Privacy Policy
How Virteffic collects, uses, protects and manages personal data
Virteffic Limited (“Virteffic”, “we”, “us” or “our”) respects the privacy of individuals whose personal data we process and is committed to handling personal data lawfully, fairly, transparently and securely.
This Privacy Policy explains how we collect, use, share, retain and protect personal data in connection with our business, our website, our professional support services, recruitment, employment and other interactions with Virteffic.
Our role: Depending on the circumstances, Virteffic may act as a controller of personal data for its own business purposes or as a processor acting on the instructions of a Client.
Where Virteffic processes personal data solely on behalf of a Client, the Client will generally determine the purposes for which that data is processed and will remain responsible for its obligations as controller.
1. About this Privacy Policy
This Privacy Policy provides information about the personal data Virteffic processes and the rights available to individuals under applicable data protection legislation.
Applicable legislation may include the Data Protection (Jersey) Law 2018, the Data Protection Authority (Jersey) Law 2018, the Data Protection (Bailiwick of Guernsey) Law 2017 and other applicable privacy and data protection laws (“Data Protection Laws”).
This Privacy Policy should be read together with any specific privacy information provided in connection with a particular service, recruitment process, employment relationship or other activity.
2. Who we are
Virteffic Limited provides governance, company secretarial support, board support, minutes and meeting support, administration, governance reviews, Board Effectiveness Reviews, training and related professional support services.
Virteffic Limited is registered with the Jersey Office of the Information Commissioner.
References in this Privacy Policy to “Client” mean an organisation or person receiving services from Virteffic.
3. Data protection governance
Virteffic maintains a data protection governance framework designed to support compliance with applicable Data Protection Laws and the responsible management of personal data.
Virteffic has appointed a Data Protection Lead responsible for day-to-day data protection management and oversight. Strategic oversight of data protection is provided by the Managing Director.
Virteffic’s data protection arrangements include policies, procedures, training, information security controls, data retention arrangements, incident-management procedures and periodic review of its data protection framework.
Data protection enquiries may be sent to our dedicated data protection mailbox at DPO@virteffic.com.
4. Scope
This Privacy Policy may apply to personal data relating to:
- Clients and prospective Clients;
- directors, officers, company secretaries and board or committee members;
- employees, workers and other members of Client organisations;
- meeting participants;
- shareholders, investors and other stakeholders whose information appears in Client materials;
- suppliers, professional advisers and business contacts;
- Virteffic employees and other team members;
- job applicants and prospective team members;
- training attendees and event participants;
- website visitors;
- people who communicate with Virteffic; and
- other individuals whose personal data is processed in connection with our business or Services.
5. Personal data we may collect
The personal data we process will depend on the nature of our relationship with you and the relevant Services or activity. It may include:
- name, title and contact details;
- job title, employer and professional information;
- correspondence and communications;
- meeting attendance, contributions, actions and decisions;
- information contained in board packs, committee papers and governance records;
- meeting recordings, transcripts and notes;
- information contained in governance reviews and Board Effectiveness Reviews;
- action trackers, governance reports and related records;
- identification and due diligence information where required;
- financial, billing and payment information;
- training and event information;
- recruitment, employment and professional history;
- qualifications, references and background information;
- performance, attendance, payroll and other employment-related information;
- technical information such as IP address, browser, device and website usage information;
- information provided through social media or online interactions; and
- any other personal data reasonably necessary for the relevant purpose.
6. Special category and sensitive personal data
In some circumstances Virteffic may process special category or otherwise sensitive personal data.
This may include information concerning health, employment matters, disciplinary or grievance matters, diversity information, criminal allegations or convictions, political opinions, trade union membership or other sensitive matters which appear in meeting materials, governance records, HR information or other documents provided to us.
Virteffic will process such information only where there is an appropriate lawful basis and, where required, an additional legal condition permitting the processing.
Where Virteffic acts as a processor, the Client remains responsible for establishing the lawful basis and any additional condition required for the Client’s processing of such information.
7. How we obtain personal data
We may obtain personal data:
- directly from you;
- from a Client or prospective Client;
- from board packs, committee papers, governance records and corporate documents;
- from governance reviews, Board Effectiveness Reviews, questionnaires and interviews;
- from meeting recordings, transcripts and notes;
- from employers, colleagues, advisers or other meeting participants;
- through emails, telephone calls, meetings and other communications;
- through our website, enquiry forms and online services;
- through recruitment or employment processes;
- from professional advisers or service providers;
- from publicly available sources;
- from social media and professional networking platforms; and
- from other third parties where lawful and appropriate.
8. How and why we use personal data
We may process personal data for purposes including:
- providing and administering our Services;
- preparing minutes, governance records and other Deliverables;
- supporting boards, committees and governance teams;
- conducting governance reviews and Board Effectiveness Reviews;
- preparing action trackers, governance reports and related records;
- providing training and professional development;
- communicating with Clients, prospective Clients and business contacts;
- responding to enquiries;
- managing Client relationships and contracts;
- billing, accounting and financial administration;
- business development and marketing;
- recruitment and workforce management;
- managing our employees and team;
- operating and improving our website and systems;
- information security, fraud prevention and incident management;
- meeting legal, regulatory, insurance and professional obligations;
- establishing, exercising or defending legal claims;
- maintaining business records; and
- other purposes which are compatible with the reason the information was collected.
9. Lawful bases for processing
The lawful basis used will depend on the particular processing activity. Virteffic may rely on one or more of the following:
| Lawful basis | Examples of when it may apply |
|---|---|
| Performance of a contract | Where processing is necessary to enter into or perform a contract with an individual. |
| Legitimate interests | Managing our business, providing professional support services, maintaining Client and business relationships, improving our Services, protecting our systems and communicating appropriately with business contacts. |
| Legal obligation | Where processing is necessary to comply with applicable legal, regulatory, tax, employment, data protection or other obligations. |
| Consent | Where consent is appropriate and required, including certain marketing or optional activities. |
| Legal claims or other applicable legal conditions | Where processing is required to establish, exercise or defend legal rights or where another lawful condition applies. |
Where we rely on legitimate interests, those interests may include operating and developing Virteffic, providing effective professional services, maintaining appropriate records, protecting our business and systems, managing relationships and communicating with relevant business contacts.
We consider whether those interests are proportionate and whether they are overridden by the rights and interests of the individual.
10. Client engagements: controller and processor roles
Virteffic may act in different data protection capacities depending on the circumstances.
Where Virteffic acts as controller
Virteffic acts as controller where it determines the purposes and means of processing personal data for its own business activities. Examples may include Client relationship management, billing, recruitment, employment, marketing, website administration, information security and the management of our own legal and business obligations.
Where Virteffic acts as processor
Where Virteffic processes personal data solely on behalf of a Client and in accordance with the Client’s instructions, Virteffic will generally act as processor and the Client will generally act as controller.
In those circumstances, the Client remains responsible for matters including determining the purpose and lawful basis of processing, giving any required privacy information to individuals and ensuring that the disclosure of personal data to Virteffic is lawful.
Virteffic’s processor obligations are also addressed in its applicable contractual arrangements with Clients.
Joint controllers
Where Virteffic and another organisation jointly determine the purposes and means of a particular processing activity, the parties will address their respective responsibilities as required by applicable Data Protection Laws.
11. Meetings, recordings, transcripts and governance records
As part of its governance support services, Virteffic may process personal data contained within board papers, committee documentation, governance reviews, Board Effectiveness Reviews, action trackers, governance reports, meeting notes, recordings, transcripts, minutes and related records.
Where a Client records a meeting or provides Virteffic with a recording, transcript or other meeting information, the Client is responsible for ensuring that the recording, collection, disclosure and processing of that information is lawful and that meeting participants have received any privacy information or notices required by applicable law.
Virteffic may use recordings, transcripts, meeting papers, previous minutes, notes and other relevant source materials to support preparation and review of minutes and other Deliverables.
Recordings, transcripts and automated outputs may contain errors or omissions. Where incorporated into a Virteffic Deliverable, such materials remain subject to appropriate professional review having regard to the agreed scope of the Services.
12. Technology and artificial intelligence
Virteffic may use approved technology, automation, transcription tools and artificial intelligence-assisted systems (“AI Tools”) in connection with its Services and business activities.
Virteffic operates a controlled and human-led approach to AI. The use of AI Tools is governed by internal policies, procedures, access controls, information security requirements and quality assurance processes.
Virteffic’s primary approved enterprise AI environment is Microsoft Copilot within its Microsoft 365 environment. Virteffic may approve other technology from time to time following appropriate consideration of privacy, confidentiality, security and risk.
Virteffic does not permit members of its team to input Client confidential information into unapproved public or consumer AI tools.
AI Tools may assist with initial drafting, transcription, summarisation, document comparison, structuring, categorisation, consistency checks and other preparatory or administrative activities.
AI does not replace professional judgement. AI-assisted content incorporated into a Deliverable issued by Virteffic remains subject to reasonable and proportionate human review, validation and quality assurance having regard to the nature, sensitivity, purpose and agreed scope of the relevant Services.
All minutes prepared by Virteffic are subject to human review and professional oversight before being issued to the Client as a Virteffic draft.
Where a Client has agreed specific restrictions concerning AI, technology providers, recording, transcription, data location, access or processing, Virteffic will apply those requirements in accordance with the relevant contractual arrangements.
13. Who we may share personal data with
Virteffic does not sell personal data.
Where lawful and appropriate, personal data may be shared with:
- Clients and relevant Client personnel;
- members of the Virteffic team;
- approved technology, cloud and AI service providers acting under appropriate contractual and security arrangements;
- IT, communications, collaboration and security providers;
- payroll, benefits and HR providers;
- professional advisers, accountants, auditors and insurers;
- recruitment providers;
- training and event service providers;
- regulators, supervisory authorities and data protection authorities;
- law enforcement bodies and courts;
- prospective purchasers, investors or advisers in connection with a legitimate corporate transaction; and
- other parties where disclosure is required or permitted by law.
Where Virteffic appoints service providers to process personal data on its behalf, it will apply appropriate contractual, confidentiality, security and data protection requirements where required by law.
14. International transfers
The technology and service providers used by Virteffic may involve personal data being accessed, stored or otherwise processed in jurisdictions outside Jersey, Guernsey, the United Kingdom or the European Economic Area.
Where an international transfer requires specific protection under applicable Data Protection Laws, Virteffic will use an appropriate lawful transfer mechanism or other permitted safeguard.
The precise arrangements may vary according to the relevant service provider, technology and Client requirements.
15. Information security and confidentiality
Virteffic maintains technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration or disclosure.
Virteffic maintains Cyber Essentials certification and applies a range of technical and organisational security controls, including multi-factor authentication, access-management controls, encryption, security monitoring, device management and information security training.
Virteffic operates in accordance with strict confidentiality requirements and professional standards. Access to Client and personal information is restricted to authorised personnel who require access for legitimate business purposes.
Virteffic also maintains internal policies and procedures relating to information security, data protection, access management, incident management, technology and responsible AI use.
No system or security measure can guarantee complete security. Virteffic therefore maintains procedures designed to identify, manage and respond to information security incidents.
16. Data retention
Virteffic retains personal data only for as long as reasonably necessary for the purposes for which it was collected and to meet applicable legal, contractual, regulatory, insurance, tax, employment, dispute-management and operational requirements.
Virteffic maintains and periodically reviews a data retention schedule which sets out retention periods for key categories of information.
Retention periods vary according to the nature of the information, the purpose for which it is held, relevant contractual arrangements and applicable legal requirements.
In determining an appropriate retention period, Virteffic may consider:
- the nature and sensitivity of the information;
- the purpose of processing;
- the duration of the relevant Client or employment relationship;
- legal limitation periods;
- regulatory, insurance and professional requirements;
- the possibility of complaints, disputes or claims;
- information security considerations; and
- whether the information can appropriately be deleted or anonymised.
Where Virteffic acts as processor, deletion or return of Client personal data will also be governed by the relevant contractual arrangements and applicable law.
17. Your data protection rights
Depending on the circumstances and applicable law, you may have rights including:
- the right to be informed about processing;
- the right to access your personal data;
- the right to request correction of inaccurate information;
- the right to request erasure in certain circumstances;
- the right to request restriction of processing;
- the right to object to certain processing;
- the right to data portability where applicable;
- rights relating to automated decision-making where applicable; and
- the right to withdraw consent where processing is based on consent.
These rights are not absolute and may be subject to legal exemptions or limitations.
To exercise a right, please contact DPO@virteffic.com. We may need to verify your identity before responding.
Where Virteffic processes your personal data solely as processor for a Client, we may refer your request to the relevant Client as controller.
18. Marketing communications
Virteffic may communicate with Clients, prospective Clients and professional contacts about Services, events, training, insights or other matters which we reasonably believe may be relevant to them.
Depending on the circumstances, marketing may be based on consent, legitimate interests or another lawful basis permitted by law.
You may opt out of marketing communications at any time by using the unsubscribe facility provided in the communication or by contacting info@virteffic.com.
Opting out of marketing will not prevent Virteffic from sending service-related, contractual, operational or other non-marketing communications where appropriate.
19. Cookies and website technologies
Our website may use cookies and similar technologies to operate correctly, remember preferences, understand website usage and support relevant functionality.
Further information about the cookies we use and the choices available to website visitors is set out in our Cookie Policy.
20. Personal data breaches
Virteffic maintains procedures for identifying, assessing, managing and responding to actual or suspected personal data breaches.
Where required by applicable Data Protection Laws, Virteffic will notify the relevant data protection authority, affected Clients and/or affected individuals within the applicable legal requirements.
Where Virteffic acts as processor, it will notify the relevant Client without undue delay after becoming aware of a personal data breach affecting personal data processed on the Client’s behalf, where required by applicable law or contract.
21. Children
Virteffic’s Services and website are primarily directed at organisations and adults acting in a professional capacity. We do not knowingly seek to collect personal data from children through our website for marketing purposes.
Personal data relating to children may nevertheless appear in Client materials or otherwise be processed where relevant to professional Services. Where Virteffic acts as processor, the Client remains responsible for ensuring that such processing is lawful.
22. Third-party websites and services
Our website and communications may contain links to third-party websites, platforms or services.
Virteffic is not responsible for the privacy practices or content of third-party websites or services which operate independently of Virteffic. You should review the relevant third party’s privacy information before providing personal data to them.
23. Changes to this Privacy Policy
Virteffic may update this Privacy Policy from time to time to reflect changes in our business, technology, legal requirements, regulatory guidance or data protection practices.
The current version will be published on the Virteffic website and the version number and “Last updated” date will be amended accordingly.
Where required by applicable law, or where we consider a change sufficiently significant, we may provide additional notice of the change by an appropriate means.
Changes to this Privacy Policy do not alter the lawfulness of processing which took place before the relevant change.
24. Contact and complaints
If you have any questions about this Privacy Policy, wish to exercise your data protection rights or have a concern about the way Virteffic has handled personal data, please contact our Data Protection Lead through:
Virteffic Limited
Norowsa, La Vallee de St Pierre,
St Lawrence, Jersey JE3 1EG
Data protection: DPO@virteffic.com
General enquiries: info@virteffic.com
We encourage you to contact Virteffic first so that we have an opportunity to consider and address your concern.
Jersey
If you remain dissatisfied and Jersey data protection law applies, you may contact the Jersey Office of the Information Commissioner.
Guernsey
Where the Data Protection (Bailiwick of Guernsey) Law 2017 applies, you may have the right to raise a concern or complaint with the Office of the Data Protection Authority in Guernsey.
You may also have the right to complain to another applicable supervisory authority depending on your location and the circumstances of the processing.
25. Notices
Formal notices relating to privacy, data protection or this Privacy Policy must be sent by email or recorded delivery.
Email notices shall be deemed received upon confirmation of transmission, provided that the sender has not received a notification that delivery has failed.
Virteffic Limited
Norowsa, La Vallee de St Pierre,
St Lawrence, Jersey JE3 1EG
Email: tess.price@virteffic.com
Data protection: DPO@virteffic.com
Privacy questions or requests?
If you have a question about how Virteffic handles personal data, wish to exercise a data protection right or want to raise a privacy concern, please contact us.
Virteffic Limited
Jersey, Channel Islands
Data protection: DPO@virteffic.com
General enquiries: info@virteffic.com
Virteffic Limited
Flexible governance resource, corporate governance and company secretarial support.
Frequently asked questions (FAQ)
Technology, access and security
Our services
We provide flexible governance resource for boards and governance teams, combining experience, structure and practical delivery.
Minutes and meeting management
Company secretarial support and secondments
Independent board effectiveness reviews
Virteffic Limited (Virteffic) is not regulated or licensed under the Financial Services (Jersey) Law 1998, as amended, and does not provide regulated financial services. Where regulated services are required, clients should engage an appropriately licensed service provider. Virteffic provides governance, company secretarial, board support, administration and related professional support services. Any work undertaken by Virteffic is provided in a support capacity only. Responsibility for reviewing, approving and implementing any work product remains with the relevant directors, company secretary, officers or authorised representatives of the client.