Privacy Policy
This privacy policy outlines how Zhestkov.Studio Ltd (“we,” “our,” or “us”) collects, uses, stores, and protects personal data obtained through email subscription forms on our portfolio website. This document complies with global privacy regulations, including the European Union’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). By subscribing to our mailing list, you consent to the practices described below.
Data Collection and Purpose
Types of Personal Information Collected
When you subscribe to our newsletter or updates via MailChimp, we collect:
-
Email address (required for communication)
-
Name (optional, if provided voluntarily through custom form fields)
-
IP address, browser type, and operating system (automatically collected by MailChimp for analytics and anti-abuse purposes).
MailChimp, our email marketing provider, may collect additional metadata such as geographic location and engagement metrics (e.g., open rates, click-through rates). This data is aggregated and anonymized for performance analysis.
Legal Basis for Processing
We process your data under two primary legal frameworks:
-
Consent: By voluntarily submitting your email, you explicitly consent to receive communications from us. You may withdraw consent at any time using the “unsubscribe” link in every email.
-
Legitimate Interest: We analyze engagement metrics to improve our content and ensure relevance, which constitutes a legitimate business interest under GDPR Article 6(1)(f).
Third-Party Data Processing via MailChimp
Role of MailChimp
MailChimp acts as a data processor under GDPR and a service provider under CCPA. They host subscriber data on servers in the United States and provide tools for email campaign management, analytics, and compliance.
Data Transfer Safeguards
MailChimp complies with international data transfer requirements through:
-
Standard Contractual Clauses (SCCs): Legal mechanisms ensuring EU/UK data protections apply to U.S.-hosted data.
-
Data Processing Addendum (DPA): A binding agreement between us and MailChimp that outlines responsibilities for GDPR compliance.
Subscribers in the European Economic Area (EEA) should note that their data may be transferred outside the EEA but remains protected under these contractual safeguards.
Data Retention and Security
Retention Period
We retain your email address indefinitely unless you unsubscribe or request deletion. MailChimp automatically deletes unsubscribed contacts from active lists but may retain anonymized engagement data for analytics.
Security Measures
MailChimp employs TLS encryption, regular security audits, and access controls to protect subscriber data. We restrict internal access to your information to authorized personnel only.
Your Rights and Choices
Access and Correction
You may request a copy of your stored data or corrections to inaccuracies by contacting us at work@zhestkov.studio. MailChimp’s platform also allows subscribers to update their preferences directly via email links.
Deletion and Opt-Out
To delete your data or opt out of communications:
-
Click the “unsubscribe” link in any email.
-
Submit a deletion request to work@zhestkov.studio.
We will process requests within 30 days and confirm completion via email.
GDPR-Specific Rights
EEA residents have the right to:
-
Object to data processing.
-
Restrict processing under certain conditions.
-
Lodge complaints with a supervisory authority (e.g., the UK Information Commissioner’s Office).
Cookies and Tracking Technologies
Our email campaigns use MailChimp’s tracking pixels to measure open rates. These pixels collect your IP address, browser type, and timestamp but do not store identifiable information beyond what you voluntarily provide.
Policy Updates and Contact Information
We may update this policy to reflect changes in laws or MailChimp’s services. Revised versions will be posted on our website with an updated effective date. For questions, contact:
Zhestkov.Studio Ltd
124 City Road, London EC1V 2NX, United Kingdom
work@zhestkov.studio
Effective Date: February 17, 2025
This policy integrates requirements from GDPR, CCPA, and MailChimp’s Terms of Use. Subscribers are encouraged to review MailChimp’s Privacy Policy for details on their data practices.