Privacy Policy.
What we collect, why we use it, who helps us process it, how long it is kept, and the choices you have.
1. Controller and contact
The controller for this website is Juan-Paul du Preez, trading as JDP Studio. For privacy requests or questions, email hello@jdpstudio.com. Known operator details are also set out in the Legal Notice.
2. What we collect
If you send an enquiry, we process the information you enter: name, email address, company (optional), area of interest, and message. To deliver and defend the form, the hosting platform also processes ordinary request data such as IP address, time, user agent, origin, and security headers. Our application logs a shortened one-way hash of the IP rather than the raw IP and never logs the enquiry text or email address.
We also receive anonymous, aggregated page-view information from Vercel Web Analytics, including page, referrer, general location, device, browser, and operating-system categories. It is not tied to a named visitor or retained as a cross-site profile.
3. Purposes and legal bases
- Enquiries and project discussions: to respond, prepare proposals, and take steps at your request before a possible contract (Article 6(1)(b) GDPR where applicable).
- Other correspondence: our legitimate interest in answering relevant business communications (Article 6(1)(f)).
- Security and abuse prevention: our legitimate interest in keeping the form and website reliable, including rate limiting, duplicate suppression, security logs, and an adaptive human-verification challenge (Article 6(1)(f)).
- Anonymous website measurement: our legitimate interest in understanding which pages are useful and improving the site without advertising profiles or tracking cookies (Article 6(1)(f)).
4. Recipients and processors
We use a small number of service providers only as needed:
- Vercel for hosting, serverless functions, request logs, and privacy-focused Web Analytics.
- Resend to deliver your enquiry to our inbox and, when configured, send a receipt.
- Upstash, when configured, to hold short-lived pseudonymous rate-limit counters and duplicate fingerprints.
- Cloudflare Turnstile only when the form identifies an elevated abuse risk and asks for a security check.
We do not sell personal data, use it for behavioural advertising, or add contact-form senders to a mailing list. Data may also be disclosed where required by law or necessary to establish, exercise, or defend legal claims.
5. International transfers
Some providers are based in, or may process data from, countries outside the European Economic Area. Where GDPR transfer rules apply, we rely on the provider's applicable transfer mechanism, such as an adequacy framework and/or the European Commission's Standard Contractual Clauses, together with appropriate safeguards. Resend states that enquiry-delivery data is stored in the United States and that its data-processing terms include the Standard Contractual Clauses.
6. Retention
- Rate-limit counters expire after 10 minutes and duplicate fingerprints after 15 minutes.
- Security and hosting logs are retained according to the applicable hosting plan and only for operational security, troubleshooting, and abuse investigation.
- Enquiry correspondence is normally deleted or anonymized within 24 months after the last substantive contact if it did not lead to a client relationship.
- If an enquiry becomes a client engagement, relevant business records may be kept for the relationship and any longer period required by tax, accounting, limitation, or other applicable law.
We delete data sooner when it is no longer needed, unless keeping it is required by law or necessary for a legal claim.
7. Cookies and local storage
JDP Studio does not set advertising or cross-site tracking cookies. Vercel Web Analytics is cookie-free. If the adaptive Cloudflare security check is triggered, Cloudflare may use strictly technical browser storage or cookies needed to assess and complete that check.
8. Is providing the data required?
There is no statutory requirement to use the form. A name, valid email address, and area of interest are required if you want us to respond through it; without them, we cannot handle the enquiry. You can always contact us directly by email instead.
9. Automated decisions
We do not make decisions with legal or similarly significant effects about you using automated processing. Automated security signals can require a Turnstile check or temporarily slow repeated requests, but they do not evaluate your project or determine whether JDP Studio will work with you.
10. Your rights
Depending on the law that applies, you may have rights to access, correct, erase, restrict, or receive a portable copy of your data; to object to processing based on legitimate interests; and to withdraw consent where consent is the legal basis (withdrawal does not affect earlier lawful processing). Email us to exercise a right. We may need enough information to verify the request.
If GDPR applies, you may also complain to a competent data protection supervisory authority, including the authority where you live, work, or believe an infringement occurred. We would appreciate the chance to address the concern first, but you do not have to contact us before approaching an authority.
11. Security and changes
We use HTTPS, request validation, origin checks, rate limiting, duplicate suppression, limited logging, and access-controlled providers. No system is risk-free. If this site's processing or providers change materially, this notice will be updated and its effective date changed.