Privacy Policy
VRS Tangent is committed to protecting your privacy and safeguarding your personal data. This policy outlines how we collect, use, and protect the information you share with us.
Last updated: September 2026
Who We Are
VRS Tangent is a strategic advisory practice founded and led by Dr. Farhat Jummani, Ph.D., specializing in cybersecurity governance, ISO 27001/42001 compliance, and enterprise AI risk management. For the purposes of this policy, "we", "us", and "our" refer to VRS Tangent, acting as the data fiduciary for any personal information collected via this platform.
Information We Collect
We collect only the personal information that you voluntarily provide to us through direct inquiries, consultation bookings, or the contact form on our website. This may include:
- Full Name — to address you appropriately during communications
- Email Address — to respond directly to your service or advisory inquiries
- Phone Number — to coordinate follow-up consultation calls and meetings
- Company Name & size — to understand your organization's context and scope
- Service Interest & timeline — to tailor our advisory response
- Message Content — to evaluate your specific risk or compliance query
Please note: We do not utilize tracking cookies, behavioral analytics tools, or third-party advertising scripts on this website.
How We Use Your Information
Information you submit is processed exclusively for legitimate business purposes:
- To respond to your consultation requests or service inquiries
- To schedule, manage, and conduct advisory meetings
- To provide relevant professional information regarding VRS Tangent services
- To maintain an accurate archival record of professional correspondence
Your personal data will never be sold, rented, leased, or shared with third parties for commercial or marketing purposes.
Legal Basis for Processing
We process your personal data in accordance with applicable data protection legislation, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDPA) of India, relying upon the following legal bases:
- Consent — by submitting your details via our website, you provide explicit, affirmative consent for us to process your data for the stated purpose
- Legitimate Interests — to effectively manage business inquiries, evaluate prospective client engagements, and maintain professional communications
Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal, tax, or regulatory mandates. General inquiry records are reviewed and securely purged on a rolling 24-month basis unless an active professional engagement or ongoing correspondence supersedes this schedule.
Data Security Safeguards
Grounded in our core expertise as ISO 27001 lead auditors, we implement robust technical, physical, and organizational security measures designed to protect your data against unauthorized access, alteration, disclosure, or loss.
However, no method of transmission over the internet or electronic storage is entirely infallible. While we deploy commercially rigorous protocols to protect your information, we cannot guarantee absolute data security.
Third-Party Services & Links
This website is hosted on a secure web server. We do not integrate third-party analytics platforms (e.g., Google Analytics), advertising networks, or social media tracking pixels. The only external platform referenced is LinkedIn, which operates independently and is governed by its own respective privacy policy.
Your Data Rights
Subject to applicable laws, you possess specific rights regarding your personal data, including:
- Right to Access — request confirmation of whether we process your data and obtain a copy of the personal data held
- Right to Correction — request the rectification of inaccurate or incomplete data
- Right to Erasure — request the secure deletion of your personal data when no longer necessary
- Right to Withdraw Consent — withdraw your consent to data processing at any time
- Right to Object — object to processing activities based on legitimate business interests
To exercise any of these rights, please submit a request to vrstangent@gmail.com. We will review and respond to all valid requests within 30 days.
Changes to This Policy
We may amend or update this Privacy Policy periodically to reflect changes in legal mandates, regulatory frameworks, or our operational practices. Any modifications will be posted directly on this page with a revised "Last updated" date.
Contact Us
If you have any formal questions, grievances, or requests regarding this Privacy Policy or our data handling practices, please contact: