Veldris
Privacy · UK GDPR · EU GDPR · last updated 2026-08-26

Privacy, by construction.

This site sets no cookies, runs no analytics, embeds no trackers, and makes no third-party requests. A privacy policy for a site like that is short. Here it is in full.

§ 1 · Controller

Who is responsible

The data controller for veldris.io is Veldris Ltd, registered in England and Wales, company no. 17366869, registered office 128 City Road, London EC1V 2NX, United Kingdom, and registered with the Information Commissioner's Office as a data controller under reference ZC222667. Our Data Protection Officer is JB Webb-Benjamin, reachable at j.benjamin@veldris.io. For anything in this policy, write to privacy@veldris.io or call 0203 195 3829 (Monday to Friday, 09:00–17:00 UK time). We answer with facts, within one calendar month as the law requires, and usually much faster.

§ 2 · What this site processes

The complete inventory

DataWhat happensLegal basisRetention
Server logs (IP address, user agent, requested URL) veldris.io is served from our own server in the United Kingdom, on infrastructure rented from Fasthosts Internet Limited (UK). The web server receives your IP address to deliver the page, as any web host must, and logs it for security and abuse prevention. We control these logs; Fasthosts provides the machine, not the data. Legitimate interest (Art. 6(1)(f)): serving the site and keeping it secure. Rotated and deleted within 30 days.
Theme preference (light/dark) Stored as veldris-theme in your browser's localStorage. It never leaves your device and is not transmitted to us or anyone. Delete it any time via your browser's site-data settings. Strictly necessary functional storage; no consent required (PECR Reg. 6(4) / ePrivacy Art. 5(3) exemption). Until you clear it. We cannot see or delete it; it is on your device.
Phone calls and voicemail If you call 0203 195 3829 outside 09:00–17:00 UK time, Monday to Friday, you can leave a voicemail; we process the recording, your number and what you say to return the call. Legitimate interest (Art. 6(1)(f)): answering enquiries. Voicemails deleted once returned or within 30 days, whichever is sooner.
Email you send us If you write to a @veldris.io address we process your address and message to answer you. Legitimate interest (Art. 6(1)(f)), or contract steps (Art. 6(1)(b)) if you are becoming a customer. Deleted when the correspondence is closed, unless a contract or legal obligation requires keeping it.

That is the whole list. There are no cookies, no analytics, no advertising, no fingerprinting, no embedded third-party content, no consent banner because there is nothing to consent to. Fonts are served from this domain, so no font provider sees your IP address. Verify any of this: open your browser's network inspector, or read the source.

§ 3 · Transfers

Where data goes

Nowhere, is the short answer. The site is served from the United Kingdom on infrastructure provided by Fasthosts Internet Limited (Gloucester, UK), and email is processed on our own UK-based infrastructure. No visitor data is transferred outside the UK or the EEA, so no transfer mechanism is needed.

One stated contingency: if our own server cannot be deployed to, the site fails over automatically to GitHub Pages (GitHub, Inc., USA), which then receives visitor IP addresses to deliver pages, as any host must. That transfer is covered by the UK Extension to the EU–US Data Privacy Framework. Normal service is the UK server; the fallback exists so the site stays reachable while we fix it.

§ 4 · Registration

On the ICO register

Veldris Ltd is registered as a fee-paying data controller with the UK Information Commissioner's Office. The entry is public; check it yourself rather than take our word for it.

The registration names a Data Protection Officer. Data-protection questions, rights requests and complaints can go to the DPO directly, or to privacy@veldris.io; both reach the same desk.

On the record
Registration referenceZC222667
Data controllerVeldris Ltd
Registered14 August 2026 · expires 13 August 2027, renewed annually
Payment tierTier 1
Data Protection OfficerJB Webb-Benjamin · j.benjamin@veldris.io
§ 5 · Security of processing

How your data is protected

Article 32 UK GDPR requires technical and organisational measures appropriate to the risk. Ours start with architecture, described in full on the security page: post-quantum sealing by default, keys that never leave the enclosure, signed lineage, zero required outbound calls, and a website that collects almost nothing in the first place. The least risky personal data is the data never gathered.

On top of the architecture sits independent assessment: Veldris Ltd is certified under Cyber Essentials, the National Cyber Security Centre-backed scheme, with the whole organisation in scope. That matters for this policy because the little personal data we do hold, the email you send us, the voicemail you leave, lives on the same laptops and accounts the certification covers: boundary firewalls, secure configuration, access control, malware protection and security-update management, assessed rather than asserted.

Our outlook on it is unsentimental. Cyber Essentials is a floor, not a ceiling: it attests that at the time of testing our defences were satisfactory against commodity attacks, and we renew it annually because a lapsed floor is a hole. The guarantees this company actually stakes its name on, encryption that assumes the computers of the 2040s, source you can read, live above that floor. Treat the certificate the way we treat every claim: as a statement with provenance, and check it on the public register.

The perimeter is also watched from outside. Veldris is registered with the National Cyber Security Centre and all of our online assets are enrolled in the NCSC's Early Warning service: if our domains or infrastructure appear in national incident, malware or vulnerability intelligence, we are alerted and act the same working day. For your data that shortens the most dangerous window there is, the one between a compromise and its discovery. If an incident ever touched personal data, we would notify the ICO within 72 hours and affected people without undue delay, as UK GDPR requires.

One thing Early Warning does not do: it observes our infrastructure, not our visitors. No visitor data is shared with the NCSC; the service watches us, on your behalf.

Cyber Essentials certified On the record
SchemeCyber Essentials · NCSC
Certificate772fd04c-3a1d-4308-8c72-92b3291be902
Certified2026-08-26 · recertification due 2027-08-26
ScopeWhole organisation
Relevance hereAssessed controls on the systems that process your correspondence and voicemail (Art. 32 UK GDPR).
Early warningNCSC Early Warning · all online assets enrolled · alerts triaged the working day received · no visitor data shared
§ 6 · Your rights

What you can demand

Under UK GDPR and EU GDPR you can demand from us: access to your data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection to processing based on legitimate interest (Art. 21).

Exercise any of them by writing to privacy@veldris.io or to the Data Protection Officer at j.benjamin@veldris.io. Since the only personal data we hold is correspondence you sent us, most requests resolve in one reply.

If you think we have handled your data unlawfully, you can complain to the UK Information Commissioner's Office (ico.org.uk/make-a-complaint, quoting our registration ZC222667) or, in the EU, to your national supervisory authority. We would prefer you tell us first, we fix facts fast, but the right is yours either way.

We make no automated decisions about you and do no profiling. There is nothing to opt out of, because we never opted you in.

§ 7 · Changes

If this policy changes

Any change appears here, with the date at the top updated. This page lives in the site's public repository, so its full history is a git log away, provenance for the policy itself.