Privacy Policy & Data Protection Charter
Effective date: September 30, 2026This comprehensive Privacy Policy defines the statutory framework under which Remi Graphic Studio processes personal data, upholds confidentiality, and ensures European data sovereignty in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation).
We only collect data strictly necessary to prepare commission estimates, execute design agreements, and fulfill statutory tax requirements.
We do not deploy marketing surveillance pixels, behavioral trackers, or monetize client identity data under any circumstance.
All records reside under the stringent privacy protections of EU law and the oversight of the Estonian Data Protection Inspectorate.
1. Identity & Contact of the Data Controller
Pursuant to Article 4(7) of Regulation (EU) 2016/679 (General Data Protection Regulation), the controller responsible for the governance and processing of personal data gathered via this digital presence and direct studio correspondence is Remi Graphic Studio.
All formal notifications, data access requests, or regulatory communications regarding data handling should be directed to our designated compliance correspondence address: contact@remigraphicstudio.center.
2. Categories of Personal Data Collected
The studio collects data directly provided by prospective patrons, client representatives, and enterprise partners across the following operational categories:
- A. Contact & Representative Identification
Full legal name, executive position, official enterprise email address, direct phone contact, and authorized institutional signatory status.
- B. Project Specifications & Commission Briefs
Anticipated design scope, brand strategy requirements, delivery milestones, confidential intellectual property disclosures, and budget tier selections.
- C. Corporate Fiscal Coordinates
Entity legal name, registered seat address, corporate registration identifier, European Union VIES VAT identification number, and statutory invoicing credentials.
- D. Technical Telemetry (Server Access Logs)
Anonymized IP address, user-agent string, timestamp of request, and referral URI necessary solely to guarantee edge server security and denial-of-service resilience.
3. Legal Grounds for Data Processing
Every act of processing personal data is anchored in one of the strict statutory grounds established by Article 6(1) of the GDPR:
Processing necessary to prepare design proposals, assess timeline feasibility, and execute signed artistic retainers.
Mandatory retention of transaction logs, contracts, and VAT 24% accounting documents pursuant to the Estonian Accounting Act.
Preservation of artistic attribution, protection of studio intellectual property, and defense against fraudulent inquiries.
Affirmative agreement given via our commission inquiry checkbox prior to transmission of creative briefs.
4. Statutory Data Retention Schedules
Remi Graphic Studio adheres to rigorous data minimization. Data is expunged once its defining legal purpose expires:
| Record Category | Retention Period | Statutory Justification |
|---|---|---|
| Uncommissioned Inquiries | 12 months from closure | Evaluation of studio capacity and recurrence |
| Executed Retainers & Contracts | 10 years from completion | Statute of limitations for contract claims |
| Fiscal Invoices (VAT 24%) | 7 years from fiscal year-end | Estonian Accounting Act § 12 (Raamatupidamise seadus) |
| Production Artwork Archives | Perpetual / Indefinite | Author moral rights & historical portfolio archiving |
5. Enforceable Data Subject Rights under GDPR
Every individual whose data is held by the studio retains irrevocable rights codified in Articles 15 through 22 of the GDPR:
- Right to Access (Art. 15)
Request full copies of stored personal records and data provenance without undue delay.
- Right to Rectification (Art. 16)
Immediate correction of inaccurate or outdated corporate information.
- Right to Erasure (Art. 17)
Deletion of records when retention is no longer grounded in statutory tax laws.
- Right to Restriction (Art. 18)
Freezing data processing pending contested claims or audit verification.
- Right to Data Portability (Art. 20)
Export of provided client materials in structured, commonly used machine-readable formats.
- Right to Lodge a Regulatory Complaint (Art. 77)
Right to file formal complaints before the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, info@aki.ee).