01 / Who controls your data
Moviadesign Studio is operated jointly. The joint controllers for personal data
processed through moviadesign.studio are:
Jakob List, Konrad-Broßwitz-Straße 45, 60487 Frankfurt am Main,
Germany; and
Sergio La Gattuta, Via Giacomo Puccini 4, 90030 Villafrati (PA),
Italy.
Additional provider information is available in our Imprint.
Privacy contact: [email protected]
You may exercise your data-protection rights against either joint controller. The email address above is the common contact point for privacy enquiries.
02 / Data we collect
Information you provide
- your email address;
- the project description and project type you submit;
- information contained in later correspondence; and
- any other information you voluntarily include in your message.
Technical information
When the Website is requested, hosting, security and content-delivery systems may process technical data such as IP address, browser and device information, requested URL, referring page, date and time, and diagnostic or security logs.
Please avoid submitting sensitive personal data or confidential third-party information unless it is necessary and you are authorised to share it.
03 / Purposes and legal bases
We process personal data only where there is an appropriate legal basis:
- to respond to project enquiries and take steps requested before entering a contract (Article 6(1)(b) GDPR);
- to manage professional communications, improve the Website, prevent abuse and keep systems secure in our legitimate interests (Article 6(1)(f) GDPR);
- to meet legal, tax, accounting or regulatory obligations (Article 6(1)(c) GDPR);
- where we specifically ask for consent, for the purpose explained at that time (Article 6(1)(a) GDPR).
We do not use Website enquiries for automated decision-making that produces legal or similarly significant effects.
04 / Contact form
The contact form sends your email address, project type and message to our own Website endpoint. We do not save the submission in our Website database. The endpoint uses Resend, operated by Plus Five Five, Inc., to deliver the enquiry to our shared inbox.
Processing is necessary to respond to your enquiry and to take requested steps before entering a contract (Article 6(1)(b) GDPR) and, where applicable, for our legitimate interest in managing business communications (Article 6(1)(f) GDPR). You may instead contact us directly by email.
05 / External services
We use Cloudflare hosting and content-delivery infrastructure to make the Website available and to protect it against abuse. The provider processes connection data such as IP address, requested URL, browser information, date and time in server and security logs on our behalf. Website scripts and visual assets are served from our own Website rather than loaded directly from jsDelivr or Framer when a visitor opens the page.
Resend processes contact and transactional email data as our email-delivery processor. We have removed Web3Forms from the contact-form data flow.
Links to Instagram and LinkedIn take you to third-party platforms. Their own privacy policies apply once you visit them.
06 / International transfers
Cloudflare and Resend are US providers and may process data outside the European Economic Area. Their data processing addenda include safeguards for international transfers, including the European Commission’s standard contractual clauses where applicable.
Details of the safeguards relevant to a particular transfer can be requested using the privacy contact below.
07 / How long we keep data
We keep project enquiries and related correspondence only for as long as reasonably necessary to respond, evaluate a potential engagement and maintain appropriate business records. As a working default, unanswered or inactive enquiries are deleted or anonymised within 24 months after the last meaningful contact, unless a longer period is needed for a contract, legal obligation or legal claim.
Technical and security logs are generally retained for shorter periods determined by the relevant infrastructure provider and security need.
Hosting and security logs are retained only for the period required by the provider for delivery, troubleshooting and abuse prevention, subject to applicable legal obligations.
Consent choices are stored for up to 180 days. Consent-based visitor statistics are retained for up to 180 days. The temporary analytics session identifier and page counters are deleted when consent is withdrawn or when the browser session ends. We do not save contact submissions in the Website database; copies delivered to our inbox follow the correspondence period described above. Provider-side delivery and security records follow the configured account and contractual retention periods.
09 / Your data-protection rights
Depending on the applicable law and circumstances, you may have the right to:
- receive information about how your data is processed;
- request access to and a copy of your personal data;
- correct inaccurate or incomplete data;
- request erasure or restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing relies on consent; and
- lodge a complaint with a competent data-protection authority.
These rights can be subject to legal conditions and exceptions. We may need to verify your identity before responding to a request.
10 / Children
The Website is intended for professional and business audiences and is not directed to children. We do not knowingly request personal data from children through the project-enquiry form.
11 / Changes to this policy
We may update this Privacy Policy when the Website, our processing or legal requirements change. The date at the top identifies the latest working version. Where appropriate, material changes will be highlighted on the Website.
12 / Contact and complaints
To ask a privacy question or exercise a right, email [email protected].
You may also lodge a complaint with the data-protection authority in the country where you live or work, or where you believe an infringement occurred.
German contact: Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, [email protected].
Italian contact: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, [email protected].
13 / Joint controllership
Jakob List and Sergio La Gattuta have entered into an arrangement pursuant to Article 26 GDPR governing their joint responsibility for the operation of this Website. Both jointly determine the purposes and essential means of Website-related processing. They jointly ensure compliance with transparency obligations, data-subject rights, processor management and appropriate technical and organisational measures. The common contact point for privacy matters is [email protected]. Data subjects may nevertheless exercise their rights against either controller individually.