1. Who We Are
VESTIONE (“we”, “us”, “our”) operates the website at https://vestione.com and is the data controller for the personal data described in this policy.
If you have any questions or wish to exercise your rights, contact us at: hello@vestione.com
2. What Personal Data We Collect
We collect the following data when you submit the contact form:
- Full name
- Work email address
- Company name (optional)
- Project type and estimated budget
- Project description / message
We also collect your IP address temporarily in server memory solely for rate-limiting purposes (to prevent abuse). It is never persisted to a database or logged.
We do not currently use cookies, browser local storage, session storage, or any tracking or analytics scripts. If this changes we will update this policy and present a consent choice before any such processing begins.
3. How and Why We Use Your Data
| Purpose | Lawful Basis (GDPR Art. 6) |
|---|---|
| Respond to your business enquiry and provide a tailored proposal | Legitimate interests (Art. 6(1)(f)) — processing is necessary to take steps at your request prior to entering a contract |
| Maintain a record of business enquiries for internal reporting and follow-up | Legitimate interests (Art. 6(1)(f)) |
| Export enquiry data to an internal Google Sheet for team access | Legitimate interests (Art. 6(1)(f)) |
We have conducted a Legitimate Interests Assessment (LIA) and determined that our processing does not override your interests, rights, or freedoms, given the purely B2B context of the enquiry form. You always have the right to object — see Section 7.
4. Who We Share Your Data With
We share your data with the following third parties:
- Google LLC — your enquiry data may be written to a Google Sheet accessible only to authorised team members. Google acts as a data processor under a Data Processing Agreement. Data may be stored on servers in the US; transfers are covered by Google's Standard Contractual Clauses.
- Cloudflare, Inc. (Turnstile) — we use Cloudflare Turnstile, a bot-detection CAPTCHA, to protect the contact form. When you submit the form, a token is validated with Cloudflare's servers. Cloudflare may process your IP address and browser signals to verify you are human. See Cloudflare's Privacy Policy.
We do not sell, rent, or otherwise share your personal data with any other third parties.
5. How Long We Keep Your Data
Enquiry data stored in our database is retained for 2 years from the date of submission, after which it is deleted. If we enter into a contract with you, we may retain relevant data for the duration of the contract and up to 7 years afterward for legal and accounting purposes.
6. Security
We take appropriate technical and organisational measures to protect your data, including TLS encryption in transit, access controls on our database, and restricted access to the Google Sheet. However, no system is completely secure and we cannot guarantee the absolute security of your data.
7. Your Rights Under GDPR / UK GDPR
If you are in the EEA or the UK, you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate data.
- Right to erasure — ask us to delete your data (“right to be forgotten”).
- Right to restriction — ask us to restrict processing of your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests at any time. We will stop unless we have compelling legitimate grounds.
To exercise any of these rights, email us at hello@vestione.com with the subject line “Data Subject Request”. We will respond within 30 days.
You also have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office (ICO).
8. Future Use of Analytics & Cookies
We are planning to add website analytics in the future. Before doing so, we will update this policy and implement a cookie consent mechanism that allows you to accept or decline non-essential cookies and tracking. No analytics data is currently collected.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.
Questions? hello@vestione.com