GDPR Privacy Rights
This notice provides additional information for visitors in the European Economic Area, United Kingdom, and Switzerland about personal-data processing and privacy rights.
Last updated: June 17, 2026
This page supplements the Privacy Policy. It is designed to explain rights in practical language and is not a claim that every provision applies identically in every country or circumstance.
1. Controller and Contact
HealthyHers is the controller for personal data it collects directly through healthyhers.com. You may contact the controller at privacy@healthyhers.com. Because HealthyHers does not intentionally conduct large-scale sensitive-data processing or systematic high-risk monitoring, it has not appointed a separate data protection officer at this time.
2. Personal Data and Purposes
Depending on your interaction, we may process contact details and correspondence you provide; IP address, browser, device, referral, page-view, approximate location, and security events; cookie and local-storage choices; and analytics, engagement, or advertising identifiers where permitted. Purposes include delivering and securing the site, responding to requests, measuring readership with consent, enabling optional features with consent, complying with law, preventing fraud and invalid traffic, and supporting advertising where lawfully configured.
Where Google services such as Google Analytics or Google AdSense are active, Google may receive automatically transmitted information such as page URL, IP address, browser and device information, cookie or local-storage identifiers, approximate location, and interactions. Google describes its processing here: How Google uses information from sites or apps that use our services.
3. Lawful Bases
- Consent: cookies, local storage, advertising storage, ad personalization, analytics, or similar processing where applicable law requires consent.
- Legitimate interests: basic website operation, network security, abuse prevention, fraud prevention, invalid-traffic detection, audience measurement where lawful, aggregate business administration, and responding to ordinary communications, after considering visitor rights.
- Contract or pre-contract steps: when you ask us to address a specific business or licensing request.
- Legal obligation: recordkeeping, lawful process, regulatory requests, or protection of legal rights.
Where processing relies on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal.
4. Your Rights
Subject to legal conditions and exceptions, you may have the right to:
- Confirm whether we process your personal data and obtain access to it.
- Correct inaccurate or incomplete personal data.
- Request deletion of personal data.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests or to direct marketing.
- Receive data you provided in a structured, commonly used, machine-readable format where portability applies.
- Withdraw consent for future processing.
- Not be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects.
HealthyHers does not currently use site visitor data to make solely automated decisions with legal or similarly significant effects.
5. How to Submit a Request
Email privacy@healthyhers.com with the subject "Privacy Rights Request." Describe the right you want to exercise and the interaction involved. We may ask for proportionate information to verify identity and prevent unauthorized disclosure. Do not email copies of sensitive identity documents unless specifically requested through an appropriate method.
We aim to respond without undue delay and generally within one month where GDPR timing applies. A complex or numerous request may permit an extension, in which case we will explain the delay. Rights are usually free, although manifestly unfounded or excessive requests may be handled as permitted by law.
6. Recipients and Processors
Personal data may be processed by hosting and security providers, Google Analytics when consented or otherwise lawfully configured, Grow.me when consented, email and technical providers, professional advisers, Google AdSense and other advertising partners if advertising is active, and fraud-prevention or invalid-traffic detection services. Some providers act as processors for specified services; others may act as independent controllers for their own purposes.
7. International Transfers
Providers may process data outside the EEA, UK, or Switzerland, including in the United States. Where required, transfers may rely on adequacy decisions, approved standard contractual clauses, the EU-U.S. Data Privacy Framework where applicable to a participating provider, or another legally recognized safeguard. Provider documentation governs the specific mechanism used by that provider.
8. Retention
We keep personal data only for a period reasonably connected to the purpose, legal duties, security, dispute resolution, and recordkeeping. Contact correspondence is retained while relevant to the request. Provider-controlled analytics and engagement retention depends on configured settings and provider terms. Consent choices remain in browser storage until changed or cleared.
9. Cookies and Consent
The homepage displays a cookie notice, and browser or provider controls can be used to limit existing analytics and engagement technologies. See the Cookie Policy. If AdSense is activated, Google requires a Google-certified CMP integrated with the IAB Transparency and Consent Framework for personalized advertising in the EEA, UK, and Switzerland. HealthyHers will use the provider-required certified mechanism before serving such personalized ads in those regions. Limited or non-personalized ads may still involve IP address, cookies, local storage, or similar technologies for delivery, frequency capping, measurement, security, fraud prevention, and abuse detection where legally permitted.
10. Complaints
You may contact us first so we can try to resolve a concern. You also have the right to lodge a complaint with the data protection authority in your country of residence, place of work, or place of the alleged infringement. European authorities are listed through the European Data Protection Board. UK visitors may contact the Information Commissioner's Office.
11. Updates
We may update this notice when processing activities, providers, or legal requirements change. The current version and revision date will remain available on this page.