Privacy Policy

Last Updated: June 19, 2026 | Brussels, Belgium

Our Commitment to Privacy

At CraftRipple Studio, we take your privacy seriously. As a Brussels-based company, we are fully committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and Belgian privacy laws. This policy explains how we collect, use, store, and protect your information.

1. Data Controller Information

Company: CraftRipple Studio

Location: Brussels, Belgium

Contact: hello@craftripple.com

We are the data controller for personal information collected through our website and services, responsible for deciding how and why your personal data is processed.

2. What Data We Collect

Contact Form Data

  • Name
  • Email address
  • Phone number (optional)
  • Company name (optional)
  • Project description and requirements
  • Budget range (optional)
  • Timeline preferences (optional)
  • Services of interest

Technical Data

  • IP address (for security monitoring)
  • Browser type and version
  • Time zone and language preferences
  • Access timestamps
  • Pages visited on our website

Security Data

We collect certain technical data necessary for maintaining the security and integrity of our systems. This is done to protect both our infrastructure and your data from unauthorized access or malicious activities.

3. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Consent: When you submit a contact form
  • Contract Performance: To provide services you've requested or contracted
  • Legitimate Interests: For security monitoring, fraud prevention, and service improvement
  • Legal Obligations: To comply with Belgian and EU laws, including tax and accounting requirements

4. How We Use Your Data

  • Service Delivery: To provide development services and technical support
  • Communication: To respond to inquiries and send project updates
  • CRM Management: To track leads, clients, and project history
  • Security: To protect our systems from unauthorized access and abuse
  • Legal Compliance: To fulfill tax, accounting, and regulatory requirements
  • Service Improvement: To analyze usage patterns and improve our offerings

We never sell your personal data to third parties or use it for purposes other than those stated in this policy without your explicit consent.

5. Data Storage & Security

Where We Store Data

Your data is stored on secure servers within the European Union. We use PostgreSQL databases with encryption at rest and in transit. All backups are encrypted and stored in EU data centers.

Security Measures

We employ industry-standard security measures including:

  • End-to-end encryption for data in transit and at rest
  • Multi-factor authentication where appropriate
  • Regular security audits and testing
  • Strict access controls based on the principle of least privilege
  • Continuous monitoring and threat detection
  • Incident response procedures

6. Data Retention

We retain personal data only as long as necessary for the purposes outlined in this policy:

  • Contact form submissions: 3 years or until project completion + 1 year
  • Client project data: Duration of project + 5 years for legal/tax purposes
  • Security logs: 90 days (unless required for investigation)
  • Cookies and analytics: Maximum 1 year

After retention periods expire, data is securely deleted or anonymized.

7. Your Rights Under GDPR

As an EU resident, you have the following rights regarding your personal data:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to certain types of processing
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Complain: Lodge a complaint with supervisory authorities

To exercise any of these rights, contact us at hello@craftripple.com. We will respond within 30 days as required by GDPR.

8. Third-Party Services

We use carefully selected third-party services that comply with GDPR:

  • Email Service: For transactional emails (EU servers)
  • Cloud Infrastructure: EU-based hosting providers
  • Payment Processing: SEPA-compliant payment providers
  • Analytics: Privacy-focused analytics (no personal data)

All third-party processors sign Data Processing Agreements (DPAs) ensuring GDPR compliance and data protection.

9. Cookies & Tracking

We use minimal cookies essential for website functionality:

  • Session Cookies: For maintaining your session
  • Authentication Cookies: For secure login (if applicable)
  • Theme Preference: To remember light/dark mode choice
  • Security Cookies: For CSRF protection

We do not use tracking cookies for advertising or share data with advertising networks.

10. International Transfers

Your data remains within the European Economic Area (EEA). If we ever need to transfer data outside the EEA, we will:

  • Ensure adequate protection through Standard Contractual Clauses
  • Only transfer to countries with EU adequacy decisions
  • Obtain your explicit consent when required
  • Implement additional safeguards as necessary

11. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it immediately.

12. Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the Belgian Data Protection Authority within 72 hours
  • Inform affected individuals without undue delay
  • Provide details about the breach and measures taken
  • Offer support and guidance on protecting your data

13. Updates to This Policy

We may update this privacy policy to reflect changes in our practices or legal requirements. Significant changes will be communicated via:

  • Prominent notice on our website
  • Request for renewed consent where required

The "Last Updated" date at the top reflects the most recent revision.

14. Contact Information

For privacy-related questions, requests, or complaints:

Email: hello@craftripple.com

Response time: Within 30 days as per GDPR requirements