Privacy Policy

Last updated 27 August 2026

This site sets no cookies, runs no analytics, and loads nothing from third-party servers. The only personal data we collect through it is what you choose to send us in the contact form. This policy explains what happens to it.

1. Who is responsible for your data

The data controller is the entity below. If you have a question about this policy or about how your data is handled, contact us first — we would rather resolve it directly.

ControllerVaira Group
Legal entity[registered name, e.g. Vaira Group LLC]
JurisdictionLimited liability company registered in the State of Wyoming, USA
Registered office[registered agent address, Wyoming, USA]
Correspondence address[Barcelona mailing address, if published]
Emailhello@vaira.group

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Enquiries go to the email address above.

2. Our representative in the European Union

We are established in the United States, but we offer our services to people and organisations in the European Union. That brings us within the GDPR under Article 3(2). Because of this, we have designated a representative in the EU under Article 27 of the GDPR.

EU Representative[appointed representative name]
Address[representative address, EU member state]
Email[representative email]

If you are in the EU, you may contact our representative on any matter relating to the processing of your personal data, as an alternative to contacting us directly. Supervisory authorities may do the same. Appointing a representative does not limit our own responsibility or liability.

3. What we collect

Information you send us

When you complete the contact form on this site, we receive the fields you fill in. Only four are required; the rest are optional and exist to save a round of emails.

If you email us directly, or we meet at an event and continue the conversation by email, we hold that correspondence and the business contact details in it.

Information we do not collect

This is worth stating plainly, because most sites cannot:

Because we use no non-essential cookies, no cookie consent banner is required. If we ever add analytics or embedded third-party content, we will publish a cookie policy and ask for your consent before any such technology loads.

4. Why we use it, and on what legal basis

Responding to your enquiryTo assess your project, reply, and prepare a proposal. Legal basis: Article 6(1)(b) GDPR — steps taken at your request before entering into a contract.
Ongoing client communicationTo deliver a project you have engaged us for. Legal basis: Article 6(1)(b) GDPR — performance of a contract.
Business records and accountingTo meet our tax and corporate record-keeping obligations. Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation.
Occasional follow-up with prior contactsTo follow up on a conversation you started. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in developing our business, balanced against your rights. You can object at any time and we will stop.

We do not send marketing newsletters. If that changes, we will ask for your consent separately, and every message will carry a one-click unsubscribe.

5. How long we keep it

6. Who else sees it

We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers who process data on our instructions under Article 28 GDPR:

Website hosting[hosting provider, e.g. Vercel Inc.] — serves this site and processes form submissions in transit.
Email[email provider, e.g. Google Workspace] — receives and stores our correspondence.
Form delivery[form/email delivery provider, if used — e.g. Resend]

We may also disclose data to our accountants or legal advisers where necessary, or to a public authority where the law requires it.

Where your data is stored, and transfers from the EU

We are a US company and our service providers are principally in the United States. If you are in the European Economic Area or the United Kingdom, your personal data will be transferred to and stored in the United States.

We rely on the European Commission's Standard Contractual Clauses to cover those transfers, supplemented where appropriate by the EU–US Data Privacy Framework in the case of providers certified under it. You can ask us for details of the safeguard applying to a specific provider, and we will tell you.

7. Photography and video at our events

We produce conferences and other live events, and those events are photographed and filmed. Where an individual is identifiable, that footage is personal data.

If you appear in a photograph or video published on this site or on our channels and would like it removed, email us and we will take it down. We will not ask you to justify the request.

8. Your rights under the GDPR

If you are in the EEA or the UK, you have the right to:

Write to hello@vaira.group, or to our EU representative above, to exercise any of these. We will respond within one month. We may ask you to confirm your identity first, so that we are not disclosing your data to someone else.

If you are not satisfied with our response, you may lodge a complaint with the data protection supervisory authority in the EU or UK country where you live or work. A current list of national authorities is published by the European Data Protection Board at edpb.europa.eu.

9. If you are in the United States

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not use personal information for cross-context behavioural advertising. Based on our size, we do not currently meet the applicability thresholds of the CCPA or of the comprehensive privacy statutes of other US states.

Regardless of whether a statute compels it, we will honour a request from any US resident to access, correct, or delete the personal information we hold about them. Email us and we will act on it.

10. Security

The site is served over HTTPS. Access to enquiry data is limited to the people at Vaira Group who need it to respond to you, and is protected by two-factor authentication on the accounts that hold it. No system is perfectly secure, but if a breach occurs that is likely to affect your rights, we will notify the competent supervisory authority within 72 hours as required by Article 33 GDPR, and tell you directly where the law requires it.

11. Children

This site and our services are aimed at businesses and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.

12. Changes to this policy

If we change how we handle personal data, we will update this page and change the date at the top. Where the change is significant — for example, introducing analytics or a new category of processing — we will make that clear rather than relying on you to re-read the page.

13. Contact

Questions about this policy, or about your data: hello@vaira.group.