Privacy Policy
VRS Tangent is committed to protecting your privacy. This policy outlines how we collect, use, and safeguard the information you share with us.
Last updated: August 2026
Who We Are
VRS Tangent is a strategic advisory practice founded and led by Dr. Farhat Jummani, PhD, specialising in cybersecurity governance, ISO 27001/42001 compliance, and enterprise AI risk management. For the purposes of this policy, "we", "us", and "our" refer to VRS Tangent.
Information We Collect
We only collect personal information that you voluntarily provide to us through the contact form on our website. This may include:
- Full name — to address you appropriately
- Email address — to respond to your enquiry
- Phone number — for follow-up consultation calls
- Company name & size — to understand your organisation's context
- Service interest & timeline — to tailor our response
- Message content — to address your specific query
We do not use tracking cookies, behavioural analytics tools, or any third-party advertising scripts on this website.
How We Use Your Information
Information you submit is used exclusively for the following purposes:
- To respond to your consultation or service enquiry
- To schedule advisory calls or meetings as requested
- To provide relevant information about VRS Tangent services
- To maintain a record of professional correspondence
Your information will never be sold, rented, or shared with third parties for marketing purposes.
Legal Basis for Processing
We process your personal data on the following legal bases under applicable data protection law (including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, India):
- Consent — by submitting the contact form, you voluntarily provide your information
- Legitimate Interest — to respond to business enquiries and maintain client relationships
Data Retention
We retain your personal information only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law. Enquiry records are typically reviewed and cleared on a rolling 24-month basis unless an active engagement or correspondence is ongoing.
Data Security
We take data security seriously. Given our expertise in ISO 27001 information security management, we apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure.
However, no method of transmission over the Internet is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
Third-Party Services
This website is hosted on a standard web server. We do not integrate third-party analytics platforms (e.g., Google Analytics), advertising networks, or social media tracking pixels. The only external service referenced is LinkedIn, which is governed by its own privacy policy.
Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Withdrawal of Consent — withdraw consent to processing at any time
- Objection — object to processing based on legitimate interests
To exercise any of these rights, please contact us at vrstangent@gmail.com. We will respond within 30 days.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or the services we offer. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact: