GDPR / RODO

GDPR notice for EU residents

We're a US studio (California) β€” but because we serve clients in the EU, GDPR still governs how we handle their data. This document supplements our general Privacy Policy with the formally-required details.

Effective: April 27, 2026

01Who we are

Aarons Zatorski is a US (California-based) digital studio. Because we serve clients in the European Union β€” including Poland β€” our processing of EU residents' personal data falls under the GDPR (Regulation 2016/679) per Article 3(2) (extraterritorial scope).

GDPR contact: hello@aaronszatorski.com.

02Purpose and legal basis

Performance of a contract or pre-contract steps β€” Art. 6(1)(b) GDPR (free-preview form, active clients).

Issuing invoices / receipts and bookkeeping β€” legal obligation under US tax law, Art. 6(1)(c) GDPR.

Service security and monitoring β€” legitimate interest, Art. 6(1)(f) GDPR.

03Data categories

Identification (business or individual name), contact (email, optional phone), transaction (invoice or receipt number, amount), technical (IP, user-agent β€” server logs only, 14 days).

04Retention period

Form submissions: 24 months from last contact.

Active client data: duration of the engagement + 7 years (US tax and bookkeeping retention requirements for transaction records).

Server logs: 14 days.

05Data recipients

Hosting provider (Hetzner Online GmbH, Germany / Finland) β€” processed within the EU.

Email provider (Brevo, France) β€” processed within the EU.

External bookkeeping β€” to the extent needed to maintain records.

AI tooling (OpenAI / OpenRouter, USA) β€” used during project generation. Operates within our own US infrastructure.

06Transfers outside the EEA

Some processing (our US-side infrastructure and AI tooling) takes place outside the EEA β€” in the United States. For those transfers we rely on the EU Standard Contractual Clauses per Commission Implementing Decision 2021/914, plus appropriate technical and organizational safeguards.

07Your rights

You have the right to: access, rectify, erase, restrict processing, port your data, and object to processing based on our legitimate interest.

To exercise any right, email hello@aaronszatorski.com. We respond within 7 business days at no charge.

You also have the right to lodge a complaint with your local EU supervisory authority (for example, the Polish DPA β€” uodo.gov.pl β€” for residents of Poland).

08Automated decision-making

We do not make fully automated decisions about you. Our AI system generates draft websites and copy β€” but every project is reviewed by a human before it reaches you.

09Cookies and local storage

We use only functional cookies (NEXT_LOCALE for language preference, session tokens for the form). No analytics cookies, no marketing cookies. No consent banner because no personal data is collected via cookies.

10Is providing data mandatory

Providing data is voluntary, but required to fulfill your request (preview form, contract signing, invoice issuance). Without it we cannot deliver the service.

Pytania? Napisz na hello@aaronszatorski.com.