• WHY WE EXIST
  • WHAT WE DO
  • OUR SOLUTION
  • OUR TEAM
  • CONTACT
  • WHY WE EXIST
  • WHAT WE DO
  • OUR SOLUTION
  • OUR TEAM
  • CONTACT

Privacy Statement

Privacy Notice

Effective date: 17th September 2026

This Privacy Notice explains how UK NIVD LTD collects and uses personal data. It is a transparency notice under the UK GDPR, the Data Protection Act 2018 and, where it applies, the EU GDPR. It is not a contract. Using Our Site does not give us consent to process your data, to change this notice, or to transfer your data overseas.

Our Cookie Policy explains cookies in more detail. Our Website Terms of Use govern use of the site itself.

Definitions and abbreviations

In this Privacy Notice, the following terms have the meanings set out below:

“UK GDPR” means the United Kingdom General Data Protection Regulation, as it forms part of UK law.

“EU GDPR” means Regulation (EU) 2016/679, the European Union General Data Protection Regulation.

“Data Protection Act 2018” means the UK Data Protection Act 2018, as amended from time to time.

“PECR” means the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended. These rules apply to matters including electronic marketing, cookies and similar technologies in the United Kingdom.

“EEA” means the European Economic Area.

“ICO” means the Information Commissioner’s Office, the United Kingdom’s data protection supervisory authority.

“AEPD” means the Agencia Española de Protección de Datos, the Spanish data protection supervisory authority.

“personal data” means information relating to an identified or identifiable living individual.

“special-category personal data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, genetic data, biometric data used for uniquely identifying a person, health data, and data concerning a person’s sex life or sexual orientation.

“controller” means the organisation that determines the purposes and means of processing personal data. For the processing described in this Privacy Notice, UK NIVD LTD is generally the controller.

“processor” means an organisation that processes personal data on behalf of a controller and in accordance with the controller’s instructions.

“subprocessor” means a third party appointed by a processor to assist it in processing personal data on behalf of a controller.

“processing” means any operation performed on personal data, including collecting, recording, organising, storing, using, sharing, altering, retrieving, restricting or deleting it.

“CRM” means Customer Relationship Management system. We currently use HubSpot as our principal CRM.

“DPA” means Data Processing Agreement — a contract governing how a processor processes personal data on behalf of a controller.

“NDA” means Non-Disclosure Agreement.

“B2B” means business-to-business.

“CV” means curriculum vitae.

“AI” means artificial intelligence.

“SCCs” means the European Commission’s Standard Contractual Clauses used as one mechanism for certain international transfers of personal data.

“IDTA” means the United Kingdom International Data Transfer Agreement, which may be used as a safeguard for certain restricted transfers of personal data from the United Kingdom.

“UK Addendum” means the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses.

“restricted transfer” means a transfer of personal data outside the United Kingdom or European Economic Area that is subject to the international-transfer requirements of applicable data protection law.

“supervisory authority” means an independent public authority responsible for enforcing data protection law, such as the ICO in the United Kingdom or the AEPD in Spain.

“Our Site” means the UK NIVD LTD website at https://www.nivd.world.

“we”, “us” and “our” mean UK NIVD LTD.

“you” and “your” mean the individual whose personal data is being processed under this Privacy Notice.

1. Who we are and how to contact us

The controller is UK NIVD LTD, a private limited company registered in England and Wales under company number 13728148.

  • Registered office: 167-169 Great Portland Street, London W1W 5PF, United Kingdom
  • Laboratory / operating location: Parc Científic de Barcelona, C/Baldiri Reixac 4-15, 08028 Barcelona, Spain
  • Website: https://www.nivd.world
  • Privacy email: info@nivd.world
  • Privacy contact: James Perry, Commercial and Operations, james@nivd.world

We have not appointed a statutory Data Protection Officer. Privacy questions should go to the contacts above.

We are registered with the Information Commissioner’s Office under number ZB341533.

Because we work from Barcelona as well as the United Kingdom, this notice is written for both UK GDPR and EU GDPR. We have not appointed a separate EU Article 27 representative. EEA individuals may still contact us at the addresses above and may complain to their local supervisory authority (see section 9).

2. Who this notice covers

This notice covers:

  • visitors to Our Site;
  • people who email us or otherwise enquire;
  • professional contacts we meet through networking, introductions and events, including partners, investors, suppliers, advisers and scientific collaborators; and
  • people who send us a CV or other work-related information.

Our Site is a public information site about our research. It does not sell products, create user accounts or collect patient or trial-subject data.

Staff and individual contractors have separate workplace information. This notice is not your employment privacy notice.

3. What we collect and where it comes from

3.1 Data you give us

If you email info@nivd.world or otherwise contact us, we typically receive your name, email address, organisation, role, and the content of your message. We do not currently operate an online form on the homepage.

3.2 Data from networking and introductions

Most of our business contacts come from in-person or online networking and from introductions by people we already know. In those cases we may receive, and then store in our HubSpot Customer Relationship Manager tool (CRM):

  • name, job title and organisation;
  • business email and sometimes a phone number;
  • where we met, who introduced us, relevant professional interests, brief business summaries of meetings, agreed next steps and follow-up tasks;
  • public professional information (for example a LinkedIn profile or company website) that helps us spell a name or confirm a role.
  • agreement and NDA information, including whether an agreement has been issued, signed and the relevant signature date;
  • If we obtain your personal data from another source rather than directly from you, we will provide or draw your attention to this Privacy Notice within the period required by applicable data protection law — normally no later than one month after obtaining the data and, where we contact you sooner, at or before our first communication with you. We will only rely on an exception to this requirement where the law permits it and we have documented the basis for doing so.

3.3 Data collected by Our Site

When you visit Our Site we process technical data: IP address, browser and device type, pages viewed, referring URL, and dates/times. Some of this sits in hosting logs. Analytics identifiers are only stored if you accept analytics cookies (see the Cookie Policy).

The homepage also loads Google Maps. If you interact with the map, Google may process location-related technical data as described in Google’s privacy policy.

3.4 What we do not collect via Our Site

We do not intentionally seek or routinely collect special-category personal data through Our Site, ordinary networking activities or as a matter of course in HubSpot CRM. Special-category personal data includes information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health, sex life and sexual orientation. We ask our team not to record clinical, health or similarly sensitive information in the CRM. If we conduct a clinical study or otherwise intentionally process special-category personal data, that processing will be governed by an appropriate separate privacy notice and documented Article 6 and Article 9 conditions. This Privacy Notice is not that document.

Our Site is not aimed at children and we do not knowingly collect data about children.

4. Purposes and lawful bases

We only use personal data where we have a lawful basis. For each processing activity we identify the applicable lawful basis or bases under Article 6. Where more than one basis may apply in different circumstances, we explain those circumstances below. You may object to legitimate-interests processing (section 9).

Electronic marketing is also subject to PECR (and the ePrivacy rules that apply in the EEA). A lawful basis under GDPR is not enough on its own to send marketing email to an individual subscriber.

PurposeDataSourceArticle 6 basis and legitimate interestRecipientsRetention
Operate, secure and repair Our SiteIP address, device/browser data, security and error logsYour visitLegitimate interests — keeping Our Site available, secure and protected against misuseWP Engine; IT/security support if neededHosting and security logs: up to 30 days, longer only if investigating an incident
Respond to enquiriesName, business email, organisation, messageYou (email or other direct contact)Legitimate interests — responding to professional enquiries about our research and collaborationGoogle Workspace; HubSpot CRM once the conversation becomes an ongoing professional relationship24 months after last meaningful contact, then review and delete or archive
Manage B2B, partner, supplier, adviser and investor relationshipsName, role, organisation, business contact details, meeting/introduction context, professional notes, interaction historyYou; introductions; events; public professional profilesLegitimate interests — running our biotechnology research business and maintaining relevant professional, supplier, adviser and investor relationships. Where the individual personally is party to a contract with us, or asks us to take steps before entering into a contract with them, Article 6(1)(b) may apply to processing that is necessary for that contract or requested pre-contractual steps.HubSpot; Google Workspace; DocuSign where documents require electronic signature; Carta where relevant to shareholders, investors or equity administration; relevant NIVD staff; professional advisers under confidentialityWhile the relationship is active, then 24 months after last meaningful contact, then review (we follow a documented regular review process to review CRM data)
Send B2B updates about NIVD (research, events, collaboration, newsletters/marketings)Business email, name, organisation, communication preferencesYou or the relationship record in HubSpotLegitimate interests — telling relevant professional contacts about our work, where PECR allows (in particular corporate subscribers, with a clear opt-out). Consent, where PECR requires it (individual subscribers / consumer emails)HubSpotUntil you opt out, or until the relationship record is deleted under the row above
Understand how Our Site is usedOnline identifiers, pages viewed, approximate location derived from IP, device typeGoogle tag / Analytics, only with cookie consentConsent (Cookie Law / PECR). Corresponding UK/EU GDPR basis: consentGoogle14 months in Analytics (confirm in Site Kit), then aggregated or deleted
Show the laboratory mapTechnical data processed by Google Maps if you load or use the mapEmbedded map, only with the relevant cookie consentConsent (Cookie Law). Corresponding GDPR basis: consentGoogleAs determined by Google’s map cookies (see Cookie Policy)
Comply with law and record-keepingIdentity and contact data, correspondence, billing identifiers if a supplier or customer relationship existsYou; our recordsLegal obligation (for example companies, tax and accounting rules)Accountants, lawyers, Companies House, HMRC, ICO as requiredStatutory periods (often 6 years for accounting records)
Consider an unsolicited CV or work enquiryCV, name, contact details, career historyYouLegitimate interests — assessing a possible working relationship. Consent if we ask to keep a CV on file after a rejectionGoogle Workspace; HubSpot where appropriate; relevant hiring managers6 months after the last relevant decision, unless you agree a longer talent-pool period

We will not use your data for a new purpose that is incompatible with the above. If we need to, we will tell you and explain the basis, unless the law requires or allows us to proceed without notice (for example a legal obligation or to establish, exercise or defend a legal claim).

We do not re-import a person who has been deleted or suppressed in response to a valid objection or opt-out unless a documented lawful basis permits it.

5. Special-category data

We do not seek special-category data through Our Site or through ordinary CRM use. Please do not send us health records, genetic data or similar information by email unless we have asked for it under a separate, documented process.

If a message you send happens to include health information (for example you mention an illness when arranging a meeting), we will only use what we need to respond and will not copy that detail into HubSpot CRM as a standing field.

6. Who we share data with

We do not sell personal data. We share it only as needed for the purposes above:

  • HubSpot — our CRM. Professional contact and interaction records. HubSpot, Inc. and its group companies act as our processor under HubSpot’s customer DPA. Our CRM data is hosted in EU/Germany.
  • WP Engine — website hosting and related security/caching.
  • Google — Site Kit / Google tag / Analytics (if you consent) and Google Maps (if you consent to that category). Google also delivers some scripts used to display Our Site.
  • Google Workspace — our principal email, calendar, document and business collaboration platform. Google may process names, contact details, correspondence, documents and related account information on our behalf. Content delivery networks — Cloudflare, jsDelivr and unpkg, which see IP addresses when your browser loads scripts.
  • DocuSign — electronic signature and agreement-management services. Where we ask you to sign an NDA, agreement or other document electronically, DocuSign may process your name, email address, signature, document contents, signing status, timestamps and associated audit information.
  • Carta Europe / Carta group companies — equity, shareholder and stakeholder administration. Where relevant to an investor, shareholder, option holder or other stakeholder relationship, Carta may process identification, contact, corporate, investment and equity-related information.
  • OpenAI / ChatGPT Business — authorised AI-assisted business tools that we may use to assist with activities such as drafting, summarising, organising or analysing business information. We minimise the personal data supplied to these tools and do not intentionally use them to process clinical, genetic or other special-category personal data as part of our ordinary business operations.
  • Microsoft — productivity, collaboration, identity and IT services used by our organisation. Depending on the service used, Microsoft may process account, contact, communication, document and technical information.
  • Other business service providers — including banking and payment providers, IT infrastructure and hosting providers, corporate administration providers and specialist professional service providers, where they need access to personal data to provide their services to us.
  • Professional advisers — lawyers, accountants, patent/IP advisers, under confidentiality, where relevant to a matter.
  • A buyer or successor — if we sell or reorganise the business, on the basis of legitimate interests in a corporate transaction, with appropriate safeguards.
  • Authorities — where the law requires, or to protect our legal rights.

Our employees and directors who access HubSpot or email do so under our authority. They are not “processors”. External vendors listed above are processors or independent controllers, as the relationship requires.

7. International transfers

We are established in the United Kingdom and also operate from Spain. Personal data may therefore be accessed and processed within the United Kingdom and European Economic Area.

Some of the service providers we use are based outside the United Kingdom and EEA, or use group companies, infrastructure or subprocessors located in other countries. This can include providers of CRM, email and collaboration, electronic signature, equity administration, website infrastructure and authorised AI-assisted business services.

Where our use of a service involves a restricted international transfer of personal data, we ensure that an appropriate transfer mechanism is in place where required.

Depending on the recipient and destination, this may include:

  • an applicable UK or EU adequacy decision, including the UK Extension to the EU-US Data Privacy Framework or EU-US Data Privacy Framework where the recipient is appropriately certified and the relevant framework applies;
  • the European Commission’s Standard Contractual Clauses;
  • the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses; and
  • other legally recognised safeguards where applicable.

Where required, we also assess the circumstances of the transfer and the technical, contractual and organisational safeguards used by the recipient.

Separately, where a service provider acts as our processor, we require appropriate contractual terms governing its processing of personal data.

You may contact info@nivd.world for further information about the safeguards applicable to a particular transfer.

8. How long we keep data

We keep personal data only as long as we need it for the purpose we collected it, including any legal, accounting or reporting need. The table in section 4 is the working rule. In outline:

  • website security logs — up to 30 days unless an incident is being investigated;
  • one-off enquiries — 24 months after last contact;
  • HubSpot CRM relationship records — while we are in a professional relationship, then 24 months after last meaningful contact, then a review to delete or (if a legal hold applies) archive;
  • marketing suppression lists — for as long as needed to honour an opt-out;
  • analytics — 14 months (to be confirmed in Google Site Kit);
  • CVs — 6 months unless you agree we may keep them longer;
  • statutory records — for the period the law requires.

Where personal data is held by one of our service providers, the applicable retention period is generally determined by the purpose for which we hold the underlying information rather than by the particular software in which it is stored. We require or configure service providers to delete or return personal data when it is no longer required, subject to appropriate backup and deletion cycles and any applicable legal, regulatory or contractual retention requirements.

Signed agreements and associated records may be retained for the duration of the relevant relationship and afterwards for as long as reasonably required for legal, regulatory, corporate record-keeping or the establishment, exercise or defence of legal claims.

If you object or ask for erasure, we will delete or restrict data unless we have a lawful reason to keep it (for example a legal claim or a legal obligation).

9. Your rights and how to complain

You have the following rights, with the usual legal limits:

  • to be informed (this notice);
  • to access your data;
  • to have inaccurate data corrected and incomplete data completed;
  • to erasure (“to be forgotten”) in the circumstances the law sets out;
  • to restrict processing;
  • to object to processing based on legitimate interests, and to object at any time to processing for direct marketing (including related profiling);
  • to data portability, where processing is automated and based on consent or on a contract with you; and
  • to withdraw consent where we rely on consent, without affecting processing already carried out.

We do not use solely automated decision-making that produces legal or similarly significant effects.

To exercise a data protection right or raise a data protection complaint, you can email info@nivd.world or write to our registered office for the attention of James Perry. We may ask for information reasonably necessary to confirm your identity.

A subject access request may be made verbally or in writing and does not need to use any particular wording or be sent to a specific person or email address. We will respond to rights requests within the applicable statutory time limits.

If you make a data protection complaint to us, we will acknowledge receipt within 30 days. We will take appropriate steps to investigate the complaint without undue delay, keep you informed as appropriate, and tell you the outcome without undue delay.

You also have the right to complain to a relevant supervisory authority.

We will not ignore a genuine rights request. If an email is obviously unrelated to the address it was sent to, we may not treat it as a formal request until it is sent to info@nivd.world.

You can complain to us first. You also have the right to complain to a supervisory authority:

  • United Kingdom — Information Commissioner’s Office, www.ico.org.uk, or 0303 123 1113;
  • EEA — the data protection authority in the country where you live, work, or where you think a breach has occurred (in Spain, the Agencia Española de Protección de Datos, www.aepd.es).

10. Security, changes and this notice

We take proportionate technical and organisational measures to protect personal data. This includes restricting access to systems containing personal data to authorised personnel who require access for their role, applying appropriate account and authentication controls, using service providers subject to appropriate confidentiality and data-protection obligations, and maintaining procedures for assessing personal-data breaches. Where notification is legally required, we notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

No internet transmission is completely secure. Please do not send clinical, genetic, medical or other particularly sensitive information by ordinary email unless we have specifically asked you to do so and have provided an appropriate method for sending it.

We will update this notice when our processing changes in a material way. We will change the date at the top and, if the change is significant, we will take reasonable steps to bring it to the attention of people we already contact (for example a note in a relevant email). We will not treat continued use of Our Site as acceptance of a new version.

UK NIVD LTD · Registered in England and Wales, company number 13728148
Registered office: 167-169 Great Portland Street, London, W1W 5PF

  • Terms & Conditions
  • Privacy Statement
  • Cookie Policy (UK)
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}