Educational information only. Nothing on this site is medical advice, and no dose mentioned here is a recommendation. Speak to a prescriber who knows your history.

Privacy Policy

Last updated 2026-08-07

Last updated: 14 August 2026

This policy explains how BioRx collects and uses personal data when you use biorx.uk. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

Who we are

BioRx is the data controller for the personal data described in this policy.

We have not appointed a statutory Data Protection Officer, as we are not required to do so. Data protection enquiries are handled by the contact above.

What we collect, why, and on what lawful basis

We collect as little as we can. We do not sell personal data, we do not operate advertising networks, and we do not build profiles of readers.

1 Contact form and email enquiries

Data: your name (if you give it), your email address, the content of your message, and the date and time of submission. A basic anti-spam check may record the submitting IP address.

Purpose: to receive, understand and reply to your enquiry, and to keep a record of what was asked and answered.

Lawful basis: legitimate interests (Article 6(1)(f)): our interest in responding to people who contact us, which we consider aligned with your own interest in receiving a reply. Where your message forms part of a pre-contractual discussion, the basis is Article 6(1)(b).

Please do not send us health information. BioRx cannot give personal medical advice and does not want your medical history. If you send special category data anyway, we rely on Article 9(2)(e) where you have manifestly made it public, or we delete it. We will not use it to build any record about you.

2 Newsletter

Data: your email address; the date, time and IP address of your subscription and confirmation; and engagement data generated by our email platform (whether a message was delivered, opened, or a link clicked).

Purpose: to send you the updates you asked for and to understand, in aggregate, whether they are useful.

Lawful basis: consent (Article 6(1)(a)), given by double opt-in. You may withdraw consent at any time using the unsubscribe link in every message, or by emailing us. Withdrawal does not affect the lawfulness of processing before withdrawal.

We do not add anyone to the newsletter who has not asked to be added.

3 Analytics

Data: pages viewed, referring page, approximate location derived at country or region level, device type, browser and operating system, and a truncated or hashed IP address where our provider supports it.

Purpose: to understand which content is read and which is not, and to find broken or badly performing pages.

Lawful basis: consent (Article 6(1)(a)), collected through our cookie banner before any non-essential analytics is loaded, as required by PECR. If you decline, no analytics cookies or similar technologies are set and no analytics events are sent. See the Cookie Policy.

4 Server logs and security

Data: IP address, timestamp, requested URL, response code, user agent.

Purpose: to operate the site securely, diagnose faults, and detect abuse such as scraping, brute-force attempts and denial-of-service traffic.

Lawful basis: legitimate interests (Article 6(1)(f)): keeping the service available and secure.

5 What we do not do

We do not use personal data for automated decision-making producing legal or similarly significant effects, and we do not carry out profiling of that kind. We do not knowingly collect data from children under 13; if you believe a child has provided us with personal data, contact us and we will delete it.

Cookies and similar technologies

Non-essential cookies are set only with your consent. Full detail, including categories and how to withdraw consent, is in the Cookie Policy.

Retention

We keep personal data only as long as we need it.

DataRetention period
Contact form and email correspondence24 months from the last message in the thread, then deleted. Correspondence forming part of a complaint or legal matter is kept until the matter is resolved plus 6 years (limitation period, England & Wales).
Newsletter subscriber recordUntil you unsubscribe, plus 30 days to action the removal across systems. A minimal suppression record (hashed email) is kept indefinitely so we do not re-add you in error.
Newsletter consent evidenceDuration of subscription plus 24 months, as proof of consent.
Analytics data14 months at event level, then aggregated or deleted. Aggregate statistics containing no personal data may be kept indefinitely.
Server and security logs90 days, unless retained longer for the investigation of a specific security incident.
Corrections correspondence6 years, as part of our editorial record.

Who we share data with

We do not sell, rent, trade or share personal data with anyone. Everything you give us stays with BioRx: your details are stored on our own systems, are used only for the purposes described in this policy, and are never passed to advertisers, analytics companies, data brokers or any other third party. Keeping the data exclusively to ourselves is how we meet our UK GDPR obligations by design.

We may also disclose personal data where we are legally required to do so (for example in response to a valid court order or a lawful request from a regulator or law enforcement) and to our professional advisers where necessary. If BioRx is sold or restructured, personal data may transfer to the acquirer, who would be bound by this policy until it lawfully notifies you of any change.

International transfers

Some of our processors may store or process personal data outside the UK. Where that happens, we ensure one of the following applies:

  • the destination is covered by UK adequacy regulations (including the EEA, and the US where the recipient is certified under the UK Extension to the EU-US Data Privacy Framework); or
  • the transfer is made under the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
  • another lawful transfer mechanism under Chapter V of the UK GDPR applies.

You can ask us which mechanism applies to a particular transfer, and we will tell you.

Your rights

Under UK GDPR you have the right to:

  • be informed about how your data is used: this policy;
  • access the personal data we hold about you;
  • rectification of inaccurate or incomplete data;
  • erasure ("right to be forgotten"), where the conditions apply;
  • restrict processing in certain circumstances;
  • data portability, for data you provided to us that we process by consent or contract, by automated means;
  • object to processing based on legitimate interests, including profiling: we will stop unless we can show compelling legitimate grounds that override your interests;
  • object to direct marketing at any time, absolutely: we will stop immediately; and
  • withdraw consent at any time where consent is the basis.

How to exercise them. Use the contact form, or write to the registered address. We do not charge a fee, unless a request is manifestly unfounded or excessive. We will respond within one month, extendable by up to two further months for complex requests, in which case we will tell you within the first month and explain why. We may ask for information to confirm your identity where we genuinely cannot otherwise be sure who you are.

Security

We use HTTPS across the site, restrict administrative access to named accounts with multi-factor authentication, apply the principle of least privilege, keep software patched, and select processors on the basis of their security posture. No system is perfectly secure, but we will notify the ICO within 72 hours of becoming aware of a qualifying personal data breach, and will notify you directly where the breach is likely to result in a high risk to your rights and freedoms.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first via the contact form so we have the chance to put it right.

You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

ico.org.uk

Complaining to us first is not a precondition of complaining to the ICO.

Changes to this policy

We review this policy at least annually and whenever our processing changes. The current version and its date always appear at the top of this page. Where a change materially affects how we use your data, we will draw attention to it on the site and, for newsletter subscribers, by email.