Legal

Privacy policy

01

Who we are

Theralon ([legal entity name and company number], registered at [registered address]) is the controller of the personal information described in this policy. “We” and “us” mean that entity.

If you have a question about this policy, or want to exercise any of the rights in section 08, write to [email protected].

02

What we collect

Two categories, and no more than that.

Information you give us. The contact form asks for your first name, last name, work email address, phone number, job title, company or institution, and country. A message is optional. What you submit is delivered as an email to our own mailbox and nothing else — the form writes to no database, sets no tracking identifier, and passes through no marketing platform. If you email us directly instead, that correspondence sits in the same mailbox.

Information collected automatically. Serving a page produces an ordinary server log: the IP address the request came from, the browser user-agent string, the URL requested, the referring page, and a timestamp. Our hosting provider records these in order to serve the site, absorb attacks, and keep it available. We do not use them to build a profile of you.

We do not ask for special category data — health, biometrics, political or religious views, and the rest — and would rather you did not send any. This site takes no payments and stores no payment details. It is not directed at children, and we do not knowingly collect information about them.

03

Cookies and browser storage

This site sets no advertising cookies and carries no third-party tracking pixels.

  • Your cookie choice is kept in your browser’s local storage so the banner does not reappear on every visit. It is essential to that function, stays on your device, and is never sent to us.
  • Analytics runs only if you press Accept. Press Decline, or ignore the banner entirely, and nothing analytical loads. At the time of writing no analytics tool is enabled on this site at all; the consent gate exists so that if one is ever added, it cannot run before you have agreed to it.

You can change your mind whenever you like — Cookie preferences, at the foot of the home page, reopens the choice.

04

Why we use it, and on what basis

Every use below is tied to the legal basis we rely on under the UK GDPR and the EU GDPR.

  • Answering your enquiry, and following it up. Legitimate interests — replying to someone who has asked us to get in touch.
  • Keeping the site available, secure and free of abuse. Legitimate interests — protecting our infrastructure and the people using it.
  • Analytics, if it is ever enabled. Consent, which you give by pressing Accept and can withdraw at any time.
  • Keeping records of contracts, correspondence and consent where we are required to. Legal obligation.

Where we rely on legitimate interests we have weighed those interests against your rights and freedoms, and we will explain that assessment on request. We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use it to train models.

05

Who else sees it

We do not sell personal information, rent it, or share it with advertising networks or data brokers.

A short list of service providers processes it on our behalf, under contract and on our instructions:

  • Cloudflare — hosting, content delivery and attack mitigation for this site, and the environment the contact form runs in. Processes request logs.
  • Google (Google Workspace) — the mailbox behind [email protected], and the interface that delivers form submissions into it.

Beyond those, we disclose personal information only where the law requires it, to professional advisers under a duty of confidence, or to a successor organisation if the business is transferred — in which case this policy travels with it and you will be told.

06

Where it is processed

The providers above operate globally, so your information may be processed outside the country you are in, including in the United States.

Where that involves a transfer out of the United Kingdom or the EEA, it is made under the safeguards those regimes require: an adequacy decision where one applies, and otherwise the relevant Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), together with the provider’s own supplementary measures. Ask us and we will tell you which mechanism covers a particular transfer.

07

How long we keep it

  • Enquiry correspondence — for as long as the conversation is live, and for up to 24 months after the last contact, so that we can pick it up where it left off. Longer if it becomes part of a contract record we are required to retain.
  • Server logs — short-lived, on our hosting provider’s standard retention, typically days rather than months.
  • Your cookie choice — up to 12 months, in your own browser, until you clear your browser storage.

Ask us to delete your correspondence earlier and we will, unless we are legally required to keep it.

08

Your rights

Under UK and EU data protection law you can ask us to:

  • Give you a copy of the personal information we hold about you, and tell you what we do with it.
  • Correct it if it is wrong or incomplete.
  • Delete it, where we have no continuing reason to hold it.
  • Restrict how we use it while a question about it is being resolved.
  • Send it to you, or to someone else, in a portable, machine-readable form, where that right applies.
  • Stop using it, where we rely on legitimate interests and you object.
  • Withdraw your consent at any time, where consent is what we relied on. Withdrawing it does not undo anything done beforehand.

Write to [email protected]. There is no charge, and we will respond within one month. We may first ask you to confirm who you are — only so that we do not hand your information to somebody else.

If you think we have handled your information badly, you can complain to a supervisory authority: in the UK, the Information Commissioner’s Office at ico.org.uk; in the EU, the authority for the country where you live or work. We would rather you raised it with us first, and we will take it seriously.

09

How we protect it

Traffic to this site is encrypted in transit over HTTPS. The credentials that let the contact form deliver mail are held as secrets in our hosting platform, are scoped to sending a single message and nothing more, and appear nowhere in the code this site serves. The form validates and length-limits every field before it accepts a submission. Access to the mailbox is limited to the people who need it.

No system is perfectly secure and we will not claim otherwise. What we can say is that we do not collect what we do not need, which remains the strongest protection available.

10

Changes to this policy

We will update this page as the site changes. The date at the top always reflects the version currently in force. If a change materially affects how we handle your information, we will make that clear on the site rather than leaving you to spot it.

11

Contact

Email [email protected], use the contact form, or write to [registered address].