Skip to main content

Privacy Policy

Last updated: August 25, 2026

1. Introduction

Vediwood Studio (we, us, our) designs and builds websites, brand identities, and the systems behind them. This policy explains what personal data we collect when you visit vediwood.com or work with us, why we collect it, who else sees it, and what you can ask us to do with it.

We have written it in plain English on purpose. A privacy policy you cannot read is not really a privacy policy. If any part of it is unclear, email us and we will explain it properly.

This policy covers this website and our client work. It does not cover other websites we link to. Those sites have their own policies and we do not control them.

2. Who We Are

Vediwood Studio is the data controller for the personal data described here. That means we decide what is collected and why, and we are the ones answerable for it.

You can reach us about anything in this policy at hello@vediwood.com. We read every message ourselves. There is no ticket queue.

3. Information We Collect

You give us some data directly. When you fill in our contact form, request a quote, use the project estimator, apply through our join page, or book a discovery call, we collect your name, your email address, and whatever project details you choose to write. If you subscribe to our newsletter we collect your name and email address.

Some data is collected automatically when you visit. Our host records standard request information, including your IP address, browser type, and the pages you open. This happens for every website on the internet and it is what keeps the site running and secure.

If you accept analytics cookies, we also collect anonymised interaction data: which pages you open, how far you scroll, where you click, and how long you stay. Text you type is masked before it leaves your browser.

We do not collect special category data such as health, race, religion, political views, biometrics, or sexual orientation. Please do not send us any of it. We do not need it and we do not want to hold it.

4. Why We Use Your Information, and Our Legal Basis

We use your data to reply to your enquiry, prepare quotes, deliver project work, invoice you, send updates you asked for, and improve this website. We never sell it. We never rent it. We do not use it to build advertising profiles.

Under UK GDPR every use needs a lawful basis. Ours are these. Replying to your enquiry and delivering work you hired us for runs on contract, Article 6(1)(b). Keeping the site secure and our records straight runs on legitimate interest, Article 6(1)(f). Analytics cookies and marketing emails run on your consent, Article 6(1)(a), which you can withdraw at any time.

Withdrawing consent is easy and costs you nothing. Use the cookie icon in the bottom-left corner of any page, or the unsubscribe link in any email we send.

5. Who We Share It With

We use the following third-party services to operate. Sanity stores and delivers the content on this website. Vercel hosts the site and logs basic request data, including IP address, for performance and security. Cloudinary stores and serves our images. Airtable stores newsletter subscribers and form submissions, which means your name and email address. Resend sends the emails our forms trigger. Cal.com handles discovery call booking and collects your name and email when you schedule. Microsoft Clarity records anonymised page interactions such as clicks and scrolling, with typed text masked before it leaves your browser, under the Microsoft Privacy Statement (opens in a new tab).

Each service operates under its own privacy policy and processes data only on our instructions. None of them get more of your data than their job requires, and none of them are allowed to use it for their own purposes.

Google Analytics is not running on this site today. If we add it later, it will sit behind the same analytics choice in our cookie banner, and nothing reaches it until you accept.

We will also disclose data where the law requires it, such as a court order, a regulator, or a legal obligation we cannot refuse. If that ever happens and we are permitted to tell you, we will.

6. Cookies and Analytics

Our website sets only necessary cookies by default. Those keep the site working and remember the cookie choice you already made.

Analytics cookies are set only after you accept them in our cookie banner, and never before. If you refuse, the analytics script is never loaded at all. It is not loaded and silenced. It simply never runs.

You can change your mind at any time using the cookie icon in the bottom-left corner of any page. Refusing analytics does not limit your access to anything on this site.

Our Cookie Policy explains each cookie by name, what it does, and how long it lasts.

7. How Long We Keep It

We keep data for as long as it is doing a job, and then we delete it.

Enquiries that do not become projects are kept for up to 12 months, in case you come back to us. Client project records and the invoices attached to them are kept for 7 years, because UK tax law requires it. Newsletter subscribers are kept until you unsubscribe. Analytics data is retained by Microsoft Clarity under its own schedule, and session recordings expire automatically.

If you ask us to delete your data sooner, we will, unless a law requires us to keep a specific record. In that case we will tell you exactly what we must keep and why.

8. Where Your Data Is Stored

Some of the services we use are based outside the UK and the European Economic Area, mainly in the United States.

When data moves outside the UK or EEA, it is protected by the safeguards UK GDPR requires, normally Standard Contractual Clauses, an adequacy decision, or an approved certification framework. Our providers publish their own transfer terms, and we do not use a provider that cannot meet this standard.

9. How We Protect It

This site runs over HTTPS on every page. Form submissions are validated on the server, not only in your browser, and carry a hidden field that filters out automated spam. API keys and secrets are stored as environment variables, never in the website code itself.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach ever affects your rights, we will notify the Information Commissioner's Office (opens in a new tab) within 72 hours as the law requires, and we will tell you directly when the risk to you is high.

10. Your Rights

Under UK GDPR you have the right to ask what data we hold about you, to get a copy of it, to have mistakes corrected, and to have it deleted. You can also ask us to limit how we use it, to send it to another provider in a portable format, or to object to us using it at all.

Where we rely on your consent, you can withdraw it whenever you like. Withdrawing consent does not undo anything we did lawfully before you withdrew it.

To make a request, email hello@vediwood.com. We will respond within one month, which is the deadline the law sets. There is no charge. We may ask you to confirm who you are first, so that we do not hand your data to someone pretending to be you.

11. Changes to This Policy

We update this policy when what we do changes, such as a new tool, a new service, or a change in the law.

The date at the top of this page always shows the last update. If a change materially affects your rights, we will do more than change the date quietly. We will say so on the site, and email you where we hold your address.

12. Contact and Complaints

For anything about this policy, or to exercise any of the rights above, email hello@vediwood.com or use the contact form on this website.

If you are not happy with how we handled your data, please tell us first. Most problems are a misunderstanding we can fix quickly. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk (opens in a new tab), and you do not need our permission to do it.