Skip to main content
Legal

Privacy Policy

Last updated: 2026-08-07

1. Introduction

Welcome to Mesmerized Studio ("we", "us", or "our"). We are committed to protecting your privacy and ensuring the security of your personal information in full compliance with the EU General Data Protection Regulation (GDPR) and the Dutch Implementation Act (UAVG).

Mesmerized Studio operates our website at mesmerized.studio and provides digital product services including web development, mobile app development, SaaS platforms, e-commerce, SEO, branding, hosting, paid advertising, and automation (collectively, the "Service"). This Privacy Policy explains how we collect, use, process, and protect your personal data.

Data Controller

Mesmerized Studio acts as the Data Controller for your personal data. For data processing related to our automation and AI services, we may act as a Data Processor on behalf of business clients, and a separate Data Processing Agreement (DPA) is available upon request.

Data Protection Officer

We have not appointed a Data Protection Officer (DPO) as we are not required to under GDPR Article 37. Data protection inquiries can be directed to [email protected].

Our Contact Information

Company: Mesmerized Studio
KVK: 85393061
VAT: NL004089148B26
Address: Gerard ter Borchstraat 46, 7944 GP Meppel, Netherlands
Email: [email protected]
Phone: +31 6 26843563

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy, our Terms & Conditions, and our Cookie Policy.

2. Legal Basis for Processing (GDPR Article 6)

We process your personal data only where we have a lawful basis:

  • Consent (Art. 6.1.a): Marketing communications, non-essential cookies, personalized advertising
  • Contract Performance (Art. 6.1.b): Delivering subscribed services, processing payments, managing subscriptions, project communication
  • Legal Obligation (Art. 6.1.c): Tax records, accounting compliance under Dutch law
  • Legitimate Interest (Art. 6.1.f): Website security, fraud prevention, analytics (pseudonymized), business operations, portfolio display

3. Personal Data We Collect

Providing your personal data is voluntary but necessary for us to deliver our services. If you do not provide certain information, we may be unable to provide specific services or respond to your inquiries.

3.1 Data You Provide

  • Contact Information: Name, email address, phone number (via contact form or booking widget)
  • Business Information: Company name, website, project requirements, service preferences
  • Subscription Data: Email address for magic link authentication, selected services and tiers, billing address
  • Booking Information: Name, email, preferred time slots (via Cal.com)
  • Project Information: Files, designs, content, API keys, and specifications you share during project execution
  • Communication Data: Messages, feedback, support requests, Trello board activity

3.2 Data Collected Automatically

  • IP address (truncated/pseudonymized where possible) and approximate location
  • Browser type, version, and language preferences
  • Device information (type, operating system, screen resolution)
  • Pages visited, scroll depth, time spent, and interaction patterns
  • Referral sources, UTM parameters, and conversion paths
  • Session recordings and heatmaps (via Microsoft Clarity, with IP masking)

3.3 Payment Data

Payment processing is handled entirely by Stripe. We do not store, process, or transmit your credit card details. Stripe creates a Customer ID linked to your email address, which we reference for subscription management. See Stripe's Privacy Policy.

3.4 Data from AI and Automation Services

If you subscribe to our Automation & AI service, we may process operational data (workflow configurations, API credentials, task descriptions) through N8N and AI providers (OpenAI, Anthropic). This data is processed under your instructions as part of service delivery. Sensitive credentials are encrypted at rest.

4. How We Use Your Data

4.1 Service Delivery

  • Providing and maintaining subscribed services (websites, apps, SaaS, e-commerce, SEO, ads, automation)
  • Processing subscription sign-ups, upgrades, downgrades, and cancellations
  • Managing Stripe billing, invoices, and bundle discounts
  • Sending magic link authentication emails for subscription management
  • Project communication via email and Trello
  • Scheduling calls via Cal.com

4.2 Service Improvement & Analytics

  • Analyzing website usage via Google Analytics 4 (with Consent Mode v2)
  • Understanding user behavior via Microsoft Clarity heatmaps and session recordings
  • Measuring marketing effectiveness via Google Ads and Meta Pixel
  • Improving service quality and developing new features

4.3 Communication

  • Service-related notifications (project updates, invoices, subscription changes)
  • Marketing communications (only with your explicit, withdrawable consent)
  • Important policy or security updates

5. Third-Party Data Processors

We share data with the following processors, each operating under their own privacy policies and GDPR-compliant data processing agreements:

ProcessorPurposeData Shared
StripePayment processing, subscription billing, customer portalEmail, billing address, payment details (processed by Stripe directly)
Google Analytics 4Website analytics (via GTM Server-Side)Pseudonymized usage data, conversion events
Google AdsConversion tracking and remarketingConversion events, audience data (with consent)
Meta/FacebookAd measurement via Pixel and Conversions APIConversion events (with consent)
Microsoft ClarityHeatmaps, session recordings, user behaviorIP-masked behavioral data
Cal.comBooking and schedulingName, email, selected time slots
StrapiHeadless CMS for content managementNo end-user personal data
HetznerServer hosting (EU-based)Server logs, hosted data
CloudflareCDN, DNS, DDoS protectionIP address (for routing), cached content
N8NWorkflow automation (self-hosted)Workflow configurations, API credentials (for automation clients only)
OpenAI / AnthropicAI-powered task execution (for automation clients only)Task descriptions, prompts (no personal data unless explicitly provided)
SMTP ProviderDelivering contact form and magic link emailsEmail content, recipient address

We do not sell your personal data to any third party.

6. International Data Transfers

Our primary infrastructure (Hetzner, Cloudflare) is EU-based. Some processors may transfer data outside the EEA:

  • Google, Meta, Stripe, Microsoft, OpenAI, Anthropic: Data transfers are protected by European Commission Adequacy Decisions (where applicable) and Standard Contractual Clauses (SCCs) executed between us and the processor.
  • OpenAI and Anthropic: API data is processed under their respective enterprise DPA terms. No personal data is sent to these providers unless explicitly required for automation client workflows.

You may request a copy of the relevant SCCs by contacting us.

7. Data Retention

Data TypeRetention PeriodLegal Basis
Contact form submissionsDuration of relationship + 2 yearsLegitimate interest
Subscription & billing dataDuration of subscription + 7 yearsLegal obligation (Dutch tax law)
Project files & deliverablesDuration of contract + 1 yearContract performance
Website analytics data14 monthsConsent (Google Analytics 4 default)
Session recordings (Clarity)Up to 30 daysConsent
Marketing dataUntil consent is withdrawnConsent
Cookie consent preference6 monthsConsent
Language preference cookie1 yearConsent
Magic link tokens15 minutes after useContract performance

8. Your Rights Under GDPR

As a data subject in the EEA, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data
  • Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing (Art. 18): Limit how we use your data
  • Right to Data Portability (Art. 20): Receive your data in a machine-readable format
  • Right to Object (Art. 21): Object to processing based on legitimate interest
  • Right to Withdraw Consent (Art. 7.3): Withdraw consent at any time without affecting prior processing
  • Right to Lodge a Complaint (Art. 77): With your local supervisory authority

To exercise any of these rights, contact us at [email protected]. We will respond within one month (may be extended by two months for complex requests, per Art. 12.3).

9. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or significant effects on you. AI tools (OpenAI, Anthropic) are used exclusively for task execution within our automation service, under client instructions and human oversight.

10. Data Security

  • HTTPS/TLS encryption for all data in transit
  • Server-side tracking via Google Tag Manager Server-Side (minimizes browser-side data exposure)
  • Rate limiting and honeypot protection on contact forms
  • Encrypted storage for API credentials and sensitive client data
  • Access controls and secure credential management
  • Regular security updates and infrastructure monitoring
  • Automated daily backups with encrypted storage

11. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Affected individuals will be notified if the breach is likely to result in high risk.

12. Children's Privacy

Our Service is not intended for individuals under 16 years old. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a minor, please contact us immediately for deletion.

13. Cookies

Detailed information about the cookies we use, their purposes, durations, and how to manage them is available in our Cookie Policy. We use Google Consent Mode v2 and a granular consent banner to ensure compliance with ePrivacy Directive requirements.

14. Data Processing Agreement (DPA)

For business clients who require us to process personal data on their behalf (e.g., through our automation, hosting, or SaaS services), we offer a standard Data Processing Agreement. Contact us at [email protected] to request a copy.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material changes will be communicated via our website or email. The "Last updated" date below reflects the most recent revision. Continued use of our Service after changes constitutes acceptance of the updated policy.

16. Complaints and Supervisory Authority

You have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens (AP)
Postbus 93374, 2509 AJ Den Haag
Website: autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500

17. Contact Information

Mesmerized Studio
KVK: 85393061
VAT: NL004089148B26
Gerard ter Borchstraat 46, 7944 GP Meppel, Netherlands
Email: [email protected]
Phone: +31 6 26843563

Last updated: August 7, 2026

We value your privacy

We use cookies to keep the site working, understand how it's used, and measure the effectiveness of our marketing. You can choose which categories to allow. See our Privacy Policy and Cookie Policy.