Privacy Notice
Last updated: May 2026
This Privacy Notice explains how VEGA collects, uses, stores, and protects personal data when you visit this website, submit a contact inquiry, contact us by email, or engage with our services.
VEGA is committed to handling personal data carefully, transparently, and in accordance with the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679) and other applicable data protection laws.
1. Who we are
VEGA stands for Viktor Egei Governance & Assurance.
VEGA is an independent consultancy focused on AI security, privacy, governance, risk, and assurance.
For the personal data described in this Privacy Notice, VEGA acts as the data controller.
Contact: Get in Touch or email us at privacy@vega-consulting.nl
2. Personal data we collect
We only collect personal data that is necessary for the purposes described in this Privacy Notice.
2.1 Identity and contact data
This may include your name, email address, company name, organization, role, selected subject, message content, and other contact details when you contact us directly or submit a contact inquiry.
2.2 Communication data
This includes the content of messages you send to us by email, contact form, or other communication channels, including information you choose to include in your inquiry.
2.3 Technical data
This may include basic technical information necessary to operate, secure, and protect the website and contact form, such as server logs, IP address, browser type, device information, timestamps, and basic anti-spam signals.
2.4 Local browser storage and session storage
This website may use strictly necessary local browser storage or session storage to support basic website functionality and user interface behavior. This may include remembering the page from which you entered the legal documents so the Back control can return you there, remembering that the home-page shield animation has already played during the current browser session, and, where enabled, storing background visual configuration for the website interface.
2.5 Contact form anti-spam data
If you use the contact form, VEGA may process basic technical and anti-spam information to help prevent abuse, automated submissions, and security incidents. This may include submission timestamps, form-completion timing, server-side validation results, rate-limiting signals, and hidden anti-spam field values.
This information is used only to protect the website, the contact form, and VEGA's communication channels.
3. How we use your personal data
We may use personal data for the following purposes:
- To receive, review, and respond to contact inquiries submitted through the website or by email.
- To communicate with prospective or existing clients.
- To assess whether VEGA can support a requested service, project, or engagement.
- To provide consultancy services where agreed.
- To operate, maintain, secure, and improve this website and contact form.
- To prevent spam, abuse, unauthorized access, or misuse of the website and contact form.
- To comply with applicable legal or regulatory obligations.
- To establish, exercise, or defend legal claims where necessary.
3.1 Contact inquiries
When you submit a contact inquiry, VEGA uses the information provided to review, manage, and respond to your inquiry.
Please do not include confidential, sensitive, special-category, or regulated information in the contact form unless this has been agreed separately.
If your inquiry may lead to a potential engagement, VEGA may also use the information to assess the requested support, prepare follow-up questions, and discuss possible next steps.
4. Legal bases for processing
We process personal data only where we have a valid legal basis under the GDPR.
- Pre-contractual or contractual necessity: where processing is necessary to take steps at your request before entering into a contract, or to provide agreed services.
- Legitimate interests: where processing is necessary for responding to business inquiries, managing prospective or existing client communications, operating and securing the website and contact form, preventing spam or abuse, or protecting our rights, provided your interests and rights do not override those interests.
- Legal obligation: where processing is required by applicable law.
- Consent: where we ask for your consent for a specific purpose.
5. Cookies and local storage
This website does not currently use analytics cookies, advertising cookies, third-party tracking cookies, or tracking pixels.
We may use strictly necessary local browser storage or session storage to support basic website functionality and user interface behavior.
For more information, please see our Cookie Notice.
6. Data sharing
We do not sell your personal data. We may share personal data only where necessary and appropriate, for example with:
- Website hosting, email, form processing, transactional email delivery, security, or IT service providers.
- Professional advisers where necessary.
- Public authorities where required by law.
Where VEGA uses service providers to operate the website, process contact form submissions, deliver email notifications, or protect the website against spam and abuse, those providers may process personal data only as necessary to provide their services to VEGA.
Relevant service providers may include Vercel for website hosting and server-side form handling, Resend for transactional email delivery, and Versio for domain and business email services.
Where service providers process personal data on our behalf, we use appropriate contractual safeguards.
7. International transfers
Where personal data is transferred outside the European Economic Area, we use appropriate safeguards where required, such as adequacy decisions or Standard Contractual Clauses.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Notice, unless a longer retention period is required or permitted by law.
Contact and communication data may be retained for as long as needed to handle your inquiry, maintain a business relationship, or comply with legal obligations.
Contact inquiries that do not lead to an engagement are normally retained for up to 12 months after the last meaningful interaction, unless a longer retention period is required or permitted for legal, administrative, security, or dispute-management purposes.
Technical and anti-spam data related to contact form submissions is retained only for as long as necessary to protect the website, investigate abuse, maintain security, or troubleshoot delivery issues.
9. Data security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure configuration, server-side validation, anti-spam controls, and appropriate service-provider safeguards.
However, no website, email system, or internet transmission can be guaranteed to be completely secure.
10. Your GDPR rights
Subject to the conditions set out in the GDPR, you may have the following rights:
- The right of access.
- The right to rectification.
- The right to erasure.
- The right to restriction of processing.
- The right to data portability.
- The right to object.
- The right to withdraw consent where processing is based on consent.
You also have the right to lodge a complaint with your local data protection supervisory authority.
11. Changes to this Privacy Notice
We may update this Privacy Notice from time to time. The latest version will always be published on this page.
12. Contact
For questions about this Privacy Notice or how VEGA handles personal data, Get in Touch or email us at privacy@vega-consulting.nl.
