Privacy policy
What we collect, why we collect it, and what you can ask us to do with it.
Effective 1 August 2026
Who we are
Eridient is a web design and development studio. We are the data controller for the personal data described in this policy, which means we decide why and how it is processed.
- Legal entity
- [REGISTERED COMPANY NAME, e.g. Eridient Digital s.r.o.]
- Registered address
- [REGISTERED STREET ADDRESS, CITY, POSTAL CODE, COUNTRY]
- Company number
- [COMPANY REGISTRATION NUMBER]
- VAT number
- [VAT NUMBER, or "not VAT registered"]
- Contact
- hello@eridient.com
We are established in the European Union, so the General Data Protection Regulation (GDPR) applies to everything described here, wherever in the world you are. If you are in the United States, the section on rights in the United States also applies to you.
What we collect
Information you give us
We only receive what you choose to send. That is the website address you enter to request a free audit, the email address you give us so we can send the results, and anything you include when you email us or discuss a project. If you become a client, we also process the contact and billing details needed to run the engagement.
Information collected automatically
Our hosting provider, [HOSTING PROVIDER, e.g. Cloudflare, Inc.], records standard server logs when a page is requested. These typically include the IP address, browser and device type, the page requested and the time of the request. They are used to serve the site, keep it secure and diagnose faults. We do not use them to build a profile of you.
What we do not collect
This website sets no cookies. It runs no analytics, no advertising pixels, no session tracking and no third-party scripts that follow you between sites. There is no consent banner because there is nothing to consent to. Fonts are served from our own domain rather than a third-party font service, so loading a page does not disclose your visit to anyone else.
We do not knowingly collect special category data — health, biometrics, political opinions, religious beliefs and the like — and ask that you do not send it to us.
Why we use it, and our lawful basis
- To answer your enquiry and prepare an audit or proposal. Lawful basis: taking steps at your request before entering a contract, and our legitimate interest in responding to people who contact us.
- To deliver website modernization or website care. Lawful basis: performance of our contract with you.
- To keep the website available and secure. Lawful basis: our legitimate interest in protecting the service from abuse and diagnosing faults.
- To meet accounting and tax obligations. Lawful basis: compliance with a legal obligation.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to make automated decisions that produce legal or similarly significant effects about you.
Who we share it with
We share personal data only with service providers who process it on our instructions, and only as far as they need it to do their job:
- [HOSTING PROVIDER, e.g. Cloudflare, Inc.] — website hosting and delivery.
- [EMAIL PROVIDER, e.g. Google Workspace] — business email.
- Our accountant and, where we are legally required to, tax authorities or other public authorities.
We may also disclose personal data if we are required to by law, or to establish, exercise or defend legal claims.
International transfers
Some of our providers are based in, or store data in, the United States. Where personal data leaves the European Economic Area we rely on a valid transfer mechanism — typically the European Commission's Standard Contractual Clauses, or the provider's certification under the EU–US Data Privacy Framework. You can ask us which mechanism applies to a specific provider.
How long we keep it
- Enquiries that do not become projects: up to 24 months, then deleted.
- Client records: for the length of the engagement and then as long as we need them to defend legal claims.
- Invoices and accounting records: for the retention period required by tax law in our country of establishment.
- Server logs: for the short period set by our hosting provider.
Your rights under the GDPR
You have the right to:
- ask what personal data we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have your data erased where there is no overriding reason for us to keep it;
- restrict or object to how we process it, including processing based on legitimate interests;
- receive data you gave us in a portable, machine-readable format;
- withdraw consent at any time, where we relied on consent;
- complain to a supervisory authority. Ours is [NATIONAL DATA PROTECTION AUTHORITY AND ITS WEBSITE], and you may also complain to the authority where you live or work.
Email hello@eridient.com to exercise any of these. We respond within one month. Exercising your rights is free, and we will not treat you differently for doing so.
Rights in the United States
Several US states give residents rights over their personal information. Thresholds under laws such as the California Consumer Privacy Act mean they may not formally apply to a studio of our size, but we do not think privacy should depend on that. If you are a US resident, you may ask us to tell you what personal information we hold about you, to delete it or to correct it, on the same terms as the rights described above.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not offer financial incentives in exchange for personal information.
Security
The site is served over HTTPS. We keep access to client data limited to the people who need it, use reputable providers, and choose tools that reduce how much personal data exists in the first place. No system is perfectly secure, but we will tell you and the relevant authority without undue delay if a breach affects your data and is likely to present a risk to you.
Children
This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
If we change how we handle personal data we will update this page and its effective date. Where a change materially affects you, we will make that clear rather than relying on you noticing.
Contact
Questions about this policy, or about your data, go tohello@eridient.com.