Legal

Privacy notice

Version 1.0 · 3 October 2026

In short. We found your name and work details in public sources. We use them only to contact you, one to one, about our CRA evidence service. We do not sell or share your data. We delete it 12 months after our last contact, or at once if you object.

Your right to object

You can object at any time to our use of your data for direct marketing (GDPR Art. 21(2)). It is free. You do not need to give a reason.

Reply "stop" to any of our messages, or email [email protected]. We will stop at once, delete your data and not contact you again.

1Who is responsible for your data

The controller is:

Chhabi Acharya, trading as Relvault
Imadol, Mahalaxmi, Lalitpur 44705, Nepal
Email: [email protected]

We do not have a data protection officer, because the law does not require one for our processing. We have not appointed a representative in the EU (GDPR Art. 27). Our processing is occasional and small in scale, so we rely on the exemption in Art. 27(2)(a). We will review this as Relvault grows.

2What data we hold

  • Your name.
  • Your work email address.
  • Your role or job title.
  • Your company and its country.
  • The source where we found these details, and the date.
  • Our messages to you, your replies, and whether you objected.

We do not collect sensitive data, such as data about health, religion or political views.

3Where we got your data

We did not get your data from you. We found it in these sources:

  • your company's website;
  • public exhibitor lists of trade fairs;
  • public profiles and organisation pages on GitHub;
  • your LinkedIn profile.

These sources are public or visible to members of the network. Our first message to you names the source that we used.

4Why we use your data, and our legal basis

Purpose. We use your data for one-to-one business contact about Relvault's service, which prepares evidence for the EU Cyber Resilience Act (CRA). We send a first message and at most two short follow-ups. We answer your replies and, if you agree, arrange a call. We write and send each message by hand. We do not use mass-mailing tools or automated sequences.

Legal basis. Our legitimate interest under GDPR Art. 6(1)(f). Recital 47 of the GDPR says that direct marketing can be a legitimate interest.

How we balance your interests and ours. Our interest is to offer a service to companies that the CRA affects. Your interest is your privacy and not getting unwanted messages. We think that the balance is fair for these reasons. We use only work details that are public. We contact only people whose role relates to product security, firmware or compliance. We send few messages, by hand. We do not sell or share your data. We keep it for a limited time. You can object at any time, free of charge, and we stop at once. You can ask us for more detail about this assessment.

Email rules in your country. We also follow the email marketing rules of the country where you work. Where those rules require consent before a business email, we do not email you without it.

5How long we keep your data

  • We delete your data 12 months after our last contact with you.
  • If you object, we delete your data at once.
  • After an objection, we keep only a do-not-contact entry: your email address, your name and company, and the date of your objection. We keep it so that we never contact you again.
  • If you become a client, a contract applies, and we will give you separate information.

6Who receives your data

We do not sell, rent or give your data to anyone. These service providers process data for us, only on our instructions:

  • Zoho Corporation (Zoho Mail) stores and sends our email. It stores the data in the United States, under its data processing agreement, which includes the EU Standard Contractual Clauses.
  • Cloudflare, Inc. hosts this website and our domain name system (DNS). Cloudflare is certified under the EU-U.S. Data Privacy Framework and also uses the EU Standard Contractual Clauses.

If we write to you on LinkedIn, LinkedIn processes those messages as a separate controller, under its own privacy policy.

7Processing in Nepal

We process your data in Nepal. Nepal is outside the EU and the European Economic Area (EEA). The European Commission has not adopted an adequacy decision for Nepal. This means that the EU has not formally found that Nepal's law protects personal data to the EU level. The GDPR still applies in full to our processing of your data (GDPR Art. 3(2)), and you keep all the rights in this notice.

8Your rights

Under the GDPR, you have these rights:

  • Access (Art. 15): ask what data we hold about you and get a copy.
  • Rectification (Art. 16): ask us to correct wrong data.
  • Erasure (Art. 17): ask us to delete your data.
  • Restriction (Art. 18): ask us to limit how we use your data.
  • Objection (Art. 21): object to direct marketing at any time. See the box at the top.
  • Portability (Art. 20): this right applies to processing based on consent or a contract. It does not normally apply here, but we will send you a copy of your data in a common format if you ask.
  • Complaint (Art. 77): you can complain to a data protection supervisory authority, especially in the EU or EEA country where you live or work. The European Data Protection Board lists all national authorities.

To use a right, email [email protected]. It is free. We reply within one month. If we are not sure who you are, we may ask you to confirm your identity.

9No automated decisions

We do not make decisions about you by automated means alone, and we do not build a profile of you (GDPR Art. 22).

10If you live in Switzerland

The Swiss Federal Act on Data Protection (FADP) also applies. You have the same rights as above. We disclose your data to Nepal and to the providers in section 6. The Swiss Federal Council has not listed Nepal as a country with adequate data protection. You can report a concern to the Federal Data Protection and Information Commissioner (FDPIC).

11This website

This website uses no cookies, no analytics and no tracking. It loads no external fonts or scripts.

Cloudflare hosts the website. To deliver the pages and to protect the site from attacks, Cloudflare processes technical data, such as your IP address, browser type and the time of your visit. Our legal basis is our legitimate interest in a safe and working website (GDPR Art. 6(1)(f)). We do not use these data to identify you.

12Changes to this notice

We will update this notice when our processing changes. The version and date are at the top of this page.

  • Version 1.0, 3 October 2026: first version.