Skip to content

Privacy notice

Version 4 October 2026. This notice explains how Studio in One handles personal data, the providers involved and your rights. Planned services are identified separately below.

1. Who is responsible?

Studio in One can be contacted at info@studioin.one, +31 6 57688804 or Zijdepark 9H, 2935 LB Ouderkerk aan den IJssel, Netherlands. Chamber of Commerce number 86655299; VAT number NL004287961B68.

Studio in One determines the purposes of processing for its own website, enquiries, customer administration and support. A photographer using the platform determines the purposes for their clients' data and photographs. For that studio content, Studio in One acts as a processor under a separate data processing agreement. For a photography project or image, contact the relevant photographer first.

2. Data and purposes

Enquiries: name, email, optional business name, subject, message, requirements, photography type and any website you supply. We use these to respond and prepare a possible proposal. The legal basis is steps requested by you before a contract, or our legitimate interest in responding to business enquiries. We cannot respond without the necessary contact details. Do not send unnecessary sensitive information.

Services: business and contact details, agreements, support records, account and access details, documents and financial administration. We process them to perform the contract, provide support, protect the service and meet statutory record-keeping duties. The bases are contract, legal obligation and our legitimate interests in secure services and documenting arrangements.

Website and security: IP addresses, request and browser details, timestamps, errors and technical security signals may be processed for delivery, troubleshooting and abuse prevention. We limit data and access to what those interests require. Analytics and marketing follow the existing consent choices and settings. Change your choices through the cookie controls; the current cookie declaration is at /en/cookies.

3. Providers and recipients

Vercel supplies the current hosting, request processing, delivery/cache, technical logs and existing Blob media storage. Neon manages PostgreSQL; this instance's database is placed in AWS eu-central-1. Database placement is not a promise that all support or log processing occurs only in the EU.

Google Workspace is currently connected for email and calendar. Addresses, messages, attachments, participants and appointment details may be processed for those functions. Recipients and their email providers receive messages we actually send. Microsoft 365/Graph and an IMAP/SMTP provider are supported alternatives, used only when the relevant account is connected and used. Amazon SES does not automatically replace transactional mailbox services.

Cloudflare Turnstile may process technical browser, network and challenge signals during protected interactions to prevent abuse. Its processing and roles also follow Cloudflare's Turnstile privacy information. This is not newsletter or marketing consent.

Stripe and Mollie are supported payment providers. Relevant name, contact, amount, transaction and payment details are transferred only for a configured payment flow. Providers may be independent controllers for statutory and fraud-prevention purposes. Requesting a proposal on this sales website does not start a payment.

Map functions may use OpenFreeMap for map tiles and Geoapify for address geocoding, involving browser/network details or relevant address/location data. OpenStreetMap is a map source and MapLibre is a browser library. Their availability does not justify sending all visitor details or client addresses to them.

Google Tag Manager and Meta Pixel/Conversions API are not currently configured on this instance. Any future activation requires a renewed assessment of purposes, events, identifiers and consent. External YouTube, Vimeo or Google Maps embeds receive data only if that content is actually used and the applicable consent is given. These sales pages do not require such embeds.

Authorised staff and service providers receive only necessary access. Advisers, accountants and authorities receive information where required for an engagement, statutory duty or legal claim. We do not sell personal data. You can request information about the subprocessors relevant to your service at info@studioin.one.

4. Planned newsletters: Amazon AWS

Amazon Simple Email Service (SES), with Amazon Simple Notification Service (SNS) for delivery, bounce and complaint feedback, is being prepared and is not deployed yet. Planned data includes email address, optional name, signup source, date and consent evidence, campaign content and sending, opt-out and suppression status. AWS processes the information needed to deliver messages and feedback. An EU SES region is planned; the actual region, agreements, logging and transfer safeguards must be confirmed before activation.

Newsletters are planned on the basis of separate consent. Contact and proposal forms do not subscribe you. Every newsletter must offer an unsubscribe option. New marketing sends stop after withdrawal; a limited suppression record may remain necessary to respect your choice. Open/click tracking is not assumed and requires its own assessment.

5. Planned galleries: Cloudflare R2

Galleries using Cloudflare R2, Workers, Containers and Durable Objects are being prepared and are not deployed yet. Planned data includes photographs/videos and derivatives, file metadata, verification emails, access rights, favourites, download and order records. Identifiable people and location metadata are personal data. The photographer must determine an appropriate basis, retention period and sharing settings.

The planned architecture provides for private R2 storage and processing in an EU jurisdiction. Global Cloudflare queues carry opaque tenant/job identifiers and have no EU location guarantee. Support and other provider components may also involve international processing. Access, processing, purchase retention and deletion require renewed checks before activation. Purchased files may have a separate retention purpose, so deleting a gallery does not necessarily immediately delete all purchased files.

6. Transfers outside the EEA

International providers and subprocessors may access or process data outside the European Economic Area even where primary storage is in the EU. Before use, recipients, countries and GDPR safeguards must be established: an applicable adequacy decision or standard contractual clauses, with additional assessment and measures where needed. EU storage alone does not replace that assessment. Contact info@studioin.one for information or a copy of applicable safeguards; security-sensitive details may be redacted.

7. Retention and deletion

We retain enquiries for as long as needed to answer and follow up the request, then delete or anonymise them unless an agreement, dispute or legal duty justifies retention. Technical logs are retained only as needed for service delivery, security and troubleshooting; incident records may be retained longer to investigate the incident or defend legal claims. When deciding retention, we consider the purpose, the last relevant contact, applicable legal periods and the technical backup cycle. Deleted data may remain temporarily in restricted rolling backups until their normal expiry; a restoration must respect earlier deletion requests. Contact us for the retention information relevant to your specific records.

Contracts follow the agreed service term and export/deletion arrangements. Financial records subject to Dutch statutory duties are generally retained for 7 years; specific exceptions may require longer. Consent evidence, necessary suppression records, incident records and legal-claim documentation need separately justified periods. Photographer content follows their instructions, the processing agreement and any purchase-retention requirement. Backups require restricted access and must not be reused for ordinary processing purposes.

8. Security and incidents

Appropriate measures include secure connections, limited permissions, protected credentials, access controls and recovery procedures. Absolute security cannot be guaranteed. We limit incident consequences and assess notification duties. Photographer content is processed within agreed instructions and permissions, without unrestricted staff access for unrelated purposes.

9. Your rights

You may request access, correction, erasure, restriction, portability or object where the GDPR provides those rights. Withdraw consent without affecting earlier lawful processing. You may always object to direct marketing. Email info@studioin.one. We request only information needed to verify your identity, not a full identity-document copy by default.

We normally respond within one month. Complex requests may qualify for a statutory extension, with an explanation within the first month. Legal retention and other people's rights may limit deletion. You can complain to the Dutch Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl. For data controlled by a photographer, we support the photographer in handling your request.

10. Other information and changes

The service targets professional studios, not independent registration by children. Studio content may include minors; the responsible photographer must arrange suitable information and legal bases. This sales setup does not provide for solely automated decisions with legal or similarly significant effects. Technical abuse detection does not assess your professional suitability.

Data comes from you, your organisation, a relevant photographer or accounts you authorise. New purposes or providers will be explained in advance where required. This version was published on 4 October 2026. Material changes will be communicated appropriately.