Privacy Policy
Last updated: January 2026
1. Who we are
This privacy policy applies to Tarlo, a nutrition guidance practice based at 91 Brick Lane, E1 6QL London, United Kingdom. The data controller for personal information collected through this website is Tarlo. You can contact us regarding data matters by email at [email protected] or by telephone at +44 20 7563 4182.
Tarlo products are nutritional food-supplements registered with the applicable local regulatory authority under food-supplement classification. Products meet compositional and labelling requirements for nutritional supplement categories.
2. What data we collect
When you submit the contact form on this website, we collect the name, email address, and message content you provide. If you select an enquiry type, that preference is also recorded. No payment information, identity documents, or sensitive personal data are collected through this website.
We also collect standard web server log data when you visit this site: your IP address, browser type, referring URL, and pages accessed. This data is retained in server logs for up to 90 days for operational and security purposes.
If you contact us by telephone or email directly, any personal data contained in that communication is collected and stored in our correspondence records.
3. How we use your data
Contact form submissions are used solely for the purpose of responding to your enquiry and, where relevant, initiating the intake assessment process. Your contact details are not used for marketing communications without your explicit written consent.
If you engage with Tarlo as an ongoing client, intake records, habit protocol documents, and correspondence are maintained in a documented archive as described in the methodology documentation. These records are retained for three years following the conclusion of an engagement.
We do not sell, rent, or share personal data with third parties for commercial purposes. Data may be shared with service providers who assist in operating this website (hosting, email routing) under data processing agreements consistent with UK data protection requirements.
4. Legal basis for processing
Processing of contact form data is carried out on the basis of legitimate interests — specifically, responding to an enquiry you have initiated. Where ongoing client records are maintained, the legal basis is the performance of a service arrangement.
Analytical cookies, where accepted, are processed on the basis of your consent. You may withdraw cookie consent at any time using the Cookie Settings link in the footer of any page on this site.
5. Your rights
Under UK data protection law, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data in certain circumstances; object to processing based on legitimate interests; and request restriction of processing pending a complaint or verification.
To exercise any of these rights, contact us in writing at [email protected]. We will respond within 30 days of receipt.
If you consider that your data has been handled incorrectly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters. Details are available at ico.org.uk.
6. Data security and retention
Personal data submitted via this website is stored on servers located within the United Kingdom and European Economic Area. We maintain appropriate technical and organisational measures to protect personal data from unauthorised access, loss, or disclosure.
Contact form data is retained for up to 12 months from the date of submission, unless an ongoing engagement is established, in which case the three-year retention schedule described above applies. Server log data is retained for 90 days.
7. Changes to this policy
This privacy policy may be updated periodically to reflect changes in our data practices or applicable law. The most recent version is always available on this page. Material changes will be communicated to active clients by email.