International Privacy Notice
Effective 2026-07-24 · For visitors in the United Kingdom and European Economic Area
The short version
GLP-1 Healthcare is a US-based publisher aimed primarily at a US audience. We process one thing: the standard server log data your browser sends to request a page. We set no cookies, run no analytics, and build no profiles — so there is no consent to collect and no special-category health data in our hands.
This notice supplements our Privacy Policy for visitors in the UK and EEA. It is written on the basis that where UK or EU GDPR applies to our processing, we will meet those standards — rather than asserting a territorial-scope conclusion that depends on facts about targeting and monitoring.
1. Controller
GLP-1 Healthcare determines the purposes and means of the limited processing described here. Contact privacy@glp1.healthcare.
We have not appointed a Data Protection Officer. A DPO is required where an organisation is a public authority, carries out large-scale systematic monitoring, or processes special categories of data at large scale. We do none of these — the whole design of this site is the absence of monitoring.
2. What we process, and why
| Data | Purpose | Lawful basis |
|---|---|---|
| Server request dataIP address, browser type and version, page requested, timestamp | Delivering the page, keeping the site secure, diagnosing faults | Legitimate interests (Art. 6(1)(f)) — operating a secure, functioning website. Assessed as not overridden by your interests, since the data is not used to identify you, profile you, or combined with anything else. |
| CorrespondenceOnly if you choose to email us | Replying to you | Legitimate interests (Art. 6(1)(f)) — responding to a message you sent us. |
Special category data. Health data is a special category under Article 9. We do not collect it. Reading a page about a medication does not create health data in our hands, because we do not record who read what.
3. Your rights
Under the UK and EU GDPR you have rights of access, rectification, erasure, restriction, objection, and portability, and a right not to be subject to solely automated decision-making with legal or similarly significant effects. We carry out no such automated decision-making.
Because we operate no accounts and hold no identifiers we can link to a person, we usually cannot connect server log data to you — which means there is typically nothing to access, rectify, or erase. Under Article 11, where we cannot identify you we are not required to acquire additional information purely to do so, and we will not ask you for identity documents we would then have to store. We will explain this plainly in response to any request.
4. International transfers
The site is hosted by Vercel Inc., a US company, and served from a global edge network. If you are in the UK or EEA, your request data is processed in the United States and possibly other locations. Where such transfers require a safeguard, they are made under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum as incorporated into our provider’s data processing terms.
5. Retention
Server log data is retained only as long as needed for security and operational purposes. Correspondence is kept only as long as needed to deal with the matter it concerns.
6. Complaints
You may complain to your local supervisory authority. In the UK this is the Information Commissioner’s Office. In the EEA it is the authority in your country of residence. We would rather you told us first at privacy@glp1.healthcare, but you do not have to.
7. A note on scope
Much of the practical content on this site — drug pricing, insurance pathways, the telehealth provider directory — is specific to the United States and will not reflect how these medications are accessed or regulated where you live. Clinical information sourced from the FDA is likewise US labelling. Check your own national regulator.