Who we are
VELLØREX Studio ("VELLØREX", "we", "us") operates the website at vellorexstudio.com and provides trust and authority consultancy services. For the purposes of applicable data protection law, VELLØREX is the data controller in respect of personal data collected through this site.
This policy explains what we collect, why, and what you can ask us to do about it. It applies to this website and to the services we provide through it.
What we collect
We collect the following categories of information:
- Information you give us directly. Your name, email address, business name, website URL, and anything else you choose to write into an Authority Audit request or contact form.
- Information about your visit. Almost nothing, and none of it by our choice. We run no analytics, so we do not know which pages you read. Our hosting provider keeps standard server logs — the kind every web server produces, including IP address, browser type and the file requested — for its own security and operational purposes. We do not query them, build profiles from them, or use them to identify you.
- Your IP address, briefly and unreadably. To stop the audit form being abused we count requests per address. The address itself is never written down: it is converted to a salted one-way fingerprint that cannot be turned back into an address, by us or by anyone holding the store.
- Correspondence. Emails and messages you send us, kept so we can respond and maintain a record of the engagement.
We do not collect payment card details through this website, and we do not purchase or enrich personal data from third-party data brokers.
Why we collect it
We process personal data on the following lawful bases:
- To perform a service you requested — delivering an Authority Audit, responding to an enquiry, or carrying out a client engagement.
- Our legitimate interests — operating and improving the website, maintaining business records, and preventing misuse. We balance these against your rights and interests.
- Your consent — where you opt in to receive occasional emails from us. You can withdraw consent at any time.
- Legal obligation — where we are required to retain records for tax or regulatory purposes.
We do not use your information for automated decision-making or profiling.
Cookies and analytics
This site sets no cookies of any kind. It runs no analytics, no advertising cookies, no retargeting pixels, and no third-party trackers that follow you across other websites. Nothing is stored in your browser, so there is no cookie banner and nothing for you to consent to or refuse.
Fonts, images and stylesheets are served from this domain. There is one exception: an animation library is fetched from Cloudflare's public CDN, so Cloudflare receives your IP address as part of sending that file. It is not told which page you were reading — this site sends only its own address with that request, never the page you are on.
Nothing else leaves this domain. No analytics, no advertising, no tracking pixels, no social buttons, no embedded video, and no fonts from Google. Apart from that one file, no other company receives your IP address or learns that you visited.
If we add analytics later, this clause will say so before it is switched on, and anything that requires consent will ask for it first.
Who we share it with
We share personal data only with service providers who process it on our behalf and under contract. Naming them is more useful to you than a category, so here is the whole list:
- Vercel — hosting and deployment. Serves every page and keeps the standard server logs described in Clause 02.
- Resend — transactional email. Carries your audit request from the form to us.
- Microsoft — our email is Microsoft 365, so an audit request arrives and is stored in a mailbox they operate.
- Cloudflare — serves one animation file from its public CDN, as described in Clause 04, and therefore sees your IP address as part of sending it.
If that list ever changes, this clause changes with it. Should we later add a customer-relationship tool or an analytics provider, it will be named here before it is switched on, not afterwards.
We may also disclose information where required by law, court order, or to establish or defend legal claims.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Some providers may process data outside your country of residence. Where that occurs, we rely on appropriate safeguards, including standard contractual clauses where applicable.
How long we keep it
We retain personal data only as long as necessary for the purpose it was collected:
- Audit requests and enquiries — up to 24 months from last contact, then deleted.
- Client engagement records — for the duration of the engagement and for the period required by applicable tax and contract law thereafter.
- Email subscribers — until you unsubscribe.
- Aggregate analytics — retained in non-identifying form.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct information that is inaccurate or incomplete
- Request deletion of your personal data
- Object to or restrict certain processing
- Receive your data in a portable format
- Withdraw consent at any time, without affecting prior processing
- Lodge a complaint with your local data protection authority
To exercise any of these, email us at the address below. We will respond within one month, and we will not charge you or make it difficult.
Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and limiting the number of people who can access records.
The strongest measure is how little exists. There is no customer database and no account system. An audit request becomes an email and, where configured, a record in our CRM — nothing else retains it. Your IP address is never written down: rate limiting uses a salted one-way fingerprint that cannot be turned back into an address, including by us.
No method of transmission or storage is completely secure. We do not claim otherwise.
If there is a breach
Where a breach is likely to result in a risk to your rights and freedoms, we will report it to the relevant supervisory authority within 72 hours of becoming aware of it, as required by Article 33 of the UK/EU GDPR. Where the risk is high, we will contact you directly and without undue delay, under Article 34.
We will not wait for legal certainty before telling you. If we are unsure whether an incident meets the threshold, we will assume it does.
Any notice you receive from us will say, in plain language: what happened and when; which of your details were involved; what the likely consequences are; what we have done about it; and what — if anything — you should do. It will come from a named person, not a no-reply address.
If a breach occurs at one of the providers listed in Clause 05 rather than with us, we will pass on what they tell us, name them, and say plainly where our knowledge ends.
Teardown subjects
VELLØREX publishes unsolicited analyses ("teardowns") of publicly accessible websites. These assess only material that is openly available to any visitor. We do not access private systems, analytics, or non-public data.
Subjects are anonymised: we identify category, approximate region, and business size, but not the business name, domain, or any individual's name. Any personal names appearing in a teardown are illustrative and altered.
Removal on request. If you believe a teardown concerns your business and you would prefer it not be published, contact us and we will remove it promptly. We will not require you to explain why, and we will not ask you to negotiate.
Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. The effective date at the top of this page will always show when it was last revised. Where changes are material, we will note what changed rather than quietly replacing the text.
Anything in this policy — including access, correction, deletion, or teardown removal — goes to the same address, and reaches a person rather than a queue.
HELLO@VELLOREXSTUDIO.COM