Privacy Policy
Last updated: 2026-08-07
1. Introduction
Welcome to Mesmerized Studio ("we", "us", or "our"). We are committed to protecting your privacy and ensuring the security of your personal information in full compliance with the EU General Data Protection Regulation (GDPR) and the Dutch Implementation Act (UAVG).
Mesmerized Studio operates our website at mesmerized.studio and provides digital product services including web development, mobile app development, SaaS platforms, e-commerce, SEO, branding, hosting, paid advertising, and automation (collectively, the "Service"). This Privacy Policy explains how we collect, use, process, and protect your personal data.
Data Controller
Mesmerized Studio acts as the Data Controller for your personal data. For data processing related to our automation and AI services, we may act as a Data Processor on behalf of business clients, and a separate Data Processing Agreement (DPA) is available upon request.
Data Protection Officer
We have not appointed a Data Protection Officer (DPO) as we are not required to under GDPR Article 37. Data protection inquiries can be directed to [email protected].
Our Contact Information
Company: Mesmerized Studio
KVK: 85393061
VAT: NL004089148B26
Address: Gerard ter Borchstraat 46, 7944 GP Meppel, Netherlands
Email: [email protected]
Phone: +31 6 26843563
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy, our Terms & Conditions, and our Cookie Policy.
2. Legal Basis for Processing (GDPR Article 6)
We process your personal data only where we have a lawful basis:
- Consent (Art. 6.1.a): Marketing communications, non-essential cookies, personalized advertising
- Contract Performance (Art. 6.1.b): Delivering subscribed services, processing payments, managing subscriptions, project communication
- Legal Obligation (Art. 6.1.c): Tax records, accounting compliance under Dutch law
- Legitimate Interest (Art. 6.1.f): Website security, fraud prevention, analytics (pseudonymized), business operations, portfolio display
3. Personal Data We Collect
Providing your personal data is voluntary but necessary for us to deliver our services. If you do not provide certain information, we may be unable to provide specific services or respond to your inquiries.
3.1 Data You Provide
- Contact Information: Name, email address, phone number (via contact form or booking widget)
- Business Information: Company name, website, project requirements, service preferences
- Subscription Data: Email address for magic link authentication, selected services and tiers, billing address
- Booking Information: Name, email, preferred time slots (via Cal.com)
- Project Information: Files, designs, content, API keys, and specifications you share during project execution
- Communication Data: Messages, feedback, support requests, Trello board activity
3.2 Data Collected Automatically
- IP address (truncated/pseudonymized where possible) and approximate location
- Browser type, version, and language preferences
- Device information (type, operating system, screen resolution)
- Pages visited, scroll depth, time spent, and interaction patterns
- Referral sources, UTM parameters, and conversion paths
- Session recordings and heatmaps (via Microsoft Clarity, with IP masking)
3.3 Payment Data
Payment processing is handled entirely by Stripe. We do not store, process, or transmit your credit card details. Stripe creates a Customer ID linked to your email address, which we reference for subscription management. See Stripe's Privacy Policy.
3.4 Data from AI and Automation Services
If you subscribe to our Automation & AI service, we may process operational data (workflow configurations, API credentials, task descriptions) through N8N and AI providers (OpenAI, Anthropic). This data is processed under your instructions as part of service delivery. Sensitive credentials are encrypted at rest.
4. How We Use Your Data
4.1 Service Delivery
- Providing and maintaining subscribed services (websites, apps, SaaS, e-commerce, SEO, ads, automation)
- Processing subscription sign-ups, upgrades, downgrades, and cancellations
- Managing Stripe billing, invoices, and bundle discounts
- Sending magic link authentication emails for subscription management
- Project communication via email and Trello
- Scheduling calls via Cal.com
4.2 Service Improvement & Analytics
- Analyzing website usage via Google Analytics 4 (with Consent Mode v2)
- Understanding user behavior via Microsoft Clarity heatmaps and session recordings
- Measuring marketing effectiveness via Google Ads and Meta Pixel
- Improving service quality and developing new features
4.3 Communication
- Service-related notifications (project updates, invoices, subscription changes)
- Marketing communications (only with your explicit, withdrawable consent)
- Important policy or security updates
5. Third-Party Data Processors
We share data with the following processors, each operating under their own privacy policies and GDPR-compliant data processing agreements:
| Processor | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing, subscription billing, customer portal | Email, billing address, payment details (processed by Stripe directly) |
| Google Analytics 4 | Website analytics (via GTM Server-Side) | Pseudonymized usage data, conversion events |
| Google Ads | Conversion tracking and remarketing | Conversion events, audience data (with consent) |
| Meta/Facebook | Ad measurement via Pixel and Conversions API | Conversion events (with consent) |
| Microsoft Clarity | Heatmaps, session recordings, user behavior | IP-masked behavioral data |
| Cal.com | Booking and scheduling | Name, email, selected time slots |
| Strapi | Headless CMS for content management | No end-user personal data |
| Hetzner | Server hosting (EU-based) | Server logs, hosted data |
| Cloudflare | CDN, DNS, DDoS protection | IP address (for routing), cached content |
| N8N | Workflow automation (self-hosted) | Workflow configurations, API credentials (for automation clients only) |
| OpenAI / Anthropic | AI-powered task execution (for automation clients only) | Task descriptions, prompts (no personal data unless explicitly provided) |
| SMTP Provider | Delivering contact form and magic link emails | Email content, recipient address |
We do not sell your personal data to any third party.
6. International Data Transfers
Our primary infrastructure (Hetzner, Cloudflare) is EU-based. Some processors may transfer data outside the EEA:
- Google, Meta, Stripe, Microsoft, OpenAI, Anthropic: Data transfers are protected by European Commission Adequacy Decisions (where applicable) and Standard Contractual Clauses (SCCs) executed between us and the processor.
- OpenAI and Anthropic: API data is processed under their respective enterprise DPA terms. No personal data is sent to these providers unless explicitly required for automation client workflows.
You may request a copy of the relevant SCCs by contacting us.
7. Data Retention
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Contact form submissions | Duration of relationship + 2 years | Legitimate interest |
| Subscription & billing data | Duration of subscription + 7 years | Legal obligation (Dutch tax law) |
| Project files & deliverables | Duration of contract + 1 year | Contract performance |
| Website analytics data | 14 months | Consent (Google Analytics 4 default) |
| Session recordings (Clarity) | Up to 30 days | Consent |
| Marketing data | Until consent is withdrawn | Consent |
| Cookie consent preference | 6 months | Consent |
| Language preference cookie | 1 year | Consent |
| Magic link tokens | 15 minutes after use | Contract performance |
8. Your Rights Under GDPR
As a data subject in the EEA, you have the following rights:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate or incomplete data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing (Art. 18): Limit how we use your data
- Right to Data Portability (Art. 20): Receive your data in a machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interest
- Right to Withdraw Consent (Art. 7.3): Withdraw consent at any time without affecting prior processing
- Right to Lodge a Complaint (Art. 77): With your local supervisory authority
To exercise any of these rights, contact us at [email protected]. We will respond within one month (may be extended by two months for complex requests, per Art. 12.3).
9. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or significant effects on you. AI tools (OpenAI, Anthropic) are used exclusively for task execution within our automation service, under client instructions and human oversight.
10. Data Security
- HTTPS/TLS encryption for all data in transit
- Server-side tracking via Google Tag Manager Server-Side (minimizes browser-side data exposure)
- Rate limiting and honeypot protection on contact forms
- Encrypted storage for API credentials and sensitive client data
- Access controls and secure credential management
- Regular security updates and infrastructure monitoring
- Automated daily backups with encrypted storage
11. Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Affected individuals will be notified if the breach is likely to result in high risk.
12. Children's Privacy
Our Service is not intended for individuals under 16 years old. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a minor, please contact us immediately for deletion.
13. Cookies
Detailed information about the cookies we use, their purposes, durations, and how to manage them is available in our Cookie Policy. We use Google Consent Mode v2 and a granular consent banner to ensure compliance with ePrivacy Directive requirements.
14. Data Processing Agreement (DPA)
For business clients who require us to process personal data on their behalf (e.g., through our automation, hosting, or SaaS services), we offer a standard Data Processing Agreement. Contact us at [email protected] to request a copy.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Material changes will be communicated via our website or email. The "Last updated" date below reflects the most recent revision. Continued use of our Service after changes constitutes acceptance of the updated policy.
16. Complaints and Supervisory Authority
You have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens (AP)
Postbus 93374, 2509 AJ Den Haag
Website: autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500
17. Contact Information
Mesmerized Studio
KVK: 85393061
VAT: NL004089148B26
Gerard ter Borchstraat 46, 7944 GP Meppel, Netherlands
Email: [email protected]
Phone: +31 6 26843563
Last updated: August 7, 2026