Privacy Policy
This document explains what personal data DANIEL DIOS receives, why and on what legal basis it is processed, who it is shared with, how long it is kept and how you can control it.
A template, not legal advice
This document is a template compiled from public sources and is not legal advice. Before it goes live on a working website, and especially before payments are accepted, it must be reviewed by a lawyer familiar with the law of Georgia and EU law.
The “Check with a lawyer” blocks flag questions research cannot settle. They must be resolved before publication and the markers removed.
Legal details are not filled in yet
Values in double curly braces are placeholders. They are replaced with real data once the sole proprietorship is registered and the domain mailbox is live. Until then the page must not be submitted to a payment platform for review: incomplete legal pages are a direct cause of rejection.
1.The short version
- We collect the minimum: what you send us in your enquiry and in conversation, plus what is needed to work on your project.
- We do not sell personal data and do not share it for anyone else’s advertising.
- The site sets no cookies and stores no analytics data in your browser. Two cookieless analytics systems are enabled, both described in section 11. The only things stored in your browser are your interface language and a mark that the intro screen has already been shown, so it is not repeated on every visit. Both are functional, contain no analytics and no identifiers.
- We never receive full card details: payment is handled by the payment provider.
- Send any request about your data to [email protected], we respond within one month.
2.Who is responsible for your data
Data controller: Danila Manko (Individual Entrepreneur), registration number 324087215, address Sakartvelo, Akhaltsikhe district, Abi, email [email protected], phone +995 995 508 588. Additional channel: Telegram @golden_dios.
The controller is Individual Entrepreneur Danila Manko, registered in Georgia on 30 May 2023. There is no other legal entity behind the DANIEL DIOS brand.
3.EU representative
EU representative: not appointed.
No representative under Article 27 GDPR has been appointed. The Studio is based in Georgia, works from inbound enquiries and does not run advertising targeted at EU countries. Orders from EU clients are not ruled out, however, so the question of a representative stays open and is settled before any EU-targeted advertising starts.
As soon as the Studio advertises into the EU, quotes prices in euro or works systematically with EU clients, the Article 27 representative question must be settled with a lawyer: the “occasional processing” exemption is read narrowly and most likely does not cover ordinary routine activity.
4.Data Protection Officer
No DPO has been appointed: the Studio’s activity does not fall into the categories where appointment is mandatory. For personal data protection questions, write to [email protected].
5.What data we collect
- Contact data: name or nickname, Telegram username, email address, phone number, if you provide them.
- The content of your enquiry and correspondence: task description, brief, files and links you send.
- Project data: copy, images, price lists, and credentials for services and accounts shared so the work can be done.
- Contract and payment details: invoicing details, amount, date and method of payment, order history.
- Technical data: IP address, browser and device type, request date and time, page requested, processed by the hosting provider in server logs.
The Studio neither receives nor stores full payment card details: payment is processed by the payment provider, which acts as an independent controller for the payment itself.
6.What we do not collect
- Special categories of data: health information, biometrics, political views, religion, sex life, we do not ask for them.
- Children’s data.
- Data scraped from public sources to build visitor profiles.
- Data for sale, exchange or transfer to data brokers.
If you send special category data on your own initiative, we delete it unless it is needed to perform the work.
7.Purposes, legal bases and retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Handling your enquiry and pre-contract correspondence | Name, contact, message content | Art. 6(1)(b) GDPR: pre-contractual steps at your request | Up to 12 months from the last contact |
| Delivering the project | Materials, credentials, project details, correspondence | Art. 6(1)(b) GDPR: performance of a contract | Project duration plus 12 months after delivery |
| Invoicing, accounting, tax | Payment and contract documents | Art. 6(1)(c) GDPR: legal obligation | The period required by Georgian law |
| Website security and spam protection | IP address, user agent, request time | Art. 6(1)(f) GDPR: legitimate interest | Normally up to 30 days, per the hosting provider’s settings |
| Establishing and defending legal claims | Correspondence, brief, quote, payment confirmations | Art. 6(1)(f) GDPR: legitimate interest | Until the limitation period expires |
| Publishing a case study naming the client | Project name, screenshots, testimonial | Art. 6(1)(a) GDPR: consent | Until consent is withdrawn |
| Measuring site traffic, if analytics is enabled | Anonymous aggregated visit data | Art. 6(1)(f) GDPR: legitimate interest | In aggregate form, not linked to an individual |
8.Our legitimate interests
Where legitimate interest is the legal basis, we mean specifically the following:
- Protecting the site and correspondence from spam, abuse and automated attacks.
- Establishing and defending legal claims, including evidence of the agreed scope of work.
- Anonymous measurement of site traffic to understand which pages are useful.
- Keeping a portfolio in anonymised form, without the client’s name, logo or data, where consent for a named case study has not been given.
On request at [email protected] we will explain how we balanced that interest against your rights.
9.Who receives your data
- Hosting and content delivery, Cloudflare: processing the technical data needed to serve pages and protect against attacks.
- PostHog Cloud EU: anonymous, cookieless statistics of on-site activity, see section 11.
- Telegram: if you message us on Telegram, your messages and profile data are processed by that service under its own rules. If you would rather avoid that, write to [email protected].
- Email provider: delivery and storage of correspondence at [email protected].
- The payment provider acting as merchant of record: taking payments, issuing receipts and processing refunds. For the payment itself it acts as an independent controller.
- Contractors engaged for a specific project, only to the extent needed for the work and under a confidentiality obligation.
- Professional advisers, banks and public authorities, only to the extent required by law.
- Advertising platforms (Google, Meta), only if and when the Studio enables advertising technologies; see section 12.
We do not sell personal data. Data processing agreements are put in place with processors acting on our instructions.
10.International data transfers
The Studio is located in Georgia, outside the European Economic Area. As at the date of this version there is no European Commission adequacy decision for Georgia, and we say so plainly.
Transfers from the EU and EEA therefore rely on Chapter V GDPR mechanisms: standard contractual clauses with processors, or, for direct orders, the derogation in Art. 49(1)(b), the transfer is necessary to perform a contract with the data subject at their request.
A copy of the applicable safeguards can be requested at [email protected]. Some processors are located in the United States and other countries outside the EEA; they are listed in section 9.
Have the adequacy status of Georgia and the chosen transfer mechanism reviewed by a lawyer. When new services are added, the list of processors and transfer bases must be updated.
11.Cookies and local storage
- 11.1This site uses two analytics systems, and neither of them stores anything in your browser. Cloudflare Web Analytics counts page views without cookies and without local storage. PostHog Cloud EU (servers in Frankfurt, Germany) collects anonymous statistics about activity: page views, button clicks, expanding the pricing and FAQ blocks, scroll depth, and language switches. PostHog runs in cookieless mode: no cookies, no localStorage, no sessionStorage. Visitors are distinguished by a daily irreversible hash computed on PostHog's servers, which cannot be traced back to an individual. IP addresses are not stored, no visitor profiles are created, and no session recordings are made. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in understanding which parts of the site are useful. No consent banner is shown because neither system writes anything to your device. If your browser sends a Do Not Track or Global Privacy Control signal, analytics does not run at all.
- 11.2Your chosen interface language is stored in the browser’s local storage (localStorage, key dd_lang). This is a technical setting strictly necessary for a feature you requested yourself: it is not used for tracking and never leaves your browser. You can clear it through your browser.
- 11.3No cookie consent banner is shown because there is no technology on the site that requires consent. We consider a misleading banner worse than none.
- 11.4Web analytics is already enabled and needs no consent, because neither system stores anything in your browser (see 11.1). If the Studio enables advertising pixels, this section will be updated in advance, and visitors from the EU and EEA will be asked for consent before such technologies fire.
The position that cookieless analytics needs no banner rests on Art. 5(3) of Directive 2002/58/EC, but some EU regulators read analytics more strictly. Confirm with a lawyer before enabling any analytics.
12.Advertising technologies
As at the date of this version, no advertising pixels or remarketing lists are installed on the site. When the Studio runs online advertising, the following applies.
- 12.1We use data about visits to our site to advertise online, including to people who have already visited our site.
- 12.2Third-party vendors, including Google, show our ads on sites across the internet.
- 12.3Third-party vendors, including Google, use cookies and/or device identifiers to serve ads based on someone’s past visits to our website.
- 12.4You can opt out of personalised Google advertising in Google Ads Settings: adssettings.google.com. You can opt out of personalised advertising from Network Advertising Initiative members at optout.networkadvertising.org.
- 12.5If a Meta Pixel is installed, site event data will be shared with Meta for ad measurement and targeting. You can opt out in the ad settings of Facebook and Instagram.
- 12.6For visitors from the EU and EEA such technologies are activated only after consent, and the relevant scripts do not load beforehand.
13.How long we keep data
- Enquiries and correspondence that did not become an order, up to 12 months from the last contact.
- Documents relating to completed orders, for the duration of the contract and 12 months after delivery, unless the law requires longer.
- Accounting and tax records, for the period required by Georgian law.
- Client materials and credentials, until the project ends. After delivery, credentials are deleted or handed over, and working copies are kept for no more than 12 months.
- Server logs, per the hosting provider’s settings, normally up to 30 days.
- Consumer consents to early performance, for the limitation period, since the burden of proof lies with the Studio.
14.Your rights
- The right of access and to a copy of your data.
- The right to have inaccurate data corrected and incomplete data completed.
- The right to erasure.
- The right to restriction of processing.
- The right to data portability in a machine-readable format.
- The right to object to processing based on legitimate interest, and an unconditional right to object to direct marketing.
- The right not to be subject to decisions based solely on automated processing, including profiling.
- The right to withdraw consent at any time, this does not affect the lawfulness of processing carried out before withdrawal.
- The right to lodge a complaint with a supervisory authority.
15.How to exercise your rights
- 15.1Send your request to [email protected]. Requests via Telegram are also accepted, but we may ask you to duplicate them by email so we can verify your identity.
- 15.2We respond within one month. That period may be extended by two further months for complex or numerous requests; we will tell you about the extension and why.
- 15.3Responses are free. A reasonable fee may be charged for manifestly unfounded or repetitive requests, or such requests may be refused with reasons given.
- 15.4We may ask for additional information to confirm the request comes from you.
16.Whether providing data is mandatory
Providing data is not a statutory obligation. But without a name and a contact we cannot process an enquiry, and without materials and access we cannot do the work. Declining to provide them means the service cannot be delivered.
Some data, invoicing details, for example, is required by law for accounting and tax purposes.
17.Automated decisions and profiling
The Studio does not take decisions producing legal or similarly significant effects based solely on automated processing, and does not carry out profiling for such purposes.
AI tools are used as assistants, for drafts, processing materials and routine work. Final decisions on a project are made by a human.
18.Security
We apply reasonable technical and organisational measures: HTTPS in transit, limiting who has access, minimising what we collect, unique passwords and two-factor authentication where the service supports it, and removing access once a project ends.
No measure provides absolute protection, and we do not promise it. We aim to comply with applicable data protection law and to fix shortcomings we learn about.
19.Data breaches
In the event of a personal data breach we notify the competent supervisory authority within 72 hours of becoming aware of it, where the breach is likely to result in a risk to people’s rights and freedoms.
Where the risk is high, we also inform the affected individuals without undue delay, using the contact details we hold.
20.Children’s data
The Studio’s services are intended for businesses and adult clients. We do not knowingly collect data from anyone under 16, or under 13 in the United States.
If you believe a child’s data has been shared with us, write to [email protected] and we will delete it.
21.For residents of the EU and EEA
Processing takes account of the General Data Protection Regulation (GDPR). Legal bases are listed in section 7, rights in section 14, and the international transfer mechanism in section 10.
You have the right to lodge a complaint with the data protection authority of your country of residence, place of work or the place of the alleged infringement. That does not prevent you from contacting us first at [email protected].
22.For residents of Georgia
Georgian personal data protection law applies to this processing. It gives you rights to information about the processing, access and a copy, correction and updating, termination of processing and erasure, blocking, portability, objection to automated decisions and withdrawal of consent.
Direct marketing messages stop within 7 business days of receiving your request; you can opt out through the same channel the message arrived in.
You may lodge a complaint with the Georgian personal data protection supervisory authority. As at the date of this version, supervision is exercised by the State Audit Office of Georgia, complaints portal: pdp.sao.ge.
The supervisory authority in Georgia has changed: functions moved from the Personal Data Protection Service to the State Audit Office. Verify the current name, address and complaint procedure before publishing.
23.For residents of the United States and California
The Studio does not meet the thresholds for the California Consumer Privacy Act (CCPA/CPRA): neither by revenue, nor by number of California consumers, nor by share of income from selling data. Even so, we make the following disclosures and grant the rights below voluntarily.
- The categories of data collected and the purposes are listed in sections 5 and 7, and retention periods in section 13.
- We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the past 12 months. A “Do Not Sell or Share My Personal Information” link is therefore not required.
- You have the right to know what data we hold, obtain a copy, correct and delete it, and limit the use of sensitive personal information.
- We do not discriminate for exercising these rights: prices and terms do not change.
- Requests go to [email protected]; the response time is 45 days, extendable by a further 45 days.
- Any mailings include the sender’s physical postal address, an honest subject line and a working unsubscribe link processed within 10 business days.
24.For residents of the UAE
Residents of the UAE may exercise their rights under UAE federal personal data protection law: access their data, request correction, erasure, restriction or cessation of processing, request portability and withdraw any consent previously given.
Requests go to [email protected]. The data categories, purposes and retention periods are the same as described in sections 5, 7 and 13.
25.Changes to this policy
The current version is always published on this page with an effective date and a last-updated date. We notify active clients by email about material changes.
Previous versions are available on request at [email protected].
26.Data contacts
Primary channel: [email protected]. Additional: Telegram @golden_dios. Postal address: Sakartvelo, Akhaltsikhe district, Abi. Phone: +995 995 508 588.
Still have questions
Message us on Telegram or write to [email protected]. Written requests are answered within 3 business days at the latest.