Privacy Notice

This Privacy Notice explains how Vesanta (operating at laventas.pro) collects, uses, stores and shares personal information in the context of executive coaching and leadership development services. We describe common scenarios — for example, when a business owner books a discovery call, when a senior leader participates in an assessment, or when we process billing — so you can see how data flows in practice and what controls are available. The policy reflects our obligations under Canadian privacy law and good practice for international clients.

2026/04/23 Vesanta, laventas.pro, 170 Eglinton Avenue East, Toronto ON M4P 1A6, Canada. Business ID: 982213787 170 Eglinton Avenue East, Toronto ON M4P 1A6, Canada [email protected]

Key Definitions

This section clarifies terms used in the policy and provides short practical examples. Each definition is followed by a scenario showing how the term applies to coaching engagements.

Personal data means any information that identifies or relates to an identifiable person. Example: a client’s name, company role, email and notes from a coaching session are personal data used to plan and track development work.
Processing covers any operation performed on personal data such as collection, storage, analysis and deletion. Scenario: recording coaching session goals in a secure client file and using them to generate a follow-up plan is processing.
A user is anyone who interacts with Vesanta services — clients, prospective clients, referral partners, and participants in assessments. For example, a CEO who books a leadership programme or an HR partner coordinating group coaching.
Service refers to Vesanta coaching, assessments, workshops and related administrative functions. Practical case: scheduling a 90-minute leadership debrief is a service activity that triggers certain data collection.
Cookies are small files placed on devices to support website functionality and analytics. Example: a cookie that remembers language preference or tracks anonymized page visits to improve booking flows.

Data We Collect

We collect data you provide directly, data generated through use of our services, and data obtained from third parties in specific cases. Below are grouped examples and practical scenarios showing typical items collected for coaching engagements and site use.

Data You Provide Directly

When you contact us, register for a programme, or complete an intake form, we collect the information necessary to deliver coaching services. Typical items include:

  • Contact details: name, email, phone number, professional title and employer (used to schedule sessions and confirm identity). Example: a founder provides a corporate email to receive session notes.
  • Professional background and role information: CV highlights, leadership responsibilities, and organizational context (used to tailor coaching scenarios and assessments).
  • Coaching intake responses: objectives, personal development goals, preferences for session timing and modality, and consent to assessments.
  • Billing and payment information provided to our payment processor (e.g., invoicing name, billing address, transaction records). We do not store full card details on our servers.
  • Session materials and feedback: assessment results, coaching homework, recordings or summaries when expressly agreed, and satisfaction feedback for continuous improvement.
  • Correspondence and support requests: emails, chat messages or uploaded documents relating to delivery, disputes or scheduling.

Automatically Collected Data

When you use our website or book services, certain technical and usage data are collected automatically to operate and improve the service. Examples and practical uses are listed below.

  • Device and browser information: device type, operating system, browser version and screen resolution used to optimize the booking experience.
  • Usage data: pages visited, session duration, and navigation paths to help identify friction points in scheduling and content delivery.
  • IP address and approximate location for fraud prevention and basic geolocation to display appropriate regional details.
  • Cookies and similar identifiers used for session management, preferences and analytics.
  • Error reports and diagnostics when a service fails, to enable timely technical fixes.
  • Interaction logs for client support, for example timestamped records of booking changes or rescheduled sessions.

Third-Party Data Sources

We may receive data from partners and service providers when that information is necessary to deliver services or complete transactions. Typical cases are listed below.

  • Payment processors and invoicing platforms that provide transaction confirmations and limited billing metadata.
  • Scheduling and video providers (calendar apps, video conferencing) that supply meeting times and attendance details.
  • Professional references or HR coordinators who share role descriptions or aggregated assessment inputs with client consent.

Why We Use Personal Data

We use personal data for clear operational reasons tied to service delivery and client support. Each purpose includes a practical example or scenario.

  • Service delivery: scheduling sessions, preparing materials, conducting assessments and delivering coaching recommendations. Example: using intake answers to design a role-play scenario.
  • Billing and administration: invoicing, payment reconciliation and managing subscriptions or plan changes.
  • Quality improvement and research: anonymized analysis of outcomes across cases to refine frameworks and tools.
  • Client communications: sending confirmations, session reminders and follow-up resources related to coaching engagements.
  • Legal and regulatory compliance: responding to lawful requests, maintaining records required by law and protecting legal rights.
  • Security and fraud prevention: detecting unauthorized use, protecting client accounts and maintaining secure systems.
  • Marketing and outreach with consent: sending newsletters, event invitations and case study requests to contacts who opt in.
  • Third-party coordination: sharing selected information with authorized partners (e.g., HR or assessment providers) when necessary for program delivery and with client approval.

Legal Basis for Processing

Depending on the jurisdiction and context, we rely on a combination of legal bases to process personal data. Examples below show which basis applies in common scenarios.

Cookies and Tracking

We use cookies to provide essential website functions, remember preferences and gather analytics data to improve user experience. Below is a short guide to cookie types and how to manage them.

Cookie types include session cookies (temporary, expire on browser close), persistent cookies (remember preferences across sessions), and third-party cookies used by analytics or integration providers.

Categories: essential (site functionality), preferences (language/timezone), analytics (usage measurement) and marketing (third-party tracking for ads). Example: an essential cookie keeps you logged into a secure client portal during a session.

You can manage cookies using browser settings, privacy extensions or by following our cookie banner controls on the website. Disabling certain cookies may affect functionality such as booking or saved preferences.

Cookie Policy

Sharing and Disclosure

We limit sharing to what is necessary to provide services, meet legal obligations or process payments. Practical sharing examples are listed below.

  • Service providers: scheduling, video conferencing, payment and assessment vendors who process data on our behalf under contract.
  • Professional advisors: legal, accounting and consulting firms assisting Vesanta on matters related to service delivery or compliance.
  • Affiliates and partners: when jointly delivering a programme or when we have clear client authorization to share information with an employer or HR partner.
  • Legal and regulatory requests: disclosure to comply with subpoenas, court orders or to protect safety and legal rights.
  • Business transfers: in the event of a sale, merger or reorganization, client data may be transferred subject to appropriate protections and notice.
  • Aggregated or anonymized data: used for research and case studies without identifying individual clients, except where explicit consent for a named case study is obtained.

International Transfers

We may transfer personal data to service providers located outside Canada when necessary for operations (for example, cloud hosting or payment processing). Transfers are selected to minimize privacy risk and are documented per our data handling procedures.

Where transfers occur, we apply safeguards such as contractual data protection clauses, vendor security assessments, and limiting the data transferred to what is necessary. For EU data subjects, standard contractual clauses or other lawful transfer mechanisms will be used as appropriate.

Data Retention

Retention periods are set according to the purpose of processing, legal obligations and the need to support client service continuity. The following practical retention rules apply.

Account records and core client files are retained for the duration of the coaching engagement plus a typical administrative period of up to seven years for professional record-keeping and potential legal requirements.

Communications such as emails, meeting notes and documented coaching agreements are retained to support service continuity and dispute resolution and are archived in accordance with our retention schedule.

Technical logs and backups are retained for operational and security reasons for a limited period (commonly 90–360 days) unless a specific incident requires longer preservation.

When retention periods expire or upon verified erasure requests, we remove or anonymize personal data, except where legal obligations require continued retention. Deletion is performed in a manner appropriate to the storage medium and sensitivity of the data.

Security Measures

We implement physical, technical and organizational measures to protect personal data. Measures include encrypted storage for sensitive data, role-based access controls, staff training on confidentiality, vulnerability management and an incident response plan. Security decisions are guided by practical risk assessments and case reviews.

  • Encryption in transit and at rest for client files and backups.
  • Role-based access controls, multi-factor authentication for administrative access and logging of privileged activity.
  • Regular staff training, vendor security evaluations and an incident response process with documented case handling.

Your Rights

Subject to applicable law, individuals have rights over their personal data. Below are typical rights and practical examples of how they apply to coaching engagements.

  • Access – obtain a copy of the personal data we hold about you, for example intake forms and session notes.
  • Rectification – correct inaccurate details such as job titles or contact information.
  • Erasure – request deletion of data where retention is not required for legal or contractual reasons.
  • Restriction – limit processing while a dispute is assessed, for example pause on marketing communications.
  • Portability – receive a machine-readable copy of data you provided, useful if you change providers.
  • Object – object to processing based on legitimate interest, such as profiling used for marketing.
  • Withdraw consent – revoke consent for specific processing such as recording sessions or marketing.
  • Lodge a complaint – contact a supervisory authority if you consider our processing unlawful; we will cooperate with lawful inquiries.

How to Exercise Your Rights

To make a rights request, contact [email protected] or send a letter to Vesanta, 170 Eglinton Avenue East, Toronto ON M4P 1A6, Canada. Include your name, contact details and a description of the request. We may require identity verification to protect confidentiality.

[email protected]

We aim to respond to verifiable rights requests within 30 calendar days. For complex requests we may extend the period by up to an additional 30 days and will inform you of the reason and expected timeframe.

GDPR and International Rights

If you are located in the EU or UK, you may have rights under GDPR in addition to those described above. Vesanta will process requests from EU/UK data subjects in line with GDPR requirements, including providing required information about processing activities and cooperating with supervisory authorities as necessary.

  • We collect personal data you provide when you request coaching, sign up for resources, or communicate with Vesanta. Typical data elements: name, business email, phone number, company role, organization size and billing information when applicable. Data is used to manage engagements, schedule sessions, and improve coaching programs through anonymized analysis of outcomes and scenarios.
  • We process data on lawful bases such as contract performance (delivering coaching services), legitimate interests (improving service delivery and conducting case study analysis), and where required, consent for marketing communications. For case studies and testimonials we seek explicit consent before publication and anonymize details where requested.
  • You have the right to access, rectify, restrict processing, request erasure, and obtain a portable copy of your personal data. For requests, Vesanta will verify identity and respond within a reasonable timeframe, providing practical next steps and any information needed to complete the request.
  • We retain client data for the term of active engagement and for a limited period afterward to support follow-up, legal compliance, and archival case review. Retention periods vary by data type; specific retention schedules are available on request and through our privacy contact channel.
  • Vesanta implements technical and organizational measures proportional to the data sensitivity, including encrypted storage for sensitive documents, access controls for coaching records, and regular review of subcontractor security practices. Access to client files is limited to coaches and authorized administrative staff.
  • If you disagree with our handling of your data you may raise a concern with our privacy contact. You also have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction. We document and review all privacy complaints and take corrective action where appropriate.

If you remain dissatisfied after contacting Vesanta, you can raise a concern with the Office of the Privacy Commissioner of Canada or the relevant provincial supervisory authority. We will provide details of the supervisory authority and guidance on how to escalate a complaint upon request.

Marketing Communications and Case Studies

We use contact data to send newsletters, event invitations, and curated leadership resources tailored to business owners and senior leaders. Content often includes anonymized case studies, scenario analyses, and practical frameworks drawn from real engagements. You can opt into specific content streams and we will respect your preferences.

Every marketing message includes a clear unsubscribe link. You can also contact [email protected] to update preferences or opt out of all marketing. Opting out will not affect transactional communications related to active coaching engagements.

Children and Minors

Vesanta’s services are designed for adults who are business owners or senior leaders. We do not knowingly collect or maintain personal data from children under 18. If we learn that we have collected data from a minor in error, we will take reasonable steps to delete it promptly and inform the requester of the corrective action.

Links to Third-Party Sites

Our website and resources may link to third-party platforms, assessment tools, or partner content. These external sites have their own privacy practices. Vesanta is not responsible for third-party policies or content. Before sharing personal data with a third party, review their privacy terms and security posture.

Policy Updates

We review and update this privacy information periodically to reflect operational changes, legal requirements, and improvements in practice. Material changes will be posted on the site with an updated effective date. Minor clarifications may be applied without prior notice when they do not adversely affect data subjects.