Privacy Policy

Welcome to Healthy Worlds (healthyworlds.co.uk). Your privacy is important to us, and we are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you visit our website. It also outlines your rights under various international laws and how we comply with them. Please read this policy carefully.

1. Who We Are

Healthy Worlds operates the website healthyworlds.co.uk. We are based in the United Kingdom and aim to provide resources and information to promote healthier living. For questions about this Privacy Policy or your data, please contact us at:
Email: nextgenzdigital.uk@gmail.com
Address: NEXTGENZ DIGITAL LTD
124 CITY ROAD
LONDON
EC1V2NX

2. What Data We Collect

When you visit healthyworlds.co.uk, we may collect the following types of data:

  • Personal Data: Information like your IP address, browser type, device information, and approximate location (derived from your IP address).
  • Usage Data: Details about how you interact with our site, such as pages visited, time spent, and clicks, collected via cookies and analytics tools.
  • Social Media Data: If you interact with embedded social media features (e.g., liking or sharing content), those platforms may collect data about you (see Section 6).
  • Uploaded Content: If you upload files (e.g., images, PDFs, or text) via forms or comments, we may store that content.

We only collect data necessary to improve your experience and operate our website effectively.

3. How We Use Cookies

Cookies are small text files stored on your device to help our website function and enhance your experience. Here’s how we use them:

  • Essential Cookies: These are necessary for the site to work, such as remembering your preferences or enabling basic functionality. Consent isn’t required for these under most laws.
  • Analytics Cookies: We use Google Analytics to track site usage (e.g., page views, visitor numbers). These cookies collect data like your IP address and browsing behavior.
  • Social Media Cookies: Embedded social media features (e.g., Facebook Like buttons, Twitter widgets) may set cookies to track your activity for their purposes.
  • Third-Party Cookies: Some cookies come from third-party services we embed (e.g., advertising or video content).

International Laws on Cookies

  • UK GDPR and PECR (Privacy and Electronic Communications Regulations): In the UK, we must inform you about cookies and obtain your consent for non-essential ones (e.g., analytics or social media cookies). Consent must be clear, specific, and opt-in, not pre-checked or assumed. You can manage your preferences via our cookie banner.
  • EU GDPR and ePrivacy Directive: If you’re in the European Economic Area (EEA), the same rules apply—non-essential cookies require consent. The ePrivacy Directive (soon to be replaced by the ePrivacy Regulation) complements the GDPR by regulating electronic communications, including cookies.
  • US Laws: The US lacks a federal cookie law, but states like California (CCPA/CPRA) require transparency about data collection and an opt-out option for selling personal data. We don’t sell your data, but we disclose cookie use here.
  • Other Regions: Laws vary globally. For example, Canada’s PIPEDA requires transparency and consent for data collection, while Australia’s Privacy Act may apply if we target Australian users.

You’ll see a cookie banner when you first visit our site. You can accept, reject, or customize your cookie settings. We won’t set non-essential cookies without your consent.

4. Google Analytics

We use Google Analytics to understand how visitors use our site. It collects:

  • IP Addresses: Google Analytics 4 (GA4) anonymizes IP addresses for EU/EEA users before processing, meaning full IPs aren’t stored.
  • User Behavior: Data like page views, session duration, and device type.
  • Unique Identifiers: Cookies assign a unique ID to track returning visitors.

International Laws on Google Analytics

  • UK GDPR and EU GDPR: Google Analytics can comply with GDPR if configured correctly. We’ve disabled data sharing with other Google products and signed a Data Processing Agreement with Google. However, data transfers to the US (where Google is based) rely on the EU-U.S. Data Privacy Framework (DPF), adopted in July 2023. The DPF ensures adequate protection for EU/UK data sent to certified US companies like Google, though it faces ongoing legal challenges.
  • Schrems II Ruling (2020): The EU Court of Justice invalidated the Privacy Shield (a prior framework), raising concerns about US surveillance laws (e.g., FISA 702). The DPF addresses some concerns, but you should know your data may still be transferred to the US.
  • Other Regions: In places without adequacy agreements (e.g., outside the EEA or UK), we rely on Standard Contractual Clauses (SCCs) with Google to safeguard data transfers.

You can opt out of Google Analytics via our cookie banner or by installing the Google Analytics Opt-Out Browser Add-on.

5. Data Saving and Storage

We save data to provide our services and improve your experience:

  • Server Logs: We store IP addresses and access times briefly for security and diagnostics.
  • User Content: Uploaded files or form submissions are stored securely on our servers or with trusted third-party providers.
  • Retention: We keep data only as long as necessary (e.g., analytics data for 14 months, server logs for 30 days) unless legally required otherwise.

International Laws on Data Saving

  • UK GDPR and EU GDPR: Data must be processed lawfully, stored securely, and deleted when no longer needed. You have the right to access, correct, or erase your data (see Section 9).
  • US CCPA/CPRA: If you’re in California, you can request data deletion or opt out of data sales (not applicable here).
  • Global Standards: Laws like Canada’s PIPEDA or Brazil’s LGPD also mandate secure storage and purpose limitation.

Our servers are located in [insert location, e.g., the UK]. If data is transferred internationally, we ensure compliance with applicable laws (e.g., DPF or SCCs).

6. Social Media Embedding

We embed social media features (e.g., Twitter feeds, YouTube videos) to enhance content. These third-party platforms may:

  • Collect your IP address, browsing data, or interaction details.
  • Set their own cookies if you’re logged into their services or interact with the embeds.

International Laws on Social Media Embedding

  • UK GDPR and EU GDPR: We must inform you about third-party data collection and obtain consent for related cookies. These platforms (e.g., Meta, Google) may transfer data to the US under the DPF or SCCs, subject to the same transfer rules as Google Analytics.
  • US Laws: Platforms comply with US laws, but their privacy practices are governed by their own policies (linked below).
  • Other Regions: Similar consent and transparency rules apply where data protection laws exist.

Check the privacy policies of Facebook, Twitter, or YouTube for details on their data practices.

7. How We Use Your Data

We use your data to:

  • Operate and improve healthyworlds.co.uk.
  • Analyze site performance (via Google Analytics).
  • Respond to inquiries or manage uploaded content.
  • Ensure security and comply with legal obligations.

We don’t sell your data or use it for automated decision-making/profiling.

8. Sharing Your Data

We may share your data with:

  • Service Providers: Companies like Google (for Analytics) or hosting providers, under strict agreements.
  • Legal Authorities: If required by law or to protect our rights.
  • Third-Party Embeds: Social media platforms, as noted in Section 6.

All transfers comply with international laws like the UK GDPR, EU GDPR, and DPF/SCCs where applicable.

9. Your Rights

Depending on your location, you have rights under various laws:

  • UK GDPR and EU GDPR: Access, rectify, erase, restrict, or object to processing your data; request data portability; withdraw consent anytime.
  • US CCPA/CPRA: Know what data we collect, request deletion, opt out of sales (not applicable).
  • Other Laws: Similar rights may apply (e.g., Canada’s PIPEDA, Australia’s Privacy Act).

To exercise your rights, email us at [insert email]. We’ll respond within one month, per GDPR requirements.

10. Security

We use reasonable measures (e.g., encryption, secure servers) to protect your data. However, no online system is 100% secure, and we can’t guarantee absolute protection.

11. Changes to This Policy

We may update this Privacy Policy. Changes will be posted here with the updated date. Check back periodically.

12. Contact Us

For questions, complaints, or rights requests, reach out at:
Email: nextgenzdigital.uk@gmail.com
Address: NEXTGENZ DIGITAL LTD
124 CITY ROAD
LONDON
EC1V2NX

If you’re in the UK/EEA and unsatisfied with our response, contact the UK Information Commissioner’s Office (ICO) or your local data protection authority.