Privacy Policy
Official Page
1. Data Controller & Scope
Self-Discipline for Freelance Designers (hereafter ‘SDFD’, ‘we’, ‘us’) is the data controller for personal data collected through this website and associated services. This policy applies to all users who access our site, purchase services, or subscribe to our newsletter.
2. Information We Collect
- Account Data: Name, email, billing address, payment method token (stored via Stripe, we never see full card numbers).
- Usage Data: IP address, browser type, pages visited, time on page, referral source (via Google Analytics with anonymized IPs).
- Communication Data: Emails sent to [email protected], content of consultation calls (with notice and consent).
3. Legal Basis for Processing
- Contractual Necessity: To fulfill service agreements (e.g., processing payments, delivering consultations).
- Legitimate Interest: To improve services, provide relevant content, and prevent fraud. We balance your rights by using minimal data and offering opt-out links.
- Consent: For non-essential cookies and marketing emails. Withdrawable at any time via unsubscribe link.
4. Data Sharing & Third Parties
We share data only with:
- Stripe for payment processing (their privacy policy applies to payment data).
- ConvertKit for email newsletters (only email address and name).
- Calendly for scheduling (calendar availability and name).
- Analytics providers (Google, Plausible) with IP anonymization enabled.
We never sell personal data. Third parties are contractually bound to use data solely for the purpose we specify.
5. Data Retention
We retain personal data for the duration of your account plus 12 months (for billing records). Usage analytics are kept for 26 months. After that, data is anonymized or deleted. You may request early deletion by emailing [email protected].
6. Your Rights
- Right to access: receive a copy of your data (within 30 days).
- Right to rectification: correct inaccurate data.
- Right to erasure (‘right to be forgotten’): delete your data, subject to legal obligations (e.g., tax records).
- Right to restrict processing: under certain conditions.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw consent: at any time, without affecting lawfulness of prior processing.
To exercise rights, contact [email protected]. We respond within one month.
7. Cookies & Tracking
We use essential cookies (session, CSRF) and analytics cookies. A cookie banner allows you to accept/reject non-essential cookies. We also use a Facebook pixel for retargeting (opt-out via your Facebook ad preferences).
8. Data Security
We implement SSL encryption, two-factor authentication for staff, regular security audits, and access controls. Payments are processed via Stripe’s PCI-DSS compliant infrastructure.
9. International Transfers
Data may be processed in the US or EU. We use Standard Contractual Clauses (SCCs) for transfers from EEA to US. For UK users, we use an International Data Transfer Agreement (IDTA).
10. Children’s Privacy
We do not knowingly collect data from children under 16. If you believe we have, contact us to delete it.
11. Policy Updates
We will notify you via email of material changes. The latest version is always available on this page.
12. Contact & Complaints
Data Protection Officer: [email protected]. You also have the right to lodge a complaint with your local data protection authority (e.g., ICO in UK, CNIL in France).
