1. Introduction and Contact Information
Photon Fusion Ltd (“Photon Fusion”, “we”, “us”, or “our”) is the data controller for personal information processed through this website. We are a private limited company registered in England and Wales.
Registered office: Suite Ra01, 195-197 Wood Street, E17 3NU, London, UKCompany number: 17087137
Email: info@photonfusion.io
This notice explains what personal data we collect through photonfusion.io, why we collect it, how we protect it, how long we keep it, and what rights you have over it. This policy applies to all visitors, regardless of where you are located.
If you are accessing this site from outside the United Kingdom, please note that your personal data will be processed in the UK and potentially in other jurisdictions where our service providers operate, as described in Section 8 (International Data Transfers).
2. Scope of This Notice
This notice covers personal data collected through this website and pre-engagement correspondence. It does not cover confidential scientific, regulatory, clinical, or proprietary materials shared during a formal consulting engagement. Once a client relationship is established, the handling of such materials is governed by our separate Client Services Agreement, Non-Disclosure Agreement, and any applicable regulatory frameworks (e.g., GCP, HIPAA, 21 CFR Part 11).
This website is not intended for the submission of sensitive personal information such as health records, genetic data, clinical trial participant data, or government identification numbers. If you need to share such materials for a prospective engagement, please contact us first so we can arrange a secure transfer mechanism.
3. Information We Collect
3.1 Information You Provide Voluntarily
We collect personal data only when you choose to provide it to us — principally when you contact us through the enquiry form or by email. This typically includes:
- Your name
- Email address
- Organisation or employer
- Job title or role
- The content of your message and any attachments
Providing this information is not a statutory or contractual requirement. However, if you do not provide your name and contact details, we will not be able to respond to your enquiry.
3.2 Information Collected Automatically
When you browse this site, our hosting and security infrastructure automatically records technical data necessary to deliver the site securely and maintain its performance. This includes:
- Internet Protocol (IP) address
- Browser type and version
- Operating system
- Referring URL
- Pages accessed and time spent
- Date and time of requests
This technical data is processed by our infrastructure providers (see Section 7) for security, fraud prevention, and service delivery. It is not used by us to identify individual visitors or to build profiles for marketing purposes.
3.3 Sensitive Personal Information
We do not intentionally collect sensitive personal information (also known as “special category data” under UK/EU law) through this website, and we do not want you to submit it here. If you believe you need to share health records, genetic data, clinical trial data, or other sensitive material with us, please contact us first so we can arrange a secure, purpose-specific transfer mechanism outside this website.
If sensitive personal information is submitted through the general enquiry form without such prior arrangement, we will not process it beyond what is necessary to direct you to an appropriate secure channel, and we will delete it promptly.
4. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis (See Section 5) |
|---|---|
| To respond to your enquiry | Legitimate interest / Contractual steps at your request |
| To communicate with you about a potential engagement | Legitimate interest / Contractual steps at your request |
| To enter into and perform a contract with you | Performance of a contract |
| To maintain website security and prevent fraud | Legitimate interest / Legal obligation |
| To comply with applicable laws and regulations | Legal obligation |
| To establish, exercise, or defend legal claims | Legitimate interest / Legal obligation |
We do not use your personal data for automated decision-making or profiling. We do not sell your personal data to third parties. We do not use your data for direct marketing unless you have explicitly opted in, and you may opt out at any time.
5. Legal Basis for Processing
We process personal data based on the following legal grounds:
- Contractual necessity: Where processing is necessary to take steps at your request prior to entering into a contract, or to perform a contract to which you are a party.
- Legitimate interests: Where processing is necessary for our legitimate interests in operating our business, responding to enquiries, and maintaining website security, provided those interests are not overridden by your rights.
- Legal obligation: Where we are required to process data to comply with applicable law.
- Consent: Where you have given us explicit consent, such as for receiving marketing communications. You may withdraw consent at any time.
6. Cookies and Tracking Technologies
This website does not use analytics, advertising, or tracking cookies. We have not configured any cookies of our own for profiling or marketing purposes.
Our hosting and security infrastructure (Cloudflare) may set strictly necessary cookies automatically as part of delivering the site securely — for example, to distinguish legitimate traffic from automated or malicious requests, to maintain session integrity, or to apply security rules. These cookies:
- Do not identify you personally beyond a transient session identifier
- Cannot be disabled without affecting site delivery
- Are not used by us for tracking, profiling, or marketing
If we introduce analytics or marketing cookies in the future, this notice will be updated accordingly and, where required by law, we will obtain your consent before placing such cookies.
7. How We Share Your Information
We do not sell, rent, or trade your personal data. We share personal data only in the following limited circumstances:
Service Providers (Data Processors):
- Cloudflare, Inc. — Website hosting, content delivery, and security infrastructure. Cloudflare may process technical data (including IP addresses) globally as part of its network operations.
- Proton AG — Encrypted email transmission and storage for messages sent via the contact form.
These providers act as data processors and are contractually bound to process data only on our instructions and in compliance with applicable data protection standards. We have executed Data Processing Addenda (DPAs) and/or Standard Contractual Clauses (SCCs) with these providers where required.
Other Disclosures:
- Legal requirements: We may disclose personal data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, property, or safety, or that of our clients or the public.
- Business transfers: In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the acquiring entity, subject to the same privacy commitments.
8. International Data Transfers
Photon Fusion is based in the United Kingdom. Your personal data may be transferred to, stored at, or processed in countries outside your jurisdiction, including the United States and Switzerland, where our service providers maintain infrastructure.
We ensure that appropriate safeguards are in place for such transfers:
- United Kingdom & European Economic Area: We rely on the UK International Data Transfer Agreement (IDTA) / EU Standard Contractual Clauses (SCCs), supplemented by Transfer Impact Assessments where appropriate. The UK and EU have granted adequacy decisions for each other’s data protection regimes.
- United States: We rely on Standard Contractual Clauses with our service providers, who maintain appropriate technical and organizational security measures.
For transfers to any other jurisdiction, we apply safeguards consistent with the standards described above and will provide further information about the specific mechanism used on request.
9. Data Security
We take the security of your personal data seriously, particularly given the sensitive nature of biotech and life sciences consulting. We implement appropriate technical and organizational measures, including:
- Encryption: All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher. Email correspondence is transmitted via Proton’s encrypted infrastructure.
- Access controls: Personal data is accessible only to authorised personnel who have a legitimate need to access it.
- Processor vetting: We engage only reputable service providers with recognised security certifications and data protection commitments.
- Incident response: We maintain procedures to detect, respond to, and report personal data breaches.
No transmission over the internet can be guaranteed as fully secure. While we strive to protect your personal data, you acknowledge that any transmission is at your own risk.
10. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Enquiry data: We retain enquiry data for 24 months from the date of our last communication with you. After this period, it is securely deleted unless a client relationship has been established.
- Client relationship data: If an engagement proceeds, data retention is governed by our Client Services Agreement and applicable legal/regulatory requirements.
- Technical logs: Server logs retained by our infrastructure providers are typically stored for 30 days to 12 months, depending on the provider’s retention policies and our security needs.
11. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, please contact us using the details in Section 1. We will respond within the timeframe required by applicable law (typically within one month for UK/EU requests).
11.1 Rights Under UK and EU GDPR
If you are located in the United Kingdom or the European Economic Area, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure (“Right to be Forgotten”): Request deletion of your data in certain circumstances.
- Restriction: Request that we limit the processing of your data.
- Data Portability: Request transfer of your data to another controller in a structured, commonly used format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
11.2 Rights Under US State Privacy Laws
If you are located in the United States, depending on your state of residence (including California, Virginia, Colorado, Connecticut, and others), you may have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Delete: Request deletion of your personal information.
- Correct: Request correction of inaccurate personal information.
- Opt-Out: Opt out of the sale or sharing of personal information for cross-context behavioural advertising. (Note: We do not sell personal information.)
- Non-Discrimination: Exercise your privacy rights without receiving discriminatory treatment.
- Appeal: Appeal a denial of your request where applicable.
To exercise your US privacy rights, contact us at the email in Section 1. We will verify your identity before processing your request. You may also designate an authorised agent to make requests on your behalf.
11.3 Rights in Other Jurisdictions
If the law of your country grants you data protection rights not enumerated above, we will honour valid requests made under that law to the extent it applies to our processing of your data. Contact us using the details in Section 1 and we will respond within the timeframe required by the applicable law.
12. Automated Decision-Making
We do not use your personal data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
13. Children’s Privacy
Our website and services are directed at business professionals and are not intended for individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.
14. Data Breaches
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Assess the nature and scope of the breach without undue delay;
- Notify the relevant supervisory authority (e.g., the UK Information Commissioner’s Office) within 72 hours of becoming aware of the breach, where required by law;
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to your rights and freedoms;
- Take appropriate measures to mitigate harm and prevent recurrence.
15. Changes to This Policy
We may update this notice from time to time to reflect changes in our practices, legal requirements, or the jurisdictions from which we operate. Material changes will be posted on this page with an updated “Last updated” date. Where required by law, we will notify you of significant changes directly.
16. Complaints and Regulatory Contacts
If you are unhappy with how we have handled your personal data, we would welcome the chance to resolve this directly — please contact us first using the details in Section 1.
You also have the right to lodge a complaint with the supervisory authority in your jurisdiction, including:
- United Kingdom: Information Commissioner’s Office (ICO)
- European Union: The supervisory authority in your country of residence, work, or the place of the alleged infringement.
- United States: The relevant state Attorney General or consumer protection authority.
- Other jurisdictions: Your local data protection authority, where one exists.
17. Cookie Summary
| Cookie Type | Purpose | Used? |
|---|---|---|
| Strictly Necessary | Security, fraud prevention, site delivery | Yes (by Cloudflare) |
| Analytics / Performance | Website traffic analysis | No |
| Functional | User preferences | No |
| Targeting / Advertising | Marketing, profiling | No |
© 2026 Photon Fusion Ltd. All rights reserved.