Privacy Policy
Last updated: 18 July 2026
This policy explains how Shpatik SRL ("Shpatik Studio", "we") collects and uses your personal data, and your rights under the EU General Data Protection Regulation (GDPR).
1. Who we are
The data controller is Shpatik SRL, a company registered in Moldova (IDNO [IDNO — add before launch]), registered address [registered address — add before launch]. You can reach us at hello@shpatikstudio.com. Full company details are in our Legal Notice.
2. What we collect
- Enquiry data — when you use our contact or sample-report forms: your name, email address, any project link, and the message you send.
- Technical data — standard server and security logs (e.g. IP address, browser type) generated when you visit, used to keep the site secure and available.
- Analytics data — privacy-friendly, cookieless usage statistics (aggregate page views and referrers). This does not identify you and does not set cookies.
- Optional marketing cookies — only if you explicitly consent via our cookie banner. Off by default.
3. Why we use it (lawful bases)
- To respond to your enquiry — performance of a contract or steps taken at your request before entering one (Art. 6(1)(b)).
- To keep the site secure and working — our legitimate interests (Art. 6(1)(f)).
- Marketing cookies / analytics that set cookies — your consent (Art. 6(1)(a)), which you can withdraw at any time.
4. Who we share it with
We use a small number of trusted processors, each bound to protect your data:
- Brevo — email delivery and contact management (your enquiry data).
- Vercel — website hosting and delivery.
- Cloudflare — DNS and content delivery / security.
- Plausible Analytics — cookieless, aggregate analytics.
We never sell your personal data.
5. International transfers
Some processors are located outside Moldova and the EU/EEA. Where that happens, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. EU representative (Article 27)
As we offer services to individuals in the EU, our appointed EU representative under Article 27 GDPR is [EU representative name & contact — appoint before launch].
7. How long we keep it
We keep enquiry data for as long as needed to answer you and, where relevant, to manage an ongoing client relationship, after which it is deleted or anonymised. Security logs are kept for a short period only.
8. Your rights
Under the GDPR you have the right to access, correct, erase, restrict or object to the processing of your data, and to data portability. You can exercise any of these by emailing hello@shpatikstudio.com. You also have the right to complain to your local data protection authority.
9. Cookies
See our Cookie Policy for details on the cookies we use and how to manage your choices.
10. Changes
We may update this policy from time to time. The date at the top reflects the latest version.
11. Contact
Questions about your data? Email hello@shpatikstudio.com.
Note for the site owner: this is a solid GDPR-aligned starting point. Replace the bracketed placeholders and have it reviewed by an EU data-protection lawyer before launch.