Privacy Policy

Below you’ll find the policies that explain how Urvantis Privacy handles information and provides personal Privacy Check-Up services.

These pages apply to urvantisprivacy.com and Urvantis Privacy Check-Up services.

For our separate business privacy and data-protection services, please visit the Urvantis legal pages.

Urvantis Privacy Policy v2.0

Last Updated: September 2026
Effective Date: September 2026

Our Commitment to Privacy

Urvantis Privacy helps individuals understand and improve their personal digital privacy through face-to-face Privacy Check-Ups and plain-English privacy guidance.

Privacy is therefore not simply something we talk about. It affects how we design and operate the service.

We aim to:

  • collect as little personal information as reasonably possible;
  • avoid unnecessary tracking and profiling;
  • keep our website technically simple;
  • be clear about what information we do need and why;
  • avoid retaining information simply because we can; and
  • give you control throughout your Privacy Check-Up.

If data isn’t needed, we don’t collect it.

Who We Are

Company Name: Urvantis Privacy Limited
Registered in: England and Wales
Data Controller: Urvantis Privacy Limited
Registered Office: Suite A, 82 James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, UK
Privacy Contact: Ben Oakley, Founder & Personal Privacy Adviser
Privacy Email: privacy@urvantis.com
Data Rights Requests: datarights@urvantis.com

Urvantis Privacy Limited is responsible for deciding how and why personal information covered by this policy is used.

Urvantis Privacy and Urvantis

Urvantis Privacy Limited operates two related services.

Urvantis Privacy is focused on individuals and personal digital privacy, including our face-to-face Privacy Check-Up service.

Urvantis provides separate privacy and data-protection services for businesses.

This policy applies to urvantisprivacy.com, enquiries about Urvantis Privacy, and personal Privacy Check-Up services.

Business services provided through Urvantis are governed by the separate privacy and legal information available through urvantis.com.

Our Website

Urvantisprivacy.com is built using WordPress and is designed to collect as little information from visitors as reasonably possible.

We currently avoid:

  • visitor analytics;
  • behavioural tracking;
  • advertising pixels;
  • marketing trackers;
  • social-media tracking;
  • public user accounts;
  • public comments;
  • customer dashboards; and
  • unnecessary third-party integrations.

The website is used to explain our services, publish privacy guidance and provide ways to contact us.

Privacy Check-Up appointments are not booked through a customer account or online booking calendar.

If you would like to ask a question or arrange a Check-Up, you contact us by email.

Information We Process When You Visit the Website

We do not deliberately collect personal information about ordinary website visitors for analytics, advertising or profiling.

Like virtually all websites, however, our hosting infrastructure processes limited technical information required to deliver and protect the website.

This may include:

  • IP address;
  • date and time of the request;
  • requested page or file;
  • browser or device information;
  • basic server and security log information.

This information is used only as reasonably necessary to operate, secure, troubleshoot and maintain the website.

We do not use server logs to build visitor profiles or track people across websites.

WordPress and Cookies

WordPress is the content-management system used to operate this website.

WordPress may use technical cookies for administrative functions, such as allowing authorised administrators to log in and manage the site.

We do not deliberately use cookies for:

  • advertising;
  • visitor profiling;
  • behavioural analytics;
  • remarketing; or
  • tracking visitors across other websites.

Any cookies or similar technologies actually used on the public website are explained separately in our Cookie Notice.

Website Hosting

Our website is hosted by Namecheap.

As part of normal website delivery, Namecheap may process limited technical information such as IP addresses, server requests and security logs.

We do not instruct Namecheap to use this information for advertising or visitor profiling on our behalf.

Our hosting environment is separate from our email system and from information handled during Privacy Check-Up appointments.

When You Contact Us

The website currently uses email rather than an online contact form.

If you email us, we may process:

  • your name;
  • your email address;
  • any telephone number you voluntarily provide;
  • the contents of your message;
  • information about what you would like help with; and
  • subsequent correspondence.

If you contact us because you are considering a Privacy Check-Up, we use this information to answer your questions, decide whether the service is suitable and, where requested, arrange an appointment.

Please do not send passwords, passcodes, banking information or unnecessarily sensitive personal information by email.

We will never ask you to email us your passwords or device passcodes.

Email and Tuta

Urvantis uses Tuta for email communication.

Tuta is a privacy-focused email provider based in Germany and stores account data within its encrypted infrastructure in German data centres.

Where both you and Urvantis use Tuta, emails between our Tuta accounts are automatically end-to-end encrypted.

If you contact us from another email provider, your message is not automatically end-to-end encrypted between both email accounts.

Where particularly sensitive email communication is necessary, alternative encrypted communication options may be offered where appropriate.

We do not use enquiry emails for advertising or unrelated marketing.

Arranging a Privacy Check-Up

If you decide to arrange a Privacy Check-Up, we may process information needed to organise and provide the appointment, including:

  • your name;
  • contact details;
  • agreed appointment date and time;
  • appointment location;
  • relevant questions or concerns you have raised;
  • payment status;
  • correspondence relating to the appointment; and
  • cancellation or rearrangement information where applicable.

We only ask for information reasonably necessary to provide the service.

Information During Your Privacy Check-Up

A Privacy Check-Up involves going through relevant privacy settings, accounts and digital choices with you.

This means we may temporarily see personal information displayed on your phone, tablet, laptop or online accounts during the appointment.

Our approach is deliberately restrictive.

Your Device, Your Passwords, Your Choice

You remain with your device throughout the appointment.

You enter your own:

  • passwords;
  • PINs;
  • passcodes;
  • authentication codes; and
  • other login credentials.

We do not ask you to disclose or write these down for us.

We do not routinely access or review:

  • private messages;
  • photographs;
  • personal documents;
  • financial information;
  • health information; or
  • unrelated private content.

If checking something relevant to your Privacy Check-Up could expose particularly private information, we will explain this and ask before proceeding.

Your appointment is not audio or video recorded.

We do not photograph, copy or export information from your device simply because it appears during a session.

Sensitive Personal Information

Because Privacy Check-Ups involve personal devices and accounts, sensitive information may occasionally be visible or voluntarily mentioned during a session.

We do not intentionally record sensitive personal information unless there is a genuine reason to do so.

If it becomes necessary to record special category personal information in order to provide something you have specifically requested, we will explain why and, where required, obtain your explicit consent before recording it.

Where sensitive information is merely visible during a Check-Up and does not need to be retained, we do not copy or record it.

Your Urvantis Privacy Plan

As part of your Privacy Check-Up, we may prepare a personalised Urvantis Privacy Plan.

This may contain information such as:

  • areas reviewed during your session;
  • privacy changes made with you;
  • general observations;
  • things you are already doing well; and
  • suggested next steps.

The Privacy Plan is deliberately designed to avoid unnecessary sensitive information.

We do not include passwords, passcodes or authentication credentials.

A copy may be provided to you electronically and/or in printed form.

Working Notes

Limited working notes may be made during a Privacy Check-Up where necessary to prepare your Privacy Plan or remember agreed actions.

These notes are not intended to become a detailed record of your digital life.

Once they are no longer required for providing the service, they are securely deleted or destroyed.

We aim to dispose of temporary Check-Up working notes within 30 days of completing your Privacy Plan unless there is a genuine reason to retain them longer.

Payments

Where you pay for a Privacy Check-Up electronically, payment may be handled by our payment provider rather than by WordPress.

Where card payment is processed through Stripe, Stripe handles the card-payment information required to complete the transaction.

Urvantis does not receive or store your full card number.

We may receive and retain information such as:

  • your name;
  • amount paid;
  • payment date;
  • transaction reference;
  • payment status; and
  • information required for invoices and accounting.

Financial and transaction records may need to be retained for longer than other service information where required for accounting, tax or legal purposes.

Appointment Locations

Urvantis Privacy Check-Ups are currently provided at suitable private office or meeting-room locations in Shrewsbury rather than from one permanent public office.

Where a venue requires visitor information for building access, security or reception purposes, we may need to provide limited information such as your name.

We do not normally tell a venue anything about your privacy concerns, digital accounts or what is discussed during your Check-Up.

We only provide venue operators with information reasonably necessary for arranging access to the appointment.

What We Do Not Collect

As part of our normal Privacy Check-Up service, we do not require or intentionally retain:

  • passwords;
  • PINs;
  • device passcodes;
  • authentication codes;
  • copies of private messages;
  • copies of photographs;
  • copies of your entire device contents;
  • browsing histories;
  • banking login credentials; or
  • unnecessary identity documents.

If we do not need it, we do not want it.

Why We Use Your Information

We only use personal information where we have an appropriate lawful basis under UK data-protection law.

Depending on the circumstances, this may include:

Contract

We use information where it is necessary to:

  • respond when you ask us to take steps towards arranging a Privacy Check-Up;
  • organise your appointment;
  • provide the Check-Up;
  • prepare and deliver your Privacy Plan;
  • take payment; and
  • provide agreed follow-up relating to the service.

Legitimate Interests

We may rely on our legitimate interests where reasonably necessary to:

  • operate and secure our website;
  • protect our systems against misuse;
  • respond to general correspondence that is not part of arranging a service;
  • maintain appropriate business records; and
  • establish, exercise or defend legal rights.

Where we rely on legitimate interests, we consider whether our interests are proportionate and whether your rights and interests override them.

Legal Obligation

We may process or retain information where necessary to comply with legal requirements, including:

  • accounting and tax obligations;
  • regulatory requirements;
  • lawful requests from public authorities; and
  • data-protection obligations.

Consent

Where processing is genuinely optional and consent is the appropriate basis, we will ask for it.

Where special category personal information needs to be intentionally recorded, an additional condition under data-protection law is also required and we will address this before recording the information.

Legal Basis Summary

Processing ActivityMain Lawful Basis
Website delivery and securityLegitimate interests
General enquiriesLegitimate interests and/or contract, depending on the enquiry
Steps requested before arranging a Check-UpContract
Appointment administrationContract
Providing the Privacy Check-UpContract
Preparing and delivering your Privacy PlanContract
Processing paymentContract
Accounting and tax recordsLegal obligation
Protecting systems and preventing misuseLegitimate interests
Handling data-protection rights and complaintsLegal obligation
Optional sensitive information where specifically requiredAppropriate Article 6 basis plus applicable special-category condition

How Long We Keep Information

We do not keep personal information indefinitely simply because storage is available.

Our normal approach is:

Enquiries that do not become appointments

Ordinary enquiry correspondence will normally be deleted when it is no longer useful, and generally within six months of the last meaningful contact, unless there is a reason to retain it longer.

Temporary Check-Up notes

Working notes used to prepare your Privacy Plan are normally securely deleted or destroyed within 30 days after the Plan has been completed.

Privacy Plans

Where we retain our own digital copy of your Privacy Plan for short-term support or correction purposes, it will normally be deleted within 90 days of your appointment, unless:

  • you ask us to retain it for longer;
  • there is an unresolved complaint or dispute; or
  • we are legally required to retain it.

You should keep your own copy if you want it for future reference.

Appointment correspondence

Routine appointment correspondence is normally retained for no longer than 12 months after the appointment, unless there is a genuine business or legal reason to retain particular information for longer.

Financial and contractual records

Minimal payment, invoice and contractual records may be retained for longer where necessary to comply with tax, accounting, legal or regulatory obligations.

Complaints or disputes

Information relevant to an unresolved complaint, dispute or legal claim may be retained for as long as reasonably necessary to deal with that matter.

When information is no longer required, we securely delete or destroy it where reasonably possible.

Who We Share Information With

We do not sell, rent or trade your personal information.

We do not provide customer information to:

  • advertisers;
  • data brokers;
  • social-media advertising platforms; or
  • marketing companies.

Limited information may be processed by providers required to operate the service, including where applicable:

  • Namecheap for website hosting;
  • Tuta for encrypted email and communication;
  • Stripe for payment processing;
  • secure file-storage providers used to store limited service documents;
  • accounting or bookkeeping systems where required for financial records; and
  • meeting-room or office providers where limited visitor information is required to provide access to your appointment.

We aim to disclose only the minimum information necessary for each provider to perform its function.

International Processing

Some organisations providing technology or payment infrastructure operate internationally.

Where personal information is transferred or processed outside the United Kingdom, we take reasonable steps to ensure that an appropriate mechanism recognised by UK data-protection law applies, such as:

  • UK adequacy regulations; or
  • appropriate contractual safeguards where required.

We do not deliberately move customer information internationally simply for convenience.

Security

We take reasonable technical and organisational measures to protect information under our control.

Our approach includes:

  • data minimisation;
  • encrypted communication and storage where appropriate;
  • strong account authentication;
  • restricting access to information;
  • keeping WordPress, themes and necessary plugins updated;
  • minimising unnecessary WordPress plugins and integrations;
  • separating public website functionality from customer service information; and
  • deleting information when it is no longer required.

No organisation can guarantee absolute security, but we design Urvantis Privacy around reducing unnecessary exposure wherever reasonably possible.

Your Data-Protection Rights

Depending on the circumstances and the lawful basis involved, UK data-protection law gives you rights over your personal information.

These may include the right to:

  • Access personal information we hold about you;
  • Rectify inaccurate or incomplete information;
  • Erase information where the right to erasure applies;
  • Restrict certain processing;
  • Object to certain processing;
  • Data portability where the legal requirements for portability apply; and
  • withdraw consent where processing is based on consent.

These rights do not apply in exactly the same way in every situation, and some are subject to legal exemptions.

How to Exercise Your Rights

Email:

datarights@urvantis.com

Please tell us what you are asking for as clearly as you can.

We normally respond to data-rights requests within the timeframe required by UK data-protection law.

We may need to take reasonable steps to confirm your identity before providing personal information, particularly where disclosure could affect your privacy or somebody else’s.

We will not request more identity information than reasonably necessary.

Data-Protection Complaints

If you are unhappy with how Urvantis Privacy has handled your personal information, you can complain directly to us.

Email:

privacy@urvantis.com

Please include enough information for us to understand what has happened and what you are concerned about.

For data-protection complaints, we will:

  • provide a clear route for you to raise the complaint;
  • acknowledge receipt within 30 days;
  • take appropriate steps to investigate the matter without undue delay;
  • keep you appropriately informed; and
  • tell you the outcome of our investigation without undue delay.

We would always prefer the opportunity to understand and resolve your concern directly.

You also have the right to raise a complaint with the UK’s data-protection regulator:

Information Commissioner’s Office (ICO)
https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113

Automated Decision-Making and Profiling

Urvantis Privacy does not use your personal information to make decisions about you through automated decision-making or profiling.

Your Privacy Check-Up and Privacy Plan involve human guidance and discussion.

We do not automatically assign you a privacy score or use your Check-Up information to profile you for advertising or marketing.

Marketing

We do not automatically add people who enquire about or purchase a Privacy Check-Up to a marketing list.

Your email address is not used for promotional marketing simply because you contacted or became a customer of Urvantis Privacy.

If we introduce an optional newsletter or other marketing communication in future, we will provide a separate and clear choice to opt in and update this policy where necessary.

Children and Family Privacy

Privacy Check-Up appointments are currently arranged with adults.

We do not knowingly enter into service contracts directly with children.

A parent or guardian may ask for guidance concerning family devices, children’s accounts or privacy settings as part of an appropriate session.

Where information relating to a child is involved, we take particular care to minimise what we see, record and retain.

Data Breaches

We take reasonable steps to protect personal information and reduce the amount of information that could be affected by an incident.

If we become aware of a personal-data breach, we will assess and respond to it appropriately.

Where legally required, this may include:

  • containing and investigating the incident;
  • documenting what happened;
  • notifying the Information Commissioner’s Office; and
  • notifying affected individuals where required.

External Websites

Our website may link to official guidance, technology providers, government services and other external websites.

Following an external link means you leave urvantisprivacy.com.

Those organisations operate under their own privacy policies, security practices and terms.

A link from Urvantis Privacy does not mean that we control how another organisation handles your information.

Changes to This Policy

Urvantis Privacy will evolve as the service develops.

If the way we collect or use personal information changes materially, we will update this policy accordingly.

The current version and date will always be shown at the top of this page.

Where a change materially affects existing customers, we will take reasonable steps to provide additional notice where appropriate.

Contact

Privacy enquiries: privacy@urvantis.com
Data-rights requests: datarights@urvantis.com
General enquiries: hello@urvantis.com

Urvantis Privacy Limited
Suite A, 82 James Carter Road
Mildenhall
Bury St Edmunds
IP28 7DE
United Kingdom

Transparency Commitment

This policy is intended to be understandable without legal training.

We avoid unnecessary legal jargon, vague promises and overly broad claims.

Our approach is simple:

collect less, explain clearly, and give people control.

If something in this policy is unclear, please ask us.

Building trust, one transparent policy at a time.
All Urvantis policies are maintained internally and version-controlled.
The most recent updates are listed at the top of each page.
© 2025-2026 Urvantis Privacy Limited. All Rights Reserved.