About this notice
This notice explains how Vulcn handles personal information. It is written for visitors to vulcn.co, for people who get in touch with us, for our clients and prospective clients, and for end-users of websites we host on behalf of those clients.
We are based in the United Kingdom and we apply the standards of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
For all matters concerning this notice, please write to privacy@vulcn.co.
- Registered name
- Vulcn Limited
- Registered in
- England and Wales
- Company number
- 17408643
- Registered office
- 20 Wenlock Road, London, England, N1 7GU
- ICO registration
- ZC226716
Our roles as controller and processor
As controller
We decide why and how personal information is handled. This covers information arising through our own business activities: visits to vulcn.co, enquiries sent to us, our contractual relationships with clients, our correspondence, and our internal records. The remainder of this notice describes how we handle that information.
As processor
We handle information on someone else’s documented instructions. This applies to personal information belonging to end-users of websites we host for our clients. In that capacity the client is the controller of their visitors’ data, and we handle it only under a written processing agreement. Section 11 explains what this means in practice.
Information we collect
Visits to vulcn.co
The vulcn.co marketing site sets one cookie only (__vcuid) for security reasons (see section 5 for more detail) and does not load third-party scripts, fonts, embeds, or trackers. Page-view statistics are produced by analytics that we operate ourselves; they are aggregated and anonymised, and we do not store request-level data such as IP addresses, user-agent strings, or referrer URLs against an individual visitor. These statistics are derived from our own server-side records: we do not write to, read from, or otherwise access any information stored on your device.
Our infrastructure provider holds connection logs as part of normal operation. These are described in section 6 and section 7, and some of that log data is accessed from outside the United Kingdom.
Enquiries
When you submit the “Request a call” form on vulcn.co, the information you provide (your name, email address, an optional telephone number, an optional company name, and the message you write) is converted into an email and delivered to our sales@vulcn.co mailbox. We use this information to reply to your enquiry.
Clients and prospective clients
In the course of doing business we record the contact details of the people we work with at client organisations, contractual records, the technical details of the websites we build and host, billing information sufficient to invoice, and the correspondence we exchange about ongoing work. We currently invoice for our services and accept payment by bank transfer; we do not use a third-party payment processor.
Information we obtain from other sources
Not all the information we hold comes from the person it relates to. We also obtain business contact details from three kinds of source:
- From our clients, who give us the details of colleagues we need to work with on a project.
- From public professional sources, such as a company website, LinkedIn, or Companies House.
- From mutual contacts who introduce us or refer us.
Where information reaches us this way, the categories we hold are limited to business contact and role information: name, job title, work email address, work telephone number, employer, and the source or context of the introduction. We do not obtain or seek personal (non-work) contact details from these sources, and we do not buy contact lists.
We provide this notice to anyone whose information we obtain in this way at the point we first contact them, and in any event within one month of obtaining it.
Information you choose to send us
From time to time you may send us additional information by email or in another form: design assets, brand guidelines, content for a site, technical credentials, and so on. We treat that information in line with this notice and with whatever specific instructions accompany it.
How we use information and the lawful bases we rely on
Under data protection law, we must have a lawful basis for each way in which we use personal information. For each activity below, we name the basis we rely on.
Replying to your enquiry
We use the contact details and message you submit through the enquiry form to respond to you. Our lawful basis is taking steps at your request prior to entering a contract (UK GDPR Article 6(1)(b)), and our legitimate interest in responding to people who get in touch (Article 6(1)(f)) where you are simply asking a question.
Operating the service for clients
We use information about clients and the people who represent them to deliver the service we have agreed: designing, building, hosting, and maintaining their website. The lawful basis is the performance of our contract with the client (Article 6(1)(b)), and our legitimate interests in operating, securing, and supporting the service we provide (Article 6(1)(f)).
Billing, accounting, and statutory records
We use billing information to issue invoices and to keep the financial records we are required to keep. The lawful basis is the performance of our contract with the client (Article 6(1)(b)) and our compliance with the legal obligations that apply to us as a UK business (Article 6(1)(c)), in particular under HMRC’s record-keeping rules.
Securing the platform
We use limited connection metadata and the rate-limit token described in section 5 to detect, prevent, and respond to abuse, brute-force attempts, and other security threats against our infrastructure. The lawful basis is our legitimate interest, and the legitimate interest of our clients, in keeping the service secure and available (Article 6(1)(f)).
Business development and marketing
We contact people at businesses we think we can help, to introduce our services and ask whether a conversation would be useful. We do this by email, telephone, LinkedIn, or through a mutual introduction, and we contact people in their professional capacity about services relevant to their role.
Our lawful basis is our legitimate interest in developing our business and reaching the organisations we are equipped to serve (Article 6(1)(f)). Under PECR we send business-to-business marketing email to corporate subscribers without prior consent, as the regulations permit. Every message we send includes a straightforward way to opt out, and we act on an opt-out immediately and permanently. We do not send unsolicited marketing to individuals, sole traders, or unincorporated partnerships without their consent.
You can object to this processing at any time, with no need to give a reason. Section 10 explains how.
Other communication
Communication we initiate outside the above is transactional or relationship-based: replies to enquiries, project correspondence, service notifications, and the like.
Where we rely on legitimate interests
Where we rely on legitimate interests, we balance our purpose against your rights and freedoms. You have the right to object to that processing; section 10 explains how.
Cookies and similar technologies
We take a minimal approach to cookies and similar technologies, and we do not use them for advertising or analytics purposes.
The one cookie we set
Our platform sets a single cookie, named __vcuid, on requests served through our infrastructure. This applies both to vulcn.co and to the client websites we host, because both run on the same platform. The cookie contains a randomly generated token that lets us rate-limit requests and identify abusive traffic patterns. It contains no information about you beyond a random identifier. It expires after 30 minutes.
The __vcuid cookie is strictly necessary for the security of the service and falls within the exemption in regulation 6(4) of the Privacy and Electronic Communications Regulations. We do not ask for consent to set it because consent is not required for cookies of this kind. We do not use it for analytics, advertising, profiling, or any purpose other than protecting the service from abuse. This is why you will not see a cookie banner on vulcn.co.
What we do not do
We set no other cookies. vulcn.co does not embed third-party content that would set cookies on its behalf, and it does not use local storage or similar mechanisms to track you between visits. Our infrastructure provider supplies the underlying servers only and does not set cookies of its own.
Cookies on client sites
Beyond __vcuid, any cookies present on a client’s website are determined by that client and disclosed in their own privacy or cookie notice. We do not add marketing or analytics cookies to the sites we build.
Who we share information with
We do not sell personal information and we do not share it for marketing purposes. The only third parties that handle personal information on our behalf are the providers we rely on to operate the service.
Infrastructure hosting
We use a third-party infrastructure provider to host the servers that run our platform. Personal information that lives on the platform, meaning client websites and their associated data, is held in a London data centre. As we expand into other regions, we will update this notice to reflect any additional locations.
Separately from the content we store there, our infrastructure provider generates its own connection and security logs as part of running the service, and processes those logs for its own operational and security purposes. Section 7 explains where that log data goes.
Our email is operated by a privacy-focused third-party provider that handles inbound delivery to our mailboxes (including privacy@vulcn.co), outbound delivery of email we send, and storage of mailboxes in individually encrypted databases. The provider does not read message contents and operates primarily within the United Kingdom and the European Union; some infrastructure is located in the United States.
What we do ourselves
Everything else we do in-house. Our analytics, our deployment tooling, our support records, our backups, and our monitoring all run on infrastructure we operate. We will update this notice if we ever introduce a new sub-processor. Both of the providers above engage sub-processors of their own; each publishes a current sub-processor list, and we will tell you which providers we use on request.
We also share information with our accountant and, where necessary, our professional advisers, in the ordinary course of running the business.
Disclosures to public authorities
We disclose personal information to law enforcement, regulators, or other public authorities only where we are legally compelled to do so, for example in response to a court order or a valid statutory request. Where the law allows it, we will tell the affected person before responding.
Where information is held and international transfers
The platform on which we host websites is operated from London, and content stored on it remains in the United Kingdom.
Our infrastructure provider generates its own connection and control-plane logs as part of running the underlying servers, and these are transferred to, and accessed from, its systems in the United States. These logs consist of network-level metadata such as IP addresses and connection times, together with records of administrative access to the hosting environment. The provider is a US-headquartered company with a global support workforce, and its personnel may access this log data from outside the United Kingdom on a least-privilege basis. The provider does not sit in the path of requests to the websites we host: it does not terminate those connections and does not have visibility of the pages requested or their contents.
Our email provider likewise operates infrastructure in the United Kingdom, the European Union, and the United States. Email passing through their service may therefore be processed outside the United Kingdom.
Where personal information is transferred to a country that does not benefit from a UK adequacy decision, we rely on appropriate safeguards under UK GDPR Article 46. In practice this means the International Data Transfer Agreement (IDTA), the UK Addendum to the European Commission’s Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework where the recipient is certified under it. Copies of the safeguards we rely on are available on request.
How long we keep information
We keep personal information only for as long as we need it. For each kind of record, the period below is what we work to in normal operation.
- Enquiries. If an enquiry does not lead to ongoing engagement, we delete the related correspondence once the enquiry is complete and there is no realistic prospect of follow-up.
- Prospect and business contact records. Kept while there is a realistic prospect of working together, and reviewed at least every two years. We delete a record where there has been no meaningful contact over that period, and immediately on request or on opt-out.
- Client correspondence and project records. Kept for the duration of the engagement and for up to six years afterwards, in line with the limitation period for contractual claims under English law.
- Billing and accounting records. Kept for at least six years from the end of the relevant accounting period, in line with HMRC’s record-keeping requirements.
- Server access and security logs. Kept for a short operational period, after which they are rotated and discarded, except where a specific incident requires us to retain them for longer.
- The
__vcuidcookie. Short-lived; it expires automatically and is not retained after that point.
Where we are unable to delete a record entirely, for example because it is part of a backup, we isolate it and ensure it is not used for any active purpose until it expires from the backup cycle.
How we protect information
We maintain technical and organisational measures appropriate to the risk, covering encryption in transit and at rest, restricted access to production systems, and regular encrypted backups.
Where a security incident occurs that affects personal information, we will investigate it, take prompt action to contain it, and notify the Information Commissioner and the people affected within the timeframes the law requires.
Your rights
Under UK data protection law, you have a number of rights in relation to the personal information we hold about you. They are not absolute, and they apply in the circumstances the law specifies, but we will consider every request carefully and explain our reasoning if we cannot fulfil it.
- Right of access. You can ask us for a copy of the personal information we hold about you, together with information about how we are using it.
- Right to rectification. You can ask us to correct information that is inaccurate or to complete information that is incomplete.
- Right to erasure. You can ask us to delete personal information where we no longer have a lawful reason to keep it.
- Right to restrict processing. You can ask us to pause our use of your information while we resolve a dispute about it.
- Right to data portability. Where we hold your information on the basis of consent or contract, and process it by automated means, you can ask us to provide it in a structured, machine-readable format.
- Right to object. Where we rely on legitimate interests, you can object to our processing on grounds relating to your particular situation. Where we are using your information for direct marketing, you can object at any time and we will stop, with no balancing test and no need for a reason.
- Right to withdraw consent. Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of what we did before you withdrew it.
- Right not to be subject to automated decisions. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
- Right to complain. If you are not satisfied with how we have handled your information, you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to address your concern first.
To exercise any of these rights, please write to privacy@vulcn.co. We will acknowledge your request within two working days and aim to complete it within ten. The law allows us up to one calendar month, and a further two months where a request is particularly complex or where you have made several at once. If either applies, we will tell you within the first month and explain why. We may need to verify your identity before acting on a request.
Acting as a processor for client websites
When we host a website for a client, the personal information that flows through that site, meaning the contents of contact forms, customer records, account data, or comments, is processed on the client’s behalf. The client is the controller; we are the processor, and our processing is governed by a written agreement with each client under UK GDPR Article 28.
Our access to a client’s end-user data is normally limited to operational artefacts (server logs, configuration, and backups) that may incidentally contain personal information. We do not routinely read the content of forms or messages submitted on client sites; the contact forms we build send submissions directly to a mailbox the client controls.
If you are an end-user of a website we host and you wish to exercise your rights, please contact the operator of that site directly. If you are unsure who that is, write to us at privacy@vulcn.co and we will help you identify the right party.
Changes to this notice
We will update this notice when our practices change, for example if we adopt a new sub-processor, expand into a new region, or introduce a new service. The date at the top of the page records when the current version came into effect. Where the change materially affects how we use your information, we will draw it to your attention by a clear means before the change takes effect. Where we intend to use personal information we already hold for a new purpose, we will tell you before that new processing begins.
Contact us
For any question about this notice, the information we hold, or the rights described above, please write to us at privacy@vulcn.co. If you would prefer to write by post, our registered office is 20 Wenlock Road, London, England, N1 7GU.
If you would like to raise a concern with the regulator instead, you can contact the Information Commissioner’s Office at ico.org.uk.