Legal · Data Protection
Privacy Policy
How Detective Health handles your personal and health data — your rights, our commitments, and how to contact us with any concerns.
Last updated: April 2026 · Applies to: detective-health.com and all associated intake tools

The short version: We collect only the health information you actively provide through our intake forms. We use it solely to deliver your clinical programme. We do not sell it, share it with advertisers, or use it for any purpose other than your care. You have full rights over your data at any time. Contact us at stephen@detective-health.com with any questions or requests.

01
Who We Are

Detective Health is operated by Stephen Duncan Nutrition, a sole trader based in Edinburgh, Scotland. The data controller for all personal data processed through this website and its associated clinical tools is:

Stephen Duncan
Stephen Duncan Nutrition / Detective Health
Edinburgh, Scotland
Email: stephen@detective-health.com
Website: detective-health.com

This Privacy Policy applies to the detective-health.com website, all intake forms and clinical tools hosted on the platform, the Test, Don't Guess book purchase via Gumroad, and any direct email communication with us.

02
What Data We Collect and Why

We collect personal and health data only when you actively provide it — through our intake questionnaires, contact forms, or direct communication. We do not collect data passively beyond standard server logs.

Type of DataWhat We CollectWhy We Collect It
IdentityName, date of birth, email addressTo identify you as a client and communicate about your programme
Health DataSymptom responses, health history, lifestyle factors, laboratory test results, questionnaire responsesTo deliver functional medicine clinical assessment and programme recommendations — this is the core purpose of the service
BiometricHeight, weight, blood pressure (if provided)Clinical context for health assessment
LifestyleDiet, exercise, sleep, stress, supplement useClinical context for programme design
Purchase DataEmail address and purchase confirmation (via Gumroad for book purchases)To confirm your purchase and deliver your digital product
CommunicationEmails and messages you send to usTo respond to your enquiries and support your programme
TechnicalStandard server/access logs (IP address, browser type, pages visited) via Netlify hostingSite security and performance — not used to identify individuals

Health data is special category data under GDPR. We process it on the basis of your explicit consent, which you provide when you submit any intake form or engage with our clinical services.

03
Legal Basis for Processing

We rely on the following legal bases under UK GDPR:

Explicit Consent (Article 9(2)(a)): For processing special category health data submitted through our intake forms and clinical tools. You may withdraw consent at any time by contacting us.

Contract Performance (Article 6(1)(b)): For processing data necessary to deliver the clinical programme or service you have engaged with us for.

Legitimate Interests (Article 6(1)(f)): For technical server logs used to maintain site security and performance. We have assessed that these interests do not override your rights.

04
How We Store and Protect Your Data

Intake form submissions are processed through Netlify Forms, which stores form data on Netlify's servers (US-based, with EU/UK data protection safeguards). Form notification emails are delivered to a private email account accessible only to Stephen Duncan.

Client programme data may also be held in Practice Better, a HIPAA and GDPR-compliant practice management platform used to deliver your programme.

Book purchases are processed through Gumroad, which operates its own privacy policy for payment and transaction data. We receive only your email address and purchase confirmation — we do not receive payment card details.

We implement the following security measures: HTTPS encryption on all data in transit across detective-health.com, security headers (Content Security Policy, HSTS, X-Frame-Options) to protect against common web vulnerabilities, and access to health data restricted to Stephen Duncan only.

We do not: sell your data to any third party · share your data with advertisers · use your data for any purpose other than delivering your clinical programme · run advertising pixels or tracking scripts on this site · store payment card details

05
How Long We Retain Your Data

We retain client health records for 8 years from the date of last contact, in line with UK healthcare practitioner record-keeping guidance. After this period, data is securely deleted.

Intake form submissions from individuals who do not proceed to a clinical programme are retained for 12 months and then deleted.

Purchase records from Gumroad are retained for the period required under UK tax legislation (currently 6 years).

You may request deletion of your data at any time. Where we are required by law to retain certain records, we will inform you of this.

06
Third Parties We Work With
ServicePurposeData Shared
NetlifyWebsite hosting and form processingForm submissions, server logs
Practice BetterClient programme managementName, health history, programme notes
GumroadDigital product delivery (book)Email address, purchase data
Randox / Regenerus Labs / Nordic LabsLaboratory testing (TDG programme clients only)Name, date of birth, test requisition data
Google FontsTypography (no cookies, no tracking)IP address (standard CDN request only)
Anthropic API (via Cloudflare Worker)AI-powered clinical analysis tools (practitioner-facing only)De-identified clinical data entered by practitioner into analysis tools

We do not use Google Analytics, Facebook Pixel, or any other behavioural tracking or advertising technology on detective-health.com.

07
Your Rights Under UK GDPR

You have the following rights regarding your personal data. To exercise any of these rights, contact us at stephen@detective-health.com. We will respond within 30 days.

Right of Access
Request a copy of all personal data we hold about you, free of charge.
Right to Rectification
Request correction of any inaccurate or incomplete data we hold.
Right to Erasure
Request deletion of your personal data, subject to any legal retention obligations.
Right to Restriction
Request that we restrict processing of your data while a complaint is being resolved.
Right to Portability
Request your data in a commonly used, machine-readable format.
Right to Object
Object to processing of your data where we rely on legitimate interests as our legal basis.
Right to Withdraw Consent
Withdraw consent for processing of your health data at any time, without affecting the lawfulness of prior processing.
Right to Complain
Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your rights have been violated.
08
Cookies

Detective-health.com does not use tracking cookies, advertising cookies, or analytics cookies. The only cookies that may be set are strictly necessary functional cookies from Netlify for form submission processing. These are not used for tracking or advertising purposes and do not require your consent under UK law.

We do not use a cookie consent banner because we have no non-essential cookies to consent to.

09
Children's Data

Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at stephen@detective-health.com and we will delete it promptly.

10
Data Breach Procedure

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and notify affected individuals without undue delay. We maintain an internal record of any data breaches, their causes, and the remedial action taken.

11
Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active clients by email. The current version is always available at detective-health.com/privacy.html. The "last updated" date at the top of this page indicates when changes were last made.

12
Contact Us

For any questions, concerns, or requests relating to your data or this Privacy Policy, please contact us:

Data Controller: Stephen Duncan

Practice: Stephen Duncan Nutrition / Detective Health

Email: stephen@detective-health.com

Website: detective-health.com

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113