VECTA.
Privacy notice

How we handle your data.

We sell compliance-grade automation, so this notice is written to be read rather than survived. It covers everyone whose data we hold: website visitors, people we contact about our services, and clients.

Last updated: 23 July 2026

1. Who we are

VECTA Consultancy Ltd ("VECTA", "we", "us") is the data controller for the personal data described in this notice. We are registered in England & Wales.

Company number17356188
Registered office71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Telephone07951 675958
Data protection contactprivacy@vectaconsultancy.com
Security disclosuressecurity@vectaconsultancy.com · security.txt

We are not required to appoint a Data Protection Officer. Questions about this notice go to the address above and are answered by a person, not a queue.

2. What we collect, and why

When you use the website or the Cost of Latency calculator

The calculator runs entirely in your browser. The figures you enter are never sent to us — they stay on your device and in your own URL. We cannot see your inputs unless you choose to send them to us.

When you request a consultation or an audit

We collect your name, work email address, company name, and anything you write in the message field. We use it to respond to you, to run the consultation, and to keep a record of what was discussed.

When we contact you about our services

We may contact people in a professional capacity at limited companies about services relevant to their role. Where we do, we hold your name, job title, work email address, employer, and a note of the publicly available signal that led us to get in touch.

When you become a client

We hold engagement records, billing details, and — through the Client Vault — records of the workflow actions and approvals carried out under your engagement. Where an automation processes personal data belonging to your clients or staff, we act as your processor under a separate data processing agreement, not as controller.

3. Our lawful bases

ActivityLawful basis
Responding to an enquiry you sent usLegitimate interests, and steps taken at your request prior to a contract
Business-to-business marketing to corporate contactsLegitimate interests (Art. 6(1)(f)) — assessed and recorded in a Legitimate Interest Assessment we keep on file
Delivering and administering an engagementPerformance of a contract
Invoicing, accounting and tax recordsLegal obligation
Keeping a suppression list of people who opted outLegal obligation — we must remember you asked us to stop

Our legitimate interest is in reaching organisations that plausibly have the problem we solve. We balance it by contacting people only in a work capacity at corporate addresses, capping contact at five messages, offering an opt-out in every message, and stopping permanently and immediately when asked.

4. Stopping contact from us

Reply "stop" to any message, use the unsubscribe link in it, or email privacy@vectaconsultancy.com. We action it immediately and permanently — no confirmation step, no "are you sure", no re-adding you from a later list. Your address stays on a suppression list precisely so we cannot contact you again by accident.

5. Who we share data with

We do not sell personal data, and we never will. We share it only with the suppliers who run our operations:

  • Hosting and infrastructure providers for the website and Client Vault
  • Email, calendar and document services used to correspond with you
  • Workflow automation and CRM tooling used to run engagements
  • Accounting and payment providers, for invoicing
  • Professional advisers, and regulators or law enforcement where we are legally required to

Each is bound by contract to process data only on our instructions. Where a supplier is outside the UK, the transfer is covered by UK adequacy regulations or the International Data Transfer Agreement.

AI and automated processing

Our workflows use automated systems to classify and route work. Your data is not used to train public AI models. Nothing consequential happens without a human approving it first — that human approval gate is a core part of how we build, not an add-on. We do not make solely automated decisions producing legal or similarly significant effects about you.

6. How long we keep it

DataRetained for
Enquiries that don't become engagements24 months from last contact
Prospect records in our outreach list12 months from last contact, then deleted
Suppression list entriesIndefinitely — this is how we honour your opt-out
Client engagement records6 years after the engagement ends
Invoices and accounting records6 years, as required by UK tax law

7. Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you
  • Correct anything inaccurate
  • Delete it, where we have no overriding reason to keep it
  • Restrict or stop a particular use
  • Port it to another provider in a machine-readable format
  • Object to processing based on legitimate interests — including all marketing, which we stop on request without needing a reason

Email privacy@vectaconsultancy.com. We respond within one month and there is no charge.

If you are unhappy with how we have handled your data, tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

8. Cookies

This site sets no advertising or tracking cookies, and there is no consent banner because there is nothing to consent to. We load fonts and stylesheets from third-party content delivery networks, which receive your IP address as a technical necessity of serving those files.

9. Security

Access is limited to those who need it. Data is encrypted in transit, credentials are held in a secrets manager rather than in code or documents, and client workspaces are separated from one another. For security-critical work we can deploy inside your own cloud tenancy so your data never leaves your control.

10. Changes

We update this notice when what we do changes. The revision date sits at the top. Material changes affecting how we use data we already hold will be notified to affected clients directly.