Skip links

Last Updated: February 2025


1. Introduction

Welcome to IVONI Limited (“IVONI,” “we,” “us,” or “our”). We are committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share, secure, and otherwise process your personal data when you use any of the websites or online platforms owned and operated by IVONI (the “Services”), including, but not limited to:

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described here, please do not use our Services.


2. Our Role Under the GDPR

For the purposes of data protection law in the United Kingdom (UK) and the European Economic Area (EEA)—including the UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU GDPR)—IVONI Limited is generally the Data Controller of the personal data we process. This means we determine the purposes for which, and the means by which, your personal data is processed.


3. How We Collect Your Data

We collect personal data about you in various ways, as described below:

3.1 Information You Provide to Us
  1. Account Registration and Login
    • When you create an account on any of our Services (e.g., core.ivoni.org, ivonicore.com), we may ask you to provide contact information such as your name, email address, and/or a username.
    • You may also be asked to provide a password or other authentication details for account security purposes.
  2. Comments and User-Generated Content
    • If you leave comments on our Services—such as on news articles, blog posts, or forums—we may collect the information you provide in the comment form, along with your IP address and browser user agent string. This helps us detect and filter spam or abusive comments.
    • An anonymized string (hash) created from your email address may be provided to a third-party service (e.g., Gravatar) to check if you have a registered profile picture.
  3. Contact and Support
    • When you contact us through our Contact Us page or via email, we collect the personal information you provide, such as your name, email address, and any additional details you share in your inquiry or support request.
  4. Subscription and Marketing
    • You may opt in to receive newsletters, updates, or marketing communications. In such cases, we will collect your contact information (e.g., email address) to facilitate the subscription.
3.2 Information Collected Automatically
  1. Log Data
    • When you visit our Services, our servers automatically record certain technical information, sometimes called “log data.” This may include:
      • Your IP address
      • Browser type and settings
      • Device information (e.g., operating system, device identifiers)
      • The date and time of your requests
      • The pages you viewed or engaged with
  2. Cookies and Similar Technologies
    • We use cookies, pixels, and similar tracking technologies to recognize you and enhance your experience on our Services. Some cookies are essential for our Services to function, while others help us understand user behavior (analytics) or remember user preferences.
    • Types of Cookies
      • Session Cookies: Temporary cookies that remain in your browser until you close it.
      • Persistent Cookies: Cookies that remain in your browser for a defined period (e.g., days, months, or years).
    • Login Cookies: When you log in, we set cookies to store your login session and screen display preferences. If you select “Remember Me,” these cookies persist for about two weeks. Logging out removes these cookies.
    • Comment-Related Cookies: If you leave a comment, you may opt in to save your name, email, and website in cookies so you do not need to fill these details again. These cookies typically last for a year.
    • Cookie Control: You can adjust your cookie settings directly in your browser settings. However, disabling cookies may limit your ability to use certain features on our Services.
  3. Analytics
    • We may use third-party analytics providers (e.g., Google Analytics) to help us evaluate and understand how our Services are used. These providers may collect your IP address and other anonymized information about your usage.
3.3 Information from Third Parties
  • If you connect to our Services via a third-party platform (e.g., single sign-on), or if we integrate external services such as Gravatar, those platforms may share certain information with us (in accordance with their privacy policies).

4. Legal Bases for Processing

We rely on one or more of the following legal grounds under the GDPR to process your personal data:

  1. Consent (Article 6(1)(a) GDPR)
    • We may process your personal data if you have given us explicit consent for one or more specific purposes (e.g., opting in to marketing communications or certain optional cookies).
  2. Performance of a Contract (Article 6(1)(b) GDPR)
    • If you register or log in to use certain features of our Services, the processing of your data is necessary to perform our contractual obligations (e.g., providing you with an account).
  3. Legitimate Interests (Article 6(1)(f) GDPR)
    • We may process data to fulfill our legitimate interests, provided these interests are not overridden by your rights and interests. Examples include:
      • Ensuring the security and integrity of our Services.
      • Collecting analytics to improve user experience.
      • Preventing fraud and detecting spam.
  4. Compliance with Legal Obligations (Article 6(1)(c) GDPR)
    • We may process your data if necessary to comply with a legal or regulatory obligation (e.g., responding to lawful requests or court orders).

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

  1. Service Delivery
    • To operate, maintain, and provide you with the features and functionalities of our Services.
    • To manage user accounts and authenticate users.
  2. User Engagement & Communications
    • To respond to your questions, requests, and feedback submitted via contact forms or email.
    • To send important administrative or service-related communications (e.g., service notices, password resets).
  3. Customization & Personalization
    • To store user preferences and personalize your experience on our Services.
  4. Security & Fraud Prevention
    • To secure our Services, protect against unauthorized access, and detect and prevent spam or fraudulent activities.
  5. Analytics & Improvements
    • To analyze usage trends and traffic patterns so we can improve the design and functionality of our Services.
  6. Legal Compliance
    • To comply with applicable laws, regulations, court orders, and lawful requests from public authorities.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law. In particular:

  1. Comments
    • Comments and their metadata are retained indefinitely, so we can automatically recognize and approve follow-up comments instead of holding them in a moderation queue.
  2. User Accounts
    • We store personal data associated with user accounts (e.g., name, email address) for as long as the account remains active or as needed to provide Services.
    • You can request deletion of your account and associated personal data, subject to certain exceptions required by law.
  3. Log Data
    • Server logs are typically retained for a short period, unless we have a legitimate reason to keep them longer (e.g., to investigate security incidents).
  4. Legal Obligations
    • We may retain certain data to comply with legal obligations, resolve disputes, and enforce our agreements.

7. How We Share Your Data

We do not sell or rent your personal data. We only share your personal data in the following circumstances:

  1. Service Providers
    • We engage trusted third-party vendors or service providers to perform certain functions on our behalf (e.g., hosting, analytics, security). These parties have access to personal data only as necessary to perform their tasks, and they are required to maintain the confidentiality and security of such data.
  2. Legal Compliance & Protection
    • We may disclose personal data to courts, law enforcement, or regulatory authorities if required to do so by law or if we believe such action is necessary to comply with legal obligations, protect our rights, or protect the safety of others.
  3. Business Transfers
    • In the event of a merger, acquisition, asset sale, or other business transaction, personal data may be transferred as part of that deal. We will notify affected users before their data is transferred or becomes subject to a different privacy policy.
  4. Comments & Public Interaction
    • Any information you post in public areas (e.g., comment sections) will be visible to other users and the public at large. Please exercise caution when sharing personal data in these areas.

8. International Data Transfers

While our primary data centers are located in the United Kingdom, we may need to transfer your data to service providers or other third parties located outside the UK or the European Economic Area (EEA). In such instances, we ensure that appropriate safeguards are in place, including standard contractual clauses approved by the European Commission (for EEA-related data) or equivalent UK-specific mechanisms, to protect your personal data.


9. Data Security

The security of your personal data is of utmost importance to us. We implement a variety of technical and organizational measures designed to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures may include, but are not limited to:

  • Encryption: We use encryption protocols (e.g., HTTPS/TLS) to protect data in transit.
  • Access Controls: Only authorized personnel can access user data, and they are required to adhere to strict confidentiality obligations.
  • Firewalls & Intrusion Detection: We deploy firewalls and other security systems to detect and mitigate unauthorized access attempts.
  • Regular Audits & Testing: We conduct periodic audits, penetration testing, and security reviews to ensure our measures remain effective.

No method of transmission or electronic storage is completely secure. Therefore, while we strive to protect your personal data, we cannot guarantee its absolute security. In the event of a data breach, we will promptly notify affected individuals and relevant supervisory authorities in accordance with applicable data protection laws.


10. Your GDPR Rights

If you are located in the UK or EEA, you have the following rights regarding your personal data:

  1. Right to Access: Request confirmation of whether we process your personal data, and receive a copy of the personal data we hold about you.
  2. Right to Rectification: Request that we correct inaccuracies or complete incomplete personal data.
  3. Right to Erasure (“Right to be Forgotten”): Ask us to delete your personal data in certain circumstances, such as when it is no longer needed, or if you withdraw your consent.
  4. Right to Restrict Processing: Request that we limit the processing of your data in certain situations (e.g., while a data accuracy dispute is resolved).
  5. Right to Data Portability: Obtain a copy of your personal data in a structured, commonly used, machine-readable format and request that we transfer it to another controller.
  6. Right to Object: Object to the processing of your personal data under certain legal grounds, including processing based on legitimate interests or direct marketing.
  7. Right to Withdraw Consent: If you have provided consent to process your personal data, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  8. Automated Decision-Making: If we engage in automated decision-making (including profiling) that significantly affects you, you have the right to obtain human intervention and contest the decision.

To exercise any of these rights, please use the contact details in the “Contact Us” section. We will respond to your request in accordance with applicable data protection laws.

If you are dissatisfied with our handling of your personal data or our response to any request you make regarding your rights, you have the right to lodge a complaint with a supervisory authority, such as the UK Information Commissioner’s Office (ICO).


11. Use of Embedded Content and Third-Party Links

Articles, posts, or pages on our Services may contain embedded content from third parties (e.g., videos, images, or articles). Embedded content behaves as though you have visited the third-party site directly. These websites may collect information about you, use cookies, embed additional third-party tracking, and monitor your interaction with the embedded content. We are not responsible for the privacy practices of these third parties, and we encourage you to review their privacy policies.


12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we process your personal data, please contact the IVONI Pre-Sales General Enquiry Team:

We will do our best to address any requests or concerns you may have in a timely and efficient manner.


13. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations, or for other legitimate reasons. When we do, we will revise the “Last Updated” date at the top of this document. We encourage you to review this Privacy Policy periodically to stay informed about our data processing practices.

Your continued use of our Services following the posting of changes to this Privacy Policy constitutes your acceptance of those changes.


Additional Disclaimers
  1. Not Legal Advice: This document is provided for informational purposes and does not constitute legal advice.
  2. Jurisdictional Variations: Data protection laws may vary based on your location. We aim to comply with the most relevant regulations applicable to us, but you should verify any special requirements based on your own jurisdiction.
  3. Third-Party Services: Any use of third-party services or websites is subject to their respective privacy policies.

Thank you for reading the IVONI Privacy Policy. If you have any questions or concerns, please contact us directly. We value your privacy and strive to ensure that your personal data is protected and handled responsibly.