Legal
Privacy Policy
Version 2026-08-27 · Last updated 27 August 2026
1. Controller
Studio ByCristian B.V. is the controller responsible for the personal data described in this policy.
KVK: 72154500
VAT: NL859007790B01
Address: Van Beverningkstraat 101B, 2582 VC Den Haag, the Netherlands
Email: office@studiobycristian.com
2. Data we collect
When you request a consultation, we collect your name, email address, telephone number, project location, requested service and consultation format, preferred date and time, indicative budget and timeline, project description, and any files you choose to upload. We also record the legal-document versions you acknowledged and the time of acknowledgement.
For security and operation, our systems may process technical data such as account identifiers, IP-derived security signals, browser information, timestamps, authentication events and audit logs.
3. Purposes and legal bases
We process booking and project information to take steps at your request before entering into a contract, to communicate about the requested consultation, prevent double booking, manage documents and follow up on your request. We process security, audit and abuse-prevention information on the basis of our legitimate interests in operating a secure and reliable service.
We do not use booking data for marketing in this version. Analytics or marketing technologies, if introduced, remain disabled unless you provide the required cookie consent.
4. Service providers and recipients
We use Firebase and Google Cloud for authentication, database, private file storage and server-side processing; Vercel for website delivery; and Studio ByCristian's SMTP provider for transactional email. Authorised Studio ByCristian administrators and staff can access data only as needed for their work. Providers act under appropriate contractual and security safeguards.
5. International transfers
We select European data locations where the service supports them. Some providers may process limited data outside the European Economic Area. Where this occurs, we rely on a lawful transfer mechanism such as an adequacy decision or standard contractual clauses, together with appropriate safeguards.
6. Retention
Submitted client records, appointments and project files are scheduled for deletion after 24 months. Unsubmitted booking drafts and abandoned uploads are deleted after 24 hours. Email delivery logs and security audit information are kept only as long as reasonably necessary for delivery, troubleshooting, security and legal obligations. An administrator can export or delete a client record earlier when appropriate.
7. Security
CRM records and files are not publicly readable. Access is role-based, sensitive changes run through verified server functions, concurrent reservations are handled transactionally, credentials remain in secret storage, and relevant activity is logged. No internet service can be guaranteed completely secure.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or object to certain processing. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Contact us at the address above to exercise a right; we may need to verify your identity.
9. Required and optional information
Fields marked as required are necessary to assess and arrange your consultation. Without them, we may be unable to process the request. File upload is optional. Booking decisions are not made solely by automated means.
10. Changes
We may update this policy when the service or law changes. The version shown with a booking remains recorded with that request. This policy is provided for transparency and should be legally reviewed before the booking service is publicly launched.
