GDPR / RODO
GDPR notice for EU residents
We're a US studio (California) β but because we serve clients in the EU, GDPR still governs how we handle their data. This document supplements our general Privacy Policy with the formally-required details.
Effective: April 27, 2026
01Who we are
Aarons Zatorski is a US (California-based) digital studio. Because we serve clients in the European Union β including Poland β our processing of EU residents' personal data falls under the GDPR (Regulation 2016/679) per Article 3(2) (extraterritorial scope).
GDPR contact: hello@aaronszatorski.com.
02Purpose and legal basis
Performance of a contract or pre-contract steps β Art. 6(1)(b) GDPR (free-preview form, active clients).
Issuing invoices / receipts and bookkeeping β legal obligation under US tax law, Art. 6(1)(c) GDPR.
Service security and monitoring β legitimate interest, Art. 6(1)(f) GDPR.
03Data categories
Identification (business or individual name), contact (email, optional phone), transaction (invoice or receipt number, amount), technical (IP, user-agent β server logs only, 14 days).
04Retention period
Form submissions: 24 months from last contact.
Active client data: duration of the engagement + 7 years (US tax and bookkeeping retention requirements for transaction records).
Server logs: 14 days.
05Data recipients
Hosting provider (Hetzner Online GmbH, Germany / Finland) β processed within the EU.
Email provider (Brevo, France) β processed within the EU.
External bookkeeping β to the extent needed to maintain records.
AI tooling (OpenAI / OpenRouter, USA) β used during project generation. Operates within our own US infrastructure.
06Transfers outside the EEA
Some processing (our US-side infrastructure and AI tooling) takes place outside the EEA β in the United States. For those transfers we rely on the EU Standard Contractual Clauses per Commission Implementing Decision 2021/914, plus appropriate technical and organizational safeguards.
07Your rights
You have the right to: access, rectify, erase, restrict processing, port your data, and object to processing based on our legitimate interest.
To exercise any right, email hello@aaronszatorski.com. We respond within 7 business days at no charge.
You also have the right to lodge a complaint with your local EU supervisory authority (for example, the Polish DPA β uodo.gov.pl β for residents of Poland).
08Automated decision-making
We do not make fully automated decisions about you. Our AI system generates draft websites and copy β but every project is reviewed by a human before it reaches you.
10Is providing data mandatory
Providing data is voluntary, but required to fulfill your request (preview form, contract signing, invoice issuance). Without it we cannot deliver the service.
Pytania? Napisz na hello@aaronszatorski.com.