Who we are
MD Info is an independent UK-English editorial project. We do not operate a casino, do not offer a reader account system, and do not sell personal data. This notice explains what data we collect when you visit the site and how we handle it under the UK GDPR and the Data Protection Act 2018.
What we collect
By default, the site collects the technical data required to serve pages: IP address (used only to route the HTTPS response), user-agent string, page requested, referrer header where present, and the timestamp. Server access logs retain these values for 30 days for security and abuse-prevention purposes, then are automatically pruned. We do not maintain a reader profile beyond this technical log.
Cookies
The site does not use cookies for tracking or advertising. A minimal essential cookie may be set to remember whether you have dismissed the site's cookie banner, if applicable. See our cookies notice for the current list.
Analytics
Where analytics are used, they are configured in a privacy-preserving way: IP truncation, no cross-site tracking, no persistent identifiers, no reader profiling. We aim to keep the editorial reader experience free of surveillance-style measurement.
Your rights
Under UK GDPR you have the right to access data we hold about you, request its correction, request its deletion, restrict processing, object to processing, and — where relevant — port your data to another controller. Given the minimal data we retain, most requests can be handled by IP-address reference during the 30-day log window. Requests should be sent to the editorial contact address.
Third parties
We do not share reader data with third parties for marketing purposes. The site is served by a standard commercial hosting provider that processes technical requests on our behalf. No affiliate networks, ad brokers or reader-remarketing services are integrated.
Legal basis for processing
Under UK GDPR, the lawful basis for processing the minimal technical data described above is our legitimate interest in operating a secure editorial website — routing responses to the correct client, defending against automated abuse (crawlers, spam bots, scraping), and understanding usage patterns at an aggregate level. We do not rely on consent as the primary basis because consent would be disproportionate to the minimal data involved, but where any cookie or storage requires it, an explicit consent mechanism is used.
Retention and deletion
Server access logs retain technical data for 30 days on a rolling window, after which the entries are automatically deleted. Editorial correspondence is retained for the length of an ongoing correction workflow and for a further 12 months in case of follow-up, then deleted. Data-subject access requests generate a short-lived record of the request itself for audit purposes; that record is retained for 24 months.
International transfers
Where our hosting or infrastructure providers process data outside the UK — typically inside the EEA under adequacy decisions, or under UK-approved Standard Contractual Clauses where a provider processes in a third country — the transfer is covered by the appropriate legal safeguards. We do not deliberately transfer reader data to jurisdictions with weaker data-protection regimes.
Data-protection contact
Data-protection queries and rights requests should be sent to privacy [at] mapmydiabetes.co.uk. If you are unsatisfied with our response, you may lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data-protection regulator. Contact details for the ICO are on the ICO's own website (searchable under "ICO make a complaint").
Changes to this notice
Material changes to this notice will be dated at the top of the page. Non-material clarifications may be made without notification. The current version supersedes all previous versions.