How we think about privacy
Three rules guide this policy. Transparency: everything we do with your data is written here, with no cross-references to other documents. Control: you can exercise any of your rights by sending an email, with no forms and no hoops. Minimum: we do not ask for data we do not need, there is no phone field, no profiling and no advertising.
This policy covers alwaysmattersagency.com and our relationship with clients. If you place an order, the order agreement also contains the data protection clauses that apply.
Data controller
Always Matters Agency. Full identifying details and the contact email will be published in the legal notice of this site.
What we collect
the bare minimum needed to help you. From the form: name, email address, business or brand name, billing country and, if you give them, your current website and your VAT number. There is no phone field: we will never call you. If your order goes by custom quote, also the message you write.
Why and on what legal basis
to answer your request and prepare your quote, on the basis of pre-contractual measures taken at your request (Article 6.1.b GDPR) and of your consent, which you tick on the form (Article 6.1.a). If you go on to contract, to perform the contract and to comply with our legal, tax and accounting obligations (Articles 6.1.b and 6.1.c).
How long
messages from requests that do not become orders are kept for one year in the mailbox and then deleted. If there is a contract, data is kept for the duration of the relationship and, afterwards, for the statutory limitation periods: four years for tax matters and six years for accounting and commercial matters.
Who else processes it
Cloudflare, Inc., as hosting provider and for delivering the form email; Stripe Payments Europe, Ltd. (Ireland) as payment gateway, which processes your name, your email and your card details in order to charge for the order; and the provider of the agency’s mailbox. Cloudflare and the mail provider act as processors under a contract compliant with Article 28 GDPR; Stripe additionally acts as an independent controller in order to meet its legal fraud-prevention and payment obligations. The agency never sees or stores your card number. No data is shared with anyone else except by legal obligation. Any international transfers are covered by adequacy decisions or by standard contractual clauses.
Visit measurement with Google Analytics (only if you accept it)
If you accept the measurement notice, we load Google Analytics 4 to learn which pages are visited, through which channel people arrive and which content works. It processes pseudonymous identifiers and technical usage data; we do not use it for advertising or commercial profiling, and advertising signals are disabled.
The legal basis is your consent (Article 6.1.a GDPR), which you can withdraw at any time by clearing this site’s data in your browser: the tool stops loading and the notice asks you again. Declining limits nothing: the site works the same.
The provider is Google Ireland Limited (Gordon House, Barrow Street, Dublin, Ireland), acting as processor, which may transfer data to Google LLC in the United States under the EU-US Data Privacy Framework. Identifiers last at most two years in your browser and measurement data is kept for two months in the tool.
Data protection officer
The studio’s activity does not fall within the cases that require a data protection officer (Article 37 GDPR and Article 37 UK GDPR): we do not process data on a large scale, we carry out no systematic monitoring and we process no special categories of data. There is therefore no designated officer, and privacy queries are handled directly by the studio’s owner.
If you hire us: the data we use to set your project up
To build your site we register your domain in your name, create the project mailbox and open the infrastructure account where the site lives. For that we process your name or company name, tax ID, address and email, and pass them to whoever needs them: the domain registrar (currently Porkbun, United States), the mailbox provider (currently Migadu, Switzerland) and the infrastructure provider (Cloudflare, United States). The legal basis is performance of the contract (Article 6.1.b GDPR).
Domain registration requires an identified holder: that is why you are the holder from day one, and we leave registration privacy (WHOIS) switched on so your details do not show up in public lookups. Switzerland holds an adequacy decision from the European Commission; transfers to the United States rely on the adequacy framework in force or on standard contractual clauses. On handover those accounts pass to your control, you receive the credentials and the agency stops accessing them.
We also receive the signed agreement by email, which is kept as contract documentation. Of the payment we only receive the gateway’s confirmation — amount, date and order reference: your card details never pass through our systems and we do not store them. Both are used only to check the payment and keep the accounts, and are retained for the legal tax and commercial retention periods. They are shared with no one else.
To build your project we use professional artificial-intelligence tools from Anthropic, PBC (United States), with which we produce texts, code and design. The materials you hand over may be processed with them as part of the development, always under service modes that do not use your content to train models; the international transfer is covered by the EU-US Data Privacy Framework.
The data of your site’s visitors
The sites we deliver store no visitor data: the form sends the message to your mailbox and nothing is kept. During development we may see test messages arriving through that form; in that case we act as processor on your behalf, under the Article 28 GDPR terms you sign in the order agreement. When the project is handed over, that access ends.
Security measures
The site is served entirely over HTTPS and has no database: there is no store of personal data to attack. Form messages travel to a mailbox protected with a unique password and second-factor verification; project credentials are kept in an encrypted password manager.
We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR, and review them whenever something relevant changes. Should a breach occur that poses a risk to your rights, we would notify you without undue delay.
Your rights
you may ask us for access to your data, its rectification or erasure, object to the processing, request its restriction or portability, and withdraw your consent at any time without affecting the lawfulness of processing before then. Just write to the contact address published in the legal notice of this site. If you feel we have not handled it properly, you may complain to the Spanish Data Protection Agency (www.aepd.es) or to the supervisory authority of your country of residence.
Automated decisions and minors
we do not build profiles or take automated decisions with legal effects on you. This service is not directed at children under fourteen.
Where it is stored
form data travels straight to our mailbox and is not stored on this website, because there is no database here. What your browser stores on your device is detailed in the cookie policy.
How to exercise your rights, one by one
Access: find out what data of yours we hold and get a copy. Rectification: correct inaccurate data or complete it. Erasure: ask us to delete it when it is no longer needed or you withdraw consent. Restriction: ask us to keep it but not use it while a disagreement is resolved. Objection: ask us to stop processing on grounds relating to your particular situation. Portability: receive the data you gave us in a commonly used format. Withdrawal of consent: at any time, without affecting processing already carried out. And not to be subject to automated decisions: there are none here.
To exercise any of them, an email to the contact address in the legal notice is enough, saying which one. No form and no explanation are needed, except for objection. We reply within one month of receipt, extendable to two if the request is complex, and we would tell you before that first month runs out.
If you believe we have not handled it properly, you may complain to the Spanish Data Protection Agency (www.aepd.es), to the supervisory authority of your country of residence in the EU, or to the Information Commissioner’s Office (www.ico.org.uk) if you are in the United Kingdom, without prejudice to court action.
Changes to this policy
We review this policy every six months and whenever something relevant changes: a new provider, a new purpose or a change in the law. The applicable version is the one published on this page, with its update date at the top. If a change materially affected processing based on your consent, we would tell you and ask for it again.