This policy explains how Darlana Studio (“we”) processes personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the supplementary Swedish Data Protection Act (lag 2018:218).
1. Controller
| Item | Details |
|---|---|
| Controller | Bonita Daniella Tóth, trading as Darlana Studio |
| Registration number (organisationsnummer) | 0002081867 |
| Address | Smedmästarebyn 3A 1603 lgh, 218 41 Bunkeflostrand, Sweden |
| Email (data protection matters) | hello@darlanastudio.com |
| Phone | +46 70 336 2431 |
| Data protection officer | Not required and therefore not appointed |
2. What we process, why, and on what legal basis
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Responding to contact form enquiries and issuing proposals | Name, email, phone (optional), website, service of interest, message content, timestamp | Art. 6(1)(b) GDPR — steps prior to entering a contract; and Art. 6(1)(f) — legitimate interest in handling business enquiries | 12 months from submission, then deleted automatically |
| Email and other business correspondence | Name, email address, signature block details, correspondence content | Art. 6(1)(b) GDPR where the correspondence relates to a contract or its preparation; otherwise Art. 6(1)(f) — legitimate interest in communicating with business contacts and documenting our business dealings | 2 years from the end of the client relationship, or from the last message if no client relationship results |
| Performing the service agreement (audit, mentoring, consultancy, ad management) | Contact details, access permissions, data held in advertising accounts, project documentation, correspondence | Art. 6(1)(b) GDPR — performance of a contract | 10 years from the end of the agreement (Swedish limitation periods) |
| Invoicing and accounting | Name, company name, billing address, VAT number, invoice details, payment data | Art. 6(1)(c) GDPR — legal obligation (Swedish Bookkeeping Act, bokföringslagen 1999:1078) | 7 years from the end of the financial year |
| Website operation and security (server logs) | IP address, browser and device data, request timestamp, referring page | Art. 6(1)(f) GDPR — legitimate interest in secure operation and abuse prevention | 30 days |
| Website analytics (Google Analytics 4) | Pseudonymous identifier, approximate location, device and browser data, pages viewed and events | Art. 6(1)(a) GDPR — consent (cookie banner) | 14 months, or until consent is withdrawn |
| Advertising measurement and remarketing (Google Ads) | Cookie identifiers, ad click identifiers, conversion data (for example a completed contact form or booking), device and browser data | Art. 6(1)(a) GDPR — consent (cookie banner, “Marketing”) | Up to 24 months, or until consent is withdrawn |
| Enhanced conversions (Google Ads): matching a contact form submission to an ad click | Email address, and phone number if given, entered in the contact form. Google’s tag hashes this data in your browser before it is sent to Google. | Art. 6(1)(a) GDPR — consent (cookie banner, “Marketing”). Without this consent the data is not passed on. | In your browser: until the thank-you page has loaded, at most until the tab is closed. At Google: as set out in Google’s terms for enhanced conversions |
| Booking consultancy and mentoring appointments | Name, email address, time zone, appointment time, answers given on the booking form | Art. 6(1)(b) GDPR — steps prior to entering a contract | 24 months, or until the calendar entry is deleted |
Contact form submissions are stored on our server (Hetzner, Helsinki, Finland) and sent to us by email via Google Workspace. They are deleted from the server automatically 12 months after submission. If the enquiry leads to further correspondence, that correspondence is kept as described for business correspondence above.
Details of the cookies and similar technologies used on the website, and how to change your choices, are set out in our Cookie Policy.
3. Source of the data
We obtain personal data directly from the data subject (contact form, booking form, email, phone or video calls, contracting). Some data is generated automatically when you use the website (server logs and, if you consent, cookies).
4. Recipients and processors
We do not sell personal data. The following providers may access data on our behalf under data processing agreements:
| Provider | Role | Location |
|---|---|---|
| Google Ireland Limited | Google Workspace (email, including delivery of contact form submissions), Google Analytics 4, Google Tag Manager, Google Ads | Ireland (EU); parent company in the USA |
| Hetzner Online GmbH | Server hosting, storage of the website and of contact form submissions | Finland (EU), Helsinki data centre; company based in Germany |
| Spiris (Visma Group) | Invoicing and bookkeeping software, storage of billing data | Sweden (EU) |
| VB Redovisning & Rådgivning | Bookkeeping within the Spiris system | Sweden (EU) |
| Calendly, LLC | Online appointment booking, processing of the booker's data | United States |
Google Analytics 4 and Google Ads (including the conversion linker) are managed through Google Tag Manager, using Google Consent Mode v2 in basic mode: these Google tags only load after you have given consent in the cookie banner, for the categories you accepted. Before or without your consent they do not load, set no cookies and send no data, including no cookieless signals, to Google. The Google Tag Manager script itself is loaded from Google's servers on every page so that it can apply your choice; like any file request, this gives Google your IP address and browser information, but Google Tag Manager sets no cookies. For advertising measurement and remarketing, Google may also act as an independent controller under its own terms and privacy policy (policies.google.com/privacy). When you point at or click a booking button, the booking window is loaded from Calendly's servers, which receive your IP address and browser information.
We may also disclose data to public authorities where required by law, and to our legal advisers for the establishment, exercise or defence of legal claims.
5. Transfers outside the European Economic Area
We aim to keep processing within the EEA. Some of our providers (in particular Google and Calendly) may nevertheless transfer data to the United States. Such transfers rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework, or on the Commission's Standard Contractual Clauses together with supplementary safeguards. We will provide details of the safeguards applied on request.
6. Is providing your data required?
You are not required by law to give us personal data. On the contact form, your name, email address, website (or that you don't have one yet), the service you are interested in and your message are needed for us to reply; the phone number is optional. If you become a client, the contact and billing details needed for the agreement are a contractual requirement, and we are legally required to keep invoicing data under Swedish bookkeeping law; without them we cannot enter into or perform the agreement. Analytics and advertising cookies are entirely optional, and refusing them has no effect on your use of the website.
7. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
8. Security
We apply appropriate technical and organisational measures, including encrypted transmission (HTTPS/TLS), two-factor authentication on critical accounts, use of a password manager, access restricted to what is necessary, regular backups and prompt software updates. In the event of a personal data breach we will notify the Swedish supervisory authority without undue delay and within 72 hours, and will inform affected individuals where the breach poses a high risk.
9. Your rights
Under the GDPR you have the following rights:
- Access — to be told whether we process personal data about you and to receive a copy.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where there is no longer a lawful basis for processing. This right is limited where we must retain data under law, for example accounting rules.
- Restriction — in certain circumstances, to require that we store but not otherwise use your data.
- Portability — to receive data you provided, processed on the basis of consent or contract, in a machine-readable format.
- Objection — to object to processing based on legitimate interest; where the processing is for direct marketing, your objection applies unconditionally.
- Withdrawal of consent — where processing is based on consent (for example analytics and advertising cookies), you may withdraw it at any time with effect for the future, for example through the cookie icon in the website footer. Withdrawal does not affect the lawfulness of processing carried out before it.
Requests can be sent to hello@darlanastudio.com. We respond without undue delay and within one month. Handling a request is free of charge; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act.
10. Complaints
If you believe our processing infringes your rights, you may lodge a complaint with the Swedish supervisory authority:
Box 8114, 104 20 Stockholm, Sweden
imy@imy.se | www.imy.se
You may also lodge a complaint with the supervisory authority in the EU or EEA country of your habitual residence or place of work, for example in Hungary:
1055 Budapest, Falk Miksa utca 9–11, Hungary
ugyfelszolgalat@naih.hu | www.naih.hu
or in Denmark Datatilsynet (www.datatilsynet.dk). That authority will forward your complaint to the competent lead authority. You are also entitled to seek a judicial remedy.
11. Changes to this policy
We may update this policy from time to time. The current version is always available on our website together with the date it was last updated. Ongoing clients will be notified separately of material changes.