What this site collects, and what happens to it.
Version 2.0 · Last updated 6 September 2026 · Reviewed every year · Next review 6 September 2027
I advise companies on information security, so it would be a poor look to be vague about my own. This page is short because the site does very little: it has no analytics, no advertising, no tracking cookies, and no login. There is one form, and this explains where it goes.
1. Who is responsible
Michael David William, trading as Veraeth Advisory, Kota Kinabalu, Sabah, Malaysia. For anything on this page, including a request to delete your data, write to michael@veraeth.com. It reaches me directly.
2. What is held
Everything on this page in one table. Each row is written out in full further down.
| What | Why I have it | What allows it | How long |
|---|---|---|---|
| What you type into the contact form: name, work email, and what you are being asked for. | To reply to you and to work out what an engagement would cost. | You sent it to me, as a step before we might do business. | 24 months. Six years after the end of an engagement if it becomes one. |
| If I wrote to you first: your name, job title, employer, company size and country, work email, and one thing I noted from your company's own site. | To send you one relevant business email about something that is likely your responsibility. | Legitimate interest, and I keep a written note of that reasoning. | For as long as I am doing this work, unless you ask me to clear it. |
| Your email address on a do-not-contact record, if you tell me to stop. | It is what stops you being written to a second time. | Your objection, which I have to act on. | Permanently, on purpose. |
| Engagement records, if you become a client. | Advisory records have to be retrievable if your own auditor asks about the work. | Our contract, and my own professional obligations. | The life of the engagement and six years afterwards. |
| Whether you chose light or dark mode. | To show you the site the way you left it. | Not personal data. It never leaves your browser. | Until you clear your browser data. |
3. What the contact form collects
The form asks for your name, your work email, and a description of what you are being asked for. Some people paste a security questionnaire or a contract clause into that box, so it can contain information about your company. Nothing else is collected: no IP-based profiling, no fingerprinting, no hidden fields.
I use it to reply to you and to work out what an engagement would cost. I do not sell it, share it for marketing, or add you to a mailing list. There is no mailing list.
4. Who else touches it
- Formspree receives the form submission and forwards it to my inbox. It is a US-based service acting on my instructions.
- Cal.com runs the booking page, and only if you choose to book a call. It sits on its own site, not on this one, and it receives the name, email address and answer you type into it so that it can put the call in both diaries. Nothing on this site loads anything from it, so if you never click through, it never sees you.
- Cloudflare serves the pages. It processes connection data such as your IP address to deliver the site and block abuse, as any web host does.
That is the complete list. Nobody else receives anything.
In particular, the typefaces are served from this site itself, not from Google Fonts or any other font service, so reading a page here does not hand your IP address to a third party. There are no analytics, no advertising tags and no embedded widgets either. If you want to check rather than take my word for it, open your browser's network tab: the only host you will see is this one.
5. If I wrote to you first
Some people reading this never filled in the form, because I emailed them. Here is that side of it, in full.
What I hold. Your name, your job title, the company you work for, roughly how big it is and which country it is in, your work email address, and one specific thing I noted from your company's own website, which is the reason I thought writing was worth your time. Nothing else: no home address, no personal email, no phone number.
Where it came from. A public business directory called Apollo, and your company's own website. I do not buy lists and nobody sold me your details.
Why. To send you one relevant business email about something that is likely your responsibility. UK and EU law allows this on a "legitimate interest" basis, and I keep a written note of that reasoning. Every email is sent to one named person at a time. Nothing tracks whether you opened it, and if you do not reply you will hear from me at most twice more and then never again.
How to stop it. Reply saying no, in whatever words you like. Your address then goes onto a permanent do-not-contact record and is never used again. I keep that record deliberately, because it is the one case where deleting your details would make things worse rather than better: it is what stops you being written to a second time. If you would rather I held nothing identifying at all, say so and I will clear your details and keep only an anonymous line noting that one contact happened, because the count of how many people I have approached is how I judge whether any of this is working.
6. How long it is kept
Enquiries that do not become engagements are deleted after 24 months. Enquiries that do become engagements are kept for the life of the engagement and for six years afterwards, because professional advisory records have to be retrievable if a client's own auditor asks about the work.
The outreach record described above works differently and it is fair to say so plainly. I keep it for as long as I am doing this, because the totals it holds are the only way to tell whether writing to people is worth anyone's time, and a do-not-contact entry is kept permanently on purpose. Either way, asking me to clear your details works and is answered the same way as any other request below.
7. Your choices
You can ask me for a copy of what I hold about you, ask me to correct it, or ask me to delete it. One email does it, and I will confirm when it is done. Depending on where you are, those rights come from the UK and EU GDPR, Malaysia's Personal Data Protection Act, or an equivalent local law; I apply the same answer either way rather than checking which one you fall under.
If you would rather not use the form at all, email me directly. Nothing on this site requires you to fill anything in to read it, including the thirty-five published documents.
8. Cookies
The site sets no cookies. It does store one item in your browser's own local storage: whether you chose light or dark mode. That never leaves your device and is not sent anywhere. Clearing your browser data removes it.
9. Changes
If this changes, the date and the version at the top change with it.
I also read this page once a year whether anything has changed or not, and the next date for that is at the top.