Privacy Policy for Drake Design Studio
Last Updated:
1. Introduction & Data Controller
Drake Design Studio is a registered trade name (handelsnaam) of Junovy, a Dutch eenmanszaak registered in Amsterdam, The Netherlands under Chamber of Commerce (KvK) number 71813977. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit drakedesign.studio or work with Drake Design Studio.
Junovy is the data controller responsible for your personal data under the General Data Protection Regulation (GDPR). Under Dutch law a handelsnaam is not a legal person and cannot be a controller; the legal entity behind Drake Design Studio is Junovy, the eenmanszaak with KvK 71813977.
Postal Address: [protected], The Netherlands
KvK Number: 71813977
Privacy Requests: the privacy request form
This policy covers drakedesign.studio. If you are a Junovy hosting or Business Suite customer, the processing attached to those services is described in the Junovy privacy policy, which covers the same controller.
2. Information We Collect
We collect information that you provide directly to us and information automatically collected when you use our website.
2.1 Personal Data You Provide
When you use our contact form or live chat, sign up for services, or communicate with us, we may collect:
- Full name
- Email address
- Phone number (if provided)
- Company name (if applicable)
- Message content and project details, such as the kind of work you are asking about
- The name you type as a signature on a form, and the fact and time you confirmed you had read this statement
- Any other information you choose to provide
If you open the live chat and send a message, we receive whatever you write there, along with any name or email address you choose to give. Chat conversations are kept for 2 years after the conversation ends (see data retention).
What the project intake form collects, and how long we keep it, is set out in the intake form section.
2.2 Automatically Collected Data
When you visit drakedesign.studio, our web servers write access logs containing:
- IP address
- Browser type and version
- Device information
- Pages visited
- Referring website
- Date and time of visit
The IP address is retained in these access logs for 90 days for security and troubleshooting, and is never used for user profiling or cross-site tracking. We do not correlate access-log IP addresses with any other data we hold. This is standard web server logging: there is no analytics product behind it, no advertising network, and no third-party tracker of any kind on this site.
2a. Intake Form Submissions
If you fill in our project intake form, this is what happens to what you send.
What we collect. Your answers to the form's questions about your project; the contact details you give (your name and email address, and your phone number and company name if the form asks for them and you provide them); and the name you type to confirm the form, with the fact and time that you ticked the box confirming you had read this privacy statement.
Do you have to fill it in? No. You don't have to fill in the form. Name and email are needed for us to reply; without them we can't prepare a proposal. Other questions are optional unless marked.
Why, and on what basis. We use your submission to reply to you and to prepare a proposal. We do this because you asked us to, as a step before a possible contract (Article 6(1)(b) GDPR). Before you send the form, we ask you to confirm that you have read this privacy statement, and we record your name and when you confirmed. That confirmation is not consent and is not the reason we process your answers, so you don't need to withdraw anything: if you want your submission gone, just ask (see below).
Where it is stored. In two places, both in the EU: in our forms service on the Junovy Private Cloud, and a copy in our business email, so we can read and reply to it. Our email delivery and business email providers are listed under data sharing.
Who sees it. Only Junovy. The providers in data sharing store or deliver it for us under contract; nobody else receives it, and we never sell it.
How long we keep it. If we don't end up working together, we delete your submission, both the database record and the email copy, 12 months after you send it. If we do work together, it becomes part of the client file and falls under the client retention terms in data retention. Copies in our encrypted backups are not edited one by one; they disappear as the backups roll over, within 90 days. Until then they are only used to restore systems.
Deleting it sooner. You can ask us to delete your submission at any time before then. Send us a request through the privacy request form, or write to us at the postal address in the contact section.
3. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Consent (Article 6(1)(a)): When you switch on the live chat in the cookie preferences. You can withdraw your consent at any time by turning the chat off in the cookie settings.
- Steps before a contract (Article 6(1)(b)): When you use the intake form, the contact form or the live chat to ask about our services, we process what you send to reply and, where you ask for one, to prepare a proposal.
- Contractual Necessity (Article 6(1)(b)): When processing is necessary to fulfill a contract or provide services you've requested.
- Legitimate Interests (Article 6(1)(f)): To reply to messages that aren't about our services, to keep the website and the infrastructure behind it secure, and to keep server logs for security and troubleshooting.
- Legal Obligation (Article 6(1)(c)): When required by law (e.g., tax records, accounting).
4. How We Use Your Data
Drake Design Studio uses your personal data for the following purposes:
- To respond to your inquiries (through the contact form, the live chat or email) and provide customer support
- To provide design services and fulfill project requirements
- To prepare a proposal from your project intake form
- To send you updates about your projects
- To improve our website and user experience
- To analyze website usage and performance, from the server logs described above
- To comply with legal obligations and prevent fraud
- To maintain website security and protect against threats
We do not send marketing email from this site, and there is no mailing list to join.
We don't make decisions about you based solely on automated processing, including profiling, within the meaning of Article 22 GDPR.
5. Cookies & Tracking Technologies
The drakedesign.studio site does not set any cookies or localStorage entries until you interact with the cookie consent banner. The banner offers three choices: Decline All, Manage Preferences (per-category toggles), and Accept All.
5.1 Consent Storage
Your choice is recorded in localStorage under the key dds_cookie_consent (not a cookie, but within scope of ePrivacy Directive Article 5(3) in the same way).
5.2 Functional Cookies (opt-in only)
If you accept the Functional category, we load our self-hosted live chat, which sets one first-party cookie (cw_conversation) to preserve your chat session. The live chat is operated by Junovy itself and is not a third party. If you decline functional cookies, the chat is not loaded at all and no cookie is set. Chat conversations themselves are kept for 2 years after the conversation ends (see data retention). Turning the chat off later stops the widget loading; it doesn't delete past conversations. To have a conversation deleted, ask us.
5.3 Analytics and Marketing
The drakedesign.studio site does not use analytics cookies, marketing cookies, advertising cookies, or any third-party tracking technology. There is no Google Analytics, no Meta Pixel, no Segment, no Mixpanel.
Typefaces are served from Junovy's own infrastructure, so loading a page sends no visitor data to a font provider or any other third party.
You can change your choice at any time with the "Cookie settings" link at the bottom of every page. For full details, see our Cookie Declaration.
6. Data Sharing & Third Parties
We do not sell your personal data. We share information only with carefully selected third-party processors who assist in operating our services, all of whom are required to comply with GDPR and maintain appropriate security measures.
These categories of recipients process personal data on our behalf:
| Recipient | What for | Where |
|---|---|---|
| Hosting and storage providers | Running and backing up our services | EU |
| Email delivery provider | Sending the emails our systems send, including form notifications | EU |
| Business email provider | Our mailboxes, including copies of contact and intake form messages | EU (limited support access from outside the EU, see transfers) |
| Payment provider (clients only) | Invoicing and payments | EU (some processing in the USA, see transfers) |
| Certificate authority | Issuing website security certificates; receives domain names only, no personal data | USA |
We have contracts with these providers that limit what they may do with your data (Article 28 GDPR). A list of the providers we use is available on request. For fraud prevention and financial regulation, our payment provider acts as an independent controller under its own privacy policy.
Our contact and intake forms and our live chat are self-hosted on the Junovy Private Cloud, Junovy's own infrastructure. They do not receive or store data independently of Junovy and are not third-party data processors; nothing you send through them is passed to another company, apart from the email described above and the hosting and storage providers in the table. The live chat is only loaded after you affirmatively accept functional cookies; see cookies.
The Junovy Private Cloud runs in data centres in Germany and on Junovy's own hardware in the Netherlands. Our storage and backup providers also keep data within the EU, including in France. Your data stays in the EU.
None of these recipients may use the data they process for their own purposes, except where stated. We do not use any analytics, advertising, or customer-data platforms.
7. International Data Transfers
The personal data we hold is stored and processed in the European Union. The exceptions are:
- Our certificate authority (USA) receives only domain names when it issues our website security certificates, not personal data.
- Our payment provider: for clients who pay through it, it may transfer payment data to its group company in the USA, under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
- Our business email provider may give group companies outside the EU limited access to our mailboxes for support and security, under the EU Standard Contractual Clauses.
To get a copy of the safeguards, send us a request through the privacy request form.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Contact Form Submissions: Retained for 2 years after last contact, unless a business relationship is established.
- Intake Form Submissions: Retained for 12 months after you send them, both the database record and the email copy, if we don't end up working together; then deleted. If we do work together, they become client project data (below).
- Chat Conversations: Retained for 2 years after the conversation ends, on the same basis as a contact form message (see legal basis).
- Client Project Data, including project correspondence: Retained for the duration of the project plus 7 years for legal and accounting purposes.
- Server Logs: Retained for 90 days for security and troubleshooting purposes.
- Other Email Correspondence: Retained for 3 years after last communication.
Copies in our encrypted backups are not edited one by one; they disappear as the backups roll over, within 90 days. Until then they are only used to restore systems.
9. Your Rights Under GDPR
As a data subject in the EU/EEA, you have the following rights:
- Right of Access (Article 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing (Article 18): Request that we limit how we use your data.
- Right to Data Portability (Article 20): Request your data in a structured, machine-readable format.
- Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: File a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
To exercise any of these rights, send us a request through the privacy request form, or write to us by post at:
Junovy (trading as Drake Design Studio)
[protected]
[protected]
[protected]
The Netherlands
If you send a request by post, we may ask you to verify your identity before we act on it. We will respond to your request within one month. If a request is complex we may extend this by up to two more months, and we'll tell you why within the first month.
10. Data Security & Privacy by Design
Privacy by design and by default (Article 25 GDPR) is built into Drake Design Studio from the ground up. Concretely, this means we host the personal data we hold inside the European Union, we use no third-party analytics, advertising, or tracking vendors of any kind on this site, typefaces are self-hosted, and consent-gated services (such as our live chat) are loaded only after affirmative user action. These choices are architectural: they cannot be toggled off, and they apply to every visitor automatically.
We also implement the technical and organisational measures required by Article 32 GDPR, including:
- Encryption in transit (TLS 1.2+) for all traffic to and from drakedesign.studio.
- Encryption at rest for backups and sensitive data.
- Access controls and authentication mechanisms, including role-based access control and least-privilege principles for staff access.
- Encrypted storage for credentials and other secrets.
- Regular security updates and automatic dependency scanning.
- Encrypted backups, kept off-site in the EU.
- Monitoring of our systems.
- A documented incident response plan.
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
11. Data Breach Notification
If a personal data breach occurs, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users directly and without undue delay, in plain language and with a description of the likely consequences and the measures we are taking, in accordance with Article 34 GDPR.
11a. Data Protection Officer (Article 37 GDPR)
Junovy is a small Dutch business and is not required to appoint a Data Protection Officer under Article 37 GDPR: we do not carry out large-scale systematic monitoring of individuals, nor do we process special categories of personal data on a large scale. All privacy questions, data subject requests, and breach reports should be sent through the privacy request form or by post to the address in the contact section.
12. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately, and we will delete the information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the updated policy on this page and updating the "Last Updated" date. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Junovy (trading as Drake Design Studio)
[protected]
[protected]
[protected]
The Netherlands
KvK: 71813977
Privacy Requests: the privacy request form
General Contact: Contact Form
All Privacy Documents: Privacy Center
Legal Notice: Legal Notice