Legal
Privacy policy
What we collect when you use this site or contact us, why we collect it, who sees it, how long we keep it, and how to get it changed or deleted. Written to be read, not skimmed past.
The short version
We are a small consulting firm, not an advertising business. We collect the information you deliberately give us — almost always through the contact form or a direct email — plus the ordinary technical records a web server creates when a page is requested. We use it to answer you, to run an engagement if you become a client, and to keep the site working.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not run advertising pixels, retargeting tags, or third-party ad networks on this site.
- We set no tracking cookies. If we ever add analytics, this policy will say so before it goes live.
- You can ask us what we hold about you, ask us to correct it, or ask us to delete it — at any time, for any reason, whatever country you are in.
The rest of this page is the detail behind those four statements.
Who we are and what this covers
TheVVProject (“TheVVProject”, “we”, “us”, “our”) is a management consulting firm founded in 2024, headquartered in the United States and delivering to clients internationally. For the purposes of the European and UK data protection laws described below, TheVVProject is the controller of the personal information described in this policy.
This policy covers the website at thevvproject.com, the forms on it, and email or phone contact that starts from it. It does not cover:
- Information handled inside a live client engagement, which is governed by the confidentiality and data terms in the signed engagement agreement. Where those terms and this policy differ, the engagement agreement wins.
- Third-party sites we link to. They have their own policies and we do not control them.
Postal address for formal notices and data requests: available on request at hello@thevvproject.com.
What we collect
Information you give us
When you submit the contact form, email us, or sign up for updates, we receive what you type. On the contact form that is:
- Required: your name, your email address, and your message.
- Optional: company name, your role, country or region, employee-count band, and the area of work you are interested in.
If you email or call us directly, we hold whatever the message or call notes contain. If you go on to become a client, we will also hold the business contact details, documents and operational information needed to do the work — under the engagement agreement rather than this policy.
Please do not send us sensitive personal information (health data, government identifiers, payment card numbers, login credentials, or anything about someone’s race, religion, politics, union membership, sex life or sexual orientation) through the website form or unencrypted email. We do not ask for it and we do not want it sitting in an inbox.
Information collected automatically
Our hosting provider records the ordinary technical detail every web server records in order to serve a page and defend itself: IP address, the URL requested, timestamp, HTTP status, referring URL, and browser user-agent string. These logs are generated by the infrastructure rather than by any tracking script we have added, and we use them only for security, abuse prevention, and diagnosing errors.
The spam trap
The contact form contains a hidden field that a human never sees and never fills in. If it comes back filled in, the submission is treated as automated and discarded. No personal information is collected by this mechanism — it simply throws the message away.
What we do not collect
We do not buy contact lists. We do not scrape personal data and add it to a database. We do not build advertising profiles, we do not fingerprint devices, and we do not track you across other websites.
Why we collect it
- To reply to you. This is the main reason anything is collected at all.
- To decide whether we are a fit. Company size, region and area of interest tell us quickly whether we are the right firm for the problem, and whether to say so honestly and point you elsewhere.
- To prepare for and run an engagement, once there is one.
- To send updates you asked for, if you opted in. Every message includes a way to stop them.
- To keep the site up and safe — error diagnosis, abuse and spam prevention, and preventing fraud.
- To meet legal, tax and accounting obligations where they apply.
We do not use your information to make automated decisions that have a legal or similarly significant effect on you. A human reads every enquiry.
Cookies and analytics
As published, this site sets no cookies of its own: no session cookies, no preference cookies, and no advertising or tracking cookies. That is why you are not being interrupted by a consent banner — there is nothing to consent to.
The site loads its typefaces from Google Fonts, which means your browser requests font files from a Google server and Google receives your IP address and user-agent as part of that request. That is the only third-party request the pages make.
If we later add analytics, we will choose a privacy-respecting, cookie-free option wherever possible, we will update this section and the “last updated” date before it goes live, and where consent is legally required we will ask for it first rather than after the fact.
Most browsers let you block or delete cookies and send a Global Privacy Control or “Do Not Track” signal. We honour Global Privacy Control signals as an opt-out of any sale or sharing of personal information — which, since we do neither, changes nothing about how we treat you, but the commitment stands if that ever changes.
Who we share it with
We share personal information with service providers, and otherwise only where the law requires it. Specifically:
- Service providers who process information on our behalf, under contract, and only for the purpose we give them: website hosting and content delivery, email delivery and hosting, form processing, calendar scheduling, document storage, and accounting. They are not permitted to use your information for their own purposes.
- Professional advisers — our own lawyers, accountants or insurers — where genuinely necessary and under a duty of confidence.
- Authorities, if we are legally compelled by a valid court order, subpoena or equivalent, or where disclosure is necessary to protect someone’s safety or to establish or defend legal claims. Where we are permitted to tell you about such a request, we will.
- A successor entity, if the firm is ever merged, acquired or reorganised — in which case this policy continues to apply to information transferred until it is replaced by a policy that is at least as protective, and we will post notice on this page.
We do not sell personal information, we do not rent or trade it, and we do not disclose client information to other clients. Client confidentiality is contractual and it is absolute unless the client releases us in writing.
International transfers
We are based in the United States and our service providers are typically based there too. If you contact us from outside the US — the United Kingdom, the European Economic Area, or anywhere else — the information you send will be transferred to and stored in the United States, which has a different data protection regime from your home country.
Where we transfer personal information out of the UK or the EEA, we rely on appropriate safeguards, in practice the European Commission’s Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement for UK transfers) in our contracts with providers, alongside the technical and organisational measures described below. You can ask us for detail on the safeguards that apply to your information.
How long we keep it
We keep information for as long as it is useful for the purpose it was collected for, and then we get rid of it. In practice:
- Enquiries that do not become engagements: up to 24 months from our last exchange, then deleted. If you tell us to delete it sooner, we will.
- Engagement records: for the life of the engagement and then for as long as we need them for legal, tax, accounting, insurance or professional-record reasons — typically up to seven years after the engagement ends, unless the engagement agreement says something different.
- Mailing list: until you unsubscribe, plus a minimal suppression record so we do not accidentally add you back.
- Server logs: a short rolling window set by our hosting provider, typically around 30 days.
How we protect it
The site is served over HTTPS. Access to enquiry and client information is limited to the people who need it to do the work, on accounts protected by strong, unique credentials and multi-factor authentication. We keep the number of systems holding personal information deliberately small, because the smallest attack surface is the one that does not exist.
No method of transmission or storage is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information and the law requires notification, we will notify you and the relevant regulator within the timeframes that apply.
Your choices and rights
Whatever country you are in, you can ask us to:
- Tell you what we hold about you and where it came from;
- Correct anything inaccurate or incomplete;
- Delete it, subject to records we are required to keep;
- Give you a copy in a portable, machine-readable format;
- Stop emailing you, which you can also do from the unsubscribe link in any update we send.
Email hello@thevvproject.com and we will respond within 30 days. We may need to verify your identity before acting — usually by confirming details already in the record, never by asking you to send identity documents to an open inbox. Exercising any of these rights costs you nothing and we will not treat you differently for it.
GDPR and UK GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, the General Data Protection Regulation and the UK GDPR apply to our handling of your personal data, and we act as controller. Our lawful bases are: legitimate interests (responding to a business enquiry you sent us, keeping the site secure, and preventing spam — interests we have balanced against your rights and consider proportionate because you initiated the contact and the data involved is ordinary business contact information); performance of a contract or steps taken at your request before entering into one (scoping, proposals and delivery); consent (mailing-list subscriptions, and any future analytics that requires it — withdrawable at any time without affecting the lawfulness of prior processing); and legal obligation (tax, accounting and regulatory record-keeping). In addition to the rights listed above, you have the right to object to processing based on legitimate interests, the right to request restriction of processing, the right not to be subject to solely automated decision-making with legal or similarly significant effects (we do not do this), and the right to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office at ico.org.uk; in the EEA, your national data protection authority — though we would appreciate the chance to put it right first. We have not appointed an EU or UK representative under Article 27, as our processing of EEA and UK personal data is occasional, limited to business contact information, and does not involve special categories of data; if that changes, we will appoint one and name them here.
CCPA and CPRA (California)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights. In the last 12 months we have collected the following statutory categories of personal information: identifiers (name, email address, IP address), commercial and professional information (company, role, employee-count band, area of interest, the content of your enquiry), and internet or network activity limited to the server-log records described above. We collect these from you directly and from the automatic technical records our host generates. We use them for the business purposes listed in “Why we collect it”, and we disclose them only to the service-provider categories listed in “Who we share it with”. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not knowingly collect or sell the personal information of consumers under 16. We do not collect “sensitive personal information” as that term is defined by the CPRA, so there is nothing to limit the use of. You have the right to know what we have collected and disclosed, the right to correct it, the right to delete it, the right to opt out of sale or sharing (nothing to opt out of, but the mechanism is the same email address), and the right not to be discriminated against for exercising any of these rights — we will not deny service, change prices, or degrade quality because you asked. To make a request, email hello@thevvproject.com with “California privacy request” in the subject line. An authorised agent may submit a request on your behalf with written permission that we can verify. We will confirm receipt within 10 business days and respond substantively within 45 days, extendable once by a further 45 days if we tell you why.
Residents of other US states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas and Oregon — have broadly equivalent rights to access, correct, delete and port their information, and to appeal a refusal. Use the same email address; we apply the same process to everyone rather than running a different standard per state.
Children
This is a business-to-business site. It is not directed to children, we do not knowingly collect personal information from anyone under 16, and we have no reason to. If you believe a child has sent us personal information, email us and we will delete it.
Links to other sites
Where we link to another organisation’s website, an article, or a tool, that site’s own privacy policy governs what happens once you land there. A link is not an endorsement of their data practices, and we have no control over them.
Changes to this policy
We will update this page when our practices change — for example if we add analytics or a new service provider. The “last updated” date at the top always reflects the current version. If a change materially affects how we handle information you have already given us, we will make a reasonable effort to tell you directly rather than relying on you re-reading this page.
How to contact us
Privacy questions, data requests, and complaints all go to the same place, and a person reads them:
- Email: hello@thevvproject.com
- Phone: +1 (786) 557-1842
- Post: mailing address available on request
If you are unhappy with how we have handled a request, say so and we will look at it again. You can also complain to your local data protection authority, and nothing in this policy is intended to limit that right.
Ready to see what 90 days can do?
Book a 30-minute discovery call. You leave with two or three things worth doing next — whether or not you hire us.