Legal

Privacy Notice

Last updated: 11 August 2026

How I handle personal information provided through the public website, secure client workspaces and consulting engagements. I keep this notice deliberately clear and practical.

Who I am

Hemanth Vishnu is a trading name of HEMANTHVA VENTURES LTD (“I”, “me”, “my”), a company registered in Scotland (company number SC744785), registered office Clyde Offices, 2nd Floor, 48 West George Street, Glasgow, Scotland, G2 1BP. I am the controller for public-site enquiries, account administration and service-security records. For workspace content handled on a client’s documented instructions, HemanthVA Ventures Ltd may instead act as a processor; the written engagement and any data-processing terms set out the parties’ roles. You can reach me about anything in this notice at hello@hemanthvishnu.com.

What I collect

  • When you contact me: your name, work email, and optionally your company and phone number, plus whatever you write in your message.
  • Automatically, for security and delivery: basic technical data such as your IP address, browser type and timestamps, recorded in standard server logs by my hosting provider.
  • When you use a secure workspace: your name and work email, authentication and session records, the business and framework you are working on, answers, comments, review decisions, actions, approval history and audit events.
  • Evidence you choose to upload: filenames, file contents and related review notes. Please avoid uploading personal information that is not needed for the engagement.

I do not use advertising or analytics trackers. Secure workspaces use strictly necessary, HTTP-only session cookies to keep signed-in users authenticated; they expire automatically and are not used to track people for marketing.

Why I use it, and my lawful basis

For enquiries, I use your information to reply and discuss the services you ask about. The lawful basis is usually legitimate interests (UK GDPR Article 6(1)(f)). Where I act as controller for consulting delivery, processing may also be necessary to take steps at your request or perform a contract (Article 6(1)(b)), or for the legitimate interests of delivering, securing and documenting the engagement. Where I act as processor, the client determines the purpose and lawful basis and I handle the information under its documented instructions. I may retain controller records where necessary to meet a legal obligation or establish, exercise or defend legal claims. I do not use this information for unrelated marketing.

Who else handles it

I keep the list of third parties short and use reputable providers, each under their own data-protection terms:

  • Hostinger: infrastructure hosting for the website, secure platform, database, uploaded evidence and server logs.
  • Resend: sends enquiries, one-time access codes and necessary workflow notifications.
  • Microsoft 365: the inbox where I read and store enquiries.
  • Connected delivery systems. Where an engagement includes a configured compliance-management system such as CISO Assistant, the approved information needed to create or update engagement records may be sent to that system. The applicable engagement documentation identifies its scope.
  • Approved associates and professional advisers. They receive information only where needed for the engagement or a legal obligation, under appropriate confidentiality and data-protection terms.

I never sell your data or share it for advertising.

Where your information is handled (international transfers)

I may access information while based in or travelling outside the UK, including India. Some technology providers may also process information in other countries. Where UK data-protection law requires a transfer safeguard, I use an applicable adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, or another recognised safeguard. You can ask me which safeguard applies.

How long I keep it

If we don’t end up working together, I delete your enquiry within 12 months. If we do, I normally keep relevant controller-side engagement records for the duration of the work and for up to 6 years afterwards to meet legal, tax and contractual obligations, unless the written agreement sets a shorter period. Workspace content and evidence handled as a processor are returned or deleted as the agreement requires, unless the law requires storage. Authentication codes and active sessions expire after short security-defined periods; technical security records are kept only as long as reasonably needed to protect and audit the service.

Your rights

Under UK GDPR you can ask me to give you a copy of your data, correct it, delete it, restrict or object to its use, or provide it in a portable form. To exercise any of these, just email hello@hemanthvishnu.com and I’ll respond within one month.

If you’re unhappy with how I’ve handled your information, you can complain to the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (ico.org.uk, 0303 123 1113), though I’d appreciate the chance to put things right first.

Changes

If I change this notice, I’ll update the date at the top. Material changes will be made clear on this page.