Cystall ("we", "us", "our") is committed to protecting your privacy. This policy explains what personal data we collect, how we use it, and your rights regarding that data.

1. Data We Collect

We collect personal data only when you voluntarily provide it. This includes:

  • Contact form submissions: Name, email address, company name, project description, and budget range.
  • Meeting requests: Preferred date, time, and timezone.
  • Email correspondence: Any information you share with us directly via email.

We do not use analytics tracking tools, advertising pixels, or third-party trackers on this website. We do not use cookies beyond those technically required for the website to function.

2. How We Use Your Data

We use the information you provide solely to:

  • Respond to your enquiry and discuss your project.
  • Schedule and conduct discovery calls if requested.
  • Send project-related communications during an active engagement.

We do not use your data for marketing purposes without your explicit consent. We do not sell, rent, or share your personal data with third parties.

3. Data Storage

Contact form submissions are stored in our secure database hosted on servers in the EU. Email communications are handled via Google Workspace.

We retain enquiry data for up to 2 years. Active client data is retained for 5 years for legal and accounting purposes. You may request deletion at any time (see Section 6).

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, we process your personal data on the following legal bases:

  • Legitimate interest: To respond to your enquiry and manage our business relationship.
  • Contract: To fulfil our obligations when you are a client.
  • Legal obligation: To comply with applicable financial and legal record-keeping requirements.

5. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure: Ask us to delete your personal data, subject to legal retention requirements.
  • Portability: Receive your data in a machine-readable format.
  • Objection: Object to our processing of your data based on legitimate interest.

To exercise any of these rights, email hello@cystall.com. We will respond within 30 days.

6. Data Deletion Requests

To request deletion of your data, email hello@cystall.com with "Data Deletion Request" in the subject line. We will delete your data within 14 days, except where we are legally required to retain it.

7. Third-Party Services

This website uses the following third-party services that may process data:

  • Google Fonts: Font files are loaded from Google's CDN. Google may log your IP address. See Google's Privacy Policy.
  • Email delivery: Outbound emails are sent via SMTP. Message contents may transit third-party mail servers.

8. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, or disclosure. Our servers use HTTPS encryption. Access to stored data is restricted to authorised personnel.

9. Children's Privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data to us, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy as our practices evolve. Significant changes will be noted with an updated effective date. We recommend checking this page periodically.

Contact

For any privacy-related questions or requests, contact us at hello@cystall.com