Privacy Policy
In short: we do not sell your data, we do not run advertising trackers on this website, and we do not log the browsing activity of end users of the VPN products we build. This page explains what we do collect and why.
Contents
1. Who we are
VANDRIQ LTD (“VANDRIQ”, “we”, “us”) is an engineering company that designs and develops VPN applications, protocol cores and server infrastructure for business clients. This policy covers the website vandriq.online and the direct business relationships we have with clients and prospective clients.
For the purposes of data protection law, VANDRIQ LTD is the data controller for the personal data described in sections 2–9. Where we build or operate systems on behalf of a client, we generally act as a data processor — see section 10.
Registered company details and our postal address are set out in section 13.
2. What data we collect
Data you give us
If you email us or otherwise get in touch, we receive whatever you choose to send: your name, email address, company, and the contents of your message. There is no contact form on this website — enquiries reach us by email, so the data we hold is simply your correspondence.
Data collected automatically
Our web server keeps standard access logs. Each request records:
- your IP address;
- the date and time of the request;
- the page or file requested and the HTTP status returned;
- the referring page, where your browser sends one;
- your browser's user-agent string.
These logs exist for security and troubleshooting. We do not use them to build profiles of visitors, and we do not attempt to identify individuals from them.
Data we do not collect
- We do not run third-party advertising or social media trackers on this site.
- We do not use behavioural profiling or automated decision-making that produces legal effects.
- We do not knowingly collect special category data (health, biometrics, political opinions and similar).
3. Why we process it
We process personal data on the following legal bases:
- Legitimate interests — to respond to enquiries, keep our website available and secure, prevent abuse, and maintain business records. We have assessed that this processing is limited in scope and does not override your rights.
- Performance of a contract — to deliver services, manage projects and handle invoicing where you are our client or a contact at a client.
- Legal obligation — to meet accounting, tax and statutory record-keeping duties.
- Consent — where we ask for it explicitly, for example before sending occasional company updates. You can withdraw consent at any time.
4. Cookies and analytics
This website sets no cookies. It is a static site: HTML, CSS, one small script for the navigation menu, and self-hosted fonts. Nothing is loaded from third-party CDNs, so no external party observes your visit.
We do not currently run analytics. If we introduce analytics in future, we will use a privacy-preserving, cookie-free tool, and we will update this page before doing so.
5. Who we share data with
We do not sell personal data, and we do not share it for advertising. We disclose data only to:
- Infrastructure providers that host our website and email under contract, acting on our instructions.
- Professional advisers — accountants and lawyers — where necessary and under a duty of confidence.
- Authorities, where we are legally required to do so. We assess every request for validity, we disclose no more than is strictly required, and we will notify you unless legally prohibited from doing so.
6. How long we keep it
- Server access logs — rotated and deleted within 30 days.
- Email correspondence — kept while the enquiry or relationship is live, and for up to 24 months afterwards.
- Contract and billing records — retained for the period required by applicable accounting and tax law.
When a retention period ends, we delete the data or irreversibly anonymise it.
7. International transfers
Our infrastructure and service providers may process data outside your country of residence. Where personal data is transferred outside the UK or the European Economic Area, we rely on an adequacy decision or on Standard Contractual Clauses together with any supplementary measures required. You may request details of the safeguards that apply.
8. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- lodge a complaint with your data protection supervisory authority.
To exercise any of these, email support@vandriq.online. We respond within one month. We do not charge a fee unless a request is manifestly unfounded or excessive.
9. Security
All traffic to this website is served over HTTPS with a valid TLS certificate, and plain HTTP requests are redirected. Access to our servers is restricted to named engineers. We apply least-privilege access, keep systems patched, and review our configuration regularly.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, you directly.
10. Data we handle for clients
When we build or operate a VPN product for a client, that client determines the purposes of processing and is the data controller. We act as a processor and handle data strictly on their documented instructions, under a written data processing agreement.
Our engineering default is to minimise data: the products we build are designed around a no-logs principle, meaning end users' browsing destinations, DNS queries and traffic contents are not recorded. Connection credentials are stored in the device's system keychain rather than in application storage.
If you are an end user of an app we built for another company, that company's privacy policy governs your data — not this one. Contact them directly, and we will support them in responding to you.
11. Children
Our services are directed at businesses, not children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as our services or the law change. The “last updated” date at the top always reflects the current version. Where a change is material, we will give reasonable advance notice through this website or by email to clients.
13. Contact us
For any privacy question, data request or complaint:
- Email: support@vandriq.online
- Entity: VANDRIQ LTD
- Registered office and company number: to be completed
If you are unhappy with our response, you may complain to your national data protection authority. In the United Kingdom this is the Information Commissioner's Office (ICO).