Sommaire
1. Who we are
This Privacy Policy explains how EASE° STUDIO ("EASE°", "we", "us", "our") collects, uses, shares, and protects personal information when you visit https://easedesigned.com and any related pages or campaign landing pages we operate (together, the "Site"), contact us, or engage us for brand, web, and motion design services.
We are the controller of the personal information described here. No third party acts as a joint controller with us in respect of this Site.
Controller / contact details
| Trading name | EASE° STUDIO |
| Privacy contact (email) | [email protected] |
2. The short version
We keep this brief because we respect your attention.
- We advertise on Meta platforms (Facebook and Instagram). To measure whether those ads work, this Site runs the Meta Pixel in your browser and sends a matching server-side event through the Meta Conversions API.
- Everything else the Site loads — fonts, images, scripts, styles — is served from our own domain. There is no third-party analytics product and no advertising network other than Meta.
- We collect what you type into the contact form, and we use it to reply to you, to scope the work, and — hashed, never in the clear — to tell Meta that an enquiry happened.
- We do not sell your personal information for money.
3. The data we collect
We collect the categories below. Not every visitor generates every category — for example, if you never submit a form, we hold no contact details from you at all.
3.1 Information you give us directly
When you submit the contact form on our home page, we collect:
| Data | Where it comes from | Why |
|---|---|---|
| Name | Contact form (name="name"), required | To address you correctly |
| E-mail address | Contact form (name="email"), required | To reply to you in writing, and to send the quote |
| Phone number | Contact form (name="phone"), required | To reply to you |
| Company or current website | Contact form (name="links"), optional | To understand the context of the request |
| Your description of the project | Contact form (name="message"), required | To prepare a relevant reply and quote |
If you write to us by email instead of using the form, we of course receive your address and whatever you put in the message.
Local storage. So that a submission is not lost if your connection drops, your browser keeps a copy of the message under the key ease_outbox until our server confirms receipt, then deletes it. It stays on your device, is never read by any third party, and clearing your browser storage removes it.
3.2 Information collected automatically when you browse
Our host records the ordinary server logs any web server produces in order to serve a page and defend itself: IP address, timestamp, the page requested, the referring page, and your browser's user-agent string.
The Meta Pixel additionally collects, on every page view: the page URL, your IP address and user-agent, and the two Meta cookies described in Section 11 (_fbp, and _fbc when you arrive from one of our ads). We do not run third-party analytics software, heatmaps, or fingerprinting.
3.3 Meta Pixel and Meta Conversions API (CAPI) data
This Site uses the Meta Pixel (a script loaded from connect.facebook.net) and the Meta Conversions API (a server-to-server call made by our own Cloudflare Worker). Both report to the same Meta dataset.
What is sent, and when. A PageView event fires on every page. A single Lead event fires only when you submit the contact form and our server accepts it — not when you open the page, not when you click, and not if the submission fails.
Between those two, a small number of events tell Meta that something on the page was used: how far down you scrolled, which service or sector you looked at, which question you opened, that you reached the form, and whether you finished it. They carry only labels we wrote ourselves and numbers — for example { section: "methode" } or { percent: 50 }. None of them carries anything you typed, and none carries your name, e-mail, phone number or message.
What the Lead event carries. Your name, e-mail and phone number are hashed with SHA-256 before they leave our server, so Meta receives an irreversible fingerprint rather than the values themselves. Alongside those we send your IP address, user-agent, the Meta cookie identifiers and the page URL. We never send the text of your message, or the name of your company.
Why the same event goes twice. The browser event and the server event share one identifier, so Meta collapses them into a single Lead. This is deduplication, not double counting: the server leg exists because browser-side tracking is frequently blocked, and without it our measurement would be wrong rather than absent.
Meta acts as an independent controller for the copy it receives, under its own terms. Its privacy policy is at https://www.facebook.com/privacy/policy/, and you can review and change what Meta shows you at https://www.facebook.com/adpreferences.
3.4 Information from third parties
- We do not receive information about you from data brokers, advertising platforms, or any other third-party source. Everything we hold about you, you gave us directly.
- Service providers listed in Section 8 may provide us with technical and security logs relating to your use of the Site.
3.5 We do not knowingly collect
- Payment card numbers — we do not take payments through the Site.
- Precise geolocation.
- Data from children (see Section 14).
4. How and why we use your data (purposes)
| Purpose | What it involves | Categories of data |
|---|---|---|
| Respond to enquiries & scope work | Reading and replying to your form submission or email, preparing proposals, scheduling calls | Name, email, company, message, correspondence |
| Provide design services | Delivering an engagement once you become a client, project communications | Contact and project data |
| Site analytics & improvement | Understanding traffic and how pages perform so we can improve them | Usage data, device/browser, approximate location |
| Security, fraud prevention & abuse | Protecting the Site and our systems, spam filtering on the form, logging | IP, device/browser, usage data |
| Legal & compliance | Keeping records, responding to lawful requests, defending claims, demonstrating consent | Relevant data as needed |
We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
5. Legal bases for processing (GDPR / UK GDPR)
If you are in the EEA or the UK, we rely on the following legal bases under the GDPR / UK GDPR:
| Processing | Legal basis | Notes |
|---|---|---|
| Replying to enquiries and scoping a possible engagement | Steps prior to a contract — Art. 6(1)(b), and/or legitimate interests — Art. 6(1)(f) | Our interest: responding to people who contact us. |
| Performing a signed engagement | Contract — Art. 6(1)(b) | |
| Security, fraud prevention, spam filtering, and essential site operation | Legitimate interests — Art. 6(1)(f) | Our interest: keeping the Site and our business secure and functional. |
| Basic, privacy-protective measurement of our own marketing | Legitimate interests — Art. 6(1)(f) | |
| Keeping records and complying with law | Legal obligation — Art. 6(1)(c), and/or legitimate interests — Art. 6(1)(f) |
Our legitimate-interests assessment. Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms and limited the processing accordingly (e.g. by not using intrusive analytics without consent, by minimising data, and by honouring objections). You can ask for more detail at [email protected], and you can object at any time (see Section 10).
Withdrawing consent. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal — see Section 11 for how.
6. Server-side (CAPI) events
The server-side event is fired by our own Cloudflare Worker at the moment it accepts your contact-form submission, using the details you typed and the Meta cookie identifiers your browser sent with the request. It is not a separate collection of data: it is the same enquiry, reported once more over a channel that ad blockers do not interrupt.
If you would rather it had not been sent, write to [email protected] and we will ask Meta to delete it and confirm to you when that is done.
7. Sharing with Meta, and joint controllership
For the Pixel and Conversions API events described in Section 3.3, we and Meta Platforms Ireland Ltd. act as joint controllers for the collection and transmission of that data, under Meta's Controller Addendum.
In practice: we are responsible for having a lawful basis, for telling you this is happening, and for answering your requests about it. Meta is responsible for what it does with the data once received, and is the contact point for exercising your rights against Meta for that processing.
We do not share your personal information with any other advertising platform, data broker, or network.
8. Other recipients & service providers
We share personal information with a deliberately small set of providers, only as needed to run the Site, reply to you, and measure our advertising:
| Purpose | Provider |
|---|---|
| Website hosting and delivery, TLS, request filtering, server logs | Cloudflare, Inc. (Pages) |
| Receiving, storing and routing contact-form submissions | Cloudflare, Inc. (Workers, KV, D1) |
| Advertising measurement — Pixel and Conversions API | Meta Platforms Ireland Ltd. |
| Lead notifications to the studio | Telegram Messenger LLP |
| E-mail and correspondence when we reply to you | Google LLC (Workspace) |
We do not use an analytics provider or a CRM, and we do not sell personal information for money.
9. International data transfers
Some of our providers — notably Meta, Cloudflare and Google — may process data outside your country or region, including in the United States.
Where we transfer personal data internationally, we rely on an appropriate safeguard, such as:
- the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum / IDTA;
- a valid adequacy decision, where one applies to the destination; and/or
- for transfers to the U.S., a recipient's certification under the EU–U.S. Data Privacy Framework (DPF) and its UK extension, where applicable.
These measures aim to ensure your data receives a level of protection consistent with the laws of your home jurisdiction. You can request a copy of the relevant safeguard (with commercial terms redacted) at [email protected].
10. Your rights (EEA / UK)
If you are in the EEA or the UK, you have the following rights, which you can exercise free of charge in most cases:
- Access — get confirmation of whether we process your data and a copy of it.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — have your data deleted in certain circumstances.
- Restriction — limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interests, and object to direct marketing / profiling for marketing at any time (we will stop).
- Portability — receive certain data in a structured, machine-readable format and have it transmitted to another controller where technically feasible.
- Withdraw consent — at any time, where we rely on consent, without affecting processing already carried out.
- Not be subject to solely automated decisions with legal or similarly significant effects — we don't make such decisions.
- Lodge a complaint with a supervisory authority (see Section 16).
How to exercise. Email [email protected] with your request. We may need to verify your identity. We will respond within one month (extendable by two further months for complex requests, and we'll tell you if so).
11. Cookie Policy
This Site sets two cookies, both belonging to Meta and both used for advertising measurement. It sets none of its own: no analytics cookie and no preference cookie.
Separately from cookies, your browser holds ease_outbox in local storage, described in Section 3.1: a copy of your contact message kept only until our server confirms receipt, so a dropped connection cannot lose it. It is never transmitted with a request and no third party can read it.
11.1 How to control cookies
Control is in your hands and in your browser:
- Block or delete cookies for this domain in your browser's site-data settings. Removing
_fbpand_fbcis enough to break the link between your visit and any ad. - Block
connect.facebook.netwith any content blocker; nothing on the Site depends on it. - Manage what Meta may use at
https://www.facebook.com/adpreferences. - Or write to [email protected] and we will handle it for you.
11.2 Cookie table
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
_fbp | Meta Pixel, first-party | Distinguishes browsers so a later enquiry can be attributed to an earlier ad view | 90 days |
_fbc | Meta Pixel, first-party — only when you arrive from one of our ads | Stores the click identifier from the ad you clicked | 90 days |
No other cookie is set by this Site. If you find one, tell us and we will explain it or remove it.
12. Your California privacy rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights. (Residents of other U.S. states with comparable laws — e.g. Colorado, Connecticut, Virginia, Utah, Texas, and others — have similar rights and may use the same contact methods.)
12.1 "Do Not Sell or Share My Personal Information"
We do not sell your personal information for money. However, sending Pixel and Conversions API data to Meta for advertising measurement is treated as "sharing" for cross-context behavioural advertising under the CCPA as amended by the CPRA, and we tell you that rather than argue about it.
To opt out, use any of these:
- Send a Global Privacy Control signal from your browser or extension; we honour it where we can detect it.
- Block
connect.facebook.net, or delete the_fbpand_fbccookies for this domain. - E-mail [email protected] with the subject "Do Not Share". We will suppress future events and ask Meta to delete what it holds from your visit, then confirm to you.
12.2 Categories collected, "sold/shared," and disclosed
In the last 12 months we have collected the categories described in Section 3: identifiers (name, phone number) and commercial information (what you tell us about your project), both provided directly by you through the contact form.
We have not sold and have not shared any personal information for cross-context behavioural advertising, and we do not do so today. We disclose personal information only to the service providers listed in Section 8, for the purposes stated there.
12.3 Your CCPA/CPRA rights
- Right to know / access the personal information we collect, use, disclose, and share.
- Right to delete personal information we hold about you (subject to exceptions).
- Right to correct inaccurate personal information.
- Right to opt out of "sale"/"sharing" (above).
- Right to limit use of sensitive personal information — note we do not use sensitive personal information for purposes that trigger this right.
- Right to non-discrimination for exercising your rights.
We do not use or disclose sensitive personal information beyond the purposes permitted under the CPRA. To exercise these rights, email [email protected]; we will verify your request and may allow an authorised agent to act for you with proof of authorisation. We aim to respond within 45 days (extendable to 90 with notice). You also have a right to appeal a decision where your state law provides one — reply to our response to start an appeal.
13. Data retention
We keep personal data only as long as necessary for the purposes in this Policy, then delete or anonymise it. Indicative periods:
| Data | Retention |
|---|---|
| Contact-form enquiries that don't become projects | up to 24 months, then deleted |
| Client project records & correspondence | Duration of engagement + 6 years for legal/tax/record-keeping |
| Server & security logs (incl. IP) | Up to 90 days, longer if needed for security investigations |
14. Children
The Site and our services are intended for business clients and adults, and are not directed to children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children, and we do not knowingly sell or share it. If you believe a child has provided us data, contact [email protected] and we will delete it.
15. How we protect your data (security)
We use appropriate technical and organisational measures to protect personal data, including:
- encryption in transit (HTTPS/TLS) across the Site;
- access controls and least-privilege access to enquiry and client data;
- reputable, security-conscious processors under data processing agreements;
- data minimisation — we collect only what we need; and
- routine review of our tools and configuration.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Where required, we will notify you and the relevant authority of a personal-data breach within applicable timeframes.
16. Complaints & supervisory authorities
If you have a concern, please contact us first at [email protected] — we'd genuinely like to put it right.
You also have the right to complain to a data protection authority:
- EEA: your local Data Protection Authority (list:
https://edpb.europa.eu/about-edpb/about-edpb/members_en). - UK: the Information Commissioner's Office (ICO),
https://ico.org.uk/. - California: the California Privacy Protection Agency (
https://cppa.ca.gov/) and the California Attorney General (https://oag.ca.gov/privacy).
17. Third-party links
The Site may link to third-party sites and profiles (for example, Instagram and Are.na in our footer). We are not responsible for the privacy practices of those sites. Please review their privacy policies.
18. Changes to this Policy
We may update this Policy to reflect changes in our practices, our tools, or the law. When we do, we will revise the "Last updated" date above and, for material changes, take additional steps to notify you where appropriate (for example, a notice on the Site or a refreshed consent request). Your continued use of the Site after an update means you accept the revised Policy, except where your consent is required and re-requested.
19. Contact us
Questions, requests, or anything privacy-related:
EASE° STUDIO
Email: [email protected]