Vengera

Legal and privacy

Privacy Policy

Privacy notice for Vengera's growth-systems website. It covers website enquiries, direct emails, and the site's privacy-first audience measurement.

Last updated: 2026-03-13

1. Who this notice applies to

This Privacy Policy explains how Vengera handles personal data connected with website enquiries, direct emails, and normal use of this website.

The website is for initial business enquiries from local service SMEs. The website itself does not create a contract; final scope, commercials, and delivery assumptions are confirmed in writing before paid work begins.

2. Controller identity and contact

Vengera is a sole-trader business operating under the trading name Vengera.

Privacy questions should be sent to [email protected]. Full trader identity and written engagement details are supplied in quotes and project documents while the public correspondence address is being finalised for publication.

3. The data we collect

The site is intentionally light-touch. We collect only what is needed to respond to enquiries, scope suitable work, and keep the website running safely.

  • Name, business or trading name, contact details, role or context information, and the operational summary you choose to provide through the enquiry form or by email
  • The contents of website enquiries, direct emails, and follow-up messages you send to Vengera
  • Basic technical request data such as IP address, timestamps, browser details, and security or delivery logs created by hosting, CDN, DNS, or email services
  • Project and commercial records if an enquiry becomes a paid engagement

4. Data we do not ask for at first contact

Do not send passwords, customer records, payroll data, card details, health information, or anything else sensitive in the first message.

5. Why we use the data and lawful bases

  • To respond to enquiries, assess service fit, and prepare a proposal or audit scope: legitimate interests and, where you ask Vengera to take steps before a contract, pre-contract steps at your request
  • To deliver agreed work, manage projects, and issue commercial documents: performance of a contract
  • To keep records required for tax, accounting, and legal compliance: legal obligation
  • To protect the website, email, and service operations from misuse or security incidents: legitimate interests

6. Who we share data with

Vengera uses third-party providers only where needed to operate the website, receive and route enquiry-form submissions, receive email, and run the business safely.

  • First-party website contact endpoint and outbound mail-delivery provider used to send enquiries into the business inbox
  • Hosting, CDN, DNS, and email providers
  • Bookkeeping, legal, or professional advisers where necessary
  • Relevant software or infrastructure vendors used during delivery if an engagement moves forward

7. International transfers

Some technology providers may process data outside the UK. Where that applies, Vengera relies on the provider's approved contractual or legal transfer safeguards.

If a future engagement introduces additional processors or overseas transfers, those details are covered in the written engagement documents.

8. Retention

  • General unsuccessful enquiries: usually up to 12 months after the last meaningful contact
  • Successful enquiries that become quoted or contracted work: retained for project delivery, support history, and normal business record-keeping
  • Accounting and tax records: retained for the period required by law or standard business record obligations
  • Security or delivery logs: retained according to the relevant provider's normal security and operational settings

9. Cookies, analytics, and tracking

Vengera uses a consent-gated first-party audience measurement tool to estimate unique visitors and identify which public pages are being viewed most often.

If you accept tracking, the site stores a pseudonymous browser identifier in local storage and sends same-origin pageview beacons to `vengera.co.uk` so aggregate audience metrics can be generated without adding third-party analytics scripts.

If you decline, the site does not create the audience identifier or send the beacon-based pageview events. Standard delivery and security logs created by hosting, CDN, DNS, and email providers may still exist for operational reasons.

Tracking preferences can be reopened from the footer at any time.

10. Security

  • Access is limited to the people handling the enquiry or delivery
  • The public site and enquiry flow do not request sensitive client data by default
  • Reasonable technical and organisational measures are used to protect business communications and project information

11. Your rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict, object to, or request transfer of personal data.

To exercise a privacy right or ask how your information is being used, email [email protected].

12. Complaints

If you are unhappy with how Vengera has handled your personal data, please raise it by email first so the issue can be reviewed.

You also have the right to complain to the Information Commissioner's Office (ICO) if you believe your data has been handled unlawfully.