Epheos Logo

Privacy Policy

Epheos respects the privacy of our users and clients. Learn how we collect, use, and protect your information.

Epheos (“we,” “us,” or “our”) is the data controller responsible for your personal data. We respect the privacy of our users and clients (“you” or “your”). This Privacy Policy describes how we collect, use, and disclose your information when you use our website (epheos.com) (the “Site”) and other related services (collectively, the “Services”).

Data Controller Information

Legal Entity: Epheos LTD

Registered Address: 61 Bridge Street Kington HR5 3DJ, United Kingdom

Company Registration Number: 15759155

Information We Collect

We collect several types of information for various purposes to improve our Services to you.

  • Personal Information: This may include your name, email address, phone number, and other information you choose to provide when you contact us through a form or chat.
  • Usage Data: This information is automatically collected when you use the Services. It may include your IP address, browser type, operating system, referring URL, pages visited, and time spent on those pages.
  • Cookies and Tracking Technologies: We use cookies and similar technologies to collect and store information about your usage of the Services.

Use of Your Information

We use the information we collect for various purposes, including:

  • To provide and maintain the Services
  • To improve and personalize the Services
  • To send you marketing and promotional communications (with your consent)
  • To respond to your enquiries and requests
  • To analyze how you use the Services
  • To improve the accessibility and usability of our Services for users with disabilities (see our Accessibility Statement for more details)
  • To comply with legal obligations

Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Consent: When you provide explicit consent for marketing communications, cookies, or other processing
  • Contract: To provide our services and fulfill our contractual obligations to you
  • Legitimate Interests: For analytics, security, fraud prevention, and direct marketing (where not overridden by your interests)
  • Legal Obligation: To comply with applicable laws and regulations

Sharing Your Information

We may share your information with third-party service providers who help us operate and improve the Services. These service providers are obligated to protect your information and use it only for the purposes we specify.

We may also disclose your information if required by law or to protect the rights, property, or safety of ourselves or others.

Cookies and Tracking Technologies

We use cookies and similar technologies to collect and store information about your usage of the Services.

  • Essential Cookies: Required for basic website functionality. These cannot be disabled.
  • Analytics Cookies: Used to understand how you use our services. We use Google Analytics with consent.
  • Marketing Cookies: Used for targeted advertising and marketing. Requires your consent.

You can manage cookie preferences through your browser settings or our cookie banner. For more information about our use of cookies, please see our Cookie Policy.

Your Data Protection Rights

Under GDPR, you have the following rights:

  • Right to Access: Request copies of your personal data we hold
  • Right to Rectification: Have inaccurate or incomplete data corrected
  • Right to Erasure: Have your personal data deleted (“right to be forgotten”)
  • Right to Restrict Processing: Limit how we use your data in certain circumstances
  • Right to Data Portability: Receive your data in a structured, commonly used format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing
  • Rights Related to Automated Decision-Making: Not be subject to automated decisions with legal effects

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you are not satisfied with our response, you can lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy:

  • Account data: Retained while your account is active and for 3 years after account closure
  • Marketing data: Retained until you unsubscribe or withdraw consent
  • Analytics data: Retained for 26 months (Google Analytics default)
  • Payment data: Retained for 7 years for tax and accounting purposes
  • Legal claims: Retained for the duration of any legal claims or investigations

Data may be retained longer if required by law or for legitimate business purposes.

Children's Privacy

Our Services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you believe your child has provided us with personal information, please contact us. We will take steps to remove the information from our systems.

Security

We take reasonable steps to protect your information from unauthorized access, disclosure, alteration, or destruction. However, no internet transmission or electronic storage method is 100% secure.

Data Breach Notification

In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will:

  • Notify the relevant supervisory authority (ICO) within 72 hours
  • Notify affected individuals without undue delay if the breach poses a high risk
  • Document all breaches and our response to them

International Transfers

Your information may be transferred to, stored, and processed in countries other than your own. When we transfer data outside the UK/EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission or UK government
  • Binding Corporate Rules
  • Certification schemes

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on the Site.

Changes to our Cookie Policy will be communicated through the same channels. Please review our Cookie Policy for the most current information about our cookie practices.

Contact Us

If you have any questions about this Privacy Policy, please contact us by email at [email protected] or through the contact information provided on the Site.

Epheos