Legal

Privacy Policy

How we collect, use, and protect your personal data

Effective: 1 April 2026

Data Controller

VectisFlow Limited is the data controller responsible for your personal data. We operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Business: VectisFlow Limited

Company No.: 14990157

Registered Office: 43 Fairfoot Rd, London E3 4EG

Email: hello@vectisflow.com

Location: London, United Kingdom

Information We Collect

We collect only the data necessary to provide our services and operate our website.

Information You Provide

  • Contact Forms: Name, email address, company name, phone number, and message content
  • Meeting Bookings: Name, email, and scheduling preferences via Cal.com
  • Client Engagements: Business information and project-related data shared during service delivery

Information Collected Automatically

  • Usage Data: Pages visited, time on site, referral source (via Plausible, cookieless)
  • Technical Data: IP address, browser type, device type, operating system
  • Security Tokens: Cloudflare Turnstile verification tokens (for spam protection)

Lawful Basis for Processing

We process your personal data under the following legal bases as defined by UK GDPR.

Contractual Necessity

Processing necessary to fulfil our obligations under a Statement of Work or to take pre-contractual steps at your request (e.g. discovery calls).

Legitimate Interest

Processing necessary for our legitimate business interests, such as website analytics, security, and responding to enquiries. We balance these interests against your rights.

Consent

Where we rely on consent (e.g. PostHog analytics cookies), you can withdraw it at any time via our cookie banner or by contacting us.

How We Use Your Data

We process your data for specific, legitimate purposes.

Service Delivery

Responding to enquiries, scheduling discovery calls, delivering AI workflow automation services, and providing ongoing support.

Contract / Legitimate Interest

Communication

Sending information you have requested, project updates, and service-related correspondence.

Contract / Consent

Analytics & Improvement

Understanding how our website is used to improve our services and user experience. Plausible (cookieless, no consent needed) and PostHog (consent-based).

Legitimate Interest / Consent

Security

Protecting our website and services from spam, abuse, and automated attacks via Cloudflare Turnstile and rate limiting.

Legitimate Interest

Data Sharing

We never sell your personal data. We share data only with trusted third-party processors who help us operate our business.

Resend

Email delivery

Cloudflare

Security, CDN & bot protection

Plausible

Privacy-focused analytics (cookieless)

PostHog

Product analytics (consent-based)

Upstash

Rate limiting (Redis)

Vercel

Website hosting

All processors are bound by data processing agreements and process data only on our instructions. We do not sell, rent, or trade your personal data to any third party.

Data Retention

We retain your data only as long as necessary for the purposes outlined.

Contact Form Submissions

24 months

Client Project Data

Duration of engagement + 7 years (legal/tax requirement)

Analytics Data

12 months (anonymised/aggregated)

Your Rights

Under UK GDPR (Articles 15-22), you have the following rights regarding your personal data.

Right of Access

Request a copy of the personal data we hold about you (Art. 15)

Rectification

Request correction of inaccurate or incomplete data (Art. 16)

Erasure

Request deletion of your personal data where there is no compelling reason to continue processing (Art. 17)

Restrict Processing

Request that we limit how we use your data in certain circumstances (Art. 18)

Data Portability

Receive your data in a structured, machine-readable format (Art. 20)

Object

Object to processing based on legitimate interests or direct marketing (Art. 21)

To exercise any of these rights, contact us at hello@vectisflow.com. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).

International Transfers

Some of our third-party processors operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place, including:

  • UK adequacy decisions (where the destination country provides adequate protection)
  • International Data Transfer Agreements (IDTAs) or UK Addendum to EU Standard Contractual Clauses
  • Data processing agreements with all third-party processors

Children's Privacy

Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised effective date. We encourage you to review this policy periodically.

View Cookie Policy

Contact Us

Questions about this policy or your data? Get in touch.

Email: hello@vectisflow.com

Business: VectisFlow Limited

Company No.: 14990157

Registered Office: 43 Fairfoot Rd, London E3 4EG

Related Policies: Terms of Service Cookie Policy