Who controls the data
Eigenvector IT LLC, a limited liability company registered in the United States, is the controller for the personal data collected through eigenvector.group.
This notice covers the website. It does not cover personal data processed inside a client engagement. That data is governed by the master services agreement and its data processing agreement, under which the client is the controller and Eigenvector IT LLC is the processor, and under which the client selects the region where the data is stored and processed.
One address, and no other route
Every question, correction, deletion, objection or complaint under this notice goes to enquiries@eigenvector.group. There is no separate data protection mailbox and no second route.
Every enquiry is answered by a named person within one working day. A privacy request is an enquiry, and is acknowledged on the same terms.
What the enquiry form collects
The enquiry form has six fields.
- Your name
- Your organisation
- Your work email address
- Your telephone number, which is optional and is used only to arrange or hold the first call
- The enquiry type you select, which routes the message to the practice that would do the work
- Your message, up to 2,000 characters
Nothing else is captured. The form does not record your IP address, the page you arrived from, or how long you spent filling it in.
Do not put incident detail, credentials, patient records or other sensitive personal information in the form. For a live security incident, retained clients use the escalation channel agreed in their retainer; everyone else writes to enquiries@eigenvector.group and puts Incident first in the message.
What the server logs record
Every request to the site is written to a log: the IP address that made it, the date and time, the page requested, the response code, and the browser user agent string. The logs exist to keep the site available and to investigate abuse of it. They are not used to build a picture of an individual visitor and they are not joined to enquiry form data.
The briefing list
The Eigenvector Briefing is sent on the first Tuesday of each month. Subscribing asks for one field, an email address. That address is used to send the briefing and for nothing else. Every issue carries an unsubscribe link that takes effect immediately.
Why each item is held
- Enquiries and the correspondence that follows them: to answer the person who wrote to us, and to take the steps before a contract that a scoping conversation involves.
- Careers correspondence: to consider you for a role and to reply. It reaches the same address as every other enquiry.
- The briefing: because you asked for it. You can stop it at any time, without giving a reason.
- Server logs: to keep the site available and to investigate abuse of it.
Where the General Data Protection Regulation applies to what we do with your data, the bases are Article 6(1)(f) legitimate interests for enquiries and server logs, Article 6(1)(b) steps taken before entering a contract where the enquiry concerns buying work or a role, and Article 6(1)(a) consent for the briefing. The legitimate interests assessments are written down and sent on request.
How long the data is kept
- Enquiry form submissions and the correspondence that follows them, careers correspondence included: 24 months from the last contact, then deleted.
- Server logs: 30 days, then deleted on a rolling basis.
- Briefing subscriber addresses: until you unsubscribe. The address leaves the sending list immediately and the system within 30 days.
Deletion covers live systems and backups. A record deleted from a live system leaves the backup rotation within 30 days.
Where the data is held, and who else sees it
Enquiries are held in the United States for 24 months, then deleted. Server logs are kept for 30 days. Briefing addresses are held in the United States for as long as you stay subscribed.
Three categories of supplier can reach data collected here: the hosting provider, the email provider, and the provider that sends the briefing. Each is engaged under written data protection terms, assessed before appointment and reviewed each year. The current list of named suppliers is sent on request.
No data collected through this site is sold, rented, shared or used for advertising. No third-party analytics runs on any page. There is no advertising network, no social media pixel, no profiling and no automated decision-making.
One request does leave this site. The pages load the IBM Plex typefaces from Google's font servers, and that request carries your IP address and browser user agent to Google. It sets no cookie. It is named here, and in the cookie notice, rather than left for you to find in the network tab.
Your rights under United States state privacy law
California residents hold rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. Residents of Colorado, Connecticut, Virginia and Utah hold a comparable set under their own state statutes. The statutes differ in detail, and some give fewer rights than others. We honour the fullest version of the list below for anyone who asks, wherever they live.
- Know what personal information we hold about you, where it came from, and which categories of supplier can reach it
- Receive a copy of it in a portable format
- Correct information that is wrong or incomplete
- Delete information we have no continuing reason to hold
- Opt out of sale, of sharing for cross-context behavioural advertising, and of profiling
- Limit the use of sensitive personal information
- Exercise any of these without being treated differently for having done so
The fifth and sixth rights have nothing to act on here. We do not sell or share personal information, we run no targeted advertising and no profiling, and we do not collect sensitive personal information through this site. Rather than publish an opt-out control that changes nothing, we state the position.
Send the request to enquiries@eigenvector.group. It is acknowledged within one working day and answered within 45 days. Where a request is complex we may take a further 45 days, and we will say so in writing, with the reason, before the first period ends. There is no charge. We may ask one question that helps us find the right record and satisfy ourselves that it is yours, such as the date and subject of your enquiry. We do not ask for identity documents to answer a website request. An authorised agent may act for you with your written permission.
If we refuse a request, the refusal says why and how to appeal it. An appeal is a reply to that message, quoting the reference number. A member of the firm's leadership reviews the appeal and answers within 45 days.
Where the General Data Protection Regulation applies
Eigenvector IT LLC is a limited liability company registered in the United States, and this site is not directed at the European Union or the United Kingdom. Where someone there sends us an enquiry or subscribes to the briefing, we handle that data as controller and honour the rights the regulation gives: access, rectification, erasure, restriction, objection to processing carried out under legitimate interests, portability, and withdrawal of consent to the briefing. The route is the same address.
Where a client appoints the firm to process personal data belonging to people in the European Union or the United Kingdom, the client is the controller and the firm is the processor, and the terms are in the data processing agreement rather than in this notice.
Personal data collected through this site is stored in the United States, and engagement data is stored in the region the client selects. Where a transfer of European Union personal data to the United States is made, it runs under the European Commission standard contractual clauses of 4 June 2021, module two for controller to processor and module three for processor to processor. Where the data comes from the United Kingdom, the transfer runs under the international data transfer addendum to those clauses, issued under section 119A of the Data Protection Act 2018. A transfer risk assessment supports each and is reviewed each year.
If our answer does not satisfy you, you may complain to the data protection authority for the country you live in. We would rather have the chance to put it right first.
Security of this site
The site is served over TLS and the enquiry form submits over the same connection. Enquiry data sits in a system reachable only by named people, from managed devices, under privileged access controls. Access is reviewed quarterly.
Report a vulnerability in this site to enquiries@eigenvector.group. The policy is at /vulnerability-disclosure.html and the machine-readable version at https://eigenvector.group/.well-known/security.txt. We take no action against good-faith research.
Cookies
The site sets two strictly necessary cookies and nothing else. What they are, and why no consent banner appears, is set out at /cookies.html.
Changes to this notice
This notice is reviewed each quarter and whenever the site changes what it collects. The date at the top of the page is the date of the last change.