Privacy policy
This policy explains what personal data TortieByte Studio (“we”, “us”) collects through this informational website, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
App privacy policies
App store privacy pages are available for each TortieByte app:
1. What data we collect
Contact form
When you submit the contact form on this site we receive:
- your email address, so we can reply;
- the topic you select from the dropdown;
- the message you write;
- your privacy acknowledgement (the checkbox you ticked before sending).
We do not ask for your name, phone number, address, or any other identifier. We do not run user accounts, payments, newsletters, analytics, advertising, or profiling on this website. The contact message is delivered to our email inbox through the hosting provider's SMTP service.
Server logs
Our hosting provider (Hostinger) keeps standard web server logs that may include the IP address of your device, the time of the request, the page requested, your user agent string, and the referrer. These logs are used only to operate and secure the website (for example, to investigate attacks or outages). We do not link them to contact form submissions.
Cookies and tracking
This website does not set cookies for analytics, advertising, or profiling. It does not embed third-party trackers. The first public version does not show or link to any TortieByte social media profiles.
Fonts
Typography is currently served by Google Fonts, which transmits your IP address to Google when the page loads. We plan to self-host fonts to eliminate this transfer; until then, the legal basis is our legitimate interest in delivering a readable site (Art. 6(1)(f) GDPR).
2. Why we process this data (legal basis)
- Contact form messages — processing is necessary to answer your enquiry or take steps requested by you before a possible contract, Art. 6(1)(b) GDPR. Where your enquiry is not related to a possible contract, processing is based on our legitimate interest in replying to messages sent to us, Art. 6(1)(f) GDPR. The consent checkbox confirms that you have read this policy before sending.
- Server logs — our legitimate interest in operating a secure website, Art. 6(1)(f) GDPR.
- Fonts — legitimate interest in displaying the site as designed, Art. 6(1)(f) GDPR.
3. How long we keep it
- Contact form messages: kept in our inbox until the conversation is resolved, then archived for up to 12 months, after which they are deleted unless a legal obligation requires longer retention.
- Server logs: rotated by our hosting provider, typically within 14 days.
4. Who we share it with
We do not sell or rent personal data. We share it only with the providers we need to operate the site:
- Hostinger (hosting, server logs, SMTP delivery). Acting as processor under a Data Processing Agreement.
- Google LLC (Google Fonts, font delivery only). May process your IP address. See Google's privacy policy.
Where a provider is based outside the EU/EEA, transfers rely on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework where applicable.
5. Your rights
Under the GDPR you have the right to:
- request access to the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict or object to processing (Art. 18, 21);
- receive your data in a portable format (Art. 20);
- withdraw consent at any time where processing is based on consent (Art. 7(3));
- lodge a complaint with a supervisory authority — for Germany, the data protection authority of your federal state.
To exercise any of these rights, email us at the address listed in the Imprint. We respond within one month.
6. Security
The site is served over HTTPS. Contact form submissions are transmitted to our server over TLS. SMTP credentials are stored outside the public web root and are not committed to source control.
7. Children
This website is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has contacted us, write to us and we will delete the message.
8. Changes to this policy
We may update this policy as the site or its providers change. Material changes will be reflected in the “Last updated” date at the top and, where the change affects existing consent, we will ask again before continuing to process.