Privacy Policy
The privacy of your information matters to us. This policy explains what we collect on veyrum.com (the "Site"), why we collect it, how we handle it, and the rights you have. We do not sell your personal information, and we never will.
Veyrum operates an informational and marketing website. We do not offer user accounts, we do not host customer data, and we do not take payments on the Site. Because of that, we collect very little about you.
1. Who we are
The Site is operated under the name Veyrum ("we", "us"). Veyrum is in the process of establishing a US company; until that is complete, the Site is operated under the Veyrum name and this policy will be updated to name the entity once it is formed. For any privacy question or request, contact [email protected]. If you are a California resident, section 5 sets out your notice at collection.
2. What we collect and why
Information you send us. If you email us (for example, to ask about a consultation or an introduction), we receive your email address, your name if you provide it, and whatever you choose to put in your message. We use this only to respond to you and to keep a record of our correspondence.
Server logs. Like most websites, our hosting provider automatically records technical data when you visit — your IP address, browser and device type, the pages you request, and timestamps. We use this to operate the Site, keep it secure, and diagnose problems.
Privacy-respecting analytics. We use cookieless, aggregate website analytics to understand how many people visit and which pages are popular. These analytics do not use tracking cookies, do not build a profile of you, and are not used for advertising. See our Cookie Policy.
We do not knowingly collect information from children, and the Site is not directed to children.
3. How we use information
We use the limited information above to: respond to your enquiries; operate, secure, and improve the Site; understand aggregate usage; and comply with our legal obligations. Where the GDPR/UK GDPR applies, our legal bases are your consent (when you contact us), our legitimate interests (running a secure, functioning website), and compliance with legal obligations.
4. Sharing and disclosure
We do not sell or "share" (as defined by California law) your personal information, and we do not use it for cross-context behavioural advertising. We disclose information only to:
- Service providers who host the Site, deliver our email, and provide analytics, acting on our instructions and bound to protect the information.
- Authorities, when required by valid legal process, or to protect the rights, safety, and security of Veyrum, our users, or the public.
- A successor, if Veyrum is involved in a merger, acquisition, or sale of assets — with notice before your information becomes subject to a different policy.
We may also use aggregated or de-identified information, which cannot reasonably identify you, for any lawful purpose.
5. California notice at collection (CCPA/CPRA)
In the preceding 12 months we have collected these categories of personal information: identifiers (e.g., name, email address, IP address) and internet/network activity (e.g., pages viewed). Categories of sources: directly from you (when you contact us) and automatically from your device and browser when you visit the Site. We collect it for the business purposes in section 3, retain it as described in section 8, and disclose it only to the categories of recipients listed in section 4 (service providers; authorities where legally required; a successor entity). We do not sell or share it, and we do not collect sensitive personal information for the purpose of inferring characteristics.
6. Your rights
Depending on where you live, you may have some or all of these rights: to know/access the personal information we hold about you; to correct it; to delete it; to opt out of sale or sharing (we do neither); to data portability; to object to or restrict processing; to not be discriminated against for exercising these rights; and, where applicable, to appeal a decision or complain to your data protection authority.
To exercise any right, email [email protected]. We may need to verify your identity before responding. We honour browser Global Privacy Control (GPC) signals as opt-out requests where applicable.
7. Security
The Site is served over encrypted connections (HTTPS/TLS). We apply reasonable technical and organisational measures to protect the limited information we hold. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
8. Data retention
We keep information only as long as needed for the purpose it was collected, then delete or de-identify it, unless a longer period is required by law. In practice: email correspondence is kept while it may be useful for answering follow-ups and is then periodically cleared; server logs are kept for a short period for security and troubleshooting and then deleted or aggregated; and website analytics are aggregate and not tied to an identifiable person.
9. International visitors and data transfers
The Site is operated in the United States, so any information described in this policy is processed in the United States. Where personal data of individuals in the EEA, the UK, or Switzerland is transferred to the United States, we rely on appropriate safeguards: the service providers we use are engaged under the European Commission's Standard Contractual Clauses and, where they are certified, the EU-US Data Privacy Framework (together with its UK Extension and the Swiss-US framework). For occasional, non-repetitive transfers we may also rely on the derogations in Article 49 of the GDPR. To ask which safeguard applies, email [email protected].
10. Changes and contact
We may update this policy to reflect new practices or legal requirements; we will refresh the date at the top when we do. Questions or requests: [email protected].