Last updated: 21 July 2026
This privacy policy explains how Leva Heal Limited collects and uses personal information when you visit or interact with the KHIRON UK website, contact us through the website or communicate with us about the website. Personal information is information that identifies you or could reasonably be linked to you. This policy applies only to the KHIRON UK website. It does not cover clinical services or other websites, products or services operated by Leva Heal Limited or another KHIRON company where a separate privacy notice is provided.
The controller for the KHIRON UK website is: Leva Heal Limited 5 Pemberton Row London EC4A 3BA United Kingdom Registered in England and Wales – Company Number 12178110 Email: info@khironeurope.uk Leva Heal Limited decides why and how personal information is processed through the KHIRON UK website. You can use the email address above to ask a privacy question, exercise your rights or make a data protection complaint.
We process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), in each case as amended, including by the Data (Use and Access) Act 2025.
4.1 Visiting the website and server logs
When you visit the website, our systems and hosting provider may automatically record your IP address, date and time of access, requested page or file, referrer URL, browser type and version, operating system, device information, host name and technical error information. We use this information to deliver the website, maintain its stability, diagnose errors, prevent misuse and protect our systems. Our lawful basis is our legitimate interest under Article 6(1)(f) UK GDPR in providing a secure and technically reliable website. Server logs are normally deleted automatically after 7 to 30 days unless they are required for investigating a security incident or establishing, exercising or defending legal claims.4.2 Contact form and direct communications
If you contact us through a website form or by email, telephone or another direct channel, we process the information you provide. This may include your name, email address, telephone number, organisation, role, the content of your message and any follow-up correspondence. We use this information to respond to your enquiry, provide requested information, manage our relationship with you and keep an appropriate record of the communication. Depending on the context, our lawful basis is Article 6(1)(b) UK GDPR where your enquiry concerns a contract or steps before entering into a contract, Article 6(1)(f) UK GDPR for our legitimate interest in responding to and managing business enquiries, or Article 6(1)(c) UK GDPR where we must retain or disclose information to meet a legal obligation. General website forms are not intended for medical records, prescription details or other special category information. Please do not submit this information through a general contact form. If special category information is required for a specific service, we will provide separate privacy information and identify the applicable condition under Article 9 UK GDPR before collecting it. We normally delete contact-form enquiries within six months after the matter has been completed. Correspondence that forms part of a business, contractual, regulatory or legal record may be retained for up to six years, or longer where required by law or necessary for legal claims.4.3 Cookie and consent preferences
We use CookieYes to display our cookie notice and record the choices you make. The record may include your consent choice, date and time, consent identifier, IP address or truncated IP address, browser and device information. We use this information to remember and demonstrate your choices and manage website technologies. Our lawful bases are Article 6(1)(c) UK GDPR where necessary to demonstrate compliance and Article 6(1)(f) UK GDPR for our legitimate interest in operating a compliant preference-management system. The storage period for each cookie or similar technology is shown in the cookie settings available through the website. You can change or withdraw your choice at any time by reopening the cookie settings.4.4 Website analytics
With your consent, we use Google Analytics to understand how visitors use the website and improve its content and performance. Google Analytics may process online identifiers, cookie identifiers, IP-derived location information, browser and device information, pages viewed, events, session duration, referrer information and similar usage data. We do not use Google Analytics to identify you by name. Analytics technologies are not enabled until you consent through the cookie banner. Our lawful basis is your consent under Article 6(1)(a) UK GDPR and PECR. You can withdraw consent at any time through the cookie settings without affecting processing carried out before withdrawal. Analytics data is retained for up to 14 months where the current Google Analytics configuration applies.4.5 Website security
We use Wordfence to protect the WordPress website against malicious traffic, unauthorised access and other cyber threats. Wordfence may process IP addresses, requested URLs, request headers, browser information and security-event data. Our lawful basis is Article 6(1)(f) UK GDPR, based on our legitimate interest in protecting the website, our organisation and website users. Security logs are normally retained for 30 days unless a longer period is required to investigate an incident or protect legal rights.4.6 LinkedIn
The website may link to our LinkedIn presence. If you follow a link to LinkedIn or interact with our page, LinkedIn processes information under its own privacy policy. We may receive aggregate page insights and information that you choose to share with us, such as comments, messages or profile details. We use this information to operate our professional social-media presence, respond to interactions and understand engagement. Our lawful basis for our own processing is Article 6(1)(f) UK GDPR, based on our legitimate interest in corporate communication and maintaining professional relationships.Cookies and similar technologies store or access information on your device. Some are strictly necessary for the website or for remembering your privacy choices and can be used without consent where PECR permits. We currently seek your consent before enabling analytics or other non-essential technologies. The cookie banner provides the current list of technologies, providers, purposes and storage periods. You can accept or reject non-essential technologies with equal ease and can change your choice at any time through the cookie settings. Blocking some technologies may affect optional website features but will not prevent access to essential content.
We disclose personal information only where necessary for the purposes described in this policy. Service providers may process information only under our instructions and contractual data-protection obligations, unless they act as an independent controller for their own services.
Hosting provider
Our hosting provider processes technical and usage data for website hosting, content delivery and the creation of server logs. It acts as a service provider and processor.
Microsoft 365 / Outlook
Microsoft 365 and Outlook are used for email communication and the management of business records. As a service provider and processor, Microsoft may process contact details and correspondence.
CookieYes
CookieYes provides the cookie notice and stores users’ consent preferences. It acts as a service provider and processor and processes consent choices as well as device and technical data.
Google Analytics
Google Analytics is used to collect website usage statistics, but only after the user has given consent. Google acts as a service provider and recipient and may process online identifiers as well as device and usage data.
Wordfence / Defiant
Wordfence and its provider Defiant are used to protect the website, detect attacks and prevent security threats. As a service provider and processor, Defiant may process IP addresses, request data and security-event data.
KHIRON Europe GmbH
KHIRON Europe GmbH supports the administration of the group website, provides technical support, manages website content and assists with enquiries. It acts as an intra-group service provider and recipient and processes only the data necessary to complete the relevant support task.
Leva Heal Limited may share limited personal information with KHIRON Europe GmbH in Germany where this is necessary for group-level website administration, technical support, content management, internal reporting or assistance with enquiries. The categories involved may include contact details, communications, website usage data and technical information, but only to the extent required for the relevant task. Some service providers operate internationally and may process personal information outside the United Kingdom, including in the European Economic Area and the United States. When a restricted transfer is made, we use a transfer mechanism permitted by UK data protection law. Depending on the recipient, this may include UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework for eligible certified US organisations, or appropriate safeguards under Article 46 UK GDPR such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission Standard Contractual Clauses. Where required, we also carry out a transfer risk assessment and apply supplementary contractual, organisational or technical safeguards. You can contact us if you would like more information about the safeguard used for a particular transfer or a copy of the relevant contractual protection, subject to appropriate redactions.
We retain personal information only for as long as necessary for the purpose for which it was collected and to meet legal, regulatory, accounting or reporting requirements. The main periods are stated in section 4 and in the cookie settings. We may keep information for longer where needed to investigate a complaint or security incident, comply with a legal hold, or establish, exercise or defend legal claims. When information is no longer needed, we delete or anonymise it securely.
We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure, access or destruction. These include encrypted transmission using TLS, access controls, security monitoring, supplier due diligence and contractual confidentiality requirements. No internet transmission or storage system can be guaranteed to be completely secure.
Depending on the circumstances, you may have the right to: ask for access to the personal information we hold about you; ask us to correct inaccurate or incomplete information; ask us to erase information where there is no valid reason for us to continue using it; ask us to restrict how we use information in certain circumstances; object to processing based on legitimate interests, including profiling based on those interests; receive information you provided to us in a structured, commonly used and machine-readable format, and ask us to transmit it to another organisation where the right to data portability applies; and withdraw consent at any time where we rely on consent. Withdrawal does not affect the lawfulness of processing carried out before it. To exercise a right, email info@khironeurope.uk. We may need information to verify your identity. We normally respond within one month. Where the law permits an extension because a request is complex or numerous, we will tell you within the first month. Rights are not absolute and exemptions may apply.
If you are concerned about how we use your personal information, please email info@khironeurope.uk with the subject line “Data Protection Complaint”. We will acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep you informed where appropriate and tell you the outcome. You also have the right to complain to the Information Commissioner's Office (ICO). We would appreciate the opportunity to address your concern first, but this does not affect your right to contact the ICO.
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk
The KHIRON UK website is intended for an adult audience and is not directed at children. We do not knowingly collect personal information from children through the website. If you believe a child has provided personal information to us, please contact us so that we can take appropriate action.
We do not use personal information collected through the KHIRON UK website to make solely automated decisions that produce legal or similarly significant effects about you.
The website may contain links to websites operated by third parties. We do not control those websites or their privacy practices. Please read the privacy notice provided by the relevant third party before submitting personal information.
We may update this privacy policy to reflect changes to the website, our suppliers, our processing activities or the law. We will publish the updated version on the website and change the “Last updated” date. Where a change materially affects how we use personal information, we will provide additional notice where appropriate.
Provider privacy information
https://www.cookieyes.com/privacy-policy
https://privacy.microsoft.com/en-gb/privacystatement
https://policies.google.com/privacy
https://www.wordfence.com/privacy-policy
https://www.linkedin.com/legal/privacy-policy