Effective 20 September 2026
Privacy policy
The opening checkpoint
VANGUARD VIGILANCE CONSULTING LTD, company number 234714224, publishes this privacy route for people who write to [email protected] or read the public pages. The company is the controller for its own contact and business records.
A split in responsibility
A briefing addressed to Vanguard is controller material because the company decides how it will answer. A client dataset handled under a written instruction is processor material and stays inside that instruction. The company’s own scheduling, billing, legal and security records have a separate controller basis.
What enters the sequence
A correspondent chooses whether to provide a name, role, reply address, facts and attachments. The browser contributes an access time, requested path, user-agent and network address. The site has no account registration and is not an invitation to send special category information.
Purpose and lawful basis
The sequence uses a briefing to understand a concern, arrange a first meeting, keep the decision trail coherent and defend the service against misuse. The lawful basis may be requested steps, legitimate interest, legal obligation or consent. A consent choice can be withdrawn for future use.
Recipients at a checkpoint
An email host, registrar, web host or adviser can receive a limited record when that is needed to deliver a named task. Contracts and confidentiality duties govern the hand-off. Vanguard does not sell a briefing list or build a behavioural advertising file.
Retention, close-out and erasure
A live briefing is reviewed when its next action is complete. Contractual, accounting and legal records stay for the period required by law; delivery and security entries are kept for a shorter period. Email [email protected] to ask for account deletion or erasure. No account is created by this site, and a legal duty or claim can require a small record to remain.
A route beyond the UK
A supplier in another country is used only with a lawful transfer mechanism, which may be adequacy, the International Data Transfer Agreement, the UK Addendum to the Standard Contractual Clauses or another recognised safeguard. The company notes the destination and the protection selected.
If the trail is broken
A suspected breach is contained, assessed and assigned an incident record. Where the threshold is met, the ICO receives a report within 72 hours of awareness; affected people are contacted when required. A processor notifies the controller without undue delay.
Rights and children
Access, correction, erasure, restriction, objection and portability are available where the UK GDPR says they are. Identity may be checked and a normal reply is due within one month. The pages are not aimed at children; a parent or guardian can ask for review of a child’s information.
The independent route
For a question, email [email protected]. A complaint can go to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, 0303 123 1113. This route is dated 20 September 2026 and the company will mark a material change on the page.