How information is handled
Corporate information, not application data
Vortexcore’s controller role on this website concerns its own public pages and business enquiries. It is distinct from the data role of a customer application. The legal entity and registered correspondence address appear below so a visitor can identify who handles a request.
Two sources of information
Page delivery involves technical request details, including network addresses, resource paths and browser data handled by Cloudflare. Correspondence is a second source: the sender chooses the contact details, requirement description and supporting context to provide. Neither a customer account nor an analytics integration is part of these pages.
Lawful bases by purpose
Maintaining an accessible, protected corporate site and handling relevant approaches are legitimate interests under Article 6(1)(f), with the necessary assessment of individual interests. An enquiry made to take steps towards a contract can be handled on Article 6(1)(b). Where a record is legally required, Article 6(1)(c) is relevant. A distinct consent-based use would need its own explanation.
Development arrangements
Vortexcore should receive live application records only under an agreed project arrangement. Acting as a processor requires documented instructions and a defined allocation of access, security, providers and end-of-project handling. An introductory brief can use synthetic or safely redacted examples instead of customer information.
Lifecycle of a record
Retention ends when the enquiry or associated relationship no longer justifies holding the information, unless a law or defensible dispute-related purpose requires a record. Global infrastructure can entail international transfers. Where needed, an adequacy decision or approved contractual mechanism supplies the relevant transfer safeguard.
Individual control
Write to the registered office to seek access, rectification, restriction or deletion of data connected with Vortexcore correspondence. Portability and objection depend on the applicable conditions. Requests should identify the interaction and a way to respond; verification is limited to what is reasonably necessary. Responses normally fall within one month.
Problems and protection
A data breach needs assessment, containment and the notifications warranted by its risk, including the ICO’s applicable 72-hour reporting threshold. People must be informed when the law requires it. The ICO also provides a complaint channel. The corporate service information is aimed at business commissioners, not children.