Legal

Privacy notice

Last updated 1 August 2026. This notice covers data collected through this website — client project data is governed by the data processing agreement in your contract.

What we collect

Only what you type into a form on this site, plus the technical details your browser sends with the request:

  • Enquiry and quote forms: name, email, phone, company, service of interest, budget range, timeline and your message.
  • Job applications: name, email, phone, portfolio URL, years of experience and your cover note.
  • Newsletter: email address only.
  • Automatically: IP address and browser user-agent string, recorded with submissions to detect abuse and rate-limit spam.

Cookies

This site sets no advertising, analytics or tracking cookies. A single session cookie (convera_session) is set only if you sign in to the staff admin area; it is HttpOnly, expires after twelve hours and holds nothing but an opaque session token.

Why we hold it

To answer your enquiry, assess your application, or send the newsletter you asked for. The lawful basis is legitimate interest for business enquiries, consent for the newsletter, and steps prior to a contract of employment for applications.

How long we keep it

  • Enquiries that do not become clients: 24 months, then deleted.
  • Job applications: 12 months, unless you ask us to keep them on file for longer.
  • Newsletter subscriptions: until you unsubscribe.
  • Client records: as set out in your contract and our retention schedule.

Who sees it

Our own staff, on a need-to-know basis. We do not sell, rent or share enquiry data with third parties for marketing. Where a sub-processor is involved in hosting or email delivery, it is bound by a written data processing agreement and listed in our sub-processor register, available on request.

Your rights

You can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, or object to how we are using it. Email privacy@converasolutions.com and we will respond within 30 days. You can unsubscribe from the newsletter using the link in any email or by asking us directly.

Security

Submissions are transmitted over TLS and stored on infrastructure we control, with access limited to named staff accounts protected by multi-factor authentication. We operate an ISO 27001-aligned information security management system and review these controls annually.

Changes

If we change this notice we will update the date above. Material changes affecting how we use data you have already given us will be notified by email where we hold one.