Last updated: 21 July 2026
This Privacy Policy explains how Relegia Holdings Inc (“we”, “us”) collects, uses, and protects information when you use our website and services.
Information we collect
We keep data collection to what we actually need to answer you and deliver our services.
- Information you give us. When you submit the contact form we receive your name, email address, phone number (optional), and the content of your message. If you email us or engage us for a project, we also receive whatever you choose to share in that correspondence.
- Client and project data. During an engagement we may process business data belonging to our clients, for example CRM records, data warehouse contents, or system credentials. We handle that data on our clients’ instructions and under the terms of the relevant engagement agreement.
- Technical information. Our hosting infrastructure records standard server logs, including IP address, browser type, referring page, and the time of the request. We also record the IP address of contact-form submissions for a short period in order to rate-limit abuse.
We do not collect special categories of personal data through this website, and we do not knowingly collect information from children.
How we use your information
- To respond to your enquiry and to follow up on it.
- To provide, manage, and support the services we have been engaged to deliver.
- To send service-related communications, such as project updates or changes to our terms.
- To keep the website and the contact form secure, including spam prevention and rate limiting.
- To meet our legal, accounting, and regulatory obligations.
We do not sell personal data, and we do not use the information submitted through this website for automated decision-making or profiling.
Legal basis for processing
Where data protection law such as the UK GDPR or the EU GDPR applies to our processing, we rely on the following bases:
- Consent for optional cookies and for any marketing communications you ask to receive. You can withdraw consent at any time.
- Performance of a contract when we process data in order to negotiate, agree, or deliver an engagement.
- Legitimate interests when we answer enquiries, secure our systems, and run our business, balanced against your rights and freedoms.
- Legal obligation when retention or disclosure is required by law.
Sharing and disclosure
We share personal data only where there is a clear reason to, and only with recipients bound by confidentiality and appropriate data-protection terms:
- Service providers that support our operations, such as website hosting, email delivery, and spam protection.
- Professional advisers, including accountants, auditors, and lawyers, where necessary.
- Authorities or third parties where disclosure is required by law, court order, or to establish or defend legal claims.
- A successor entity in the event of a reorganisation, merger, or sale of the business.
International transfers
We are established in the British Virgin Islands and work with clients and providers in a number of countries, so your information may be processed outside the country where you live. Where such a transfer involves personal data protected by the UK or EU GDPR, we put appropriate safeguards in place, such as standard contractual clauses or a transfer to a jurisdiction recognised as providing adequate protection.
Data retention
We keep personal data only for as long as it serves the purpose it was collected for:
- Contact-form enquiries that do not lead to an engagement: up to 24 months, then deleted.
- Client records and project correspondence: for the duration of the engagement and for as long afterwards as we need them for contractual, tax, and legal purposes.
- Server logs and rate-limiting records: short-term only, typically no more than 12 months.
When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), access controls on a need-to-know basis, authenticated email transport for form submissions, and confidentiality obligations for everyone who works with client data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we do review our controls regularly.
Your rights
Subject to the law that applies to you, you may have the right to:
- Request access to the personal data we hold about you.
- Ask us to correct data that is inaccurate or incomplete.
- Ask us to delete data where we no longer have grounds to keep it.
- Object to, or ask us to restrict, processing based on our legitimate interests.
- Receive a copy of data you provided to us in a portable format.
- Withdraw consent at any time, without affecting processing carried out before you withdrew it.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, write to finance@relegiaholding.com. We will respond within one month, and we may ask you to confirm your identity before we act on a request.
Where we process data on behalf of a client (for example while building or maintaining their CRM or data platform), we act as a processor. In that case please direct your request to that client, who is the controller, and we will support them in responding.
Cookies
See our Cookie Policy for details on cookies and similar technologies.
Changes to this policy
We may update this policy to reflect changes in our practices or in the law. The revised version takes effect when it is published on this page, and the “last updated” date above will tell you when that happened. If a change materially affects how we use your personal data, we will take reasonable steps to notify you directly.
Contact
For privacy questions, contact finance@relegiaholding.com. Relegia Holdings Inc, Quijano Chambers, P.O. Box 3159, Road Town, Tortola, British Virgin Islands.