Vioren Consulting is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, contact us, or engage us for services.
We are required by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 to be transparent about how we use your data. We take this responsibility seriously — your data is used only for the purposes set out in this policy, and we will never sell it to third parties.
If you have questions about how we handle your personal information at any time, please contact us at viorenconsulting@gmail.com. We are here to help.
01
Who We Are
The data controller responsible for your personal information is:
Vioren Consulting
Email: viorenconsulting@gmail.com
Operating in: England and Wales
As the data controller, Vioren Consulting determines the purposes and means by which your personal data is processed. We are committed to processing your data lawfully, fairly, and transparently.
02
Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
| Category | Examples |
|---|---|
| Identity data | First name, last name, job title, company name |
| Contact data | Email address, phone number, business address |
| Business data | Information about your business, its operations, challenges, and goals, as shared during consultations |
| Financial data | Invoice and payment records (we do not store card details — payments are processed by third-party providers) |
| Communications data | Emails, messages, and records of conversations exchanged between you and Vioren Consulting |
| Technical data | IP address, browser type, device type, pages visited, and time spent on our website (collected via cookies — see Section 10) |
| Usage data | Information about how you use our website and services |
We do not knowingly collect special category data (such as health, ethnicity, or religious information) and ask that you do not provide such information unless specifically requested and necessary for the service.
03
How Data Is Collected
We collect your personal data through the following means:
- Direct interactions: When you complete a contact or enquiry form on our website, send us an email, or book a call;
- Consultations and meetings: Information shared during discovery calls, meetings, or as part of an active engagement;
- Contracts and proposals: When you engage our services and enter into an agreement with us;
- Payments: When you pay invoices, your payment details are processed by our payment provider — we retain only records of transactions, not card data;
- Website usage: Automatically collected technical and usage data via cookies and analytics tools when you visit our website (see Section 10);
- Third-party sources: Occasionally, we may receive information about you from third parties such as referral partners or publicly available business information, where this is relevant to an enquiry.
04
How We Use Your Data
We use your personal data only for defined purposes. The table below sets out what we use your data for and the legal basis for each use:
| Purpose | Description |
|---|---|
| Responding to enquiries | To respond to contact form submissions, emails, or meeting requests |
| Service delivery | To deliver the consulting services you have engaged us for, including communication and project management |
| Invoicing and payments | To issue invoices, process payments, and maintain financial records |
| Client communication | To keep you informed about the progress of your engagement, share deliverables, and provide post-engagement support |
| Legal compliance | To comply with legal and regulatory obligations, including tax and accounting requirements |
| Service improvement | To analyse how our website and services are used in order to improve them |
| Marketing (opt-in only) | Where you have given consent, to send relevant updates, insights, or service information by email |
We will not use your data for any purpose that is incompatible with the purposes set out above without informing you and, where required by law, obtaining your consent.
05
Legal Basis for Processing
Under UK GDPR, we are required to have a lawful basis for processing your personal data. The bases we rely on are:
- Contract performance (Article 6(1)(b)): Processing that is necessary to perform a contract with you or to take steps at your request before entering into a contract — for example, delivering services you have engaged us for, issuing invoices, and communicating about your engagement.
- Legitimate interests (Article 6(1)(f)): Processing that is necessary for our legitimate business interests, provided these are not overridden by your rights — for example, responding to enquiries, improving our services, and maintaining records of our business activities. We have conducted legitimate interests assessments where applicable.
- Legal obligation (Article 6(1)(c)): Processing that is necessary to comply with a legal obligation — for example, maintaining financial records for HMRC purposes.
- Consent (Article 6(1)(a)): Where we rely on your consent — for example, for marketing emails — you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
06
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
| Data type | Retention period |
|---|---|
| Client engagement records | 6 years from the end of the engagement (for legal and contractual purposes) |
| Financial records (invoices, payments) | 7 years (HMRC requirement) |
| Pre-engagement enquiry data | 12 months from the date of enquiry if no engagement follows |
| Email correspondence | 6 years for material business correspondence; otherwise 2 years |
| Website analytics data | Up to 26 months (anonymised after 13 months where possible) |
| Marketing consent records | Until consent is withdrawn, plus 2 years |
When personal data is no longer needed, we delete or anonymise it securely. Where anonymisation is not possible, we ensure the data is stored in a manner that prevents unauthorised access.
07
Data Sharing
We do not sell, rent, or trade your personal data. We share your data only in the following limited circumstances:
- Service providers: We use trusted third-party tools and platforms to operate our business — including email services, project management software, accounting tools, and website analytics. These providers act as data processors on our behalf and are contractually required to protect your data and use it only for the purposes we specify.
- Professional advisors: We may share data with our accountants, solicitors, or insurers where necessary for legitimate business purposes.
- Legal and regulatory obligations: We may disclose your data to law enforcement, regulatory bodies, or courts if required to do so by law or to protect the rights, property, or safety of Vioren Consulting or others.
- Business transfers: In the event of a merger, acquisition, or sale of business assets, your data may be transferred to the relevant third party. We will notify you of any such change.
Third-party tools currently used by Vioren Consulting may include (but are not limited to): email providers (e.g. Google Workspace), project management tools, accounting software (e.g. Xero or similar), and website analytics platforms. Each is selected for its compliance with UK/EU data protection standards.
Where any third-party provider transfers data outside the UK, we ensure appropriate safeguards are in place — such as UK Standard Contractual Clauses or equivalent protections — in accordance with Chapter V of UK GDPR.
08
Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or disclosure.
These measures include:
- Use of encrypted communication channels for sensitive information;
- Password-protected and access-controlled storage for client records;
- Use of reputable, security-vetted third-party service providers;
- Restricted internal access to personal data on a need-to-know basis;
- Regular review of data handling practices.
While we take reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure. If you are concerned about the security of information you are sending to us, please contact us to discuss alternative arrangements.
Data breach: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, and will inform you directly where required under UK GDPR.
09
Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
Right of access
You may request a copy of the personal data we hold about you (a "Subject Access Request"). We will respond within one month.
Right to rectification
You may ask us to correct any personal data that is inaccurate or incomplete.
Right to erasure
You may ask us to delete your personal data where there is no longer a legitimate reason for us to hold it. This right is subject to certain legal exceptions.
Right to restrict processing
You may ask us to suspend processing of your data while a concern is investigated, or where processing is unlawful but you prefer restriction to erasure.
Right to data portability
Where we process your data by automated means on the basis of consent or contract, you may request that we provide it in a structured, machine-readable format.
Right to object
You may object to processing based on legitimate interests or direct marketing. We will stop processing unless we have compelling legitimate grounds that override your interests.
Right to withdraw consent
Where processing is based on your consent, you may withdraw it at any time. This does not affect processing already carried out.
Right to complain
You have the right to complain to the Information Commissioner's Office (ICO) if you believe we have not handled your data correctly.
To exercise any of these rights, please contact us at viorenconsulting@gmail.com. We will respond within one calendar month of receiving your request. We may need to verify your identity before processing your request.
Information Commissioner's Office (ICO): If you are not satisfied with our response to a data query or complaint, you have the right to lodge a complaint with the ICO, the UK's supervisory authority for data protection. You can contact them at ico.org.uk or by calling 0303 123 1113.
10
Cookies
Our website uses cookies — small text files placed on your device — to help us understand how visitors use our site and to improve the experience over time.
We use the following types of cookies:
| Cookie type | Purpose |
|---|---|
| Essential cookies | Required for the website to function correctly. These cannot be disabled. |
| Analytics cookies | Used to understand how visitors interact with our website — for example, which pages are visited most. This data is aggregated and anonymised where possible. We use this to improve the site. |
| Preference cookies | Used to remember your preferences and settings for future visits. |
We do not currently use advertising or tracking cookies that follow you across other websites. Where we use third-party analytics tools (such as Google Analytics), they are configured to anonymise IP addresses and comply with UK GDPR requirements.
Your choices: You can control and delete cookies through your browser settings. Disabling non-essential cookies may affect some features of our website. On your first visit, you will be presented with a cookie preference notice where you can indicate your choices.
For more information about cookies and how to manage them, visit aboutcookies.org.
11
Children's Data
Our services are directed at businesses and professional individuals. We do not knowingly collect or process personal data of children under the age of 18.
If you believe we have inadvertently received data relating to a child, please contact us immediately at viorenconsulting@gmail.com and we will delete it promptly.
12
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make changes, we will update the effective date at the top of this page. For significant changes, we will take reasonable steps to notify you — for example, by emailing active clients or displaying a notice on our website.
We encourage you to review this policy periodically to stay informed about how we protect your information.
13
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please get in touch:
Vioren Consulting
Email: viorenconsulting@gmail.com
Jurisdiction: England and Wales
We will acknowledge your enquiry within two Working Days and aim to provide a full response within one calendar month of receipt. For complex requests, we may require additional time and will notify you accordingly.
If you are not satisfied with our response, you have the right to contact the Information Commissioner's Office (ICO) at ico.org.uk.
We take data privacy seriously and will always aim to resolve your concern fairly and transparently. You are always welcome to raise anything directly with us before escalating to a regulatory authority.