Privacy policy
Last updated
This policy sets out what personal data Rubra Digital collects through this website and in the course of client work, why it is collected, and what rights you have. I am the data controller for the processing described here.
Who I am
Rubra Digital, a sole trader established in TODO Country.
TODO Street and number, TODO Postcode TODO City, TODO Country.
Data protection enquiries: hello@rubradigital.com.
What is collected
Website visits. This site sets no cookies for analytics, advertising or tracking, and runs no third-party tracking scripts. Fonts are served from this domain rather than from a third-party font service. The hosting provider (Cloudflare) processes standard server request data, meaning IP address, user agent, requested URL and timestamp, in order to deliver the site and protect it from abuse.
Contact form. An enquiry sent through the form collects your name, email address, company name if you give one, indicative budget if you select one, and the content of your message. The originating IP address is also recorded and retained for 30 days, solely to investigate abuse of the form.
Client engagements. During an engagement I process business contact details for the people I work with. Where a project requires access to personal data held in your systems, I act as your processor under a separate data processing agreement rather than as a controller, and that agreement governs the processing.
Why, and on what legal basis
- To reply to your enquiry. Legitimate interests (Article 6(1)(f) GDPR): you made contact and expect an answer.
- To deliver and administer an engagement. Performance of a contract (Article 6(1)(b)).
- To keep the site available and secure. Legitimate interests in operating a functioning, non-abused website.
- To meet accounting and tax obligations. Legal obligation (Article 6(1)(c)).
Your data is not used for profiling, automated decision-making, advertising, or to train any machine learning model.
How long it is kept
- Enquiries that do not become engagements. 24 months, then deleted.
- Form submission IP addresses. 30 days.
- Client records. For the duration of the engagement plus 7 years, to meet statutory accounting retention requirements in TODO Country.
- Server request logs. As retained by Cloudflare under their policy.
Who it is shared with
Personal data is never sold and never shared for marketing. A small number of processors are used to run the business and they are listed on the sub-processors page, which is kept current. Each is bound by a data processing agreement.
International transfers
The site is configured to keep website data within the EEA where possible. Where a processor transfers data outside the EEA, that transfer relies on an adequacy decision or on Standard Contractual Clauses with supplementary measures. For client engagements I design around whatever residency requirement applies to you, including EU-only, Swiss-only, UK, US or Canadian residency, and fully on-premise deployment where no external processing is permitted.
Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to data portability. Where processing relies on legitimate interests you may object at any time. To exercise any of these, email hello@rubradigital.com. I respond within one month.
You may also complain to a supervisory authority. The competent authority here is TODO your national data protection authority, but you may complain to the authority where you live or work. Residents of the UK may contact the ICO, residents of Switzerland the FDPIC, and residents of Canada the Office of the Privacy Commissioner. California residents have rights under the CCPA and CPRA including access, deletion and the right to opt out of sale. No personal information is sold.
Security
Access is granted on a need-to-know basis, data is encrypted in transit and at rest, all business systems use multi-factor authentication, and processor arrangements are reviewed periodically. No system is perfectly secure, but the most effective control available is not collecting data that is not needed, and that is the one applied first.
Changes
This policy is updated when the processing changes. The date at the top reflects the current version. Material changes affecting existing clients are notified directly.
Responsible person: Your Name.