jurisdictions, including those under South Africa’s POPIA, Japan’s APPI, and South Korea’s PIPA, where those laws apply to us.
11. Children’s privacy (COPPA and state child-privacy laws)
[SITE NAME] is a general-audience website intended for adults. The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13 within the meaning of the Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501–6506) and the FTC Rule as amended (compliance deadline 22 April 2026). We apply enhanced protections consistent with the UK Age Appropriate Design Code and, as they become effective, the Australian Children’s Online Privacy Code. If we become aware that a child under 13 has provided personal information, we will delete it promptly. Parents or guardians who believe we may have inadvertently collected information from a child under 13 may contact [PRIVACY EMAIL]. Minors under 16 in the EEA and under 13 in the UK and US whose data we receive through error may likewise have it deleted on request.
12. Affiliate disclosure and advertising (FTC 16 C.F.R. Part 255)
[SITE NAME] participates in affiliate programs, including [Amazon Associates, ShareASale, Impact, CJ, Rakuten, other]. Some links on this Site are affiliate links. If you click an affiliate link and make a purchase, we may earn a commission at no additional cost to you. Affiliate relationships do not influence editorial independence; see our Editorial Policy at [SITE URL]/editorial-policy. We disclose affiliate relationships at point of use in accordance with the FTC Endorsement Guides. We also display advertising through the networks listed in § 6.
13. Breach notification
If we discover a personal data breach affecting your information, we will notify the relevant supervisory authority within 72 hours where required (GDPR Art. 33; UK GDPR Art. 33; LGPD Art. 48), and affected individuals without undue delay where there is a high risk to their rights and freedoms (GDPR Art. 34) or a real risk of significant harm (PIPEDA s. 10.1). In Canada, we report to the OPC and maintain breach records for 24 months. In Washington, Nevada, and Connecticut, we comply with applicable consumer health data breach duties. If the FTC Health Breach Notification Rule (16 C.F.R. Part 318) applies to a feature we offer, we will provide the notice it requires (individuals, FTC, and, for breaches of 500+ individuals, media), no later than 60 days from discovery.
14. Do Not Sell or Share My Personal Information / Your California Privacy Choices
We have “sold” or “shared” the following categories of personal information, as those terms are defined in Cal. Civ. Code § 1798.140, for cross-context behavioral advertising in the last 12 months: identifiers (cookies, device IDs, IP), internet or network activity (pageviews, referrers), and coarse geolocation, to advertising networks listed in § 6. We have not sold sensitive personal information. Opt out at [SITE URL]/do-not-sell-or-share or by turning on Global Privacy Control in your browser.
15. Community, comments, and user-generated content
Comments you post are public. Do not post personal health information, contact details, or anything you want to keep private. We moderate for spam, abuse, defamation, and content that appears to reveal a third party’s sensitive information. Community rules and DMCA/copyright takedown procedures are in our Terms of Use (Part B). Under the UK Online Safety Act and equivalents, we remove illegal content expeditiously once we know of it.
16. Newsletter and email
We send the newsletter only to email addresses that have completed double opt-in. Every email includes a one-click unsubscribe link and our postal address, as required by CAN-SPAM (15 U.S.C. §§ 7701–7713), Canada’s Anti-Spam Legislation (CASL), and ePrivacy Directive Art. 13. You may also write to [PRIVACY EMAIL] to unsubscribe.
17. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects about you using solely automated processing. We use basic analytics-derived audience segments for editorial planning, which is not automated decision-making within the meaning of GDPR Art. 22, CCPA profiling, or LGPD Art. 20.
18. Do we rely on HIPAA? No.
For clarity and to avoid any misimpression: we make no claim of HIPAA compliance, and we do not offer a HIPAA “covered entity” or “business associate” service. Representations to the contrary, whether by us or any third party, would be inaccurate.
19. Changes to this Policy
We may update this Policy to reflect changes in law, our services, or our practices. Material changes will be highlighted at the top of this page, and we will notify newsletter subscribers by email where reasonable. The “Last updated” date at the top of this Policy always reflects the current version.
20. Contact
- Email: [PRIVACY EMAIL]
- Post: [COMPANY NAME], [POSTAL ADDRESS]
- EU representative: [EU REPRESENTATIVE CONTACT]
- UK representative: [UK REPRESENTATIVE CONTACT]
- Brazilian representative: [BRAZILIAN REPRESENTATIVE CONTACT]
Appendix A — Consumer Health Data Privacy Policy (Washington MHMDA required standalone)
Publish at a distinct URL (e.g., [SITE URL]/consumer-health-data-privacy), link prominently on the homepage as a separate link, and include only the MHMDA-required content below.
[SITE NAME] Consumer Health Data Privacy Policy — Last updated: [LAST UPDATED DATE]
- Categories of consumer health data we collect and purposes. We may collect the following categories of consumer health data as defined in RCW 19.373.010: (a) information reasonably linkable to you that you voluntarily submit about health topics in comments, emails, or contact forms; (b) information derived from your interaction with specific health-topic article URLs when you have consented to analytics or advertising cookies, which may permit inferences about health interests. We collect these to operate the Site, display and moderate community features, measure audience, and — where you consent — deliver advertising.
- Categories of sources. Directly from you; automatically from your device when you consent to non-essential cookies.
- Categories of consumer health data shared and purposes of sharing. We share the categories described in (1) with the categories of third parties identified below for analytics and — where you consent — advertising.
- Categories of third parties and specific affiliates. Third-party categories: analytics providers; advertising networks; email service providers; hosting and CDN providers; spam-filtering providers; comment platforms. Specific named affiliates receiving consumer health data: [LIST SPECIFIC NAMED AFFILIATES — e.g., “Google LLC, Meta Platforms Ireland Ltd., Cloudflare Inc., Amazon Web Services Inc., [Newsletter platform], [Other named entities]”].
- Your rights and how to exercise them. You have the right to confirm whether we collect, share, or sell your consumer health data; to access it with a list of third parties and specific affiliates (including contact information); to withdraw consent; and to have your consumer health data deleted, including from archives, backups, and downstream recipients. Email [PRIVACY EMAIL] or use [SITE URL]/privacy-requests. We will respond within 45 days. You may appeal a denial to the same address, and complain to the Washington Attorney General (atg.wa.gov). We do not sell consumer health data, and we will not do so without first obtaining a valid written authorization meeting RCW 19.373.070.
PART B — Terms of Use
[SITE NAME] Terms of Use Last updated: [LAST UPDATED DATE]
1. Acceptance. By accessing [SITE NAME] at [SITE URL] (“Site”), you agree to these Terms of Use and our Privacy Policy and Medical Disclaimer. If you do not agree, do not use the Site.
2. Eligibility. You must be at least 16 years old (13 in the US and UK) to use interactive features. The Site is not directed to children under 13.
3. Informational content only. Content on the Site is published for general informational and educational purposes. It is not medical, legal, financial, or professional advice and is not a substitute for consultation with a qualified professional. See our separate Medical Disclaimer. You use the information at your own risk.
4. License to you. Subject to these Terms, we grant you a limited, revocable, non-exclusive, non-transferable license to access the Site for personal, non-commercial use. You may quote short excerpts with attribution and a link back. All other rights reserved.
5. User-generated content (comments, forum posts, submissions). (a) You retain ownership of content you submit, but grant [COMPANY NAME] a worldwide, royalty-free, sublicensable, perpetual license to host, reproduce, adapt, publish, translate, and display that content on and in connection with the Site and its promotion. (b) You represent that your content is yours, does not infringe any third-party rights, is not unlawful, defamatory, threatening, harassing, hateful, obscene, or misleading, and does not contain personally identifying information about others without consent. (c) Health-topic conduct rules. Do not post identifiable personal health information about yourself that you wish to keep private — comments are public. Do not solicit or provide medical advice to specific individuals, dosing instructions for prescription or controlled substances, vendor referrals for unapproved drugs or “research chemicals,” or content that could reasonably be interpreted as encouraging self-harm. (d) Moderation. We may, but are not obliged to, remove, edit, or refuse any content, and may suspend or terminate accounts that violate these Terms. We will act on illegal content once notified. (e) Reporting. Contact [MODERATION EMAIL] for content concerns.
6. Prohibited uses. You may not (i) scrape or systematically copy the Site; (ii) use the Site to train AI models without our written permission (we reserve all TDM rights under Directive (EU) 2019/790 Art. 4); (iii) bypass security or rate limits; (iv) upload malware; (v) use the Site to violate any law; (vi) impersonate any person; (vii) resell access or content; (viii) use automated access except for standards-compliant search crawlers consistent with our robots.txt.
7. Third-party links and affiliates. The Site links to third-party sites and contains affiliate links. We are not responsible for third-party content, products, or privacy practices. Affiliate relationships are disclosed under the FTC Endorsement Guides.
8. Copyright and DMCA (17 U.S.C. § 512). If you believe content on the Site infringes your copyright, send our designated agent a DMCA notice including: (i) your signature; (ii) identification of the work; (iii) identification of the infringing material and URL; (iv) your contact information; (v) a good-faith statement; (vi) a statement under penalty of perjury of ownership/authorization.
- DMCA Agent: [DMCA AGENT NAME]
- Email: [DMCA EMAIL]
- Post: [POSTAL ADDRESS]
- We follow notice-and-takedown, accept counter-notices, and maintain a repeat-infringer policy.
9. Trademarks. [SITE NAME], our logo, and related marks are our trademarks. Other names are the property of their respective owners.
10. Disclaimers. THE SITE AND ALL CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT ANY HEALTH INFORMATION IS ACCURATE, CURRENT, COMPLETE, OR APPROPRIATE FOR YOUR CIRCUMSTANCES.
11. Limitation of liability. TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT WILL [COMPANY NAME], ITS OFFICERS, EMPLOYEES, CONTRIBUTORS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF YOUR USE OF THE SITE. OUR AGGREGATE LIABILITY WILL NOT EXCEED THE GREATER OF USD 100 OR AMOUNTS YOU PAID TO US IN THE PRIOR 12 MONTHS. Nothing in these Terms limits liability that cannot be limited under applicable law (including consumer-protection statutes, gross negligence, willful misconduct, or personal injury caused by our negligence in jurisdictions that do not permit such limitation).
12. Indemnification. You will indemnify and hold harmless [COMPANY NAME] and its affiliates from any claim arising out of your breach of these Terms, your content, or your misuse of the Site.
13. Changes to the Site and Terms. We may modify or discontinue any part of the Site and may update these Terms. Material changes take effect 30 days after posting; continued use after that date is acceptance.
14. Termination. We may suspend or terminate your access for any violation. Sections 4(b)–(e), 5, 7–12, and 15–18 survive termination.
15. Governing law and venue. These Terms are governed by the laws of [JURISDICTION], excluding its conflict-of-laws rules. Courts located in [JURISDICTION] have exclusive jurisdiction, except that consumers may bring proceedings in the courts of their country of residence where mandatory consumer-protection laws so require.
16. Dispute resolution. Before filing suit, parties will attempt good-faith negotiation for 30 days. [Optional: arbitration clause; class-action waiver. Consult local counsel — these are unenforceable in several jurisdictions (EU consumer law, California in many contexts, Quebec, etc.).]
17. Notices. Legal notices to [COMPANY NAME], [POSTAL ADDRESS], Attn: Legal. To you: by email to the address on file or by on-Site notice.
18. Miscellaneous. If any provision is unenforceable, the rest remains in effect. No waiver is implied. These Terms, together with the Privacy Policy and Medical Disclaimer, are the entire agreement and may not be assigned by you without consent.
19. Contact. [CONTACT EMAIL].
PART C — Medical disclaimer
[SITE NAME] Medical Disclaimer Last updated: [LAST UPDATED DATE]
Please read carefully before relying on any content from [SITE NAME].
1. Informational purpose only. All content on [SITE NAME] — articles, comments, newsletters, images, videos, podcasts, and any other material — is provided for general informational and educational purposes only. Content reflects the opinions of the authors at the time of publication and may not reflect the most current medical research.
2. Not medical advice. Nothing on this Site constitutes medical advice, diagnosis, treatment, or a professional recommendation. No doctor–patient, therapist–client, or other professional relationship is formed by your use of the Site or by any communication with the authors or [COMPANY NAME]. Always seek the advice of a qualified licensed healthcare professional about any medical condition, medication, or treatment. Never disregard, avoid, or delay seeking professional medical advice because of something you read on [SITE NAME].
3. Emergencies. If you believe you are experiencing a medical emergency, call your local emergency number or go to the nearest emergency department immediately. [SITE NAME] is not an emergency service.
4. Medical tourism content. Articles about medical tourism are educational. Providers, clinics, drugs, devices, or procedures abroad may not be licensed, approved, regulated, or insured to US/EU/UK standards; laws regarding standard of care, malpractice recourse, product liability, and data protection differ by country; returning patients may face complications that domestic providers may decline to treat. We do not vet, endorse, coordinate, refer, or have any financial interest in any specific foreign provider unless clearly disclosed on the page. Consider consulting your own physician before traveling for any procedure.
5. Therapeutic peptides, GLP-1s, and compounded or unapproved substances. Content discussing peptides (including BPC-157, TB-500, thymosin analogs, and similar), GLP-1 receptor agonists (semaglutide, tirzepatide, retatrutide and related compounds), hormone analogs, SARMs, “research chemicals,” or compounded or unapproved drugs is educational and scientific. Many of these substances are not FDA-approved for the uses discussed, may be illegal to import or possess in your jurisdiction, may be mislabeled, adulterated, or unsafe, and may cause serious harm. [SITE NAME] does not sell, prescribe, facilitate the purchase of, or endorse any vendor of these substances. Nothing on this Site should be read as a recommendation to use, buy, import, or administer them. Do not use them except under the care of a licensed prescribing clinician who has evaluated you personally.
6. No claims evaluated by a regulator. Statements about products, supplements, diets, routines, or treatments on this Site have not been evaluated by the US Food and Drug Administration and are not intended to diagnose, treat, cure, or prevent any disease within the meaning of the Federal Food, Drug, and Cosmetic Act. Equivalent statements apply under the EMA, MHRA, Health Canada, TGA, ANVISA, and other regulators.
7. Individual variability. Medical science evolves. Individual responses to any intervention differ. Dosage and other quantitative information in articles is taken from published sources and is not a dosing instruction. Do not self-treat.
8. Third-party content and links. Links to external sites, citations, and comments by third parties are not endorsements and are not verified by us.
9. Limitation of liability. To the maximum extent permitted by law, [COMPANY NAME], authors, contributors, and affiliates are not liable for any loss, injury, damage, or harm — direct, indirect, consequential, or otherwise — arising from reliance on Site content. By using the Site you accept this risk and waive such claims to the extent permitted by law.
10. Consent to updates. We may revise this Disclaimer at any time. The “Last updated” date reflects the current version.
11. Contact. [CONTACT EMAIL].
PART D — Operational compliance guide (plain language)
The documents above only work if your site actually behaves the way they say. Below is a practical checklist of what you still need to configure. Items flagged ⚖ are ones where small health publishers most often fail compliance audits — prioritize these.
Cookie banner and consent
- ⚖ Install a Google-certified Consent Management Platform that supports Google Consent Mode v2 and IAB TCF v2.2/2.3. For a small health blog, Complianz (WordPress), CookieYes, or Iubenda are cost-effective. OneTrust and Cookiebot/Usercentrics fit larger budgets.
- Configure prior blocking — no analytics, advertising, or affiliate scripts load until consent is granted. Strictly necessary and the consent-record cookie are the only cookies set before action.
- First layer must display Accept All / Reject All / Manage Preferences with equal prominence. No pre-ticked boxes, no dark patterns, no “legitimate interest” sliders for advertising (ICO August 2023 position; EDPB Guidelines 03/2022).
- Persistent “Cookie settings” link in the footer so users can withdraw consent as easily as they gave it (GDPR Art. 7(3)).
- Re-prompt for consent at least every 12–13 months (CNIL) or when your vendor list materially changes.
- Keep time-stamped consent logs for at least 3 years.
Global Privacy Control
- ⚖ Implement server-side or client-side GPC detection (the
Sec-GPC: 1header ornavigator.globalPrivacyControl). When detected, automatically treat the request as an opt-out of sale/sharing and propagate to ad/analytics tags via Consent Mode v2ad_user_dataandad_personalizationsignals set to “denied.” - Display a visible confirmation on-page for California visitors (11 C.C.R. § 7025, as amended effective 1 Jan 2026).
Data subject request handling
- Build a privacy-requests intake form ([SITE URL]/privacy-requests) that captures jurisdiction, request type, identity verification, and authorized-agent information.
- Maintain an internal workflow with deadlines: 45 days (CCPA, most US state laws), 30 days (GDPR, UK GDPR — extendable), 15 days (LGPD), 30 days (PIPEDA), 30 days (Quebec Law 25).
- Document your identity-verification procedure and refusal grounds.
- Set up an appeal inbox for states that require an appeal mechanism (VA, CO, CT, TX, OR, MT, DE, NH, NJ, TN, MN, MD, IN, KY, RI).
Retention schedules
- Set GA4 event-data retention to 2 or 14 months in Admin → Data Settings → Data Retention.
- Configure server log rotation to 14 days.
- Implement automatic comment IP truncation or deletion at 12 months.
- Document the retention schedule in your Record of Processing (ROPA).
Vendor and Data Processing Agreements
- ⚖ Sign DPAs with every processor (usually auto-accepted in terms of service: Google, Meta, Mailchimp, Cloudflare, AWS, Stripe). Archive PDFs.
- Verify EU-US Data Privacy Framework certification at dataprivacyframework.gov for each US vendor. Re-check at least quarterly.
- Keep 2021 SCCs (or UK IDTA/Addendum) as fallback in every DPA.
- Complete a Transfer Impact Assessment for material US transfers.
- Maintain a public sub-processor list at /subprocessors and update before material changes.
Newsletter operations
- Turn on double opt-in in your newsletter platform.
- Put a physical postal address and one-click unsubscribe in every email (CAN-SPAM, CASL, ePrivacy).
- Store consent timestamps and the source of signup.
- Do not segment your list by health condition.
Comments and community
- Display a pre-submission notice: “Comments are public. Please do not post personal health details.” This creates a clearer consent record if a commenter discloses Art. 9 data.
- ⚖ Disable Gravatar or disclose it. Consider Hyvor Talk or native WordPress in preference to Disqus.
- Keep a moderation log.
Health-topic technical hygiene
- ⚖ Do not install Meta Pixel, Google Ads remarketing, TikTok Pixel, LinkedIn Insight Tag, or similar on pages discussing specific conditions, symptoms, medications, or treatments. Use contextual advertising instead. This is the single most important control for avoiding FTC enforcement (GoodRx, BetterHelp, Monument, Cerebral) and MHMDA class-action exposure.
- Disable Advanced Matching on the Meta Pixel if you keep it on general pages.
- Avoid custom event parameters that contain health terms.
- Strip query strings that might contain health terms before they reach analytics.
- Review ad creative: do not use retargeting creative that implies knowledge of a user’s condition.
Washington MHMDA specifics
- Publish your Consumer Health Data Privacy Policy at a separate URL with only MHMDA-required content, and link it separately and prominently on the homepage — not bundled with the general privacy policy.
- Maintain the list of specific named affiliates receiving consumer health data, including contact information.
- Do not operate geofences within 2,000 feet of healthcare facilities.
- Build an opt-in consent UI that is unbundled from general terms and not a dark pattern; hovering, muting, or inactivity cannot count as consent.
- Maintain a valid-written-authorization workflow in case you ever sell consumer health data (you should not).
Children
- Add a signup age gate or age-verification banner if your audience is likely mixed.
- Train moderators to remove content that looks like it was posted by a child under 13, and to process deletion promptly.
- Review the FTC’s final COPPA Rule amendments (compliance 22 April 2026) against any interactive features.
Security baseline
- MFA on admin accounts, CMS, DNS registrar, hosting, and payments.
- Automated patching of CMS and plugins.
- Offsite encrypted backups; test restore at least yearly.
- Breach response plan with 72-hour notification runbook (GDPR/UK GDPR/LGPD) and PIPEDA RROSH assessment template.
Representatives and registrations
- Appoint an EU Article 27 representative if you target EU readers. Budget €200–500/year.
- Appoint a UK Article 27 representative if you target UK readers.
- Appoint a Brazilian representative under LGPD Art. 23 if you target Brazilian readers.
- Register as a data controller with the ICO if you are UK-established (fee ~£40/year for small orgs).
- Appoint a privacy officer for Quebec Law 25 and publish contact details.
- Register a DMCA agent at the US Copyright Office DMCA Designated Agent Directory ($6, renew every 3 years).
Records and governance
- Keep an Art. 30 ROPA listing each processing activity, purpose, data categories, recipients, transfers, retention, and security measures.
- Complete a DPIA for any condition-specific forum, health quiz, or symptom tracker before launch; likely unnecessary for a pure content blog.
- Run a legitimate-interest assessment (LIA) for each LI-based processing activity.
- Quarterly: review cookie scan output; verify DPF status of US vendors; review breach log.
Content-side operational controls (health-specific)
- Apply the Medical Disclaimer as a sticky link in the footer, as a modal the first time a peptide/medical-tourism/compounded-drug article is opened, and within the article’s top 200 words.
- Editorial checklist for peptide/GLP-1/medical-tourism posts: (i) no dosing instructions; (ii) no vendor links; (iii) disclaimer block; (iv) no claims to diagnose/treat/cure; (v) no “HIPAA” language anywhere; (vi) sensitive-tag flag prevents ad pixels from loading.
What to avoid saying in the policy (audit reminders)
- Do not claim HIPAA compliance or display HIPAA seals.
- Do not promise that you “never share” or “never sell” health data if any third-party script loads on health pages.
- Do not promise “100% confidential,” “anonymous,” or “fully secure.”
- Do not claim to provide medical advice, diagnosis, or treatment.
- Do not bundle MHMDA disclosures into the general privacy policy (Washington AG guidance requires standalone).
- Do not list affiliates only by category where the named-affiliate disclosure is required (MHMDA).
- Do not omit the US state list from your rights section just because you “don’t think you meet the threshold” — most small health publishers meet Maryland, Delaware, New Hampshire, and Rhode Island thresholds at 10,000–35,000 consumers.
When to consult a lawyer
Have counsel review before launch, and at least annually thereafter, for: (i) your specific jurisdiction-of-establishment rules; (ii) whether you need an Article 27 representative; (iii) whether Maryland MODPA’s strict-necessity limit affects your business model; (iv) whether your specific features (quizzes, symptom tools, accounts, telehealth referrals) bring you within the FTC Health Breach Notification Rule or HIPAA; (v) arbitration/class-action-waiver enforceability in your governing-law jurisdiction; (vi) editorial content on therapeutic peptides, GLP-1s, compounded drugs, or medical tourism — FDA warning letters increased sharply in 2025, and multi-state AG actions are expanding; (vii) any feature involving children or mixed-audience content; (viii) LLM/AI features that touch user data.
Sources and authorities relied on (for your auditor)
Regulation (EU) 2016/679 (GDPR), Arts. 5, 6, 7, 9, 13–22, 27, 30, 33–34, 37, 45–46; Directive 2002/58/EC Art. 5(3), Art. 13; Commission Implementing Decision (EU) 2021/914 (2021 SCCs); Commission Implementing Decision (EU) 2023/1795 (EU-US DPF); EDPB Guidelines 05/2020 (consent), 03/2022 v2.0 (deceptive design), 1/2024 (legitimate interests), Opinion 08/2024 (consent or pay); CJEU Planet49 C-673/17, Schrems II C-311/18, IAB Europe C-604/22, KNLTB C-621/22, OT C-184/20, Latombe T-553/23; UK Data Protection Act 2018; PECR 2003 Reg. 6; Data (Use and Access) Act 2025; ICO Online Tracking Strategy 2025; Cal. Civ. Code §§ 1798.100, .105, .106, .110, .115, .120, .121, .125, .130, .135, .140, .150, .185; 11 C.C.R. §§ 7001–7304 (CPPA regs effective 1 Jan 2026); Va. Code §§ 59.1-575 et seq.; Colo. Rev. Stat. §§ 6-1-1301 et seq.; Conn. Gen. Stat. §§ 42-515 et seq.; Utah Code § 13-61-101 et seq.; Tex. Bus. & Com. Code Ch. 541; Or. Rev. Stat. §§ 646A.570 et seq.; Mont. Code §§ 30-14-2801 et seq.; Iowa Code Ch. 715D; Del. Code tit. 6 Ch. 12D; N.H. Rev. Stat. Ch. 507-H; N.J.S.A. 56:8-166.4 et seq.; Neb. Rev. Stat. § 87-1101 et seq.; Tenn. Code § 47-18-3201 et seq.; Minn. Stat. Ch. 325O; Md. Code, Com. Law §§ 14-4601 et seq.; Ind. Code Art. 24-15; Ky. Rev. Stat. § 367.3611 et seq.; R.I. Gen. Laws § 6-48.1-1 et seq.; RCW Ch. 19.373 (MHMDA) and RCW Ch. 19.86; Nev. Rev. Stat. Ch. 603A as amended by SB 370 (2023); 2023 Conn. Pub. Act 23-56; PIPEDA (S.C. 2000, c. 5); CQLR c. P-39.1 as amended by Quebec Law 25; Privacy Act 1988 (Cth) as amended by Privacy and Other Legislation Amendment Act 2024; Lei nº 13.709/2018 (LGPD); 15 U.S.C. § 45 (FTC Act § 5); 15 U.S.C. §§ 6501–6506 and 16 C.F.R. Part 312 (COPPA, as amended 22 Apr 2025; compliance 22 Apr 2026); 16 C.F.R. Part 255 (Endorsement Guides, 88 Fed. Reg. 48092, 2023); 16 C.F.R. Part 318 (Health Breach Notification Rule, 89 Fed. Reg. 47028, effective 29 Jul 2024); 45 C.F.R. § 160.103 (HIPAA definitions); FTC enforcement actions in GoodRx, BetterHelp, Premom, Monument, Cerebral; Meta Business Tools health policy; Google Ads/Analytics EU transfer and consent guidance.
This package is provided as a template for deployment. It is not legal advice. Have a lawyer in your jurisdiction review before publishing, and re-review at least annually.