GDPR & CCPA Privacy Policy

Effective date: November 01, 2025
This Privacy Policy explains what personal data is collected, why it is processed, how long it is retained, and how users can exercise their rights under GDPR and CCPA/CPRA.

Who we are and how to contact us

  • Controller: HealthyWarmPlate (contact via the site’s contact page).
  • The controller is responsible for website interactions, communications, and handling privacy requests.

What data we collect

  • Identifiers: name, email address, IP address, and device/browser information submitted via forms or collected through site interactions.
  • Internet activity: page views, referring URLs, approximate geolocation from IP, and interactions with analytics or advertising (if enabled).
  • User‑generated content: comments, messages, and form submissions provided voluntarily.

Why we process data (purposes)

  • To operate, secure, and improve the website, respond to inquiries, and measure performance via analytics.
  • To support advertising, affiliate attributions, and email communications with appropriate disclosures and controls.

Legal bases for processing (GDPR)

  • Consent for analytics, advertising cookies, and marketing emails where applicable.
  • Legitimate interests for basic analytics, fraud prevention, and security balanced against user rights.
  • Contract or pre‑contract steps when responding to requests or providing requested features.
  • Legal obligations where processing is necessary to comply with applicable laws.

Data recipients and transfers

  • Service providers such as analytics platforms, advertising partners, content delivery networks, and affiliate platforms may process limited data under instructions.
  • Where data is transferred internationally, appropriate safeguards are applied consistent with GDPR requirements.

Retention and security

  • Data is retained only as long as needed for the stated purposes or legal obligations, with reasonable measures to reduce risks of unauthorized access or disclosure.
  • Retention criteria consider purpose, legal requirements, and operational needs to avoid unnecessary storage.

Your rights (GDPR)

  • Access, rectification, erasure, restriction, portability, and objection to processing, plus the right to withdraw consent at any time.
  • You may lodge a complaint with a supervisory authority if you believe your rights have been infringed.

Your rights (CCPA/CPRA)

  • Right to know, delete, opt‑out of sale/share of personal information, and the right to non‑discrimination for exercising these rights.
  • Instructions to exercise rights are provided below and via the contact page for verification and timely response.

Cookies and consent

  • Non‑essential cookies (analytics/advertising) require prior consent and remain off until you choose to enable them.
  • You can accept, reject, or manage granular preferences at any time through the consent banner or a “Cookie Preferences” link.

How to exercise your rights

  • Submit requests through the site’s contact page with sufficient details to verify your identity; responses will be provided within required timelines.
  • If your request relates to cookie consent, adjust settings via the banner or the “Cookie Preferences” link at any time.

Updates to this policy

  • This policy may be updated to reflect changes in practices or law, and the effective date will be revised accordingly.