Privacy Policy – vifome

Privacy Policy

Effective Date: 1 June 2025  |  Last Updated: 1 June 2025

This Privacy Policy explains how vifome (trading as vifome, and referred to throughout this document as “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you visit and interact with our website at vifome.info (the “Website”). We are committed to protecting your privacy and handling your personal data in a transparent, fair, and lawful manner.

We operate under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These laws give you important rights regarding your personal data, and this policy is designed to help you understand and exercise those rights. If you have any questions about this policy or how we handle your data, please contact us using the details provided in Section 14 below.

1. Who We Are

vifome is the data controller responsible for your personal data collected through this Website. As data controller, we determine the purposes and means by which your personal data is processed.

  • Company Name: vifome
  • Trading Name: vifome
  • Website: vifome.info
  • Address: London
  • Telephone: +44 7400 425860
  • Email: [email protected]

If you have questions or concerns regarding the way in which we process your personal data, or if you wish to exercise any of your data protection rights, you may contact us at any time at the email address above.

2. Data We Collect

We collect personal data that you voluntarily provide to us when you submit an enquiry or contact form on our Website. We also collect certain technical data automatically when you browse our Website. The categories of personal data we collect are described below.

2.1 Information You Provide to Us

When you complete and submit a contact or enquiry form on our Website, we collect the following personal data:

  • Full Name: so that we can address you appropriately in our response.
  • Email Address: so that we can respond to your enquiry by email.
  • Telephone Number: if you choose to provide it, so that we may contact you by phone if required.
  • Message Content: the content of the message or enquiry you submit via the form, which may contain additional personal information that you choose to share with us.

You are not required to provide all of the above fields; however, without certain information (such as your name and email address) we may be unable to respond to your enquiry.

2.2 Technical and Usage Data Collected Automatically

When you visit our Website, our web servers and third-party analytics tools (where enabled) may automatically collect certain technical information, including:

  • IP Address: your internet protocol address, which may be used to identify your approximate geographical location.
  • Browser Type and Version: the software you use to access the Website.
  • Operating System: the operating system of your device.
  • Referring URLs: the web page from which you navigated to our Website.
  • Pages Visited: the pages of our Website you view and the time spent on each page.
  • Date and Time of Visit: the timestamp of your visit to our Website.
  • Device Information: general device type and screen resolution data.

This technical data is collected using cookies and similar tracking technologies. Please see Section 5 for full details about our use of cookies.

3. How We Process Contact Form Submissions

When you submit a contact form on our Website, the information you provide is transmitted securely to our system for handling. The processing of your form submission involves the following steps:

  1. Your form data (name, email, phone, and message) is transmitted via an encrypted HTTPS connection to our web server.
  2. The data is processed by our server-side application (PHP) and delivered to our designated email inbox, enabling our team to read and respond to your enquiry.
  3. We may store a copy of your submission in a secure database or email system to allow us to track and manage correspondence.
  4. A member of our team will review your enquiry and respond using the contact details you have provided.
  5. Once your enquiry has been resolved, your data will be retained for the period specified in Section 9 of this policy, after which it will be securely deleted.

We do not use automated decision-making or profiling in relation to contact form submissions. No automated decisions with legal or similarly significant effects will be made solely on the basis of the information you provide through our forms.

4. Legal Basis for Processing

Under the UK GDPR, we are required to identify a lawful basis for each type of personal data processing we undertake. The lawful bases on which we rely are as follows:

  • Legitimate Interests (Article 6(1)(f) UK GDPR): When you submit a contact form, we process your personal data on the basis of our legitimate interest in responding to your enquiry and managing our business communications. We have carried out a legitimate interests assessment and are satisfied that our interests are not overridden by your rights and freedoms.
  • Consent (Article 6(1)(a) UK GDPR): Where we use optional analytics cookies or similar tracking technologies, we rely on your freely given, specific, informed, and unambiguous consent, which you may withdraw at any time.
  • Legal Obligation (Article 6(1)(c) UK GDPR): In some circumstances, we may need to process your personal data to comply with a legal obligation, such as retaining financial records or responding to a lawful request from a public authority.

We will always ensure that we have a valid lawful basis before processing your personal data, and we will not process your data for purposes that are incompatible with the original purpose for which it was collected.

5. Cookies and Similar Technologies

Our Website uses cookies and similar technologies to ensure the Website functions correctly and, where you have consented, to help us understand how visitors use the Website. A cookie is a small text file placed on your device by a website you visit.

5.1 Types of Cookies We Use

  • Strictly Necessary / Functional Cookies: These cookies are essential for the Website to operate correctly. They enable core functionality such as security, network management, and form submission handling. You cannot opt out of these cookies as the Website cannot function properly without them. No consent is required for strictly necessary cookies under the UK Privacy and Electronic Communications Regulations (PECR).
  • Analytics Cookies (Optional): With your consent, we may use analytics cookies to collect anonymised or pseudonymous information about how visitors use our Website — for example, which pages are visited most often and whether visitors encounter error messages. This helps us improve the Website over time. You may decline analytics cookies without affecting your ability to use the Website.

5.2 Managing Your Cookie Preferences

When you first visit our Website, you will be presented with a cookie consent notice that allows you to accept or decline non-essential cookies. You may change your preferences at any time by clearing your browser cookies and revisiting the Website.

You can also control and delete cookies through your browser settings. Most browsers allow you to refuse all or certain cookies and to delete cookies that have already been set. Please refer to your browser’s help documentation for instructions. Note that disabling certain cookies may affect the functionality of the Website.

For more information about cookies and how to manage them, you can visit www.allaboutcookies.org or the Information Commissioner’s Office (ICO) guidance at ico.org.uk.

6. Third-Party Services

Our Website may make use of certain third-party services and technologies that may result in limited personal data (such as your IP address) being processed by those third parties. We take care to use only reputable third-party services and to ensure that appropriate safeguards are in place.

6.1 Google Fonts

Our Website may load fonts from Google Fonts, a service provided by Google LLC. When your browser requests a font file from Google’s servers, Google may receive your IP address and information about your browser. Google’s use of this data is governed by Google’s Privacy Policy, available at policies.google.com/privacy. We use Google Fonts to ensure a consistent and readable typographic experience.

6.2 Tailwind CSS CDN

Our Website may load the Tailwind CSS framework via a content delivery network (CDN). When your browser requests the CSS file from the CDN provider’s servers, limited technical data such as your IP address may be transmitted to those servers. CDN providers typically process this data solely for the purpose of delivering the requested file and do not use it for profiling or advertising purposes.

6.3 Web Hosting Provider

Our Website is hosted by a third-party web hosting provider. Our hosting provider processes technical data (including IP addresses and server log files) in the course of providing hosting services. This data is processed in accordance with our hosting provider’s data processing agreement with us.

6.4 No Sale of Personal Data

We do not sell, rent, or otherwise transfer your personal data to third parties for their own marketing or commercial purposes. We only share your data with third parties where necessary to provide our services, comply with the law, or protect our legal rights, and always in accordance with applicable data protection legislation.

7. International Data Transfers

The United Kingdom has its own data transfer regime following its departure from the European Union. Under the UK GDPR and the Data Protection Act 2018, transfers of personal data to countries outside the UK must be conducted in accordance with the law. Specifically, transfers may only take place to countries that the UK Secretary of State has determined provide an adequate level of data protection (known as “adequacy regulations”), or where appropriate safeguards are in place.

Some of the third-party services we use (for example, Google Fonts served from Google’s servers in the United States) may result in your personal data being transferred to and processed in countries outside the United Kingdom. Where such transfers occur, we rely on the following safeguards:

  • UK Adequacy Regulations: transfers to countries that the UK has recognised as providing an adequate level of data protection.
  • International Data Transfer Agreements (IDTAs): the UK-approved contractual clauses for international transfers, equivalent to the EU’s Standard Contractual Clauses, which provide appropriate safeguards for your personal data.
  • UK Extension to the EU-US Data Privacy Framework (where applicable): for transfers to US entities that are certified under an applicable framework recognised by the UK.

You may contact us at [email protected] if you wish to obtain further information about the specific safeguards in place for any particular international data transfer.

8. Data Security

We take the security of your personal data seriously and have implemented a range of appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures include:

  • HTTPS Encryption: All data transmitted between your browser and our Website is encrypted using Transport Layer Security (TLS) via an HTTPS connection.
  • Access Controls: Access to personal data stored in our systems is restricted to authorised personnel who require it for legitimate business purposes.
  • Secure Email Handling: Contact form submissions are delivered to a secure, password-protected email inbox accessible only to authorised members of our team.
  • Server Security: Our web server and hosting infrastructure is maintained in accordance with industry-standard security practices, including regular software updates and patching.
  • Data Minimisation: We collect only the personal data that is necessary for the purposes described in this policy, in accordance with the principle of data minimisation under the UK GDPR.

Whilst we take all reasonable steps to protect your personal data, no method of electronic transmission or storage is 100% secure. In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, as required by Article 33 UK GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.

9. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements.

Our specific retention periods are as follows:

  • Contact Form Submissions: We retain the personal data submitted via our contact forms for a period of two (2) years from the date of submission, or until your enquiry has been fully resolved and there is no further business need to retain the data, whichever is the shorter period. After this time, your data will be securely deleted or anonymised.
  • Server Log Files: Technical log files, including IP addresses and access records, are retained for a period of up to twelve (12) months for security and diagnostic purposes, after which they are deleted automatically.
  • Analytics Data: Where analytics cookies are used, aggregated and anonymised usage data may be retained for up to twenty-six (26) months. Where the analytics data is linked to identifiable information, it will be subject to the same retention periods as above.

At the end of the applicable retention period, we will securely delete or anonymise your personal data. If you request deletion of your data before the end of the retention period, we will comply with your request unless we have a legal obligation to retain it or there is another lawful basis for continuing to process it.

10. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation and the Data Protection Act 2018, you have a number of important rights in relation to the personal data we hold about you. These rights are summarised below:

  • Right of Access (Article 15 UK GDPR): You have the right to request a copy of the personal data we hold about you, along with information about how we use it. This is known as a Subject Access Request (SAR). We will respond to your request within one calendar month.
  • Right to Rectification (Article 16 UK GDPR): You have the right to ask us to correct any inaccurate or incomplete personal data we hold about you.
  • Right to Erasure / ‘Right to be Forgotten’ (Article 17 UK GDPR): You have the right to request that we delete your personal data in certain circumstances — for example, where the data is no longer necessary for the purpose for which it was collected, or where you withdraw your consent and there is no other lawful basis for processing.
  • Right to Restriction of Processing (Article 18 UK GDPR): You have the right to ask us to restrict the processing of your personal data in certain circumstances — for example, where you contest the accuracy of the data, while we verify it.
  • Right to Data Portability (Article 20 UK GDPR): Where we process your data on the basis of consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit it to another data controller where technically feasible.
  • Right to Object (Article 21 UK GDPR): You have the right to object to the processing of your personal data where we rely on legitimate interests as our lawful basis. We will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Right to Withdraw Consent: Where we rely on your consent as the lawful basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Rights in Relation to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you. We do not currently carry out such automated decision-making.

To exercise any of your rights, please contact us in writing at [email protected] or by post to London. We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.

11. Right to Lodge a Complaint with the ICO

If you are not satisfied with the way in which we have handled your personal data, or if you believe that we have failed to comply with our obligations under the UK GDPR or the Data Protection Act 2018, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the supervisory authority responsible for data protection in the United Kingdom.

The ICO can be contacted as follows:

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the opportunity to address your concerns before you approach the ICO, and we encourage you to contact us in the first instance at [email protected].

12. Children’s Privacy

Our Website is not directed at or intended for use by children under the age of 13 years. We do not knowingly collect personal data from children under 13. If you are under 13, please do not submit any personal data through our Website.

If you are a parent or guardian and you believe that your child has provided us with personal data without your consent, please contact us immediately at [email protected] and we will take steps to delete such information from our systems as soon as reasonably practicable.

For users between the ages of 13 and 17, we encourage parents and guardians to monitor and supervise their children’s use of the internet and to ensure that any personal data submitted to us is done so with parental awareness and approval.

13. Changes to This Privacy Policy

We may update or revise this Privacy Policy from time to time to reflect changes in our data processing practices, applicable legislation, or operational requirements. Any changes we make will be posted on this page with an updated “Last Updated” date at the top of the policy.

Where changes are significant and materially affect how we process your personal data, we will take reasonable steps to bring those changes to your attention. This may include, where appropriate:

  • Displaying a prominent notice on our Website homepage or at the point of data collection.
  • Sending an email notification to individuals whose contact details we hold (where we have a lawful basis to do so).
  • Updating the effective date and version number of this policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of the Website following the posting of changes to this policy will constitute your acknowledgement of those changes.

14. Contact Us

If you have any questions, concerns, or requests in relation to this Privacy Policy or the way in which we process your personal data, please do not hesitate to contact us using the details below:

  • Company: vifome
  • Address: London
  • Telephone: +44 7400 425860
  • Email: [email protected]
  • Website: vifome.info

We aim to respond to all privacy-related enquiries within five (5) working days and to fulfil all valid data subject requests within one (1) calendar month of receipt, in accordance with our obligations under Article 12 of the UK GDPR.

15. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any disputes arising in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales, without prejudice to your right to bring a claim before the Information Commissioner’s Office.

This policy complies with the requirements of the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the European Union (Withdrawal) Act 2018, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR) as applicable.


vifome — Registered in the United Kingdom — vifome.info — © 2025 vifome. All rights reserved.