Legal
Privacy notice
Last updated 24 August 2026
This notice explains how QuoVira Health Ltd (“we”, “us”) handles personal data collected through this website, quovirahealth.co.uk. It does not cover our products, which have their own privacy notices.
Who we are
QuoVira Health Ltd (company no. 17322340) is a company registered in England and Wales and a subsidiary of QuoVira Ltd, with its registered office at 128 City Road, London, EC1V 2NX. We are registered with the Information Commissioner's Office as a data controller under registration number ZC190656. We are the data controller for personal data processed through this site. For any privacy question, contact [email protected].
What we collect
- Enquiry details you submit through our contact form: your name, email, optional organisation, project type and message.
- Basic technical data your browser sends (such as IP address and user agent) and standard server logs, used to keep the site secure and available.
How we use it
- To respond to your enquiry and provide the information you ask for.
- To operate, secure and improve this website.
- To comply with our legal obligations.
Our lawful bases are your consent and our legitimate interests in responding to enquiries and running a secure website.
Sharing and storage
We use trusted service providers to host the site and deliver email (for example our cloud hosting and email providers). They process data on our behalf under appropriate agreements. We do not sell your personal data. Data is hosted in the UK/EEA wherever practical; where a provider processes data elsewhere, appropriate safeguards apply.
Retention
We keep enquiry data only as long as needed to deal with your enquiry and for a reasonable period afterwards, then delete it.
How we protect it
This site runs on UK-region infrastructure behind TLS, with a full set of security response headers, encrypted secrets and least-privilege access. We maintain an information security policy set, a record of processing activities covering every processor we use, and a documented incident response procedure — including assessment against the 72-hour personal data breach reporting clock. Our wider assurance position, including what we do not yet hold, is published on our trust and compliance page.
Your rights
Under UK GDPR you have rights to access, correct, delete and restrict the use of your personal data, and to object to certain processing. To exercise any right, email [email protected]. You may also complain to the Information Commissioner's Office (ico.org.uk), the UK supervisory authority for data protection.
Changes to this notice
We may update this notice from time to time. The date at the top of this page shows when it was last revised.