Privacy Policy
What we collect through this site, why, who else touches it, and what you can ask us to do about it.
Effective 14 August 2026
1. Who we are
Volnaris Security LLC ("Volnaris", "we", "us") is a cloud security and compliance consultancy registered in Florida, United States, serving clients worldwide. For the personal data described here, we are the controller under the GDPR and the business under the CCPA/CPRA.
For any question about this notice or about your data, write to info@volnaris.com.
2. What this site collects
We collect personal data only where you deliberately give it to us, plus the technical data any web server necessarily records.
Contact form
Your name, company, email address, and the message you write.
Project brief form
Your name, company, email address, and the project details you provide — desired timeframe, project scope, any additional context, and the services and estimate you assembled on the pricing page.
Booking a consultation
Scheduling runs on Calendly, embedded on our contact page. When you book, Calendly collects your name, email address, chosen time, and anything you enter in its form, and passes it to us. Calendly operates under its own privacy notice and sets its own cookies within its frame.
Aggregate usage measurement
We use Cloudflare Web Analytics to see how many people reach each page. It sets no cookies, stores nothing on your device, and builds no profile or identifier for you — it cannot follow you to another site, and we cannot use it to single you out. What we get is counts: page views, referring sites, countries, device categories. If you block it, nothing on this site stops working.
Technical data
Our hosting provider records standard server information for every request: your IP address, the pages requested, timestamps, referring page, and your browser's user-agent string. This is used to deliver the site, keep it available, and defend it against abuse. Where our bot-protection challenge is active, it additionally assesses signals from your browser to distinguish people from automated traffic.
3. The assistant on this site
The chat window in the corner of the site is not a large language model and does not call one. It matches what you type against a fixed list of keywords and replies with pre-written text pointing you to the right page.
Everything it does happens inside your own browser. What you type into it is not transmitted to us, not sent to any third party, and not stored anywhere — including on your own device. Closing the tab discards the conversation entirely. We cannot read what you typed into it, and we keep no record that a conversation took place.
If we ever connect the assistant to a language model, the exchange would necessarily leave your browser, and we will update this notice — naming the provider, what is sent, and how long it is kept — before that change goes live. Until this section says otherwise, nothing you type into the assistant reaches us.
Please do not enter credentials, access keys, client names, or details of unremediated vulnerabilities into any field on this website, including the assistant. For anything sensitive we will agree a secure channel with you first.
4. What we do not do
Stated precisely, so you can hold us to it:
- We run no advertising or cross-site tracking analytics — no Google Analytics, no session recording, no heatmaps, no fingerprinting. The one measurement tool we use is described in section 2 and is cookieless: it counts pages, not people.
- We set no cookies of our own, for any purpose.
- We carry no advertising, and no advertising or social-media tracking pixels.
- We do not sell or share personal information, as those terms are defined by the CCPA/CPRA, and have not done so in the preceding twelve months.
- We do not use your data for automated decision-making or profiling.
- We do not use inquiries submitted through this site to train machine-learning models.
- Our typefaces are served from our own servers, so displaying this site does not disclose your IP address to a font provider.
Two honest qualifications. First, our hosting provider necessarily processes request data, including your IP address, in order to deliver the page to you at all — that is described in section 2. Second, if you use the embedded scheduler, Calendly sets cookies inside its own frame that we neither control nor read.
5. Why we process it, and on what basis
- To respond to you. When you submit a form or book a call, we use your details to reply and to discuss the engagement you asked about. Under the GDPR this is processing necessary to take steps at your request before entering a contract (Art. 6(1)(b)), and our legitimate interest in responding to business inquiries (Art. 6(1)(f)).
- To keep the site running and secure. Server logs and bot protection rest on our legitimate interest in operating a functioning, non-abused website (Art. 6(1)(f)).
- To meet legal obligations. Where we must retain records for tax or professional reasons, the basis is compliance with a legal obligation (Art. 6(1)(c)).
We do not ask for, and have no use for, special-category data through this website.
6. Service providers
We deliberately keep this list short, and we prefer providers who act only as transport rather than accumulating your data. Each is bound to process personal data only on our instructions.
- Hosting, delivery, bot protection and aggregate analytics — currently Cloudflare, Inc. Processes request data including IP addresses, and provides the cookieless page-view measurement described in section 2.
- Email delivery and mailboxes — currently Zoho Corporation. Our mailboxes run on Zoho Mail; form submissions are delivered through Zoho ZeptoMail, which acts as transport rather than storing your inquiry as a product.
- Consultation scheduling — currently Calendly LLC, and only if you choose to use the booking widget.
Named providers are those in use on the effective date above. We may change a provider within one of these categories, and if we do we will keep this section accurate. If we ever add a category — a hosted language model behind the assistant, for instance — we will add it here and describe it before it goes live, not afterwards.
To request the current list in writing, or to be told when it changes, email info@volnaris.com.
7. International transfers
We are based in the United States, and personal data you send us is processed there. Our providers also operate globally, so data may be processed in other countries where they maintain infrastructure.
Where personal data moves out of the European Economic Area, the United Kingdom, or Switzerland, that transfer is covered by an appropriate safeguard — in practice the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with any supplementary technical measures the provider applies, or certification under the EU–US Data Privacy Framework where the provider participates in it.
You can ask us which mechanism applies to a particular provider, and we will tell you.
8. When we disclose data otherwise
Outside the providers named above, we disclose personal data only in these circumstances:
- Where the law compels it — in response to a valid, legally binding demand from a court, regulator, or law-enforcement authority with jurisdiction over us. We review such demands, decline those that are overbroad or defective, and disclose no more than is required.
- To establish or defend legal claims, or to enforce our terms.
- To protect against imminent harm to the rights, safety, or property of any person.
- In a corporate transaction — if Volnaris is merged with or acquired by another entity, personal data may transfer as part of that transaction. The receiving entity would remain bound by commitments no weaker than those in this notice, and we would say so here.
Where we are legally permitted to tell you that a demand has been made for your data, we will.
9. How long we keep it
- Inquiries that do not become engagements — up to 24 months, so we can pick up a conversation you resume later.
- Inquiries that become engagements — for the life of the engagement, then as long as our tax and professional obligations require.
- Server and delivery logs — retained by our providers on their standard schedules, measured in days rather than months.
- Assistant conversations — never retained; see section 3.
Ask us to delete your data sooner and we will, unless we are legally required to keep it.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we relied on it.
If you are a California resident, you have the right to know what personal information we collect, use, and disclose and for what purpose; to delete it; to correct it; to opt out of its sale or sharing and of profiling; to limit the use of sensitive personal information; and not to be discriminated against or offered inferior service for exercising any of these. As stated in section 4, we do not sell or share personal information and we do not collect sensitive personal information through this site, so there is nothing to opt out of — but the right to ask remains, and you may exercise it through an authorized agent.
Residents of other US states with comparable privacy statutes have equivalent rights, and we handle those requests the same way.
To exercise any right, email info@volnaris.com. We will verify your request against the data we hold — usually by replying to the address that submitted it — and respond within the period the applicable law allows. We do not charge for this. If we decline a request, we will tell you why and how to appeal it.
If you are in the EEA, the UK, or Switzerland and believe we have handled your data improperly, you may complain to your national data protection authority. We would rather you told us first.
11. Cookies and local storage
We set no cookies of our own, for any purpose — our analytics is cookieless — and there is therefore no consent banner on this site.
The site stores one item in your browser's local storage — volnaris-theme, remembering whether you chose the light or dark appearance. It contains no personal data, never leaves your device, and is not used to identify you. Clearing your browser's site data removes it.
If you interact with the embedded Calendly scheduler, Calendly may set its own cookies within its frame, under its own policy. Our bot-protection challenge, where active, may store a short-lived token to avoid re-challenging you on every page; it is used to tell people from bots and not to track you across sites.
12. Security
Security is our profession, and we apply it to our own site.
- The site is served exclusively over HTTPS, with HSTS and preload, so a browser will not connect to it insecurely.
- A restrictive Content Security Policy permits no inline scripts, and framing of the site is refused outright.
- Form submissions travel over an encrypted connection to an endpoint we operate. They are screened for automated abuse, then delivered to our mailbox — they are not stored in a third-party form service, and no database of inquiries sits on this website.
- Submitted content is treated as untrusted input and neutralized before it is rendered anywhere.
- Access to our mailbox is restricted and protected by multi-factor authentication.
- Our mail domain is protected by SPF, DKIM, and DMARC, so mail claiming to come from us can be verified.
No transmission over the internet is ever entirely without risk, and we do not claim otherwise. Please do not send credentials, access keys, or detailed vulnerability information through this website; we will agree a secure channel with you first.
If a breach affecting your personal data occurs, we will notify the relevant supervisory authority and, where the law requires it, you — without undue delay.
13. Children
This site is aimed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this notice
If we change how we handle personal data, we will update this page and move the effective date above. Material changes — a new category of provider, a new purpose, a new retention period — will be described here before they take effect, not quietly after. Where the change requires your consent, we will ask for it.
15. Contact
Volnaris Security LLC
Florida, United States
info@volnaris.com
Security researchers: please see our security.txt, or write to security@volnaris.com.