How we handle personal information, what we do and do not do with client data, and the terms that govern this site. Written plainly, because a policy nobody reads protects nobody.
Effective28 August 2026
Last updated28 August 2026
EntityVolvera
Contactsupport@volvera.net
Before you publish
This is a drafted framework, not legal advice, and it has not been reviewed by a lawyer. It has been written to stand up without a registered address or phone line: every route runs through support@volvera.net, and the retention, sub-processor and contact facts have been set to sensible working defaults. Confirm each one is true of how you actually operate before you publish.
Three items still carry a gold marker because they need a lawyer, not a decision: the governing-law state, the arbitration and class-action waiver in the Terms of Use, whose enforceability turns on state law and on how it is presented, and the limitation of liability cap, which should be set against your actual insurance cover and the contract value of your engagements. Once the entity is incorporated, add its registered name, state and office to section 2 of the Privacy Policy and to Contact & Complaints. Then delete this banner.
Privacy Policy
What personal information Volvera (“Volvera”, “we”, “us”) collects through volvera.net and our business dealings, why we collect it, who we give it to, and the rights you have over it.
Effective 28 August 2026 · Last updated 28 August 2026
Notice at collection. We collect identifiers, commercial information, internet activity, professional information and inferences, as set out in section 3, to respond to enquiries, deliver our services, secure our site and meet legal obligations. We retain each category for the periods in section 6. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not collect or process sensitive personal information for any purpose that would give rise to a right to limit its use.
1Who this notice covers
This notice applies to personal information we handle as a business (a controller): visitors to volvera.net, people who request a Funnel Read, prospective and current client contacts, applicants, suppliers and recipients of our business communications.
It does not apply to personal information we process inside systems we build, host or operate for a client. In that work our client decides why and how the data is used, and we act only as a service provider (a processor) under their instructions and their contract. If you are a customer, patient or contact of one of our clients and want to exercise rights over your data, contact that organisation directly; we will support them in responding. Our obligations in that role are set out in the AI & Client Data Statement.
2Who we are and how to reach us
Who we are: Volvera, a United States–based operating team. We are a remote business with no public office, so we do not publish a street address; every route below reaches the same people.
Privacy contact: support@volvera.net — put “Privacy request” in the subject line and it is routed to the founder who owns privacy.
General contact: support@volvera.net
Response time: we acknowledge within 10 business days and substantively answer within 45 calendar days, extendable once by a further 45 days where the request is complex, in which case we tell you why before the first period ends.
If you need to reach us by post — for example to serve a formal legal notice — email support@volvera.net and we will provide a mailing address for that purpose within 5 business days.
We operate exclusively online and have a direct relationship with the people from whom we collect personal information, so under the CCPA regulations we accept privacy requests by email rather than by toll-free telephone number.
3What we collect
Categories below use the statutory labels from the California Consumer Privacy Act so that the disclosure is directly comparable to the law.
Categories of personal information collected in the preceding 12 months.
Category
Examples
Why we collect it
Identifiers
Name, business email, telephone, employer, job title, IP address, browser and device identifiers
To reply to you, deliver the Funnel Read, run the engagement, and secure the site
Customer records (Cal. Civ. Code §1798.80)
Billing contact, business address, payment reference
To judge whether we are a fit and to scope work accurately
Audio and electronic
Call or meeting recordings and notes, where you are told and consent
Accurate diagnosis notes; declining does not affect the service
Inferences
Which service line likely fits your situation
To route the enquiry to the right person
Sensitive personal information
None sought
Not collected through this site — see below
Sensitive personal information. We do not ask for government identifiers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, health information or data about sex life or sexual orientation through this website. Where a client engagement requires us to process health information, we do so only as that client’s service provider under a written agreement and, where the client is a covered entity, a Business Associate Agreement. We do not use or disclose sensitive personal information for purposes that trigger a consumer’s right to limit its use under the CCPA.
What the interactive parts of the site do not do. The symptom picker and the step tabs on our home page run entirely in your browser. They set no cookie, write nothing to storage and send nothing to us. Your selection is not recorded.
4Where the information comes from
From you — when you email us, request a Funnel Read, sign a contract or speak with us.
Automatically — from your browser and our server logs when you visit the site.
From your organisation — when a colleague introduces you or names you as a contact.
From public and business sources — company websites, professional networks, business directories and referrals, used only to establish whether there is a fit and to verify who we are dealing with.
5Why we use it
To answer enquiries and deliver the Funnel Read.
To scope, price, deliver and support engagements, and to train client teams.
To administer contracts, invoice and keep accounting records.
To secure the site and our systems, prevent fraud and abuse, and debug faults.
To understand in aggregate how the site is used and improve it.
To send business communications about our services to business contacts, with an unsubscribe link in every message.
To comply with law, respond to lawful requests, and establish, exercise or defend legal claims.
We do not use personal information collected through this site for any materially different purpose without telling you first.
6How long we keep it
Retention periods. Where a period is a maximum, we delete sooner when the data is no longer needed.
Data
Kept for
Why
Enquiries that do not become engagements
24 months from last contact
To follow up sensibly and avoid re-contacting people who declined
Client contract and billing records
7 years after the engagement ends
Tax, audit and limitation periods
Server and security logs
12 months
Security investigation and abuse prevention
Marketing contact records
Until you unsubscribe, then a suppression record indefinitely
So that an unsubscribe stays honoured
Call and meeting recordings
12 months
Accuracy of diagnosis notes
Client and end-customer data in delivered systems
Per the client’s instructions and our Data Processing Agreement
The client is the controller of that data
7Who we disclose it to
We disclose personal information for business purposes to the following categories of recipient, each under a written contract that restricts what they may do with it:
Cloud hosting and infrastructure providers.
Email, calendar and CRM providers used to run our own business.
Professional advisers — lawyers, auditors and insurers, where needed.
A buyer or successor in a merger, acquisition, financing or sale of assets, subject to this notice continuing to apply.
Courts, regulators and law enforcement, where we are legally required to disclose or need to defend legal claims.
No sale. No sharing. No targeted advertising. In the preceding twelve months we have not sold personal information, have not shared personal information for cross-context behavioral advertising, and have not processed personal information for targeted advertising or for profiling that produces legal or similarly significant effects. We have never sold or shared the personal information of anyone we knew to be under 16.
8Your rights
Depending on where you live, some or all of the following apply. We extend them to every person who asks, regardless of state, because operating one standard is simpler than operating twenty.
Know and access — what we collect, why, where it came from, who we disclose it to, and a copy of the specific pieces we hold.
Delete — subject to exceptions such as completing a transaction, security, legal compliance and defending claims.
Correct — inaccurate personal information.
Portability — a copy in a portable, readily usable format where technically feasible.
Opt out of sale or sharing — we do neither, but the right stands and we honour opt-out signals regardless.
Opt out of targeted advertising and of profiling with legal or similarly significant effects.
Limit the use of sensitive personal information — we do not use it in ways that trigger this right.
Non-discrimination — we will not deny service, charge a different price or give you a lower quality of service because you exercised a right. We operate no financial incentive programmes.
Appeal — if we refuse a request, you may appeal; see section 9.
9How to exercise them
Email support@volvera.net with the subject line “Privacy request”, or use the options under Your Privacy Choices. Tell us what you want us to do and enough detail for us to find your records.
Verification
We will ask you to confirm information we already hold so that we do not hand your data to someone else. We ask for the minimum necessary and use anything you send for verification only, then delete it. If we cannot verify you, we will tell you why.
Authorised agents
An agent may act for you if they provide your signed written permission. We may still contact you directly to confirm.
Timing
We acknowledge requests within 10 business days and respond substantively within 45 calendar days. Where a request is complex we may extend once by a further 45 days and will tell you why within the first period. Requests are free unless manifestly unfounded or excessive, in which case we will explain before charging or refusing.
Appeals
If we decline, you may appeal within 45 days by replying with “Appeal” in the subject line. We will respond in writing within 45 days with our decision and reasons. If the appeal is denied you may complain to your state Attorney General — or, in California, to the California Privacy Protection Agency.
10Opt-out preference signals
We recognise the Global Privacy Control (GPC) as a valid opt-out request for the browser and device that sends it. Because we neither sell nor share personal information, a GPC signal has no sale to stop; we treat it instead as an instruction to disable non-essential analytics on that device and to record your opt-out. You can see what your browser is currently sending in Your Privacy Choices.
There is still no common standard for Do Not Track browser signals, so we do not respond to DNT separately. GPC is the signal we honour.
11Automated decision-making and AI
We do not use automated decision-making technology to make decisions about visitors to this site that produce legal or similarly significant effects. Nothing on this site profiles you, scores you or decides anything about you.
Automated decision-making is, however, the substance of what we build for clients. Where an engagement involves it, the client is the business making the decision and we act as their service provider. We build in a documented human review step for any decision with a significant effect on a person, keep audit logs, and maintain risk assessments for processing that involves sensitive information, profiling, or the use of personal information as training data — consistent with the California Privacy Protection Agency’s regulations on automated decisionmaking technology, risk assessments and cybersecurity audits, which took effect on 1 January 2026. Details are in the AI & Client Data Statement.
12State-specific disclosures
California
The disclosures in sections 3, 5, 6, 7 and 8 are our CCPA disclosures. Note that California, unlike every other state with a comprehensive privacy law, does not exempt business-to-business contact data — so if you are a California resident dealing with us in a professional capacity, these rights apply to you in full. California’s “Shine the Light” law (Cal. Civ. Code §1798.83) permits residents to ask about disclosures of personal information to third parties for their direct marketing purposes; we make no such disclosures.
Colorado, Connecticut, Virginia, and other states with comprehensive laws
Residents of states including Colorado, Connecticut, Virginia, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas and Utah have the rights in section 8, including the right to appeal at section 9. Consent is required before we process sensitive data, and we do not process it in that capacity. Most of these laws exempt business-to-business and employment data; we apply the same standard to everyone regardless.
Nevada
Nevada residents may direct a covered operator not to sell certain covered information. We do not sell it; you may still submit a request to support@volvera.net.
Washington and Nevada consumer health data
We do not collect consumer health data through this website, and we do not use, sell or share it. Health information we encounter in client engagements is processed only as that client’s service provider under contract, and under a Business Associate Agreement where HIPAA applies.
Applicability
Some of these laws apply only above volume or revenue thresholds that we may not meet. Where a law does not apply to us we still honour the substance of these rights voluntarily. This is a commitment in this notice, not an admission that any particular statute governs us.
13Children
This site is aimed at businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18, and never knowingly sell or share the personal information of anyone under 16. If you believe a child has given us information, write to support@volvera.net and we will delete it.
14How we protect it
We encrypt personal information in transit and at rest, require multi-factor authentication on the systems that hold it, grant access on a least-privilege basis and review that access, separate client environments from one another, manage credentials in a secrets manager, log administrative activity, and assess vendors before we send them data. Our security practices are reviewed at least annually.
No system is perfectly secure, and we do not claim otherwise. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.
15Where it is processed
We are based in the United States and process personal information there, using providers whose infrastructure is located in the United States and, for some cloud and AI services, in the European Union. If you contact us from outside the United States, you are sending your information to a country whose data protection laws may differ from your own. Where a client engagement requires data to stay in a particular jurisdiction, we configure it that way and record it in the contract.
16Changes
We will post any revised version here and update the effective date at the top. If a change materially affects how we use information we already hold, we will give notice by email to the addresses we hold, or by a notice on the site, before the change takes effect.
Cookie & Tracking Notice
What this site stores on your device, and how to stop it.
Effective 28 August 2026
1Our position
This is a marketing site for a consultancy, not an advertising business. We run no advertising or retargeting cookies, no advertising pixels and no third-party ad networks, and we do not build cross-site profiles of visitors. The only things we set are what the site needs to work and, if enabled, a first-party measure of how many people read which page.
2What is set
Everything this site stores on your device, as at the effective date above.
Category
What it does
Duration
Consent
Strictly necessary
Serves the page, balances load, blocks abuse and keeps the site secure. Set by our hosting provider, not by us
Session
Not required
Analytics
None. We run no third-party analytics script on this site and set no analytics cookie. Our hosting provider produces aggregate traffic counts from server logs, which are not linked to you and are kept for 12 months
—
—
Preferences
None. The symptom picker and step tabs hold their state in memory only and are forgotten when you close the tab
—
—
Advertising
None set
—
—
If we later add a measurement tool, we will name it here with its cookie, host and lifetime before we switch it on, and it will respect Global Privacy Control from the first day.
3Fonts and other third-party requests
This site loads typefaces from Google Fonts. Doing so discloses your IP address to Google as a technical necessity of serving the file. No cookie is set by that request, and it is the only third-party request either page makes.
4How to control it
Global Privacy Control — the cleanest option. Turn it on in a browser or extension that supports it and we will disable non-essential analytics on that device automatically. Check your current status under Your Privacy Choices.
Browser settings — every major browser lets you block or delete cookies. Blocking strictly necessary items may break parts of the site.
Ask us — email support@volvera.net and we will exclude you.
Because we set no advertising cookies and do not sell or share personal information, we do not display a consent banner. If that changes, we will add one and update this notice first.
Terms of Use
The terms on which you may use volvera.net. These govern the website. Paid work is governed by a separate signed agreement.
Effective 28 August 2026
1Agreement
By using this site you agree to these terms. If you do not agree, do not use the site. If you are using it for an organisation, you confirm you have authority to bind that organisation, and “you” means both you and it. You must be at least 18.
2The site is information, not advice
Nothing on this site is legal, medical, financial, tax, regulatory or compliance advice, and nothing on it creates a consulting, advisory or professional relationship. We are not your lawyers, accountants or compliance officers. No engagement exists until both parties sign a written services agreement. Do not act on anything here without professional advice specific to your situation.
3The Funnel Read
The Funnel Read is offered free and without obligation on either side. Findings are our professional opinion on the information you give us in a short session; they are not a guarantee, a warranty, an audit or a certification, and they depend entirely on the accuracy and completeness of what you tell us. Any figures we put on a revenue gap are estimates. We give no assurance of any commercial outcome, and requesting one does not oblige either of us to go further.
4Our intellectual property
The site and everything in it — text, design, code, layout, graphics, the Volvera name and mark — is owned by us or our licensors and protected by intellectual property law. You may view, and print or download a copy for your own internal reference. You may not otherwise copy, republish, sell, sublicense or exploit it.
You may not scrape, crawl, harvest or use automated means to extract content from this site, and you may not use any content from it to train, fine-tune, ground or evaluate a machine-learning model, without our prior written permission. We expressly reserve all rights in respect of text and data mining. Building AI systems is our trade; we are not donating the description of it as training data.
5What you send us
Do not send us confidential information through this website or by unsolicited email. Anything you send before a confidentiality agreement is in place is not treated as confidential, and we accept no obligation of confidence in respect of it. If you send us feedback, ideas or suggestions, you grant us a perpetual, irrevocable, worldwide, royalty-free licence to use them without restriction, attribution or payment. You keep ownership of your own material; you confirm you have the right to send it and that it is lawful.
6Acceptable use
You must not use the site to break the law or infringe anyone’s rights; to introduce malware; to probe, scan or test its security or circumvent access controls; to overload or interfere with it; to impersonate anyone or misstate your affiliation; to collect other users’ information; or to reverse engineer any part of it. We may suspend access, remove material or take legal action if you do.
7Third-party links
Links to third-party sites are provided for convenience. We do not control them, do not endorse them and are not responsible for their content, security or privacy practices. Read their terms before you rely on them.
8AI outputs
Systems built with large language models and other machine learning can produce output that is wrong, incomplete, biased or fabricated, and they can fail in ways that are hard to predict. Any material on this site describing what such systems can do is a description of capability, not a promise of accuracy. Systems we build for clients are delivered with documented human oversight, and the client remains responsible for how output is used, for meeting the rules of their sector, and for the decisions they take. Do not use an AI system to make a legal, medical, financial or employment decision about a person without a human review step.
9Disclaimer of warranties
The site is provided “as is” and “as available”. To the fullest extent permitted by law we disclaim all warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, title and non-infringement, and any warranty that the site will be uninterrupted, secure, error-free or that its content is accurate or current. Some jurisdictions do not allow the exclusion of implied warranties, so parts of this section may not apply to you.
10Limitation of liability
To the fullest extent permitted by law, neither we nor our officers, employees or contractors are liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, revenue, data, goodwill or business opportunity, arising out of your use of this site, however caused and on any theory of liability.
Our total aggregate liability arising out of or relating to this site and these terms will not exceed the greater of US$100 and the total amount you paid us in the twelve months before the claim arose. [Counsel: confirm this cap against your professional indemnity and cyber cover before publishing.]
Nothing in these terms excludes liability that cannot lawfully be excluded, including for fraud, fraudulent misrepresentation, or death or personal injury caused by negligence. Some jurisdictions do not allow certain limitations, so parts of this section may not apply to you. Liability for paid engagements is governed by the signed services agreement, not by these website terms.
11Indemnity
You agree to indemnify and hold us harmless against claims, damages, losses and reasonable legal costs arising from your use of the site, your breach of these terms, or your infringement of a third party’s rights. We will notify you of any such claim and you may control the defence, provided you do not settle in a way that imposes an obligation on us without our written consent.
12Governing law and venue
These terms are governed by the laws of the State of [GOVERNING-LAW STATE — set this to your state of incorporation with counsel], without regard to its conflict of laws rules. Subject to section 13, the state and federal courts located in that state have exclusive jurisdiction, and both parties consent to that venue.
13Disputes
Read this section carefully. It affects how disputes are resolved and, if it stands, requires them to be brought individually rather than as part of a class.
Talk first
Before starting formal proceedings, email a written description of the dispute and the relief you want to support@volvera.net with “Dispute notice” in the subject line. Both parties agree to try in good faith to resolve it for 30 days. Most disputes end here. If you need to send that notice by post instead, ask us at the same address and we will give you a mailing address within 5 business days.
Arbitration
If that fails, any dispute arising out of or relating to these terms or the site will be resolved by binding individual arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before one arbitrator, seated in the governing-law state named in section 12 or, by agreement, conducted remotely, with judgment on the award enforceable in any court of competent jurisdiction. The Federal Arbitration Act governs the interpretation and enforcement of this section.
Exceptions
Either party may bring a claim in small claims court if it qualifies, and either may seek injunctive relief in court to protect intellectual property or confidential information.
Individual basis only
Claims must be brought individually. Neither party may bring a class, collective, consolidated or representative action, and the arbitrator may not consolidate claims or preside over any form of representative proceeding. Both parties waive any right to a jury trial. If this paragraph is found unenforceable in whole or in part, that part is severed and the affected claim proceeds in court.
How to opt out
You may reject this arbitration section by emailing support@volvera.net with the subject “Arbitration opt-out” within 30 days of first accepting these terms. Opting out costs you nothing and affects no other part of these terms.
[Counsel: arbitration and class-waiver clauses are heavily litigated and enforceability turns on state law and on presentation. Confirm this section or delete it and rely on section 12 alone.]
14Changes
We may revise these terms. The updated version takes effect when posted, with a new effective date. Continuing to use the site after that means you accept the change. If a change is material we will make it prominent rather than silent.
15General
If a provision is unenforceable, the rest stands and the offending provision is limited to the minimum extent necessary. Failing to enforce a right is not a waiver of it. You may not assign these terms; we may assign them in a merger, acquisition or sale of assets. Neither party is liable for delay caused by events beyond its reasonable control. These terms, with the Privacy Policy and the other notices on this page, are the entire agreement about the website. Where a signed services agreement conflicts with these terms, the signed agreement governs the work it covers.
AI & Client Data Statement
What happens to your data, and your customers’ data, once we start building. This is the document most buyers in regulated sectors actually need, and the one their procurement team will ask for.
Effective 28 August 2026
1Our role
When we design, build, host or operate a system for you, you are the controller and we are your service provider — a processor. You decide why the data is processed and broadly how. We act on your documented instructions and nothing else. We become a controller only for our own business records: your billing contact, our correspondence, our project notes.
This matters practically: your customers’ privacy rights are exercised against you, not against us, and we are contractually bound to help you answer them.
2The contractual floor
Every engagement runs on a signed services agreement with a Data Processing Agreement attached. The DPA commits us, at minimum, to the service provider terms the CCPA requires:
We will not sell or share personal information we receive from you.
We will not retain, use or disclose it for any purpose other than performing the services, or as permitted by law — and never for our own commercial purposes.
We will not combine it with personal information from other sources, except as the law permits.
We will not act on it outside the direct business relationship between us.
We will tell you promptly if we determine we can no longer meet these obligations, and you may stop and remediate the processing.
We will let you take reasonable steps to confirm we are using the data as agreed.
Where you are a HIPAA covered entity or business associate, we execute a Business Associate Agreement before any protected health information reaches us. We do not accept PHI without a BAA in place. Where other sector rules apply — GLBA, FERPA, state insurance or professional-conduct rules — we accommodate them in the contract. We do not give legal or compliance advice about your obligations; that is your counsel’s job.
3Model providers and training
We do not use your data, or your customers’ data, to train models. Not our own, not anyone else’s. Where we use third-party model providers, we contract on enterprise or API terms under which the provider does not train on submitted data, and we enable zero-retention or minimum-retention processing wherever the provider offers it.
Practically, that means: enterprise or business tier agreements rather than consumer accounts; training explicitly disabled; retention set to the shortest the provider supports; no client data pasted into a consumer chatbot by anyone on our team, ever. Where a provider cannot meet these terms for a capability you need, we tell you before we use them and you decide.
If an engagement genuinely requires fine-tuning on your data, that is a separate, explicit, written instruction from you, scoped to your own dedicated model, and the resulting weights are yours.
4Sub-processors
We use the categories of sub-processor below. Because the named vendors differ from one engagement to the next, the current named list for your engagement is attached to your DPA and forms part of it, and we will send the current list to anyone who asks: email support@volvera.net with “Sub-processor list” in the subject line and we will reply within 5 business days.
Categories of sub-processor. Named vendors are listed in your engagement’s DPA.
Category
Purpose
Where the data sits
Cloud infrastructure
Hosting and storage for delivered systems
Your own cloud account wherever the architecture allows; otherwise ours, scoped per client
AI model providers
Language and embedding models behind assistants
Enterprise or API tier with training disabled and retention minimised
CRM and sales tooling
Systems we configure inside your own tenant where possible
Your tenant, under your licence
Email and messaging
Outbound and lifecycle sequences
Your sending domain and your provider account
Observability and logging
Monitoring, error tracking, audit trails
Alongside the environment being monitored
We give you 30 days’ notice before adding or replacing a sub-processor that will handle your data, and you may object on reasonable data-protection grounds. Every sub-processor is bound to obligations no less protective than ours, and we remain responsible to you for their performance.
5Human oversight
We do not build systems that take a decision with a legal or similarly significant effect on a person — hiring, credit, insurance, housing, education, healthcare access, or the termination of a service — without a documented human review step with real authority to overturn the output. The system records what was recommended, what was decided, and by whom.
Where you use automated decision-making technology at a scale that engages California’s ADMT regulations, we will help you produce the pre-use notice, the access response and the opt-out route those rules require, and we maintain the technical documentation you need for a risk assessment. We do not decide for you whether the rules apply; take that to counsel.
6Minimisation, retention and return
We take the least data the use case needs, and we say so when a request would take more than the job requires. We prefer working in your tenant and against your systems rather than copying data into ours. Where a copy is unavoidable it is scoped, logged and time-limited.
On termination we return or delete your data, at your election, within 30 days, and delete it from backups on their normal expiry cycle, which does not exceed 90 days. We certify deletion in writing on request. Anything we must keep for legal reasons stays isolated and is used for nothing else.
7Security
Encryption in transit and at rest; multi-factor authentication on every system holding client data; least-privilege access reviewed quarterly; separate environments per client; credentials in a managed secrets store and never in code; administrative activity logged; endpoint protection and patching on all devices; background checks and confidentiality undertakings for personnel; vendor security review before onboarding; and an annual review of the whole set.
We hold no third-party security certification. We do not claim SOC 2, ISO 27001 or HITRUST, and we will say so in any procurement questionnaire. What we offer instead is the contractual commitments above, evidence of the controls on request, and a willingness to work inside your own certified environment rather than pulling data into ours.
8Incidents
If we become aware of a security incident affecting your data we notify you without undue delay and within 72 hours, with what we know, what we are doing, and what we recommend. We help you meet your own notification duties to regulators and to affected people. We do not notify your customers on your behalf unless you instruct us to in writing. We do not make public statements about your incident.
9Risk assessments and records
We maintain documented risk assessments for processing that involves sensitive personal information, profiling, automated decision-making for significant decisions, or the use of personal information as training data, and we update them within 45 days of a material change to the processing. We keep records of processing activities and make the parts relevant to your engagement available to you on request.
10Your responsibilities
The division of labour is worth stating plainly, because most failures happen on this line:
You establish the lawful basis for the processing and give your own customers the notices they are owed.
You confirm you have the right to give us the data you give us.
You respond to your customers’ rights requests; we give you the tooling and the answers to do it.
You decide what the system is used for, and you own the decisions it informs.
You tell us before sending any category of data the contract does not already cover — particularly health, financial, biometric or children’s data.
11Where processing happens
Processing takes place in the United States, in the regions listed in your contract. If your data must remain in a particular jurisdiction, tell us at scoping and we will configure it that way and record it. Onward transfers by sub-processors are covered by their contracts with us.
Your Privacy Choices
Every right described in the Privacy Policy, with the button that actually exercises it. No account required, and no charge.
Effective 28 August 2026
1Make a request
Choose the one that fits. Each opens an email to our privacy address with the subject pre-filled — you only need to send it. If email is not workable for you, the alternatives in section 5 reach the same place.
Do Not Sell or Share My Personal Information
We do not sell personal information and we do not share it for cross-context behavioural advertising. This link is provided so the choice is available to you regardless, and so your preference is on record with us.
Limit the Use of My Sensitive Personal Information
We do not collect sensitive personal information to infer characteristics about you, and we use what little we hold only to deliver the service you asked for — a use the law does not require us to limit. The choice is offered anyway.
Ask what we hold about you, where it came from, who we disclosed it to and why — or ask for a portable copy in a machine-readable format you can hand to someone else.
We will delete what we hold and direct our service providers to do the same, keeping only what a legal obligation, an active contract or a live dispute requires us to keep. We will tell you what we kept and why.
Every email we send carries an unsubscribe link that works immediately. Use this if you would rather tell us directly, or if you never signed up in the first place.
Or copy the address and write to us however you prefer:
2Global Privacy Control
A Global Privacy Control signal is an opt-out preference your browser sends automatically to every site you visit. We honour it as a valid opt-out of sale and sharing, and as a request to disable non-essential analytics on that browser. You do not need to be identified to us for it to work, and we do not require you to create an account or take any further step.
Checking your browser for a Global Privacy Control signal…
Because the signal is tied to a browser rather than to a person, it applies to the device you are reading this on. If you use several browsers or devices, enable it on each. Clearing your cookies may clear the record of it, in which case the signal will simply be read again on your next visit.
3What happens after you send a request
We acknowledge receipt within 10 business days and tell you how we will handle it.
We verify that the request comes from you, using information we already hold. We ask for the minimum needed, and we do not create a new account or collect new identifiers in order to verify you.
We respond substantively within 45 calendar days. If the request is genuinely complex we may extend once, by up to a further 45 days, and we will tell you before the first period runs out.
If we decline, we say so in writing, give our reason, and tell you how to appeal.
There is no fee. We will only charge, or refuse, if a request is manifestly unfounded or repetitive — and we will explain why in writing if we ever do.
4Authorised agents
Someone may make a request for you. We will ask for written permission signed by you, and we may contact you directly to confirm it. A valid power of attorney removes that step. Agents acting for California residents must also be registered with the California Secretary of State where the law requires it.
5Appeals and other routes
If we refuse a request, you may appeal by replying to our decision or writing to support@volvera.net with “Privacy Appeal” in the subject line. We will review and respond within 45 days, in writing, with our reasoning. If we still say no, we will give you a working link to submit a complaint to your state Attorney General — several states require that, and we do it regardless of which state you are in.
We are a remote team and operate by email rather than by phone or post, so support@volvera.net is the fastest route and reaches a person, not a queue. If email is not workable for you — or if you need this page or the request process in an alternative format such as large print, plain text or a read-aloud walkthrough — say so at that address and we will arrange it, including a callback or a postal exchange where that is what you need. See Accessibility below.
We will not retaliate. Exercising any of these rights will not cost you a service, a price, a quality of service or a level of access. If you think it has, tell us and we will fix it.
Accessibility
What we have built for, what we know is imperfect, and how to tell us when it fails you.
Effective 28 August 2026
1Our commitment
We aim to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 at Level AA. We treat that as a floor rather than a finish line, and we test against it when we change this site. Where the guidance and real use diverge, we follow real use.
2What that means in practice
Every interactive element is reachable and operable by keyboard alone, with a visible focus indicator that is never suppressed.
Text meets or exceeds the 4.5:1 contrast ratio against its background; large text and interface components meet 3:1.
Headings are properly nested so a screen reader can navigate the page by structure, and landmarks are marked up rather than implied by styling.
Images that carry meaning have text alternatives; images that are purely decorative are hidden from assistive technology instead of announced as noise.
Motion respects your system setting. If your operating system requests reduced motion, animation and parallax are switched off — not merely slowed.
Colour is never the only way information is conveyed.
The page reflows without horizontal scrolling down to 320 pixels wide, and remains usable at 200% zoom.
3Known limitations
Stating these is more useful than claiming perfection:
Third-party embeds and any externally hosted booking or scheduling tool are outside our direct control. We choose accessible vendors where we can and press the ones we cannot replace.
Documents we publish for download — particularly older PDFs — may not be fully tagged. Ask and we will supply an accessible version.
Some data tables require horizontal scrolling on very narrow screens. The content is complete and reachable; the ergonomics are not ideal.
4Alternative formats
Any document on this page — the Privacy Policy, the Terms, the AI & Client Data Statement — is available in large print, plain text or another format you need, at no cost. Ask and we will send it. If a barrier on this site prevents you from exercising a privacy right, tell us and we will process the request through whatever channel works for you.
5Feedback
If something here does not work with your assistive technology, we want the specifics: the page, what you were trying to do, and the browser and assistive technology you were using. Write to support@volvera.net with “Accessibility” in the subject. We aim to acknowledge within 5 business days and to propose a fix or a workaround with it.
Contact & Complaints
Who to write to, what to expect back, and where to go if we do not resolve it.
Effective 28 August 2026
1Reaching us
We are a small remote team and we run on email. One address reaches all of it — support@volvera.net — and the subject line routes it to the right founder. Every row below is the same inbox with a different subject; use whichever fits and we will sort it out at our end.
All routes are monitored on business days, 9am to 6pm US Eastern Time.
Volvera is a United States–based operating team of three co-founders. We work remotely and hold no public office, so we do not publish a street address or a switchboard number on this page — a listed address we do not staff would be worse than none.
If you need to serve a formal legal notice or a DMCA notice by post, email support@volvera.net with “Legal Notice” in the subject line and we will supply a mailing address for service within 5 business days. We will not use the absence of a published address to avoid or delay a notice, and we will not argue that a notice sent to this address was not received. A DMCA notice sent to that address is also treated as received on the day it arrives, so nothing about this arrangement shortens your rights.
2Who is accountable
Privacy questions are owned by the Volvera founding team — Ethan Leeds, Adi Gold and Benjamin Jones — and in practice by whichever of us takes the request; there is no support layer to get past. Between us we own the privacy programme, the risk assessments and the sub-processor register. We are not currently required to appoint a statutory Data Protection Officer or a US privacy representative; if that changes, this section changes with it and the appointee is named here by name and address.
3Complaining to us first
We would rather hear it than read it in a regulator’s letter. Tell us what happened, what you want done about it, and how to reach you. We will acknowledge within 5 business days, investigate, and give you a written answer with our reasoning within 30 days. If it will take longer than that, we will tell you why and when to expect it.
4Complaining to a regulator
You may complain to a regulator at any point, whether or not you come to us first. Nothing on this page removes that right, and we will not treat it as a breach of any agreement between us.
California. The California Privacy Protection Agency and the California Attorney General both accept consumer complaints.
Other states. Comprehensive privacy laws are enforced by the state Attorney General. Your state’s office publishes a consumer complaint form.
Federal. The Federal Trade Commission accepts reports about unfair or deceptive practices at reportfraud.ftc.gov.
If we deny a rights request and you appeal unsuccessfully, we will send you the correct complaint link for your state with our decision, so you do not have to go looking for it.
5Changes to these documents
When we make a material change to any document on this page, we update the effective date, describe what changed in a short summary at the top of the affected document, and — where the law requires it or the change reduces your rights — give notice by email before it takes effect. Superseded versions are kept and available on request, so you can see what applied at the time of your dealings with us.
This page was last reviewed on 28 August 2026. We review it at least annually, and sooner whenever we change a tool, a sub-processor or the way we handle data.