Trust Centre
One place for everything that touches your data, your rights, and our compliance posture. The Trust Centre is the umbrella surface for VulaCap's privacy, security, and accountability documentation.
Privacy notice
How we process personal data collected through this website, under UK GDPR Articles 13 and 14. VulaCap acts as a controller for personal data processed in connection with website enquiries, course applications, learner administration, assessment records, and credential management. Where VulaCap processes personal data on behalf of a client as part of a client engagement, it does so under the applicable contract and data processing terms.
Cookies notice
This site uses essential cookies and similar technologies to function and to remember your preferences. Where optional analytics cookies are used, we ask for your consent before setting them. Marketing cookies are not used. You can change your preferences at any time using the Cookie preferences link in the footer.
Security and technical and organisational measures
VulaCap is building its security baseline with reference to ISO/IEC 27001:2022 controls and the UK GDPR requirement to implement appropriate technical and organisational measures (UK GDPR Article 32). VulaCap is not currently ISO/IEC 27001 certified. As we move into commercial operation, this section will publish:
- Encryption posture (in-transit and at-rest)
- Access control and authentication standards
- Hosting and data residency arrangements
- Business continuity and incident response posture
- Penetration testing and vulnerability management cadence
Certification standard alignment
The EMBED Ambassador™ and EMBED Practitioner™ credentials are being designed with reference to ISO/IEC 17024:2026 — the current international standard for bodies operating certification of persons (which replaced ISO/IEC 17024:2012). VulaCap is not currently accredited to ISO/IEC 17024 and no accreditation claim is made. Where any third party becomes the accredited certification body, that arrangement will be published here.
Service providers and sub-processors
The register below lists each third-party service that processes personal data on our behalf. We update it when providers change. When VulaCap acts as a controller, the third parties below are service providers and (where applicable) processors. When VulaCap acts as a processor for a client engagement, the same third parties may be sub-processors under the relevant contract.
| Provider | Nature of processing | Data categories | Location | Transfer mechanism (where applicable) |
|---|---|---|---|---|
| Netlify, Inc. (Delaware, USA) | Website hosting, edge content delivery, form submission processing, function execution for transactional email triggering | Form submission contents (name, email, organisation, role, interest, context, marketing-consent flag), IP address, technical request metadata, server logs | United States (primary edge: global Netlify Edge Network) | UK Addendum to the EU SCCs (Netlify DPA, current version) |
| Microsoft Corporation (Washington, USA) | Email and document infrastructure (Microsoft 365 — Outlook, OneDrive, SharePoint, Teams); identity and access management | Email correspondence content, attachments, calendar entries, document content, identity records, mailbox metadata | European Union (Microsoft EU Data Boundary commitments); some metadata and support data may be processed in the United States | UK Addendum to the EU SCCs (Microsoft Products and Services DPA / Data Protection Addendum); UK Extension to the EU-US Data Privacy Framework where applicable |
| GoDaddy.com, LLC (Arizona, USA) | Domain registration and DNS record hosting (vulacap.com and group domains) | Domain registrant contact details, billing data; no end-user personal data | United States | UK Addendum to the EU SCCs (GoDaddy DPA); the processing involves registrant data only, not website visitor data |
| Resend, Inc. (Delaware, USA) | Transactional email delivery (cohort application confirmations, DPO correspondence acknowledgements, system notifications) | Submitter name, submitter email address, email content of system-generated transactional messages | United States with EU region available for EU-resident submissions | UK Addendum to the EU SCCs (Resend DPA); UK Extension to the EU-US Data Privacy Framework where applicable |
Where personal data is transferred outside the UK, we rely on an appropriate transfer mechanism as set out in the table above and in our Privacy notice. Adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement (IDTA), and the UK Addendum to the EU SCCs all sit under UK GDPR Article 46.
This register is updated when providers are added, removed, or materially changed. Customers and partners with substantive engagement relationships will be notified of material changes before they take effect, where reasonably practicable. The Resend addition was made on 5 June 2026 ahead of confirmation-email roll-out.
Your rights as a data subject
Under UK GDPR Articles 13–22, you have the right to be informed, the right of access, rectification, erasure, restriction, data portability, the right to object, and the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects.
These rights are not absolute and may apply differently depending on the lawful basis for processing and the circumstances of the request. For example, the right to portability applies where the lawful basis is consent or contract and the processing is automated; the rights to erasure and restriction are conditional; and the right to object depends on the lawful basis or whether the processing is for direct marketing.
Where we rely on consent, you may withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact privacy@vulacap.com. We respond within one calendar month (UK GDPR Article 12(3)), with the right to extend by a further two months for complex requests — we will tell you within the first month if an extension applies.
Data Protection Officer
VulaCap has appointed Frederick Oberholzer as Data Protection Officer. This appointment is on a voluntary basis. The voluntary appointment of a DPO under UK GDPR Article 37(4) attracts the same statutory duties as a mandatory appointment under Articles 37–39 — including independence, no conflict of interest, direct reporting to the highest level of management, and the privacy contact role for individuals and the supervisory authority.
- DPO: Frederick Oberholzer
- Contact: privacy@vulacap.com
- Postal: Vula Capability Systems Ltd, registered office on Companies House register
Supervisory authority
If you believe we have not handled your personal data lawfully, you have the right to complain to a supervisory authority.
For UK matters, the supervisory authority is the Information Commissioner's Office (ico.org.uk).
For EU residents, you may complain to a supervisory authority in the Member State where you live, where you work, or where the alleged infringement took place.
We would, of course, appreciate the opportunity to address your concern first — please write to privacy@vulacap.com.
Incident and breach notification
Our incident response posture covers detection and triage, internal escalation, breach assessment methodology, and the process for notifying the ICO within 72 hours where a personal data breach meets the notification threshold under UK GDPR Article 33. Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, affected individuals will also be notified without undue delay under UK GDPR Article 34. Not every personal data breach is notifiable; each is assessed against the risk threshold the ICO sets out.
Compliance posture
VulaCap is building its commercial operation on the following baseline. Each item is labelled with its current status — mapped, planned, designed with reference to, or certified — so the position is unambiguous.
| Area | Standard / framework | Current status |
|---|---|---|
| Accountability | ICO Data Protection Audit Framework | Mapped to |
| Certification of persons | ISO/IEC 17024:2026 | Designed with reference to (not accredited) |
| Information security | ISO/IEC 27001:2022 controls | Mapped to (not certified) |
| Baseline cyber hygiene | NCSC Cyber Essentials | Mapped to (not certified) |
| Training delivery | ISO/IEC 29993:2017 (learning services outside formal education) | Mapped to |
Updates to this Trust Centre
This page is updated as new content is published, when policies are revised, or when the regulatory landscape changes materially. Each section carries its own “Last updated” date when populated.
Last updated: 5 June 2026