What this policy covers
This policy applies to the website at GlaadBlog.org and to the email addresses published on it. It covers three groups of people: readers who arrive from search or a shared link, people who send us a message through our contact page, and subscribers to our email newsletter.
It does not cover any other site you reach by following a link from ours, and it does not cover how a dental practice, insurer or retailer treats your information if you go on to deal with them. Those organisations have their own policies, and we have no control over how they behave.
For the purposes of data protection law, GlaadBlog.org is the controller of the personal data described below. If your question is instead about who writes and checks the content, that is answered on our about page and in the editorial policy.
What GlaadBlog.org collects
There are only three routes by which we end up holding information about you.
1. Information you deliberately give us
- Contact form and email. Your name (or whatever you type in that field), your email address, the subject you pick, and the message itself. If you report a factual error we also keep the URL of the page you were reading.
- Newsletter sign-up. Your email address, the date you subscribed, and the page you subscribed from. Nothing else - no name, no age, no location, and nothing about your teeth.
Please do not send us clinical details, photographs of your mouth, radiographs or treatment plans. We cannot interpret them, we are not able to give you a diagnosis, and handling sensitive health data is something this site is deliberately built to avoid. The medical disclaimer explains why at greater length.
2. Information collected automatically
- Server and security logs. Every web server records requests. Ours log the IP address, user agent, requested URL, referring URL, response code and timestamp. They exist so we can diagnose outages and block abusive traffic, not so we can profile readers.
- Analytics. Which pages were opened, roughly how long each was in view, the device and browser type, a country or city-level region derived from the IP address, and the source that sent you here. We read this in aggregate - which guides people finish and which they abandon halfway - because that is how we decide what to rewrite.
3. What we deliberately do not collect
No behavioural advertising, no cross-site profiles, no device fingerprinting, and no selling, renting or trading of personal information to anybody, ever. We do not ask you to create an account, because nothing on this site needs one.
Why we process it, and our legal bases
If the UK or EU GDPR applies to you, we have to name a lawful basis for each activity rather than simply assert that we need the data. Here they are.
| What we do | Why | Legal basis |
|---|---|---|
| Serve pages and keep logs | Deliver the site, diagnose faults, block abuse | Legitimate interests |
| Measure traffic | See which guides are useful and which need rewriting | Consent where cookie rules require it, otherwise legitimate interests |
| Reply to your message | Answer the question you actually asked | Legitimate interests, or steps taken at your request |
| Send the newsletter | Deliver the emails you signed up for | Consent, withdrawable at any time |
| Log corrections and complaints | Show what was changed, when and why | Legitimate interests; legal obligation where one applies |
Where we rely on legitimate interests we have weighed that interest against your privacy, and you can object at any time using the details at the foot of this page.
Cookies and similar technologies
A cookie is a small file a site asks your browser to store. We use as few as we can, in two categories.
- Strictly necessary. Security, load balancing, and remembering your cookie choice so the banner does not reappear on every page. These need no consent and cannot be switched off without breaking the site.
- Analytics. A first-party identifier that lets the analytics tool tell a returning reader from a new one, so one person reading four guides is not counted as four people. Where consent is legally required these are set only after you give it, and withdrawing consent stops them.
There are no advertising cookies, retargeting pixels or social-media tracking widgets on this site. Every browser lets you block or delete cookies in its settings, and blocking ours will not stop you reading anything on GlaadBlog.org: no guide is gated, paywalled or account-only.
Who else handles your data
Like any small publisher we depend on a handful of specialist suppliers, which act as processors on our instructions. Described generically, they are:
- a hosting and content-delivery provider, which serves the pages and holds the security logs;
- an analytics provider, which produces the aggregate traffic reports;
- an email service provider, which stores the newsletter list and sends the emails;
- a form and inbox provider, which delivers and stores messages sent through the contact page;
- an error-monitoring service, which records technical faults so they can be fixed.
Each is bound by a written processing agreement, may use the data only to provide the service to us, and may not use it for its own purposes. This section is due to be replaced with the real vendor names and links to their own privacy notices; if it has not been by the time you read it, tell us and we will fix it.
We may also disclose information where the law requires it - a valid court order, for example - or where it is necessary to investigate abuse of the site. Nobody else gets it.
How long we keep things
- Server and security logs: up to 30 days, then deleted or anonymised.
- Analytics data: up to 14 months in identifiable form. Aggregate reports, which cannot be traced back to a person, may be kept longer.
- Contact messages: up to 24 months, so we can pick up the thread if you write again about the same issue.
- Correction reports: for as long as the guide they relate to stays published, because that audit trail is part of our editorial policy.
- Newsletter subscriptions: until you unsubscribe. After that we keep your address on a suppression list so you are not accidentally added again.
Your rights under GDPR and CCPA
Depending on where you live you have some or all of the rights below. We do not charge for exercising them and we will not treat you differently for doing so.
- Access - ask for a copy of the personal data we hold about you.
- Correction - have inaccurate data fixed.
- Deletion - ask us to erase it, subject to any legal obligation to retain it.
- Restriction and objection - ask us to pause processing, or object to processing based on legitimate interests.
- Portability - receive what you gave us in a machine-readable format.
- Withdrawal of consent - at any time, without affecting anything done before you withdrew it.
- Opt out of sale or sharing - under the CCPA and CPRA. We do not sell or share personal information and have not done so in the preceding twelve months, so there is nothing here to opt out of.
- Complaint - to your data protection authority. In the UK that is the Information Commissioner's Office; in the EU it is the supervisory authority where you live.
To exercise any of these, email hello@glaadblogsorg.com or use the contact page and say plainly what you want. We answer GDPR requests within one month and CCPA requests within 45 days. We may ask a question or two to confirm the request really comes from you - usually just that you can reply from the address in question - but we will never demand identity documents for a newsletter unsubscribe.
The fastest route out of the newsletter is the unsubscribe link at the foot of every email. It works immediately and does not pass through a human.
Privacy of children
This site is written for adults, including parents and carers looking after a child's teeth. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. There is no age-verification step because there are no accounts - the newsletter is the only thing you can sign up for. If you believe a child has submitted their details to us, write to hello@glaadblogsorg.com and we will delete the record.
International transfers
Our suppliers are mostly based in the United States, so personal data covered by this policy may be transferred outside the UK and the European Economic Area. Where that happens we rely on the safeguards available under data protection law: typically Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision such as the EU-US Data Privacy Framework where the supplier is certified under it. Ask us and we will tell you which mechanism applies to a particular supplier.
Security
The site is served over HTTPS. Access to the mailbox, the newsletter platform and the analytics account is limited to the people who need it and protected by multi-factor authentication. Collecting little is itself a security measure: data we never gathered cannot leak.
No system is perfectly secure and we will not pretend otherwise. If a breach affects your rights and freedoms we will notify the relevant regulator and, where the law requires it, you directly.
Links to other websites
Our guides cite outside sources on purpose - it is the only honest way to write about health. When you follow one of those links, for example to the American Dental Association or the National Institute of Dental and Craniofacial Research, you leave GlaadBlog.org and that organisation's privacy policy takes over. We have no control over what they collect and no visibility of what you do once you arrive. The same applies to any retailer, clinic or journal we cite.
Changes to this policy
If we change tools, start collecting something new, or the law moves, we will update this page and change the date at the top. Material changes - anything altering what is collected or why - will be flagged on the page for at least 30 days. We will not retroactively apply a new purpose to data collected under the old policy without asking you first.
How to contact us
Privacy questions, access requests and deletion requests all go to the same place: hello@glaadblogsorg.com, or the form on the contact page. Postal mail reaches us at 1180 Harbour Way, Suite 400, Portland, OR 97204, US.
If your question is about the accuracy of something we published rather than about your data, the editorial policy explains how corrections work, and the guides hub lists everything currently in print.