Last updated: December 2024

Introduction

The Igniting Studio is committed to protecting your personal data. This privacy policy details how we collect, use, and protect your personal information when you use our website and services. Please read this document carefully as using our services means you accept the terms described here.

Personal Data We Collect

We may collect the following personal data: (1) Contact information: your name, email address, phone number when you fill out contact forms or email us; (2) Business data: your company name, position, industry when you make business inquiries; (3) Marketing data: your email address when subscribing to our newsletter; (4) Project data: messages, files, documents you share with us during project work; (5) Payment data: billing information (name, address) when ordering our services; (6) Communication data: content of messages, emails, chat conversations, phone calls.

Automatically Collected Data

When using our website, we automatically collect technical data: (1) Your IP address, browser type and version, operating system; (2) Visit data: which pages you viewed, time spent on site, referring pages; (3) Device information: device type, screen resolution, timezone; (4) Referrer information: which search engine or website brought you to us.

Cookies Usage

Our website uses various cookies to improve user experience: (1) Essential cookies: necessary for basic website functionality, cannot be disabled; (2) Analytics cookies: measure website performance and usage through Google Analytics; (3) Marketing cookies: used for remarketing and advertising purposes; (4) Functional cookies: store your preferences and provide personalized content. You can modify cookie settings in your browser at any time.

Google Analytics and Tracking Technologies

We use Google Analytics 4 to measure website performance and analyze visitor behavior. Analytics collects: number of visits, most popular pages, average session time, source/medium data, demographic data (age, gender – anonymously), interest categories. We also use: Google Tag Manager for tracking code management, Facebook Pixel for remarketing purposes, LinkedIn Insight Tag for B2B marketing. These services operate according to their own privacy policies.

Forms and Data Collection

Our various forms collect data: (1) Contact form: name, email, phone number, message; (2) Marketing audit questionnaire: business data, marketing goals, budget, current situation; (3) Project consultation form: project details, expectations, deadlines; (4) Newsletter signup: email address, name (optional); (5) Calendly appointment booking: name, email, time preferences; (6) Quote request: project description, budget, contact details. All form completion is voluntary, but necessary for certain services.

Email Marketing and Newsletter

Our email marketing activities: (1) Monthly newsletter to subscribers; (2) Project updates and communication with clients; (3) Marketing materials to prospects; (4) Event invitations and industry news; (5) Personalized offers based on previous interest. Every marketing message includes an unsubscribe option. We never sell or share our email list with third parties for marketing purposes.

Message and Communication Storage

Communication data storage: (1) Email correspondence saved in our CRM system for client relationship management; (2) Chat conversations logged for customer service improvement; (3) Phone call notes (never audio recordings) for meeting summaries; (4) Project documents and files securely stored in Google Drive; (5) Meeting minutes and project history kept for professional relationship maintenance.

Legal Basis for Data Processing (GDPR)

Our legal basis for data processing: (1) Contract performance: data necessary for service agreement execution; (2) Legitimate interest: website optimization, marketing, client relationship maintenance; (3) Consent: newsletter subscription, marketing communication; (4) Legal obligation: retaining billing and accounting data; (5) Vital interest: data security and system protection. For any legal basis, you have the right to limit or withdraw data processing.

Data Sharing with Third Parties

In certain cases, we share your data with controlled third parties: (1) Technology partners: Google (Analytics), Microsoft (Office 365), Mailchimp (email marketing); (2) Payment providers: PayPal, Stripe for billing; (3) Legal advisors and accountants: for compliance purposes; (4) Subcontractors: for specific project tasks (always with confidentiality agreements); (5) Authorities: only when legally required. We never sell your data to third parties for marketing purposes.

Data Security and Protection

We take serious measures to protect your data: (1) SSL encryption for all data transfers; (2) Two-factor authentication for all systems; (3) Regular security backups; (4) Access limited to necessary personnel only; (5) Regular security audits and updates; (6) Physical protection: servers in secure data centers; (7) Data loss protection with redundant storage; (8) Staff training on data protection protocols.

Data Retention and Deletion

Our data retention periods: (1) Contact data: 2 years without active communication; (2) Marketing data: until unsubscribe or 3 years of inactivity; (3) Project data: 5 years after contract completion (legal requirement); (4) Analytics data: 26 months (Google Analytics default); (5) Financial data: 8 years (legal obligation); (6) Newsletter data: until unsubscribe. For active deletion requests, we comply within 30 days, except for legally required retention.

Your GDPR Rights

Under the European Union General Data Protection Regulation, your rights include: (1) Right of access: you can request what data we have about you; (2) Right of rectification: you can request correction of inaccurate data; (3) Right of erasure: you can request deletion of your data (with valid reason); (4) Right of restriction: suspension of certain processing activities; (5) Right of portability: receiving your data in structured format; (6) Right to object: objection to marketing and profiling; (7) Protection against automated decision-making. You can exercise these rights at info@theignitingstudio.com or in writing.

Marketing and Profiling

Our marketing activities and profiling: (1) Creating interest profiles based on website activity; (2) Sending personalized content based on previous interactions; (3) Displaying remarketing ads on other websites; (4) Conducting A/B tests for email campaigns; (5) Client segmentation for better service delivery. You can object to profiling at any time, which will not affect our basic services.

International Data Transfers

Some of our service providers (Google, Microsoft, Mailchimp) may store data in the United States or other countries. These transfers: (1) Comply with EU-US data protection framework; (2) Are protected by standard contractual clauses; (3) Have compliance certifications; (4) Provide the same level of protection as the EU. We do not transfer data to countries without adequate data protection levels.

Children’s Data Protection

Our services are exclusively for persons over 18 years old. We do not knowingly collect personal data from individuals under 16. If we become aware that we have collected data from a child under 16: we immediately delete it, notify parents/guardians, review our processes for prevention. Parents/guardians can contact us anytime if they believe we have collected data about their child.

Data Breach Management

In case of a data protection incident: (1) We notify the supervisory authority within 72 hours; (2) We notify affected individuals if the incident poses high risk; (3) We document the incident and measures taken; (4) We investigate causes and take preventive measures; (5) We prepare quarterly reports on incidents. We maintain transparent communication with all affected parties.

Data Controller and Privacy Contact

Data Controller: The Igniting Studio, 1033 Budapest, Szentendrei út 89-95., Hungary. Contact person: Fejes Benedek, Email: info@theignitingstudio.com, Phone: +36 30 717 8637. Data Protection Officer: Not required under GDPR Article 37 (small enterprise). Privacy inquiries and complaints: (1) We respond within 5 business days of receipt; (2) We investigate the matter and take necessary measures; (3) We provide detailed response within 30 days; (4) If unsatisfied, you can contact the NAIH (National Authority for Data Protection and Freedom of Information). Supervisory Authority: NAIH – 1125 Budapest, Szilágyi Erzsébet fasor 22/C.

Changes and Updates

This privacy policy may be updated from time to time: (1) We notify of significant changes via email; (2) Minor modifications are indicated on the website; (3) All changes are announced at least 30 days before taking effect; (4) Previous versions are available in archives; (5) Continued use indicates acceptance of new terms. Regularly check this page for the latest information.

The Igniting Studio

We handle the digital side, you focus on your next big move. Your creative partner for digital growth.

Don't want to miss any marketing news and updates about our services?

Sign up to our newsletter!


© 2025 The Igniting Studio. All rights reserved. Made with love for amazing clients.