Policy

Privacy policy

Last updated: May 2026

This page sets out how VisionRelic processes personal data. It is written to be compliant with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the UK Data Protection Act 2018. Final entity details should be confirmed by counsel before publication on a production domain.

1. Who we are (data controller)

VisionRelic ("VisionRelic", "we", "us", "our") is the controller of personal data collected through this website. For privacy matters, contact us at privacy@visionrelic.com. For routine enquiries, use info@visionrelic.com.

2. What personal data we collect

Enquiry data. Name, business email, company name, and the content of any message you submit through our contact or assessment forms.

Assessment results. The self-assessment answers you provide and the resulting readiness tier, alongside any contact details you choose to share to receive a tailored briefing.

Technical data. IP address, user agent, referring URL, pages visited, and approximate location. Collected by our hosting infrastructure for security, fraud prevention, and reliability.

Analytics data (with consent). Aggregate, privacy-preserving measurement of page views and interactions. Loaded only after you give consent through our cookie banner.

3. How we use personal data and the lawful basis

We process personal data only where we have a lawful basis under Article 6 GDPR:

Responding to enquiries and evaluating engagements — legitimate interests (Art. 6(1)(f)) in operating a B2B consultancy and replying to prospective clients.

Operating and securing the site — legitimate interests in keeping the service available and protected against abuse.

Analytics and non-essential cookies — your consent (Art. 6(1)(a)), which you may withdraw at any time.

Compliance with legal obligations — record-keeping required by applicable law (Art. 6(1)(c)).

4. Sharing and processors

We do not sell personal data. We share personal data only with service providers acting as processors under written contracts that meet Article 28 GDPR, including: our website hosting and database provider, our email delivery provider, and our analytics provider (when consented). A current list of sub-processors is available on request.

5. International transfers

Some of our service providers are located outside the European Economic Area or the United Kingdom. Where personal data is transferred to a country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, together with supplementary measures where required by the Schrems II ruling.

6. Retention

We keep personal data only for as long as necessary for the purposes described above:

Enquiry and assessment data: up to 24 months from last contact, then deleted or anonymised.

Engagement records (where we work with you): for the duration of the engagement and, where required, for a further 7 years for legal, tax, and audit purposes.

Server logs: up to 90 days unless required longer for security investigations.

7. Your rights

Subject to applicable law, you have the right to: access a copy of your personal data; request correction or deletion; restrict or object to processing; data portability; and withdraw consent at any time without affecting prior processing. To exercise any of these rights, email privacy@visionrelic.com.

You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EU it is the data protection authority of your member state of residence.

8. Automated decision-making

We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects.

9. Security

We apply appropriate technical and organisational measures, including encryption in transit (TLS), encryption at rest for personal data, access controls, and least-privilege role-based access for all production systems.

10. Children

This site is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this policy from time to time. Material changes will be highlighted at the top of this page. The "last updated" date always reflects the current version.

12. Contact

Privacy enquiries: privacy@visionrelic.com. General enquiries: info@visionrelic.com.