1. Data controller

The controller of your personal data is:

Flamin Joe Studio Dominika Kasprzyk
Polish Tax ID (NIP): 5792303226
Email: hej@flaminjoe.studio

For any matters related to the processing of your personal data, you can contact us at the email address above.

2. What data we collect

2.1. Contact form

When you fill out the contact form, we collect:

  • first name,
  • phone number or email address,
  • the content of your message.

2.2. Newsletter and ebook download

When you sign up to download our free ebook or receive the newsletter, we collect:

  • first name (if you provide it),
  • email address,
  • a record of the marketing consent you gave (its content and date).

You confirm your sign-up in two steps — after filling out the form, we send an email asking you to click a confirmation link. You can withdraw your consent at any time by clicking "Unsubscribe" in the footer of any email, or by writing to hej@flaminjoe.studio.

2.3. Free Marketing Audit (quiz)

When you complete the Free Marketing Audit at /en/marketing-audit/ and request the full report, we collect:

  • first name,
  • email address,
  • your answers to the quiz questions and the calculated score.

We use this data to display your report, email you its extended version, and — if you show interest — contact you about the paid audit or our other services.

2.4. Cookies and analytics

The website uses cookies and analytics tools. The full, automatically updated list of cookies used on this website is in Section 6 below.

2.5. Ordering a paid audit

When you order a paid audit, we collect the billing data passed to the payment provider, plus the information needed to deliver the service: full name, email, company name, tax ID, domain, offer description, competitors, and your questions.

The paid audit form submits data directly to a flaminjoe.studio server maintained by lh.pl, and the server forwards it to our email inbox. The application does not build a separate database from the form content and does not save it in its own logs. The host still logs standard technical data as described in point 2.8, and we retain the received message for the period stated in point 3.

2.6. What we send to AI tools during the audit

During the assessment, we use our company's direct connections to OpenAI, Anthropic, Google Gemini, and Perplexity Sonar. We send only the public information needed to check the company's visibility: brand name, domain, public description of the offer, service area, competitor names, and test questions.

We do not send the tax ID, email address, phone number, payment data, contact-person details, or private notes from the form to these tools. A person reviews the results before they go into the report.

  • Business OpenAI service: we turn off response/history saving. By default, OpenAI does not use data from this service to train its models, but standard safety logs may be retained for up to 30 days.
  • Business Anthropic service: data is not used to train the models. By default, prompts and responses are deleted within 30 days, with exceptions for safety and legal obligations.
  • Paid Gemini service: we turn off conversation saving, and Google does not use the content to improve its products. The Google Search grounding used in the assessment does, however, retain the question, context, and answer for 30 days; this period cannot be disabled.
  • Perplexity Sonar: the content of questions and answers is not stored or used to train the models. Perplexity retains technical billing data, such as the number of units used, the service tier, and the call timestamp.

2.7. Local audit-form draft

While you fill out the audit form, we save a draft in your browser's local storage on that device. The draft never leaves your device until you submit the form. We delete it automatically after a successful submission, or treat it as stale after 7 days. You can delete it earlier with the "Clear draft" button.

We temporarily store the Stripe payment return reference in your browser's current-tab session storage so it doesn't disappear if the form refreshes. We delete it once your data is submitted successfully, or when you close the browser tab.

2.8. Server logs

The server hosting the website automatically logs technical information: IP address, date and time of the visit, browser and operating system type, and the page visited.

3. Purposes and legal bases for processing

Purpose Legal basis (GDPR) Retention period
Responding to contact-form inquiries, business contact Article 6(1)(b) GDPR (steps taken prior to entering into a contract) or Article 6(1)(f) GDPR (legitimate interest) Up to 2 years from the last contact
Calculating your Free Marketing Audit score, emailing the extended report, and contacting you about the results Article 6(1)(b) GDPR (performing the service you requested) and Article 6(1)(f) GDPR (legitimate interest — presenting an offer related to your result) Up to 2 years from the last contact
Sending the newsletter and marketing emails (tips, new resources, offers), delivering the downloaded ebook Article 6(1)(a) GDPR (consent) Until consent is withdrawn
Processing payment, issuing the sales document, and delivering the paid audit Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR (tax and accounting obligations) Contract and billing data: for the period required by law; audit form and report: up to 3 years from delivery; local form draft: up to 7 days or until successfully submitted
Website analytics (Google Analytics 4) Article 6(1)(a) GDPR (consent) 14 months
Marketing and preference cookies Article 6(1)(a) GDPR (consent) As stated in the cookie declaration (Section 6)
Server logs, security, and diagnostics Article 6(1)(f) GDPR (legitimate interest — ensuring security) 12 months

4. Recipients of data

We only use services necessary to run the website, process payments, and deliver the audit. Some providers may process data outside the European Economic Area. The legal basis for such a transfer depends on the agreement and policies of the given provider — it may be an adequacy decision or standard contractual clauses. Where the public documentation does not explain this clearly enough, we say so explicitly below.

Your data may be processed by the following entities:

  • Web3Forms / Web3Creative (Kerala, India; US-East servers) — handles the contact form and the Free Marketing Audit form. The paid audit form does not use Web3Forms. According to public documentation, the provider forwards submissions by email or directly to the specified system and does not store the form content itself; technical logs, which may contain personal data, are periodically deleted every two months. The documentation does not describe the basis for the EEA transfer clearly enough. That's why we limit the data we collect, offer a direct email option, and treat this provider's terms as requiring separate legal review before scaling the process.
  • UAB MailerLite (Lithuania, EEA) — handles newsletter sign-ups, ebook delivery, and marketing messages.
  • Gumroad, Inc. (USA) — alternative channel for delivering the ebook. Transfer to the USA under the EU-US Data Privacy Framework.
  • Stripe Payments Europe, Limited (Ireland, EEA) - payment processor, handles the payment page, payment confirmations, and sales documents.
  • Google LLC (USA) — Google Analytics 4, Google Search Console. Transfer to the USA under the EU-US Data Privacy Framework.
  • OpenAI Ireland Ltd. / OpenAI OpCo, LLC — testing answers and sources via the business OpenAI service. We send only the public company data described in point 2.6.
  • Anthropic, PBC (USA) — testing answers and sources via the business Anthropic service. We send only the public company data described in point 2.6.
  • Google Ireland Limited / Google LLC — testing answers and sources via the paid Gemini service with Google Search grounding. We send only the public company data described in point 2.6.
  • Perplexity AI, Inc. (USA) — testing answers and sources via the business Sonar service. We send only the public company data described in point 2.6.
  • Cybot A/S (Denmark, EEA) — Cookiebot, cookie consent management.
  • lh.pl (Poland, EEA) — website hosting, receiving the paid audit form submission on the flaminjoe.studio server and forwarding it to our email inbox.

5. Your rights

In connection with the processing of your personal data, you have the following rights:

  • the right of access to your data (Article 15 GDPR),
  • the right to rectification of data (Article 16 GDPR),
  • the right to erasure of data — the "right to be forgotten" (Article 17 GDPR),
  • the right to restriction of processing (Article 18 GDPR),
  • the right to data portability (Article 20 GDPR),
  • the right to object to processing (Article 21 GDPR),
  • the right to withdraw consent at any time (Article 7(3) GDPR) — withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal,
  • the right to lodge a complaint with a supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland, kancelaria@uodo.gov.pl.

To exercise any of the rights above, write to us at hej@flaminjoe.studio.

6. Cookies

We use cookies to run the website, for analytics, and to improve user experience. Marketing and analytics cookies only run after you give consent in the banner. You can change your preferences at any time by clicking the cookie icon at the bottom of the page.

Current list of cookies used on this website:

7. Data security

We apply appropriate technical and organizational measures to protect the personal data we process: encrypted HTTPS connections, up-to-date server software, and restricted access to data.

8. Changes to this policy

This policy may be updated to reflect changes in the law or in how we process data. The current version is always available at flaminjoe.studio/en/privacy-policy — the Polish version at flaminjoe.studio/polityka-prywatnosci remains the legally binding one.