Privacy Policy
Last updated 27 August 2026
This site sets no cookies, runs no analytics, and loads nothing from third-party servers. The only personal data we collect through it is what you choose to send us in the contact form. This policy explains what happens to it.
1. Who is responsible for your data
The data controller is the entity below. If you have a question about this policy or about how your data is handled, contact us first — we would rather resolve it directly.
| Controller | Vaira Group |
|---|---|
| Legal entity | [registered name, e.g. Vaira Group LLC] |
| Jurisdiction | Limited liability company registered in the State of Wyoming, USA |
| Registered office | [registered agent address, Wyoming, USA] |
| Correspondence address | [Barcelona mailing address, if published] |
| hello@vaira.group |
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Enquiries go to the email address above.
2. Our representative in the European Union
We are established in the United States, but we offer our services to people and organisations in the European Union. That brings us within the GDPR under Article 3(2). Because of this, we have designated a representative in the EU under Article 27 of the GDPR.
| EU Representative | [appointed representative name] |
|---|---|
| Address | [representative address, EU member state] |
| [representative email] |
If you are in the EU, you may contact our representative on any matter relating to the processing of your personal data, as an alternative to contacting us directly. Supervisory authorities may do the same. Appointing a representative does not limit our own responsibility or liability.
3. What we collect
Information you send us
When you complete the contact form on this site, we receive the fields you fill in. Only four are required; the rest are optional and exist to save a round of emails.
- Required: your name, email address, company, and the nature of the project you describe.
- Optional: website, location, timeline, expected attendance, project type, budget range, target audience, and any additional context you choose to add.
If you email us directly, or we meet at an event and continue the conversation by email, we hold that correspondence and the business contact details in it.
Information we do not collect
This is worth stating plainly, because most sites cannot:
- No cookies of any kind are set by this website.
- No analytics, tag managers, advertising pixels, session recording, or heat mapping.
- No social media embeds, live chat widgets, or comment systems.
- Fonts are served from our own domain, not from Google Fonts or any other font network.
- Videos are served from our own domain. There is no YouTube or Vimeo player, so no third party learns that you watched them.
- We do not profile you and we take no automated decisions about you.
Because we use no non-essential cookies, no cookie consent banner is required. If we ever add analytics or embedded third-party content, we will publish a cookie policy and ask for your consent before any such technology loads.
4. Why we use it, and on what legal basis
| Responding to your enquiry | To assess your project, reply, and prepare a proposal. Legal basis: Article 6(1)(b) GDPR — steps taken at your request before entering into a contract. |
|---|---|
| Ongoing client communication | To deliver a project you have engaged us for. Legal basis: Article 6(1)(b) GDPR — performance of a contract. |
| Business records and accounting | To meet our tax and corporate record-keeping obligations. Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation. |
| Occasional follow-up with prior contacts | To follow up on a conversation you started. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in developing our business, balanced against your rights. You can object at any time and we will stop. |
We do not send marketing newsletters. If that changes, we will ask for your consent separately, and every message will carry a one-click unsubscribe.
5. How long we keep it
- Enquiries that do not become projects: up to 24 months from our last exchange, then deleted. Event planning cycles are long and enquiries often revive a year or more later.
- Client records: for the duration of the engagement and 6 years afterwards, for contractual and limitation-period reasons.
- Invoices and tax records: up to 7 years, in line with US federal record-retention practice.
6. Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers who process data on our instructions under Article 28 GDPR:
| Website hosting | [hosting provider, e.g. Vercel Inc.] — serves this site and processes form submissions in transit. |
|---|---|
| [email provider, e.g. Google Workspace] — receives and stores our correspondence. | |
| Form delivery | [form/email delivery provider, if used — e.g. Resend] |
We may also disclose data to our accountants or legal advisers where necessary, or to a public authority where the law requires it.
Where your data is stored, and transfers from the EU
We are a US company and our service providers are principally in the United States. If you are in the European Economic Area or the United Kingdom, your personal data will be transferred to and stored in the United States.
We rely on the European Commission's Standard Contractual Clauses to cover those transfers, supplemented where appropriate by the EU–US Data Privacy Framework in the case of providers certified under it. You can ask us for details of the safeguard applying to a specific provider, and we will tell you.
7. Photography and video at our events
We produce conferences and other live events, and those events are photographed and filmed. Where an individual is identifiable, that footage is personal data.
- Attendees are informed before or on arrival — through the registration process, ticket terms, or signage at the venue — that the event is being recorded.
- Wide audience shots and general coverage of the event are used on the basis of our legitimate interest in documenting and promoting our work, under Article 6(1)(f) GDPR.
- Close-up portraits, interviews, and any use of a person as the focus of promotional material are used only with that person's explicit consent.
- Speakers agree to recording and publication as part of their speaker agreement.
If you appear in a photograph or video published on this site or on our channels and would like it removed, email us and we will take it down. We will not ask you to justify the request.
8. Your rights under the GDPR
If you are in the EEA or the UK, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Have inaccurate data corrected.
- Have your data erased where we have no overriding reason to keep it.
- Restrict how we process your data while a dispute is resolved.
- Receive your data in a portable, machine-readable format.
- Object to processing carried out on the basis of our legitimate interest.
- Withdraw consent at any time, where consent was the basis for processing.
Write to hello@vaira.group, or to our EU representative above, to exercise any of these. We will respond within one month. We may ask you to confirm your identity first, so that we are not disclosing your data to someone else.
If you are not satisfied with our response, you may lodge a complaint with the data protection supervisory authority in the EU or UK country where you live or work. A current list of national authorities is published by the European Data Protection Board at edpb.europa.eu.
9. If you are in the United States
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not use personal information for cross-context behavioural advertising. Based on our size, we do not currently meet the applicability thresholds of the CCPA or of the comprehensive privacy statutes of other US states.
Regardless of whether a statute compels it, we will honour a request from any US resident to access, correct, or delete the personal information we hold about them. Email us and we will act on it.
10. Security
The site is served over HTTPS. Access to enquiry data is limited to the people at Vaira Group who need it to respond to you, and is protected by two-factor authentication on the accounts that hold it. No system is perfectly secure, but if a breach occurs that is likely to affect your rights, we will notify the competent supervisory authority within 72 hours as required by Article 33 GDPR, and tell you directly where the law requires it.
11. Children
This site and our services are aimed at businesses and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
12. Changes to this policy
If we change how we handle personal data, we will update this page and change the date at the top. Where the change is significant — for example, introducing analytics or a new category of processing — we will make that clear rather than relying on you to re-read the page.
13. Contact
Questions about this policy, or about your data: hello@vaira.group.