Violicom Privacy Policy

DocumentPrivacy Policy
Version1.0
Effective date28 July 2026
Applies towww.violicom.co.uk

Contents

Privacy at a glance

This summary highlights the main points from our Privacy Policy and does not replace the full Privacy Policy, which provides the complete information about how Violicom handles personal information.

QuestionAt a glance
Who controls your information?Violicom Medical Limited is the controller of personal information collected for its own business purposes, unless a client engagement states otherwise
What do we collect?Primarily business contact details, advisor information, enquiry and correspondence information, client and supplier records, recruitment information, and limited website/server data
Why do we use it?To respond to enquiries, develop and deliver services, manage business relationships, operate and secure the website, administer finances, recruit people and meet legal obligations
Do we sell personal information?No. Violicom does not sell personal information
Do we use advertising or analytics cookies?Violicom does not use any advertising or analytics cookies on its website
Who may receive information?Authorised Violicom personnel and carefully selected service providers, advisers, regulators or authorities where a lawful reason applies
How long is it kept?Only for as long as necessary for the relevant purpose, legal duties, contractual requirements and the establishment or defence of legal claims
What rights do you have?Depending on the circumstances: information, access, correction, erasure, restriction, objection, portability, withdrawal of consent and complaint to the Information Commissioner’s Office (ICO)

Violicom does not sell personal information. Where third-party service providers process information for Violicom, they do so only for agreed purposes and under appropriate contractual and security safeguards

Our privacy principles

TransparencyWe explain what information we use, why we use it and the choices available to you
Data minimisationWe aim to collect only personal information that is relevant and reasonably necessary
Purpose limitationWe use personal information for clear and legitimate purposes and do not repurpose it in any way
Security and confidentialityWe apply proportionate technical and organisational measures to protect information
AccuracyWe take reasonable steps to keep personal information accurate and up to date
Retention disciplineWe keep information only for as long as it remains necessary or legally justified
AccountabilityWe review our practices, suppliers, documentation and controls as our business and technology evolve

How information moves through Violicom

1You contact or work with Violicom For example, through the website, email, telephone, a meeting, an event, a proposal, a client project or a recruitment enquiry

2We collect relevant information We receive the information you provide and may generate related records such as correspondence, project notes, contracts, invoices or security logs

3We use it for a defined purpose We use the information to respond, provide services, manage relationships, operate securely or comply with legal duties

4We protect and control access Access is limited according to business need, and appropriate technical, contractual and organisational safeguards are used

5We retain or securely dispose of it Information is kept only while needed and is then deleted, anonymised or securely archived where appropriate

6You can exercise your rights You may contact Violicom about your information or complain to the ICO

Privacy Policy

Trust is central to every relationship we build. Whether we are supporting a scientific meeting, developing educational materials, creating digital solutions or responding to a website enquiry.

This Privacy Policy explains how Violicom collects, uses, stores, shares and protects personal information when you visit our website, contact us, work with us or otherwise interact with our business. It also explains the rights available to you under UK data protection law.

1. Who we are and when this policy applies

Violicom Medical Limited is a company registered in England and Wales under company number 12871017. Our registered office is at 1 Andromeda House, Calleva Park, Aldermaston, Reading, Berkshire, RG7 8AP, United Kingdom. Violicom provides medical communications, medical education, scientific, strategic, digital and related consultancy services.

For personal information processed for Violicom’s own purposes, Violicom is normally the ‘controller’. This means we determine why and how the information is used. In some client projects, Violicom may act as a ‘processor’ and handle personal information on the instructions of a client. In those circumstances, the client’s privacy information and relevant contract will also apply.

This policy applies to personal information collected through or in connection with:

  • The Violicom website and its contact form
  • Email, telephone, video calls and written correspondence
  • Client, prospective-client, supplier and partner relationships
  • Proposals, contracts, projects, meetings, workshops, conferences and events
  • Recruitment, freelance or consultancy enquiries, where applicable
  • Business administration, finance, security, legal and compliance activities

This policy does not govern third-party websites, platforms or services that are independently controlled by other organisations. Their own privacy notices apply.

2. The law and key terms

Violicom processes personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations 2003 (PECR).

‘Personal information’ or ‘personal data’ means information relating to an identified or identifiable living individual. It can include obvious identifiers, such as a name or email address, and online identifiers such as an IP address or cookie identifier.

‘Special category data’ includes certain more sensitive information, such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, genetic or biometric data used for identification, and information about a person’s sex life or sexual orientation. Criminal-offence data is protected under separate rules.

3. Personal information we may collect

Information you provide directly

Depending on your relationship and interaction with Violicom, you may provide:

  • Identity and professional information, including name, title, role, employer, professional interests and areas of expertise
  • Business contact details, including email address, telephone number and postal address
  • Enquiry and correspondence information, including the content of messages, meeting notes and follow-up actions
  • Client and project information, including briefs, schedules, contact lists, approvals, feedback, deliverables and relevant records
  • Commercial and contractual information, including proposals, quotes, contracts, purchase orders, invoices, payment status and supplier details
  • Event information, including attendance and dietary or accessibility requirements
  • Recruitment information, including a CV, work history, qualifications, references, portfolio, right-to-work information and interview notes
  • Any other personal information you choose to provide

Information generated through our relationship

Violicom may create or receive records during business activities, such as project correspondence, meeting records, task allocations, review comments, contract records, invoicing records, quality-control records and information needed to manage a professional relationship.

Website and technical information

When you access our website, the website host, server, security tools or WordPress components may process limited technical information. This may include IP address, date and time of access, requested page, browser and device information, referring page, error information and security-related logs.

Violicom uses strictly necessary non-tracking cookies on its website(s). These cookies are used for the essential functions of our website(s), such as security, navigation, and session management. Additionally, we use third-party analytical cookies that help us analyse how you use our website(s), store your preferences, and provide content relevant to you. These cookies will only be stored in your browser with your prior consent.

Information received from other sources

Violicom may receive professional contact information from clients, colleagues, event organisers, publicly available professional sources, referrals, company websites, professional networks or service providers. Where required, we will provide appropriate privacy information within the period required by law.

Special category and criminal-offence information

Violicom does not seek to collect special category or criminal-offence data through our general website. Such information may occasionally arise in a professional, event, recruitment or client-project context. Where Violicom acts as controller, it will process that information only where a lawful basis and any additional legal condition apply, and with safeguards appropriate to the sensitivity of the information.

4. How and why we use personal information

ActivityPurposeLikely lawful basis
Website and service enquiriesTo respond, provide requested information, arrange discussions, understand requirements and follow upLegitimate interests in responding to business enquiries and developing relationships; steps at your request before entering a contract
Proposals and contractsTo prepare proposals, agree terms, conduct due diligence and enter or administer a contractSteps before contract; performance of a contract; legitimate interests in business administration
Client projects and servicesTo plan, deliver, quality-control, document and communicate about agreed servicesPerformance of a contract; legitimate interests; legal obligations where relevant
Client, partner and supplier relationshipsTo maintain contact, coordinate work, manage performance, resolve issues and administer the relationshipContract; legitimate interests in operating and improving our business
Finance and administrationTo issue and process invoices, maintain accounts, manage payments and comply with tax and audit requirementsContract; legal obligation; legitimate interests
Website operation and securityTo operate, troubleshoot, secure and protect the website, systems, devices and communicationsLegitimate interests in security, service availability and fraud or misuse prevention; legal obligations where applicable
Business developmentTo manage professional relationships and, where legally permitted, communicate about relevant services or opportunitiesLegitimate interests; consent where required by PECR or other law
Events and meetingsTo organise attendance, logistics, communications, accessibility and appropriate follow-upContract; legitimate interests; consent or special-category condition where necessary
Recruitment and resourcingTo assess applications, arrange interviews, verify suitability and maintain appropriate recruitment recordsSteps before contract; legitimate interests; legal obligations; consent in limited cases
Legal and complianceTo comply with law, respond to lawful requests, manage disputes and establish, exercise or defend legal claimsLegal obligation; legitimate interests; legal claims conditions where applicable
Business changeTo evaluate or implement a reorganisation, investment, merger, acquisition or saleLegitimate interests, subject to appropriate confidentiality and safeguards

The applicable lawful basis depends on the specific facts. Where we rely on legitimate interests, we consider the purpose, necessity and potential effect on individuals. You may object to processing based on legitimate interests, although the right is not absolute.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing undertaken before withdrawal. Violicom will not rely on consent where another lawful basis more appropriately reflects the relationship.

Violicom does not currently use personal information from the website for solely automated decisions that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law.

5. Medical, scientific and client-project information

Violicom works in medical communications and may handle scientific or healthcare-related material for clients. This does not necessarily mean that the material is personal information. Where project materials do contain personal information, the roles of the parties must be assessed for the relevant project.

Where Violicom acts as a processor for a client, Violicom will handle personal information in accordance with the client’s documented instructions, the project contract or data-processing agreement, confidentiality requirements and applicable law. Individuals should normally direct questions about that processing to the client controller identified in the relevant privacy notice.

Where project information can be anonymised or de-identified without undermining the agreed purpose, Violicom encourages the use of appropriately minimised data.

Confidentiality is fundamental to Violicom’s work. Client information will be accessed only by people who need it for an authorised purpose and handled in line with contractual, security and professional obligations

6. Direct marketing and professional communications

Violicom may communicate with existing and prospective business contacts about services, projects, events or professional matters where permitted by law. Depending on the recipient and the communication channel, Violicom may rely on legitimate interests, consent or an applicable PECR rule.

You may ask Violicom to stop sending direct marketing at any time by using an unsubscribe method provided in the message or by contacting violicom@violicom.co.uk. We may retain a minimal suppression record to respect the request.

Service, contractual, project, safety, legal and administrative communications are not normally marketing communications and may continue where necessary.

7. Cookies and similar technologies

Cookies and similar technologies can store information on, or access information from, a device. PECR generally requires clear information and consent before non-essential technologies are used. Strictly necessary technologies may be exempt from the consent requirement, but users should still receive appropriate information.

Only strictly necessary cookies (that are necessary for the technical functionalities of our website) are enabled on our website(s) until further cookies are specifically accepted, as per GDPR regulations. This means any cookie that does not fall under the category of ‘strictly necessary’ are not set on your browser until you have given consent to use it, and are therefore blocked and no data collected from you. If you reject the use of non-strictly necessary, the use of these cookies are not set and no data will be collected from you.

Please see our Cookies Policy for further information on the cookies used on our website(s).

8. Who we share personal information with

Violicom does not sell personal information. We may share it where reasonably necessary and lawful with:

  • Clients, project partners, speakers, consultants, freelancers or collaborators involved in an authorised project
  • Website hosting, email, cloud storage, collaboration, document-management, backup, IT-support, cybersecurity and communications providers
  • Accountants, auditors, insurers, banks, legal advisers and other professional advisers
  • Event venues, travel or logistics providers where required for arrangements
  • Regulators, the Association of the British Pharmaceutical Industry (ABPI), courts, law-enforcement agencies, tax authorities or other public bodies where disclosure is required or legally justified
  • Parties involved in a proposed or completed business reorganisation, investment, merger, acquisition or sale, subject to appropriate confidentiality and safeguards

Service providers acting as processors are always selected with due care and bound by written terms addressing confidentiality, security, permitted processing, sub-processors, assistance with rights, deletion or return, and audit or assurance as appropriate.

The precise categories and identities of recipients can vary by project and are documented internally. On request, Violicom can provide further information where required and appropriate.

9. International transfers

Some service providers, clients, project participants or systems may be located outside the United Kingdom or may make information accessible from another country. A transfer of personal information outside the UK will take place only where permitted by applicable law.

Depending on the destination and arrangement, safeguards may include:

  • UK adequacy regulations
  • The UK International Data Transfer Agreement
  • The UK Addendum to the European Commission’s Standard Contractual Clauses
  • Another legally recognised transfer mechanism
  • Supplementary technical, contractual or organisational controls where appropriate

Violicom maintains an up-to-date supplier and transfer register identifying relevant countries, safeguards and transfer-risk assessments. Individuals may contact us for further information about safeguards applicable to their information, subject to confidentiality and security considerations.

10. Security

Violicom uses proportionate technical and organisational measures intended to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures will depend on the information, system and risk, and may include:

  • Encrypted website connections using HTTPS
  • Access controls, strong passwords and multi-factor authentication where supported
  • Device, software, anti-malware and security-update controls
  • Role- or need-based access to client and business information
  • Secure cloud, email, file-transfer, storage and backup arrangements
  • Confidentiality obligations and secure working practices
  • Supplier due diligence and contractual controls
  • Incident identification, escalation and response procedures
  • Secure deletion, disposal or anonymisation where appropriate

No internet transmission or storage system can be guaranteed completely secure. Users should avoid sending highly sensitive information through ordinary email or website forms unless the risks have been considered and suitable arrangements agreed.

If a personal-data breach occurs, Violicom will assess the risk, take reasonable containment and remediation steps, document the incident, and notify the ICO and affected individuals where the legal thresholds are met.

11. Retention and deletion

Violicom keeps personal information only for as long as it is reasonably needed for the purpose for which it was collected, related business requirements, legal and accounting obligations, contractual requirements, dispute resolution, or the establishment, exercise or defence of legal claims.

Record categoryIndicative retention approach
General website or service enquiryNormally up to 24 months after the last meaningful contact, unless it develops into a client, supplier or other continuing relationship
Prospective-client and proposal recordsNormally up to 3 years after the last substantive activity; longer where needed for relationship history, tender requirements or legal claims
Client contracts, project correspondence and core project recordsNormally 10 years after project or relationship completion, subject to contract, client instruction, regulatory context and legal-claim considerations, but may be longer depending on ongoing relationships
Financial, tax and accounting recordsNormally 6 years after the end of the relevant accounting period, or longer where law or professional advice requires
Supplier and consultant recordsFor the relationship and normally up to 7 years afterwards where relevant to contracts, payments, tax or legal claims
Recruitment – unsuccessful candidatesNormally 6 to 12 months after the process, unless the individual agrees to a longer talent-pool period or a dispute requires retention
Recruitment – successful candidates and workforce recordsIn accordance with the relevant workforce privacy information and legal, contractual and tax requirements
Event attendance recordsFor the event and an appropriate follow-up period; longer where records form part of a client project, contract, finance record or consented relationship
Website and security logsAccording to host and security settings; typically between 30 days and 12 months unless required for investigation or legal purposes
Marketing preference and suppression recordsFor as long as necessary to demonstrate consent or ensure that an opt-out continues to be respected

These are indicative periods, not inflexible guarantees. A shorter or longer period may apply according to the specific purpose, contract, client instruction, legal requirement, limitation period, security investigation or dispute. When information is no longer required, it will be securely deleted, anonymised or otherwise disposed of.

12. Your data protection rights

Subject to the circumstances and legal exemptions, you may have the following rights:

Be informedReceive clear information about the collection and use of your personal information
AccessAsk whether Violicom processes your personal information and request a copy and related information
RectificationAsk Violicom to correct inaccurate or complete incomplete personal information
ErasureAsk for deletion in circumstances where the law provides this right
RestrictionAsk Violicom to restrict processing in specified circumstances
ObjectObject to processing based on legitimate interests and object at any time to direct marketing
Data portabilityReceive certain information you provided in a structured, commonly used and machine-readable format where processing is automated and based on consent or contract
Withdraw consentWithdraw consent at any time where consent is the lawful basis
Automated decisionsReceive safeguards where a solely automated decision with legal or similarly significant effects is used
ComplainRaise a concern with Violicom and complain to the ICO

Rights are not absolute. Their application depends on the lawful basis, circumstances and statutory exemptions. For example, Violicom may need to retain information to comply with law or to establish, exercise or defend legal claims.

To make a request, contact violicom@violicom.co.uk. Please describe the request and the information concerned. Violicom may ask for information reasonably necessary to confirm identity and protect personal information from unauthorised disclosure.

Violicom will normally respond without undue delay and within one month after receiving a valid request. The period may be extended by up to two further months for a complex request or multiple requests, in which case Violicom will explain the extension within the first month. A fee will not normally be charged, although, the law permits a reasonable fee or refusal in limited circumstances involving manifestly unfounded or excessive requests.

Contact violicom@violicom.co.uk to raise a data protection enquiry. Please do not send identity documents unless Violicom asks for them and provides an appropriate method for transfer

13. Children

The Violicom website and services are directed primarily to businesses, healthcare and life science organisations, professionals and adult users. The general website is not intended for children, and Violicom does not knowingly seek to collect children’s personal information through the contact form.

If you believe a child has provided personal information through the website, contact us so the circumstances can be assessed and appropriate action taken. A client project that legitimately involves information relating to children will be governed by the relevant project arrangements, legal roles, privacy information and safeguards.

The website may link to or embed content from third-party websites or services. Those organisations may independently collect information and apply their own cookies or similar technologies. Violicom does not control independent third-party privacy practices.

Before introducing or retaining embedded maps, videos, forms, social-media content, fonts or similar services, Violicom assess their data flows, cookie behaviour, international transfers and consent requirements. Users should review the privacy information provided by the relevant third party.

15. Changes to this policy

Violicom may update this policy to reflect changes in law, regulatory guidance, business activities, suppliers, website technology or privacy practices. The current version will be published on the website with an effective or last-updated date.

Where a change materially affects how existing personal information is used, Violicom will take reasonable steps to provide additional notice where required. Archived versions are retained.

16. Contact and complaints

Questions, requests and concerns about this policy or how Violicom is handling personal information may be directed to:

OrganisationViolicom Medical Limited
Emailviolicom@violicom.co.uk
Registered office1 Andromeda House, Calleva Park, Aldermaston, Reading, Berkshire, RG7 8AP, United Kingdom
Websitehttps://violicom.co.uk/

Violicom welcomes the opportunity to address concerns directly. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator. The ICO can be contacted through its official website at https://ico.org.uk/. You may also have a right to seek a judicial remedy.

Violicom aims to make its privacy information understandable. Contact us if anything is unclear or if you would like further information about how your personal information is handled

17. Definitions

TermMeaning
ControllerThe organisation that determines the purposes and means of processing personal information
ProcessorAn organisation that processes personal information on behalf of a controller
Personal information / personal dataInformation relating to an identified or identifiable living person
ProcessingAny operation performed on personal information, including collecting, recording, organising, storing, using, sharing, altering or deleting it
Special category dataSpecified sensitive data protected by additional UK GDPR rules
ConsentA freely given, specific, informed and unambiguous indication of wishes given by a clear affirmative action
Legitimate interestsA lawful basis that may apply where processing is necessary for a legitimate purpose and is not overridden by an individual’s interests, rights or freedoms
PECRThe Privacy and Electronic Communications Regulations 2003, which include rules on electronic marketing and cookies or similar technologies

Last updated: 28 July 2026

Scroll to Top