Violicom Privacy Policy
| Document | Privacy Policy |
| Version | 1.0 |
| Effective date | 28 July 2026 |
| Applies to | www.violicom.co.uk |
Contents
- Privacy at a glance
- Our privacy principles
- How information moves through Violicom
- Privacy Policy
- 1. Who we are and when this policy applies
- 2. The law and key terms
- 3. Personal information we may collect
- 4. How and why we use personal information
- 5. Medical, scientific and client-project information
- 6. Direct marketing and professional communications
- 7. Cookies and similar technologies
- 8. Who we share personal information with
- 9. International transfers
- 10. Security
- 11. Retention and deletion
- 12.Your data protection rights
- 13. Children
- 14. Third-party links and embedded services
- 15. Changes to this policy
- 16. Contact and complaints
- 17. Definitions
Privacy at a glance
This summary highlights the main points from our Privacy Policy and does not replace the full Privacy Policy, which provides the complete information about how Violicom handles personal information.
| Question | At a glance |
| Who controls your information? | Violicom Medical Limited is the controller of personal information collected for its own business purposes, unless a client engagement states otherwise |
| What do we collect? | Primarily business contact details, advisor information, enquiry and correspondence information, client and supplier records, recruitment information, and limited website/server data |
| Why do we use it? | To respond to enquiries, develop and deliver services, manage business relationships, operate and secure the website, administer finances, recruit people and meet legal obligations |
| Do we sell personal information? | No. Violicom does not sell personal information |
| Do we use advertising or analytics cookies? | Violicom does not use any advertising or analytics cookies on its website |
| Who may receive information? | Authorised Violicom personnel and carefully selected service providers, advisers, regulators or authorities where a lawful reason applies |
| How long is it kept? | Only for as long as necessary for the relevant purpose, legal duties, contractual requirements and the establishment or defence of legal claims |
| What rights do you have? | Depending on the circumstances: information, access, correction, erasure, restriction, objection, portability, withdrawal of consent and complaint to the Information Commissioner’s Office (ICO) |
Violicom does not sell personal information. Where third-party service providers process information for Violicom, they do so only for agreed purposes and under appropriate contractual and security safeguards
Our privacy principles
| Transparency | We explain what information we use, why we use it and the choices available to you |
| Data minimisation | We aim to collect only personal information that is relevant and reasonably necessary |
| Purpose limitation | We use personal information for clear and legitimate purposes and do not repurpose it in any way |
| Security and confidentiality | We apply proportionate technical and organisational measures to protect information |
| Accuracy | We take reasonable steps to keep personal information accurate and up to date |
| Retention discipline | We keep information only for as long as it remains necessary or legally justified |
| Accountability | We review our practices, suppliers, documentation and controls as our business and technology evolve |
How information moves through Violicom
| 1 | You contact or work with Violicom For example, through the website, email, telephone, a meeting, an event, a proposal, a client project or a recruitment enquiry |
↓
| 2 | We collect relevant information We receive the information you provide and may generate related records such as correspondence, project notes, contracts, invoices or security logs |
↓
| 3 | We use it for a defined purpose We use the information to respond, provide services, manage relationships, operate securely or comply with legal duties |
↓
| 4 | We protect and control access Access is limited according to business need, and appropriate technical, contractual and organisational safeguards are used |
↓
| 5 | We retain or securely dispose of it Information is kept only while needed and is then deleted, anonymised or securely archived where appropriate |
↓
| 6 | You can exercise your rights You may contact Violicom about your information or complain to the ICO |
Privacy Policy
Trust is central to every relationship we build. Whether we are supporting a scientific meeting, developing educational materials, creating digital solutions or responding to a website enquiry.
This Privacy Policy explains how Violicom collects, uses, stores, shares and protects personal information when you visit our website, contact us, work with us or otherwise interact with our business. It also explains the rights available to you under UK data protection law.
1. Who we are and when this policy applies
Violicom Medical Limited is a company registered in England and Wales under company number 12871017. Our registered office is at 1 Andromeda House, Calleva Park, Aldermaston, Reading, Berkshire, RG7 8AP, United Kingdom. Violicom provides medical communications, medical education, scientific, strategic, digital and related consultancy services.
For personal information processed for Violicom’s own purposes, Violicom is normally the ‘controller’. This means we determine why and how the information is used. In some client projects, Violicom may act as a ‘processor’ and handle personal information on the instructions of a client. In those circumstances, the client’s privacy information and relevant contract will also apply.
This policy applies to personal information collected through or in connection with:
- The Violicom website and its contact form
- Email, telephone, video calls and written correspondence
- Client, prospective-client, supplier and partner relationships
- Proposals, contracts, projects, meetings, workshops, conferences and events
- Recruitment, freelance or consultancy enquiries, where applicable
- Business administration, finance, security, legal and compliance activities
This policy does not govern third-party websites, platforms or services that are independently controlled by other organisations. Their own privacy notices apply.
2. The law and key terms
Violicom processes personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations 2003 (PECR).
‘Personal information’ or ‘personal data’ means information relating to an identified or identifiable living individual. It can include obvious identifiers, such as a name or email address, and online identifiers such as an IP address or cookie identifier.
‘Special category data’ includes certain more sensitive information, such as data revealing health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, genetic or biometric data used for identification, and information about a person’s sex life or sexual orientation. Criminal-offence data is protected under separate rules.
3. Personal information we may collect
Information you provide directly
Depending on your relationship and interaction with Violicom, you may provide:
- Identity and professional information, including name, title, role, employer, professional interests and areas of expertise
- Business contact details, including email address, telephone number and postal address
- Enquiry and correspondence information, including the content of messages, meeting notes and follow-up actions
- Client and project information, including briefs, schedules, contact lists, approvals, feedback, deliverables and relevant records
- Commercial and contractual information, including proposals, quotes, contracts, purchase orders, invoices, payment status and supplier details
- Event information, including attendance and dietary or accessibility requirements
- Recruitment information, including a CV, work history, qualifications, references, portfolio, right-to-work information and interview notes
- Any other personal information you choose to provide
Information generated through our relationship
Violicom may create or receive records during business activities, such as project correspondence, meeting records, task allocations, review comments, contract records, invoicing records, quality-control records and information needed to manage a professional relationship.
Website and technical information
When you access our website, the website host, server, security tools or WordPress components may process limited technical information. This may include IP address, date and time of access, requested page, browser and device information, referring page, error information and security-related logs.
Violicom uses strictly necessary non-tracking cookies on its website(s). These cookies are used for the essential functions of our website(s), such as security, navigation, and session management. Additionally, we use third-party analytical cookies that help us analyse how you use our website(s), store your preferences, and provide content relevant to you. These cookies will only be stored in your browser with your prior consent.
Information received from other sources
Violicom may receive professional contact information from clients, colleagues, event organisers, publicly available professional sources, referrals, company websites, professional networks or service providers. Where required, we will provide appropriate privacy information within the period required by law.
Special category and criminal-offence information
Violicom does not seek to collect special category or criminal-offence data through our general website. Such information may occasionally arise in a professional, event, recruitment or client-project context. Where Violicom acts as controller, it will process that information only where a lawful basis and any additional legal condition apply, and with safeguards appropriate to the sensitivity of the information.
4. How and why we use personal information
| Activity | Purpose | Likely lawful basis |
| Website and service enquiries | To respond, provide requested information, arrange discussions, understand requirements and follow up | Legitimate interests in responding to business enquiries and developing relationships; steps at your request before entering a contract |
| Proposals and contracts | To prepare proposals, agree terms, conduct due diligence and enter or administer a contract | Steps before contract; performance of a contract; legitimate interests in business administration |
| Client projects and services | To plan, deliver, quality-control, document and communicate about agreed services | Performance of a contract; legitimate interests; legal obligations where relevant |
| Client, partner and supplier relationships | To maintain contact, coordinate work, manage performance, resolve issues and administer the relationship | Contract; legitimate interests in operating and improving our business |
| Finance and administration | To issue and process invoices, maintain accounts, manage payments and comply with tax and audit requirements | Contract; legal obligation; legitimate interests |
| Website operation and security | To operate, troubleshoot, secure and protect the website, systems, devices and communications | Legitimate interests in security, service availability and fraud or misuse prevention; legal obligations where applicable |
| Business development | To manage professional relationships and, where legally permitted, communicate about relevant services or opportunities | Legitimate interests; consent where required by PECR or other law |
| Events and meetings | To organise attendance, logistics, communications, accessibility and appropriate follow-up | Contract; legitimate interests; consent or special-category condition where necessary |
| Recruitment and resourcing | To assess applications, arrange interviews, verify suitability and maintain appropriate recruitment records | Steps before contract; legitimate interests; legal obligations; consent in limited cases |
| Legal and compliance | To comply with law, respond to lawful requests, manage disputes and establish, exercise or defend legal claims | Legal obligation; legitimate interests; legal claims conditions where applicable |
| Business change | To evaluate or implement a reorganisation, investment, merger, acquisition or sale | Legitimate interests, subject to appropriate confidentiality and safeguards |
The applicable lawful basis depends on the specific facts. Where we rely on legitimate interests, we consider the purpose, necessity and potential effect on individuals. You may object to processing based on legitimate interests, although the right is not absolute.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing undertaken before withdrawal. Violicom will not rely on consent where another lawful basis more appropriately reflects the relationship.
Violicom does not currently use personal information from the website for solely automated decisions that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law.
5. Medical, scientific and client-project information
Violicom works in medical communications and may handle scientific or healthcare-related material for clients. This does not necessarily mean that the material is personal information. Where project materials do contain personal information, the roles of the parties must be assessed for the relevant project.
Where Violicom acts as a processor for a client, Violicom will handle personal information in accordance with the client’s documented instructions, the project contract or data-processing agreement, confidentiality requirements and applicable law. Individuals should normally direct questions about that processing to the client controller identified in the relevant privacy notice.
Where project information can be anonymised or de-identified without undermining the agreed purpose, Violicom encourages the use of appropriately minimised data.
Confidentiality is fundamental to Violicom’s work. Client information will be accessed only by people who need it for an authorised purpose and handled in line with contractual, security and professional obligations
6. Direct marketing and professional communications
Violicom may communicate with existing and prospective business contacts about services, projects, events or professional matters where permitted by law. Depending on the recipient and the communication channel, Violicom may rely on legitimate interests, consent or an applicable PECR rule.
You may ask Violicom to stop sending direct marketing at any time by using an unsubscribe method provided in the message or by contacting violicom@violicom.co.uk. We may retain a minimal suppression record to respect the request.
Service, contractual, project, safety, legal and administrative communications are not normally marketing communications and may continue where necessary.
7. Cookies and similar technologies
Cookies and similar technologies can store information on, or access information from, a device. PECR generally requires clear information and consent before non-essential technologies are used. Strictly necessary technologies may be exempt from the consent requirement, but users should still receive appropriate information.
Only strictly necessary cookies (that are necessary for the technical functionalities of our website) are enabled on our website(s) until further cookies are specifically accepted, as per GDPR regulations. This means any cookie that does not fall under the category of ‘strictly necessary’ are not set on your browser until you have given consent to use it, and are therefore blocked and no data collected from you. If you reject the use of non-strictly necessary, the use of these cookies are not set and no data will be collected from you.
Please see our Cookies Policy for further information on the cookies used on our website(s).
8. Who we share personal information with
Violicom does not sell personal information. We may share it where reasonably necessary and lawful with:
- Clients, project partners, speakers, consultants, freelancers or collaborators involved in an authorised project
- Website hosting, email, cloud storage, collaboration, document-management, backup, IT-support, cybersecurity and communications providers
- Accountants, auditors, insurers, banks, legal advisers and other professional advisers
- Event venues, travel or logistics providers where required for arrangements
- Regulators, the Association of the British Pharmaceutical Industry (ABPI), courts, law-enforcement agencies, tax authorities or other public bodies where disclosure is required or legally justified
- Parties involved in a proposed or completed business reorganisation, investment, merger, acquisition or sale, subject to appropriate confidentiality and safeguards
Service providers acting as processors are always selected with due care and bound by written terms addressing confidentiality, security, permitted processing, sub-processors, assistance with rights, deletion or return, and audit or assurance as appropriate.
The precise categories and identities of recipients can vary by project and are documented internally. On request, Violicom can provide further information where required and appropriate.
9. International transfers
Some service providers, clients, project participants or systems may be located outside the United Kingdom or may make information accessible from another country. A transfer of personal information outside the UK will take place only where permitted by applicable law.
Depending on the destination and arrangement, safeguards may include:
- UK adequacy regulations
- The UK International Data Transfer Agreement
- The UK Addendum to the European Commission’s Standard Contractual Clauses
- Another legally recognised transfer mechanism
- Supplementary technical, contractual or organisational controls where appropriate
Violicom maintains an up-to-date supplier and transfer register identifying relevant countries, safeguards and transfer-risk assessments. Individuals may contact us for further information about safeguards applicable to their information, subject to confidentiality and security considerations.
10. Security
Violicom uses proportionate technical and organisational measures intended to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures will depend on the information, system and risk, and may include:
- Encrypted website connections using HTTPS
- Access controls, strong passwords and multi-factor authentication where supported
- Device, software, anti-malware and security-update controls
- Role- or need-based access to client and business information
- Secure cloud, email, file-transfer, storage and backup arrangements
- Confidentiality obligations and secure working practices
- Supplier due diligence and contractual controls
- Incident identification, escalation and response procedures
- Secure deletion, disposal or anonymisation where appropriate
No internet transmission or storage system can be guaranteed completely secure. Users should avoid sending highly sensitive information through ordinary email or website forms unless the risks have been considered and suitable arrangements agreed.
If a personal-data breach occurs, Violicom will assess the risk, take reasonable containment and remediation steps, document the incident, and notify the ICO and affected individuals where the legal thresholds are met.
11. Retention and deletion
Violicom keeps personal information only for as long as it is reasonably needed for the purpose for which it was collected, related business requirements, legal and accounting obligations, contractual requirements, dispute resolution, or the establishment, exercise or defence of legal claims.
| Record category | Indicative retention approach |
| General website or service enquiry | Normally up to 24 months after the last meaningful contact, unless it develops into a client, supplier or other continuing relationship |
| Prospective-client and proposal records | Normally up to 3 years after the last substantive activity; longer where needed for relationship history, tender requirements or legal claims |
| Client contracts, project correspondence and core project records | Normally 10 years after project or relationship completion, subject to contract, client instruction, regulatory context and legal-claim considerations, but may be longer depending on ongoing relationships |
| Financial, tax and accounting records | Normally 6 years after the end of the relevant accounting period, or longer where law or professional advice requires |
| Supplier and consultant records | For the relationship and normally up to 7 years afterwards where relevant to contracts, payments, tax or legal claims |
| Recruitment – unsuccessful candidates | Normally 6 to 12 months after the process, unless the individual agrees to a longer talent-pool period or a dispute requires retention |
| Recruitment – successful candidates and workforce records | In accordance with the relevant workforce privacy information and legal, contractual and tax requirements |
| Event attendance records | For the event and an appropriate follow-up period; longer where records form part of a client project, contract, finance record or consented relationship |
| Website and security logs | According to host and security settings; typically between 30 days and 12 months unless required for investigation or legal purposes |
| Marketing preference and suppression records | For as long as necessary to demonstrate consent or ensure that an opt-out continues to be respected |
These are indicative periods, not inflexible guarantees. A shorter or longer period may apply according to the specific purpose, contract, client instruction, legal requirement, limitation period, security investigation or dispute. When information is no longer required, it will be securely deleted, anonymised or otherwise disposed of.
12. Your data protection rights
Subject to the circumstances and legal exemptions, you may have the following rights:
| Be informed | Receive clear information about the collection and use of your personal information |
| Access | Ask whether Violicom processes your personal information and request a copy and related information |
| Rectification | Ask Violicom to correct inaccurate or complete incomplete personal information |
| Erasure | Ask for deletion in circumstances where the law provides this right |
| Restriction | Ask Violicom to restrict processing in specified circumstances |
| Object | Object to processing based on legitimate interests and object at any time to direct marketing |
| Data portability | Receive certain information you provided in a structured, commonly used and machine-readable format where processing is automated and based on consent or contract |
| Withdraw consent | Withdraw consent at any time where consent is the lawful basis |
| Automated decisions | Receive safeguards where a solely automated decision with legal or similarly significant effects is used |
| Complain | Raise a concern with Violicom and complain to the ICO |
Rights are not absolute. Their application depends on the lawful basis, circumstances and statutory exemptions. For example, Violicom may need to retain information to comply with law or to establish, exercise or defend legal claims.
To make a request, contact violicom@violicom.co.uk. Please describe the request and the information concerned. Violicom may ask for information reasonably necessary to confirm identity and protect personal information from unauthorised disclosure.
Violicom will normally respond without undue delay and within one month after receiving a valid request. The period may be extended by up to two further months for a complex request or multiple requests, in which case Violicom will explain the extension within the first month. A fee will not normally be charged, although, the law permits a reasonable fee or refusal in limited circumstances involving manifestly unfounded or excessive requests.
Contact violicom@violicom.co.uk to raise a data protection enquiry. Please do not send identity documents unless Violicom asks for them and provides an appropriate method for transfer
13. Children
The Violicom website and services are directed primarily to businesses, healthcare and life science organisations, professionals and adult users. The general website is not intended for children, and Violicom does not knowingly seek to collect children’s personal information through the contact form.
If you believe a child has provided personal information through the website, contact us so the circumstances can be assessed and appropriate action taken. A client project that legitimately involves information relating to children will be governed by the relevant project arrangements, legal roles, privacy information and safeguards.
14. Third-party links and embedded services
The website may link to or embed content from third-party websites or services. Those organisations may independently collect information and apply their own cookies or similar technologies. Violicom does not control independent third-party privacy practices.
Before introducing or retaining embedded maps, videos, forms, social-media content, fonts or similar services, Violicom assess their data flows, cookie behaviour, international transfers and consent requirements. Users should review the privacy information provided by the relevant third party.
15. Changes to this policy
Violicom may update this policy to reflect changes in law, regulatory guidance, business activities, suppliers, website technology or privacy practices. The current version will be published on the website with an effective or last-updated date.
Where a change materially affects how existing personal information is used, Violicom will take reasonable steps to provide additional notice where required. Archived versions are retained.
16. Contact and complaints
Questions, requests and concerns about this policy or how Violicom is handling personal information may be directed to:
| Organisation | Violicom Medical Limited |
| violicom@violicom.co.uk | |
| Registered office | 1 Andromeda House, Calleva Park, Aldermaston, Reading, Berkshire, RG7 8AP, United Kingdom |
| Website | https://violicom.co.uk/ |
Violicom welcomes the opportunity to address concerns directly. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator. The ICO can be contacted through its official website at https://ico.org.uk/. You may also have a right to seek a judicial remedy.
Violicom aims to make its privacy information understandable. Contact us if anything is unclear or if you would like further information about how your personal information is handled
17. Definitions
| Term | Meaning |
| Controller | The organisation that determines the purposes and means of processing personal information |
| Processor | An organisation that processes personal information on behalf of a controller |
| Personal information / personal data | Information relating to an identified or identifiable living person |
| Processing | Any operation performed on personal information, including collecting, recording, organising, storing, using, sharing, altering or deleting it |
| Special category data | Specified sensitive data protected by additional UK GDPR rules |
| Consent | A freely given, specific, informed and unambiguous indication of wishes given by a clear affirmative action |
| Legitimate interests | A lawful basis that may apply where processing is necessary for a legitimate purpose and is not overridden by an individual’s interests, rights or freedoms |
| PECR | The Privacy and Electronic Communications Regulations 2003, which include rules on electronic marketing and cookies or similar technologies |
Last updated: 28 July 2026
