Golden Health Science
In one line
We do not sell your data and we do not advertise. If you accept analytics cookies, one measurement tool runs. You can ask us at any time what we hold about you, and ask us to delete it.
This page says what this site collects and why. It also says how long it keeps it, and what you can make us do about it.
There are no accounts here. There is no shop, and there is no advertising. Most people who read this site never hand over anything personal at all.
Ikechukwu Raymond, who runs this site from Finland.
He is the data controller for this website. That is the legal term for the person who decides what gets collected and why.
Write to us about privacy at privacy@goldenhealthscience.com, or through the contact page at goldenhealthscience.com/contact/
Golden Health Science works under the laws of Finland and the European Union. That includes the General Data Protection Regulation, or GDPR. GDPR is the European law on personal data. It hands people rights over their own information, and it requires anyone holding that information to be careful and open about it.
Your email if you write to us. Some technical detail from your visit. Nothing else.
What reaches us is this.
We use it to read your message and answer it. Nothing more.
Please do not send us medical records, detailed symptoms, or other personal health information. We cannot give personal medical advice, and email is neither secure nor clinical. Send it anyway and we delete it once your message is dealt with, unless the law requires us to keep it.
Like almost every website, this one records some technical detail when you visit. Our web host keeps server and security logs. Those usually hold your IP address, the pages asked for, the time, and your browser type. They exist to keep the site up and keep it safe.
Accept analytics cookies and this site runs Google Analytics 4. It shows us which pages get read, how people arrive, and how they move through the site.
Google Analytics uses pseudonymous identifiers. That means it can tell one browser apart from another without knowing who you are. We never ask it to name anybody. We read the reports as patterns across everybody, not as a trail behind one person. Google states that Google Analytics 4 does not log or store IP addresses.
Decline analytics cookies and Google Analytics never loads at all. None of this is collected.
A cookie is a small text file a website saves on your device. Think of a coat check ticket. It does not hold your coat. It only lets the desk match the ticket next time.
Essential cookies keep the site working. Analytics cookies are optional and load only if you say yes. We record your answer so the banner stops asking on every page. We do not use cookies to follow you to other websites, and we do not use them for advertising. The Cookie Policy lists each one.
We do not sell it, trade it, profile you with it, or advertise to you.
Running a website means a few service providers necessarily handle some data. They are listed further down. That is not the same as sharing or selling it. Each of them acts on our instructions and on nobody else’s.
Consent for analytics. Legitimate interests for the logs and for answering you. Legal obligation where the law says so.
Under GDPR, nobody may handle your personal data just because they feel like it. They need a lawful reason, picked from a short list. Think of it as needing a ticket before you board. Here are ours.
Analytics cookies, and the data they gather, run only if you accept them. Withdraw that consent in the cookie settings at any time and the collecting stops there.
We keep server and security logs to hold the site up, keep it safe, and keep it working. That interest is weighed against your privacy. Answering an email sits here too, since you wrote to us and expect a reply.
Where the law requires us to keep or produce a record, we do.
As briefly as the job allows. Emails about a year, privacy requests two, analytics fourteen months.
Kept while we deal with your message. Then a while longer, in case you write again about the same thing. Normally up to 12 months. Then they go.
Up to 2 years, as proof that we handled the request properly.
For the period our web host sets. Usually a matter of weeks or months.
For as long as that choice stays valid, so we can show that you gave it.
For the period set on our Analytics property. At most 14 months.
Overwritten on a rolling cycle. A copy of something deleted can sit in a backup briefly before the cycle reaches it.
Three providers, each working to our instructions, none of them allowed to market to you.
Provides our web hosting and email. It stores the site and keeps the server and security logs. Based in Lithuania, inside the European Economic Area.
Provides Google Analytics, and only if you accepted analytics cookies.
Records whether you accepted or declined.
Add another service that handles personal data and we will name it here.
It can. When it does, a legal promise recognized under GDPR travels with it.
Some providers may store or handle data outside the European Economic Area. The United States, for instance.
Where that happens we rely on a transfer route that GDPR recognizes. There are two.
One is an adequacy decision. The European Commission judges a country’s protection good enough, as it did for the EU-US Data Privacy Framework.
The other is the Commission’s Standard Contractual Clauses. That is a set contract, and it binds whoever receives the data to European standards.
Picture a sealed envelope carried abroad. The seal helps. It is not the same as never letting the envelope leave the country, and we would rather say so.
Encrypted connections, locked accounts, updated software, and honesty about the limits.
The site is served over HTTPS. That scrambles the connection between your device and the site, so nobody in between can read it.
Access to the website, its email accounts, and its analytics is limited to those who need it. Strong passwords guard it, and two-factor authentication where that exists. Software is kept updated. Backups are taken.
No website or email system is completely secure, and we will not pretend otherwise. If a breach happens and is likely to put your rights at risk, we tell the Finnish supervisory authority. We tell the people affected too, where that is required.
Eight of them. Ask us to use any one and we answer within a month.
Most of these apply in defined circumstances, and none of them is absolute. If one does not apply to your request, we will tell you why.
Ask what personal data we hold about you, and receive a copy.
If something we hold is wrong or incomplete, ask us to fix it.
Ask us to delete personal data we hold about you. This applies in specified circumstances, and we may have to keep some records where the law requires it.
Ask us to limit how we use your data without deleting it. While a correction request is being weighed, for example.
Object to anything we handle on legitimate interests. We stop unless we have compelling grounds that override your rights.
Where we rely on consent, such as analytics cookies, take it back at any time. That does not undo what was lawful before.
Where we handle data on consent or a contract, and by machine, ask for what you gave us. We send it in a common format another service can read.
Complain to the data protection authority where you live. In Finland that is the Office of the Data Protection Ombudsman, at tietosuoja.fi.
To use any of these, email privacy@goldenhealthscience.com. We answer without undue delay, normally within one month. A complicated request, or several at once, may take up to two months more. If that happens, we tell you inside the first month. We may need to confirm who you are before we act.
None are made here.
We make no automated decision about you that carries a legal effect, or anything close to one. We do no profiling of that kind.
Follow one and this policy stops applying.
This site links out to scientific journals, health organizations, and other resources. Once you leave Golden Health Science, we are not responsible for how that site handles privacy. Please read its own policy.
We collect nothing knowingly from anybody under 16.
The articles here are written for adults, though plainly enough that younger readers may get something from them.
Nothing on this site asks a reader to register, subscribe, or hand over personal information. If you are under 16, please do not email us without a parent or guardian. If you believe a child under 16 has sent us personal data, tell us and we will delete it.
The date at the top says when we last changed it.
We may update this policy, for instance if we add a service that handles personal data. Where a change matters, it appears here before it takes effect. So please look at this page now and then.
Questions about this policy, or about how your data is handled? Email privacy@goldenhealthscience.com or use the contact page at goldenhealthscience.com/contact/
First published July 2026 · Last updated August 2026 · Last reviewed August 2026
The rest of the record: Medical Disclaimer · Editorial Policy · How We Review Health Content · Corrections Policy · Terms and Conditions · Cookie Policy · Contact