A2Legal

Privacy Policy.

How VibeCoders collects, uses and protects personal data when you use our website or contact us — aligned with UK GDPR and the Data Protection Act 2018.

1. Who we are (controller).

VibeCoders (“we”, “us”, “our”) is the organisation operating the website https://vibecoders.org.uk (vibecoders.org.uk). We are based in the United Kingdom.

For personal data collected through the Site and related business enquiries, we are the data controller. That means we decide how and why that personal data is processed.

Privacy contact: info@vibecoders.org.uk. Please use this address for data-protection requests (access, erasure, complaints about our handling of your data, and similar).

2. Scope of this policy.

This Privacy Policy explains how we process personal data when you:

  • Visit or browse the Site.
  • Contact us by email, contact form, or to book a discovery call.
  • Receive proposals, contracts or project communications from us as a prospective or current client contact.
  • Interact with cookies or similar technologies on the Site (see also our Cookie Policy).

It does not cover how we process personal data solely as a processor on a client’s instructions inside a delivered product or system. Those arrangements are governed by the client contract and, where required, a data processing agreement.

It also does not cover third-party websites we link to; their own policies apply.

3. Personal data we collect.

We only collect what we need for the purposes described below. Categories include:

Identity and contact data

  • Name, email address, organisation name, job title or role (if you provide them).
  • Phone number or preferred meeting times, where you include them in an enquiry.

Enquiry and correspondence data

  • Message content, project descriptions, constraints, attachments you send, and our replies.
  • Call notes or follow-up emails from discovery conversations.

Technical and usage data

  • Standard server and security logs that may include IP address, date/time, requested URL, user-agent (browser/device), referrer, and approximate location derived from IP at a coarse level.
  • Basic diagnostics needed to keep the Site available and secure.

Cookie and similar technology data

  • Information stored or read via cookies, local storage or pixels, as described in our Cookie Policy. Today the Site is primarily a static marketing experience; any non-essential tracking will only run with an appropriate lawful basis and, where required, consent.

We do not intentionally collect special category data (such as health, biometric or political opinions) through the Site. Please do not include such information in enquiry forms unless it is strictly necessary and you have a clear reason to share it.

We do not knowingly collect personal data from children under 16 via the Site. The Site is aimed at business users.

4. How we collect data.

Directly from you — when you email us, complete a form, book a call, or otherwise send information.

Automatically — when your browser or device interacts with the Site (logs, essential technical storage, and any consented analytics).

From third parties — rarely, for example if a mutual contact introduces you, or if a scheduling tool you choose shares booking metadata with us.

5. Purposes and lawful bases.

Under UK GDPR we need a lawful basis for each purpose. The main ones we rely on are:

Legitimate interests (UK GDPR Art. 6(1)(f))

  • Operating, securing and improving the Site.
  • Responding to business enquiries and assessing whether we can help.
  • Keeping records of prospective and client communications that are necessary for running a professional services practice.
  • Defending legal claims and preventing misuse or fraud.

Contract / pre-contract steps (Art. 6(1)(b))

  • Taking steps at your request before entering a contract (proposals, scoping, scheduling discovery).
  • Performing a contract once you engage us (billing contacts, project coordination).

Consent (Art. 6(1)(a))

  • Non-essential cookies or marketing communications where consent is required. You can withdraw consent at any time without affecting prior lawful processing.

Legal obligation (Art. 6(1)(c))

  • Retention of records where tax, accounting or other law requires it.
  • Responding to lawful requests from authorities where we are obliged to comply.

Where we rely on legitimate interests, we consider and balance any potential impact on you. You may object to processing based on legitimate interests — see “Your rights” below.

6. Marketing.

We do not operate a bulk email newsletter from this Site by default. If we send marketing emails in future, we will do so in line with UK GDPR and the Privacy and Electronic Communications Regulations (PECR), including consent or soft-opt-in where applicable, and a clear unsubscribe method.

Service messages about an active enquiry or contract are not marketing.

7. Who we share data with.

We do not sell personal data. We may share it with:

  • Service providers who support our operations under contract — for example email hosting, domain/DNS, website hosting, security tooling, and (if enabled) analytics or scheduling platforms.
  • Professional advisers (lawyers, accountants, insurers) where needed.
  • Authorities or courts where required by law or to protect rights, safety or security.
  • A buyer or successor if we restructure or transfer business assets, under appropriate safeguards.

Processors are only permitted to process personal data on our instructions and must implement appropriate security measures.

8. International transfers.

We are UK-based. Some subprocessors (for example global cloud or email providers) may process data in the European Economic Area, the United States, or other countries.

Where UK GDPR requires it, we use appropriate safeguards such as the UK International Data Transfer Agreement / Addendum, adequacy regulations, or other lawful transfer mechanisms, together with a transfer risk assessment where needed.

9. How long we keep data.

We keep personal data only as long as needed for the purposes above, then delete or irreversibly anonymise it, unless a longer period is required by law.

  • General website enquiries: typically up to 24 months after last meaningful contact, unless you become a client or ask us to delete sooner where we can.
  • Client and proposal records: for the life of the engagement and thereafter for a period consistent with limitation periods and accounting rules (often up to 6–7 years for contractual/financial records).
  • Security and server logs: usually a shorter rolling period (commonly 30–90 days) unless needed to investigate an incident.
  • Cookie consent records (if implemented): for the period needed to demonstrate compliance.

10. Security.

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. Measures are proportionate to risk and may include access controls, TLS in transit where supported, least-privilege access to mailboxes and hosts, and staff awareness.

No method of transmission or storage is completely secure. Please use discretion when emailing sensitive commercial or personal information.

11. Your rights (UK GDPR).

Subject to exemptions and conditions in UK law, you have the right to:

  • Be informed about how we use your data (this policy).
  • Access a copy of your personal data.
  • Rectify inaccurate or incomplete data.
  • Request erasure (“right to be forgotten”) in certain cases.
  • Restrict processing in certain cases.
  • Object to processing based on legitimate interests, and to direct marketing.
  • Data portability, where processing is based on consent or contract and carried out by automated means.
  • Withdraw consent where we rely on consent.
  • Complain to the Information Commissioner’s Office (ICO).

To exercise rights, email info@vibecoders.org.uk with enough detail for us to verify your identity and locate the data. We aim to respond within one month, or explain if we need more time (up to two further months for complex requests).

ICO: ico.org.uk — you can complain if you are unhappy with how we handled your data. We would appreciate the chance to resolve concerns first.

12. Automated decision-making.

We do not use purely automated decision-making that produces legal or similarly significant effects about you based on Site interactions.

13. Client projects and third-party data.

If you are a client and provide us with personal data about your users, customers or staff for a project, you must ensure you have a lawful basis to share it and that appropriate notices are in place. Processing instructions should be documented in the engagement paperwork.

14. Changes to this policy.

We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Significant changes may also be highlighted on the Site.

15. Contact.

Privacy enquiries and rights requests: info@vibecoders.org.uk.

General contact: info@vibecoders.org.uk.