Privacy Policy
1. Overview and scope
This Privacy Policy describes how VoltricEdge ("we", "us") collects, uses, and safeguards information when you use this website, submit an enquiry or a Cloud Migration Assessment, or engage our services. It covers the information we handle as a business. It does not describe how we handle data inside a client's own cloud environment during a migration engagement — that is governed by the written agreement for that engagement.
2. Information we collect
Information you provide. When you submit the contact form, we collect your name, business email address, company, country, the service you are interested in, how you heard about us, an optional phone number, and your message.
When you submit a Cloud Migration Assessment, we additionally collect your role, company size, and your answers to the assessment questionnaire. Those answers describe your IT environment and plans, and may include information about your infrastructure and hosting, applications and workloads, resilience and disaster-recovery posture, and your security and regulatory compliance requirements. Please do not include credentials, access keys, or other secrets in an assessment or enquiry.
Information collected automatically. Our hosting provider processes standard request information, including IP address and browser user-agent, in order to deliver and secure the site. When you submit an assessment we store a salted, irreversible hash of the submitting IP address together with the browser user-agent for abuse prevention and submission integrity. We do not store the raw IP address alongside your submission.
We do not use website analytics or advertising trackers. This site loads no analytics, advertising, or session-recording scripts, and sets no analytics or advertising cookies. We do not build advertising profiles and we do not sell personal information.
3. How we use information
We use the information to respond to your enquiry, to review and qualify an assessment submission and prepare for the resulting discussion, to deliver and improve our services, to protect our systems against abuse, and to meet our contractual and legal obligations.
4. Legal bases for processing
Where data-protection law requires a legal basis, we rely on: our legitimate interests in responding to enquiries, operating and securing our services, and pursuing business relationships; the steps necessary to enter into or perform a contract with you; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time.
5. Service providers
We use a small number of providers to operate this website and our internal systems. They process information on our instructions and under their own data-protection terms. We publish the current list, including what each provider receives and why, on our Subprocessors page.
In summary: Cloudflare hosts this website and our internal console and stores assessment records in its D1 database; Amazon Web Services (Amazon SES) delivers transactional email, which means it processes the email addresses and the message content of the notification and acknowledgement emails we send. Beyond these providers, we share information only where required by law or to establish, exercise, or defend legal claims.
Customers who require a Data Processing Addendum can request one by writing to [email protected].
6. International transfers
Our service providers operate global infrastructure, so information may be processed in countries other than your own. Where such transfers are subject to data-protection law, they rely on the transfer mechanisms offered by those providers, including standard contractual clauses where applicable. If you need to know the specific regions applicable to your engagement, contact us and we will confirm what we can.
7. Security
Traffic to and from this site is encrypted in transit using TLS. Form submissions are validated server-side, rate-limited, and protected against automated abuse by Cloudflare Turnstile. Our internal consulting console is not publicly reachable: it is protected by Cloudflare Access, restricted to authorised VoltricEdge personnel through single sign-on, and further governed by role-based access control, with access to assessment records recorded in an internal audit log.
These are descriptions of controls we operate. They are not a certification — see section 11.
8. Data retention
We retain information for as long as necessary for the purposes described in this policy, to maintain a record of our business dealings, and to meet legal obligations. We have not yet published fixed retention periods for each category of data. You can ask us to delete information, as described in section 9, and we will do so unless we are required to keep it.
9. Your rights
Depending on your jurisdiction, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to receive it in a portable form. To exercise any of these, write to [email protected]. We may need to verify your identity before acting. If you are in a jurisdiction with a data-protection regulator, you also have the right to complain to it.
10. Cookies and local storage
We do not use analytics, advertising, or tracking cookies. Cookies are used only where strictly necessary for the site to function or to be secure:
- Cloudflare Turnstile — bot protection when you submit a form.
- Cloudflare Access — authentication for VoltricEdge staff signing in to internal systems. This does not apply to public visitors.
- Cloudflare network and security — cookies our hosting provider may set to deliver and protect the site.
Separately, your light or dark theme preference is stored locally in your own browser. It is a display setting only, it is never transmitted to us, and it is not used to identify or track you.
11. Our compliance status
We think it is important to be precise about this, because these three things are often conflated:
- Our infrastructure providers hold their own certifications. Cloudflare and Amazon Web Services maintain independent compliance programs for their platforms. Those certifications belong to those providers.
- VoltricEdge operates its own security controls, described in section 7 and in our Trust Center.
- VoltricEdge itself does not currently hold a security or privacy certification. We are not SOC 2 certified, ISO 27001 certified, HIPAA compliant, or PCI DSS compliant, and we do not claim to be "GDPR certified" — no such certification exists. A provider's certification does not transfer to us, and we will not present it as though it does.
If that status changes, we will say so here and date the change.
12. Changes to this policy
We may update this policy as our services or providers change. The "last updated" date above reflects the most recent revision. Material changes to how we handle personal information will be reflected here before they take effect where practicable.
13. Contact
Questions about this policy, or about how we handle your information, can be directed to [email protected].