Privacy & cookies
Data controller: skinoncology.net is operated by its author (a UK-registered NHS consultant). Identity can be verified for legitimate enquiries via the contact page. ICO registration number: ZB280884.
Summary
- No advertising. None.
- No cookies are set by this site unless you opt in via the cookie banner.
- If you opt in, Google Analytics 4 is used for anonymous, aggregate site-flow data only — no advertising features, no profile building, IP anonymised.
- You can withdraw consent any time via the Cookie preferences link in the footer.
What is collected
Without your consent (always)
- The site itself sets no cookies until you have given consent.
- Standard server-level access logs (IP address, user-agent string, requested URL, timestamp) are written by the hosting provider for security and abuse prevention. They are not used for analytics and are retained for 30–90 days per the provider's default.
With your consent (opt-in via cookie banner)
- Google Analytics 4 sets two first-party cookies that record an anonymous visitor ID and session state.
- GA4 collects: pages visited, time on page, navigation flow, referring website, browser and operating-system family, approximate geographic location (country / region, derived from anonymised IP). No personal identifiers are collected. IP addresses are anonymised before storage.
- GA4 is configured with IP anonymisation on, Google Signals off and ad-personalisation features off — the most privacy-respecting GA4 configuration that still gives anonymous flow data.
When you use the contact form
- The content of your message, plus your name and email if you supply them. Used only to respond to your enquiry; not stored beyond what is needed.
Cookies set by this site
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
_ga | Google Analytics (only with your consent) | Distinguishes unique browsers for anonymous analytics | ~13 months |
_ga_8RF9QQS9WM | Google Analytics (only with your consent) | Session state for this property | ~13 months |
No advertising cookies. No third-party tracking cookies. No browser-fingerprinting. No social-media tracking pixels.
Newsletter subscription
If you choose to subscribe to the fortnightly skinoncology.net newsletter, the following applies. Subscription is entirely optional; the rest of the site is fully usable without it.
- What is collected: your email address, and optionally your first name and professional role (e.g. dermatologist, plastic surgeon, oncologist, GP, specialist nurse, trainee). You provide these only by completing the sign-up form.
- Purpose: to send you a fortnightly digest of UK skin-oncology developments (NICE technology appraisals, NHS England commissioning, BAD / RCPath guidance, key trials) and notable new content added to this site. It is used for no other purpose.
- Lawful basis: your explicit consent (UK GDPR Article 6(1)(a); PECR 2003 Regulation 22). We use double opt-in — you must confirm via a link emailed to you before any newsletter is sent.
- Where your data is stored: your subscription data is not stored on skinoncology.net's servers. It is held by our email-service processor, Kit (kit.com, operated by ConvertKit LLC, United States), which stores the list, sends the emails and handles unsubscribes on our behalf. See Kit's privacy notice. Where data is transferred outside the UK / EEA, transfers rely on Standard Contractual Clauses and the UK–US Data Bridge.
- Unsubscribe: every newsletter contains a one-click unsubscribe link. You may withdraw consent at any time, immediately and at no cost.
- Retention: your data is kept only while your subscription is active. If you unsubscribe, your data is removed from active sending and deleted within 30 days.
- Transfer of the subscriber list: if skinoncology.net is sold, merged with, or transferred to another organisation, the subscriber list may transfer to the new owner for continued use for the same purpose (a UK skin-oncology newsletter). You will be notified before any such transfer and given the opportunity to unsubscribe beforehand.
- No sale or sharing: the subscriber list is never sold, rented or shared with advertisers or other third parties, other than the email-service processor named above and any future transfer-of-business described above.
Legal basis
- Analytics: your consent (Privacy and Electronic Communications Regulations 2003 Regulation 6; UK GDPR Article 6(1)(a)). You may withdraw at any time.
- Newsletter: your explicit consent (UK GDPR Article 6(1)(a); PECR 2003 Regulation 22), captured by double opt-in. You may withdraw at any time via the unsubscribe link.
- Contact form: legitimate interest in responding to your enquiry.
- Server access logs: legitimate interest in site security and abuse prevention.
Processors
- Google Ireland Limited (Google Analytics 4) — data is processed under Google's standard data processing terms. Where data is transferred outside the UK / EEA, transfers rely on Standard Contractual Clauses and the UK–US Data Bridge as appropriate.
- Kit / ConvertKit LLC (newsletter, United States) — stores the subscriber list and sends the newsletter on our behalf, only if you subscribe. Transfers rely on Standard Contractual Clauses and the UK–US Data Bridge. See Kit's privacy notice.
- Hosting provider — static file hosting; access logs only.
No data is sold. No data is shared with advertising networks (the site uses none).
Retention
- Google Analytics: user-level and event-level data are deleted after the property's data retention period (configured to 2 months). Aggregated reports are retained indefinitely and contain no individual data.
- Server access logs: 30–90 days, provider default.
- Contact-form messages: kept only while needed to action the enquiry; routinely deleted within 12 months.
- Newsletter subscription: kept while your subscription is active; deleted within 30 days of unsubscribing.
Your rights under UK GDPR
You have the right to:
- Access — request a copy of any personal data held about you.
- Rectify — correct inaccurate data.
- Erase — request deletion (‘right to be forgotten’).
- Restrict — limit how data is processed.
- Object — to processing on the basis of legitimate interest.
- Portability — receive data in a portable format.
- Withdraw consent — for analytics, via the Cookie preferences footer link, immediately and at no cost.
- Complain to the Information Commissioner's Office — ico.org.uk or 0303 123 1113.
Requests via the contact form are responded to within 30 days.
How to control cookies
- On this site: click the Cookie preferences link in the footer to accept or reject anonymous analytics. Your choice is saved in your browser's local storage; clearing site data resets it.
- In your browser: all modern browsers let you block all cookies, block third-party cookies, clear cookies on close, or use private / incognito mode.
- Across all GA-using sites: install the Google Analytics Opt-out Browser Add-on.
Contact
Data-protection enquiries via the contact form. The author of the site acts as the data controller and as the contact for all data-protection matters.

