Skip to main content

Legal

Privacy Policy

What we collect through this site, why, where it is stored, who processes it, how long we keep it, and how to get it back or have it deleted.

Effective 26 July 2026 · Version 1.0 · Applies to velocitymind.ai

In short

What we collect
Only what you type into the contact form or the newsletter field, plus standard server and security logs.
Where it is stored
A Cloudflare D1 database on Cloudflare's network. Email notifications are delivered by Resend.
Trackers
No advertising, analytics, or third-party tracking cookies are used on this site.
Model training
We do not sell personal information and do not use it to train any AI model.
01

Who we are and what this covers

VelocityMind is an AI agent consultancy. We design, build, and deploy custom multi-agent AI systems for enterprise operations — and take them past the pilot into governed production. This policy covers personal data we collect through velocitymind.ai, where VelocityMind acts as the data controller. Personal data we handle inside a client engagement is covered separately in section 10. Our full registered entity details are set out in the written agreement for each engagement and are available on request at info@velocitymind.ai.

02

Information we collect

We keep collection deliberately narrow. There is no account system, no advertising pixel, and no third-party analytics on this site.

Contact form
Name, work email, company, industry, and the free-text message you write. All five fields are required to submit.
Newsletter form
Work email address only.
Server and security logs
Generated automatically by our hosting provider: IP address, user agent, requested URL, timestamp, and response status. Used to operate the site, mitigate abuse, and investigate incidents.
Theme preference
A single browser storage key recording whether you chose the light, dark, or system theme. It stays in your browser and is never sent to us.

We do not ask for, and ask that you do not send, special-category data, patient data, or confidential client material through the website forms. Use the agreement channels set up for your engagement instead.

03

Why we use it, and our legal basis

Under the GDPR and UK GDPR we rely on the following bases.

Responding to enquiries
Legitimate interests — replying to a business enquiry you initiated, scoping the work, and keeping a record of the exchange. We reply within one business day.
Newsletter
Consent, given when you submit the form. You may withdraw it at any time; withdrawal does not affect processing carried out before then.
Site security and availability
Legitimate interests — keeping the service running and defending it against abuse.
Legal and accounting records
Compliance with legal obligations, where a record must be retained.

Where we rely on legitimate interests, we have weighed those interests against your rights and use the minimum data needed. You can object at any time — see section 11.

04

Where your data is stored, and who processes it

Website submissions are written to a Cloudflare D1 database and reach us by email. We use two sub-processors, both bound by written data-processing terms that restrict them to acting on our instructions.

Cloudflare, Inc.
Hosting, content delivery, DNS, bot and DDoS mitigation, and the D1 database that stores contact and newsletter records.
Resend (Plus Five Five, Inc.)
Transactional email delivery — the notification that tells us a submission arrived, and the confirmation sent back to you.

We do not share your information with advertisers, data brokers, or any other third party for their own purposes. We disclose data outside this list only where legally compelled, and we will tell you unless we are prohibited from doing so.

05

International transfers

Both sub-processors are established in the United States and operate global infrastructure, so personal data may be processed outside the EEA and the UK. Those transfers are made under the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, and are supported by the encryption and access controls described in section 9. A copy of the transfer terms is available on request.

06

How long we keep it

We do not keep personal data indefinitely on the chance it becomes useful.

Contact form submissions
Up to 24 months from our last exchange with you, then deleted or anonymised.
Newsletter subscribers
Until you unsubscribe or ask to be removed, after which the record is deleted.
Server and security logs
Up to 30 days, unless a log is retained longer as part of an active security investigation.
Engagement records
For the term of the agreement plus the period required by the contract and applicable law.

If you ask us to erase your data sooner, we will — see section 11.

07

Cookies, storage, and analytics

This site sets no advertising cookies, no analytics cookies, and no cross-site tracking identifiers. There is no Google Analytics, no advertising pixel, and no social media tracker embedded in these pages.

  • A browser storage key holds your light/dark theme choice. It is a preference, it never leaves your device, and clearing site data removes it.
  • Our hosting provider may set strictly necessary cookies or equivalent identifiers for security, bot mitigation, and load balancing. These are required to serve the site and carry no profiling function.
  • If we ever introduce privacy-respecting analytics, we will say so here before it goes live, and we will not add tracking that profiles you across other sites.
08

We do not sell your data, and we do not train models on it

We do not sell, rent, or trade personal information, and we do not share it for cross-context behavioural advertising. We do not use information submitted through this site — including the free text of your enquiry — to train, fine-tune, or evaluate any AI model, ours or a third party's. Where a client engagement involves model training or evaluation on real data, that is governed by the engagement agreement and a specific written data agreement, never by this website policy.

09

How we protect it

Traffic to this site is served over TLS. Access to the submissions database and the email tooling is limited to the people who need it to respond to you, protected by strong authentication, and reviewed as staffing changes. Credentials and API keys are held as managed secrets, never in source control. We build to recognised security and privacy control frameworks and design for the regimes our clients operate under; VelocityMind does not hold, and does not claim, a SOC 2 attestation or any other third-party certification.

10

Data we handle for clients

In a client engagement, the client is normally the data controller and VelocityMind acts as a processor on documented instructions under a data processing agreement. In that role we do not decide the purposes of processing, we do not reuse client data for our own purposes, and we do not use it to train models outside the scope the client has agreed in writing. If you believe your personal data was processed as part of one of our client engagements, contact that organisation first; we will support them in responding.

11

Your rights

Subject to the conditions in applicable law, you can exercise the following rights over the personal data we hold about you.

  • Access — get confirmation of what we hold and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where we no longer have grounds to keep it.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Restriction — have processing paused while an accuracy or objection question is resolved.
  • Objection — object to processing based on legitimate interests, including any direct marketing, which we stop on request without needing a reason.
  • Withdraw consent — unsubscribe from the newsletter at any time, with no effect on processing already carried out.
  • Complain — raise the matter with your national data protection supervisory authority, or the UK Information Commissioner's Office if you are in the UK. We would rather you came to us first, but you are not required to.

Email info@velocitymind.ai with the subject line "Data request". We answer within one month, and will tell you if a request is complex enough to need the extension the law allows. There is no charge, and we may ask a question or two to confirm we are talking to the right person.

12

Automated decisions and children

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile visitors to this site. The site is a business-to-business service, is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has submitted information, email us and we will delete it.

13

Changes to this policy

If we change how we handle personal data — a new sub-processor, a new purpose, a different retention period — we update this page and move the version and effective date at the top. Material changes affecting people already on our list are announced by email before they take effect. Previous versions are available on request.

14

How to reach us

Questions about this policy, a data request, or a vendor privacy questionnaire — email info@velocitymind.ai. A person reads every message; we reply within one business day. See also our Terms of Service.