Privacy, security and AI governance across 50+ jurisdictionsTalk to us
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01

Legal

Privacy notice

This notice explains what personal data Vedhacon collects when you use this website, attend our training, or engage us for consultancy, implementation or DPO services. It also explains the lawful bases we rely on, who we share data with, how long we keep it, and how you can exercise your rights.

Last reviewed: September 2026. Version 1.0.

Who we are

The controller for this processing

Vedhacon is the data controller for personal data processed through this website and through our direct client relationships. Where we deliver services on a client’s instructions, for example as an outsourced DPO or during an implementation engagement, we act as a processor for that client’s data and their own notice governs that processing.

Contact

Write to us through the contact page for any privacy question, including rights requests, complaints and queries about this notice.

Controller or processor

We are a controller for our website, marketing, recruitment and business administration. We are a processor when we handle personal data inside a client engagement under a written services agreement.

What we collect

Categories of personal data and why we hold them

Categories of personal data processed by Vedhacon
CategoryExamplesPurposeLawful basis
Contact dataName, work email, organisation, job title, phone numberResponding to enquiries and delivering the services you ask forContract, and legitimate interests for business correspondence
Engagement dataScope documents, meeting notes, assessment findings, deliverablesPerforming consultancy, implementation and DPO engagementsContract
Training dataRegistration details, attendance, assessment results, certificatesRunning courses and issuing certification recordsContract
Website dataIP address, device and browser type, pages viewed, referrerKeeping the site secure and understanding which content is usefulLegitimate interests, and consent for non-essential analytics
Marketing dataSubscription status, preferences, engagement with our updatesSending updates you have asked to receiveConsent, withdrawable at any time
Recruitment dataCV, work history, references, right-to-work informationAssessing applications for roles at VedhaconLegitimate interests and, where applicable, legal obligation

We do not seek special category data through this website. If you volunteer it, for example accessibility requirements for a training session, we process it only to meet that request and delete it once the session has passed.

Recipients

Who we share personal data with

We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose it only where it is necessary to run the service you have asked for, or where the law requires it.

Service providers

Hosting, email, scheduling, document storage and learning platform providers, each engaged under a written processing agreement limiting them to our instructions.

Professional advisers

Legal, accounting and insurance advisers where necessary to establish, exercise or defend a legal claim.

Regulators and authorities

Where we are under a legal obligation to disclose, or where disclosure is necessary to protect our rights or the safety of others.

Business transfers

If our business is reorganised or transferred, personal data may move with it, subject to the protections in this notice.

Cross-border

International transfers

We work across more than fifty jurisdictions, so personal data may be accessed from, or stored in, a country other than your own. Where that transfer leaves a jurisdiction that restricts onward transfers, we rely on a recognised safeguard and document it.

Safeguards we use

Adequacy decisions where one exists, standard contractual clauses or the equivalent local mechanism where one does not, and supplementary technical measures where a transfer risk assessment calls for them.

Transfer records

Each transfer is recorded in our own record of processing activities, with the destination, the mechanism relied on and the date of the last review.

Retention

How long we keep personal data

We keep personal data only for as long as it serves the purpose it was collected for, then delete it or bring it into an aggregate form that no longer identifies anyone. Where a statutory retention period applies, that period governs.

Enquiries

Deleted twelve months after the last contact, unless the enquiry becomes an engagement.

Engagement records

Retained for the life of the engagement and then for the period required by contract, limitation and tax rules.

Training records

Certification records are kept for as long as the certificate remains verifiable, because learners rely on them.

Marketing

Deleted promptly when you unsubscribe, other than a minimal suppression record proving you asked not to be contacted.

Your rights

Exercising your rights

The exact rights available to you depend on the law that applies where you are. In practice we handle every request to the highest applicable standard rather than asking you to prove which law covers you.

Access and portability

Obtain confirmation of whether we process your data, a copy of it, and where technically feasible a structured machine-readable export.

Correction and erasure

Ask us to correct inaccurate data or to delete data we no longer have a basis to hold.

Objection and restriction

Object to processing based on legitimate interests, or ask us to pause processing while a dispute about accuracy or basis is resolved.

Withdrawing consent

Withdraw consent at any time where consent is the basis. Withdrawal does not affect processing already carried out.

Complaints

Raise a complaint with us first if you can, so we have the chance to put it right, and with your supervisory authority at any time.

How to ask

Use the contact page. We acknowledge requests promptly and respond within the shortest period the applicable law allows.

Cookies

Cookies and similar technologies

This site uses a small number of cookies. Strictly necessary cookies are set without consent because the site cannot function without them. Anything else is set only after you opt in, and you can change that decision at any time.

The full list, including purposes and durations, is in our cookie policy.

Maintenance

Changes to this notice

We review this notice at least annually and whenever we change how we process personal data. The version number and review date at the top of this page tell you which version you are reading. Where a change materially affects you, we will tell you directly rather than relying on this page alone.