Privacy notice

How Visionary Dynamics handles personal data submitted through this website.

Version 2026-09-draft-1.

Draft awaiting client approval. This notice describes what the website actually does, but it has not yet been reviewed or approved by Visionary Dynamics or by a qualified legal adviser. It is not a statement of legal compliance. The open points listed at the end must be settled before launch.

Who this notice is about

This notice covers the Visionary Dynamics website only. It does not cover data handled inside a client assignment, which is governed by the written terms of reference or contract for that assignment.

Questions about this notice can be sent to visionarydynamic1s@outlook.com, or to the firm at Accra, Ghana.

What this website collects

When you send a project enquiry

The enquiry form asks for:

  • your name;
  • your email address;
  • your organisation (optional);
  • the service area your enquiry concerns;
  • a summary of the project or decision;
  • the geography the work covers (optional);
  • an indicative deadline (optional).

Alongside your message, the site stores:

  • the date and time the enquiry was received;
  • a one-way keyed hash of your IP address, used only to limit automated and repeated submissions — the address itself is not stored;
  • a one-way keyed fingerprint of your email address and message, used only to detect an accidental duplicate submission;
  • your browser's user-agent string, used only to investigate abuse.

Please do not send personal data about other people, confidential procurement information or commercially sensitive material through this form. Use it to describe the decision you need to make; detail follows under the appropriate confidentiality arrangement.

When an administrator signs in

The administration area stores an account email address, a public display name, a hashed password, sign-in timestamps, a record of failed sign-in attempts and an audit trail of content changes. Those records also hold a one-way keyed hash of the IP address rather than the address itself.

Server and application logs

The application writes error logs to a private directory on the server. These can record the time, the page, the error and a keyed IP hash. Your web host may also keep its own server logs; that arrangement is listed as an open point below.

What this website does not do

  • There is no analytics or measurement service running on this site and none is configured.
  • There are no advertising or marketing trackers, and no tracking pixels.
  • There are no third-party embeds, and no third-party fonts or scripts: every font, stylesheet and script is served from this site's own domain.
  • There is no newsletter and no marketing consent bundled into the enquiry form.
  • Your enquiry is never sold, rented or used for profiling.

Why your data is used

Enquiry data is used to read, assess and reply to your enquiry, and to prepare a scoping note if the work is a fit. The abuse-control values described above exist to keep the form usable and to protect the site. Nothing you submit is used for any other purpose.

Who it is shared with

  • The people at Visionary Dynamics who handle enquiries.
  • The email provider the firm uses, when a notification of your enquiry is sent to the firm's own inbox. The specific provider is listed as an open point below.
  • The web hosting provider that runs the site and its database. Also an open point below.

Your data is not shared with anyone else unless the firm is required to do so by law, or you ask for it to be shared.

Storage in your browser

This site sets as little as possible in your browser. There are currently no optional or tracking cookies of any kind, so there is nothing optional to consent to. The only storage used is essential:

Essential storage used by this website
Name Purpose Lifetime
vd_session Keeps an administrator signed in and carries the security token that protects forms against cross-site request forgery. It is set only when you open a page that contains a form (Contact or Cookie Settings), when you submit a form, or when you use the administration area. Reading the rest of the site sets nothing. Until the browser is closed, or sooner if the session expires.
vd_consent Records a cookie choice, with the policy version it was given against. Only set when optional categories are configured and a choice has been made. 180 days.

You can review and change what is stored on the Cookie Settings page at any time.

How long it is kept

Enquiries are kept while they are live, and afterwards as a record of what was asked and what was offered. A specific retention period has not yet been set by the firm; it is listed as an open point below rather than invented here. You can ask for your enquiry to be deleted at any time using the contact details above.

How it is protected

  • Administrator passwords are stored only as a one-way hash, never as text.
  • Administration pages require authentication and are excluded from search-engine indexing and from public caches.
  • Every form that changes data is protected against cross-site request forgery.
  • Database queries use bound parameters, so submitted text cannot alter a query.
  • Uploaded images are re-encoded, stripped of embedded metadata, and served from a location that cannot execute code.
  • Database and email credentials are held in server configuration outside the web root and are never editable through the dashboard.

No website can promise that data will never be compromised. What is described above is what has actually been implemented.

Your rights

Depending on where you are and which law applies, you may have the right to ask for a copy of the personal data held about you, to have it corrected, to have it deleted, to object to its use, or to complain to a supervisory authority. To exercise any of these, write to the contact address above and say what you would like done. The firm will respond and explain what it can and cannot do.

The specific statutory framework, the named data controller and the relevant supervisory authority are confirmed as part of the open points below, rather than asserted here without confirmation.

Open points, still to be confirmed

These are recorded so that nothing in this notice is guessed. They are tracked in the project handover document and must be settled before this notice is approved:

  • the registered legal entity and the named data controller;
  • the applicable data-protection law, the registration position and the supervisory authority;
  • the hosting provider and where the server and its backups are located;
  • the email provider used for enquiry notifications;
  • how long enquiries and logs are kept;
  • the postal address for written requests.

Changes to this notice

This notice is versioned. The current version is 2026-09-draft-1. If it changes in a way that affects how your data is used, the version changes with it.