Our principles
- Lawfulness and transparency — we process personal data for clearly stated purposes only.
- Purpose limitation — data collected for an engagement is not reused for unrelated purposes.
- Data minimisation — we ask for the least information needed to deliver the work.
- Accuracy — we correct records promptly when told they are wrong.
- Storage limitation — data is retained only as long as it serves a documented purpose.
- Integrity and confidentiality — access is restricted, logged and reviewed.
- Accountability — a named owner is responsible for data protection decisions.
Scope
This policy applies to all Ventiora Group personnel, associates, coaches and subcontractors, and to every system we use to handle personal or client information — including our website, database, email delivery, scheduling tools and learning platforms.
Client and participant data
- Where we process personal data on a client's behalf, we act as processor under the client's written instructions and a data processing agreement.
- Assessment results, coaching notes and 360-feedback are treated as confidential and shared only with the individuals and sponsors agreed in advance.
- Coaching conversations are confidential; only themes agreed with the participant are reported to sponsors.
- Client materials, data samples and use-case content are used only for the engagement in which they were shared, and never to train third-party models without written permission.
Security controls
- Encryption in transit (HTTPS/TLS) across our website and platforms, and encryption at rest for stored records.
- Role-based access on a least-privilege basis, with access reviewed when roles change and revoked on exit.
- Multi-factor authentication on administrative accounts.
- Row-level access rules on our database so records are reachable only by authorised roles.
- Rate limiting, spam controls and bot detection on public forms.
- Automated backups with restore testing, plus monitoring and alerting on availability and configuration issues.
- Confidentiality obligations in every associate and subcontractor contract.
Responsible AI and data use
Our AI transformation and AI coaching work often touches client data. We use anonymised or synthetic data for experimentation wherever possible, keep sandbox environments separate from production data, document what a model may access, and require human review of AI outputs that affect people. Client data is never entered into consumer AI tools.
Sub-processors and transfers
We use a small set of vetted providers for hosting, database, email delivery, analytics, scheduling and event registration. Each is assessed for security and data protection before use and bound by contract. Where personal data crosses borders, we rely on recognised safeguards such as standard contractual clauses or an adequacy decision, and we honour client-specific data residency requirements agreed in the engagement contract.
Retention and deletion
Each category of data has a defined retention period. Enquiry records are held for up to 24 months from last contact; engagement records for the term of the engagement plus any legally required period; anti-abuse logs for a short operational window. At the end of an engagement, client data is returned or securely deleted on request.
Breach response
Suspected incidents are reported internally without delay, triaged and contained. Where a personal data breach is likely to affect rights and freedoms, we notify affected clients promptly and the relevant supervisory authority within the timeframe required by applicable law — 72 hours where GDPR applies. Every incident is documented with root cause and corrective actions.
Individual rights requests
Requests to access, correct, delete, port or object to the processing of personal data can be sent to enterprise@ventiora.net. We acknowledge requests promptly and respond within statutory deadlines. Where we act as processor for a client, we forward the request to that client and support their response.
Governance and review
This policy is reviewed at least annually and after any material change to our systems, providers or legal obligations. Personnel receive data protection guidance on joining and refreshers as practices change.