How information is handled
A small amount of useful context
Vuko handles corporate enquiries as controller through the legal entity set out below. This notice concerns the company website, not a customer’s separate application. To discuss work, a business contact and description of the desired change are more useful than an unsolicited database or credential.
The website request
Cloudflare supplies the hosting layer for Vuko. Serving and protecting a page can involve IP information, the requested path, browser characteristics and request time. Fonts are stored with the site. The company has added no advertising script, analytics measurement or visitor-registration function.
Reasons to use information
The lawful bases are linked to the task: legitimate interests in safe publication and relevant business correspondence under Article 6(1)(f), requested steps before a contract under Article 6(1)(b), and applicable legal obligations under Article 6(1)(c). The legitimate-interest assessment must account for the individual, rather than treating convenience as unlimited permission.
Who needs access
People dealing with an enquiry and necessary technical providers may handle the relevant information. A customer project in which Vuko is a processor needs a written definition of permitted use, access and protective measures. The project terms should address provider involvement and the disposition of data when the work ends.
When to let information go
Retention should follow an identifiable enquiry, contract, record-keeping or dispute purpose. When none remains, data is removed or anonymised. International transfers associated with technical providers require an appropriate legal route, which may be adequacy or approved contractual safeguards according to the circumstances.
Requests, concerns and incidents
Contact Vuko at its registered office to request access, correction or deletion of data, and to exercise applicable objection, restriction and portability rights. Identify the correspondence so the company can locate it, with proportionate identity checks where needed. The usual response window is a month. A personal data breach is evaluated against the ICO notification rules, including the 72-hour deadline where applicable, and any duty to inform people. Unresolved issues can be taken to the ICO. These business-oriented pages do not solicit information from children.