Privacy Policy
Last updated:
This Privacy Policy explains how personal data is processed when you visit krejci3d.com, contact me, or use a private client portal. It is intended to provide the information required by the EU General Data Protection Regulation (GDPR) and the Czech Electronic Communications Act.
1. Data Controller
The controller is Filip Krejci, an independent 3D artist based in Prague, Czech Republic. For privacy questions or to exercise your rights, email filip@krejci3d.com.
2. Data Processed and Why
Website delivery and security
When you request a page, the hosting infrastructure necessarily processes technical data such as your IP address, request date and time, requested URL, response status, browser or user-agent information, and referring page. This is used to deliver the website, maintain security, diagnose faults, and prevent abuse. The legal basis is my legitimate interest in operating a secure and reliable website (Article 6(1)(f) GDPR).
Analytics — optional
If you enable analytics, Google Analytics processes information about website use, including page views, session information, device and browser characteristics, and approximate location derived from an IP address. Google Analytics is configured without Google Signals or advertising personalisation. Google states that IP addresses are not logged or stored by Google Analytics. The legal basis is your consent (Article 6(1)(a) GDPR and Section 89(3) of the Czech Electronic Communications Act). Analytics does not load before consent.
External media — optional
Project videos and private review media may be stored, encoded, or delivered through Vimeo, YouTube, Google Drive, Bunny Stream, or Cloudflare Stream. When you enable external media, these providers can receive your IP address, browser information, the page containing the media, and information about playback or interaction. The legal basis for loading playback services in your browser is your consent (Article 6(1)(a) GDPR and Section 89(3) of the Czech Electronic Communications Act).
Enquiries
If you contact me by email or through the enquiry form, I process your name, email address, message, and any information or files you choose to send so I can respond, prepare a quote, or discuss a project. The form also processes limited technical and timing data needed to validate the request, rate-limit submissions, and prevent spam. Cloudflare Turnstile may process browser and security signals for bot detection if it is enabled. The legal bases are taking steps at your request before entering a contract (Article 6(1)(b) GDPR) and my legitimate interests in responding to correspondence and protecting the form from abuse (Article 6(1)(f) GDPR).
Private client portals
A private portal may contain a client's name, project name, project status, feedback guidance, versions, and project media. Project videos may be stored and encoded by Bunny Stream or Cloudflare Stream on my behalf. Access tokens and administrator session data are processed to restrict access and protect project information. The legal bases are performance of a contract (Article 6(1)(b) GDPR) and my legitimate interest in secure project administration (Article 6(1)(f) GDPR). Portal pages are marked noindex and are not intended for public access.
3. Cookies and Local Storage
Optional technologies remain disabled unless you actively consent. Rejecting them does not prevent you from browsing the website. The choices “Accept all” and “Reject non-essential” are available at the same level. You can also choose analytics and external media separately.
- Privacy preference (essential local storage): stores whether analytics and external media are allowed, the consent version, and the time of your choice. It is read only in your browser. An accepted choice is requested again after 12 months; a rejected choice after 6 months.
- Enquiry-form security (essential session cookie): created only when you open the enquiry form, binds a short-lived security token to your browser, and expires when the browser session ends.
- Google Analytics (optional): may set
_gaand_ga_<container-id>to distinguish visits. These cookies can last up to 2 years, subject to your browser settings and Google's controls. - External media (optional): Vimeo, YouTube, Google Drive, Bunny Stream, or Cloudflare Stream may use cookies or similar storage when their content is loaded. Their names and durations are controlled by the relevant provider and can change.
- Private portal access (essential): after a valid access link is used, a secure HTTP-only access cookie keeps the token out of the address bar and remains valid for up to 60 days. A separate secure administrator session cookie is used only after an authorised administrator signs in and expires with the session.
4. Recipients and Service Providers
Personal data may be processed by the following recipients only where relevant:
- WEDOS Internet, a.s. — website and email hosting infrastructure.
- Google Ireland Limited and its group companies — Google Analytics, YouTube, and Google Drive.
- Vimeo.com, Inc. — embedded project video.
- BunnyWay d.o.o. — private project video streaming where used.
- Cloudflare, Inc. — Cloudflare Stream video storage, encoding, delivery, and playback, and Turnstile bot protection where enabled.
I do not sell personal data, use it for cross-context behavioural advertising, or make it available to data brokers.
5. International Transfers
Some external providers may process data outside the European Economic Area, including in the United States. Where required, transfers are covered by an applicable European Commission adequacy decision, including the EU–US Data Privacy Framework for participating organisations, or by safeguards such as the European Commission's Standard Contractual Clauses. Provider privacy notices contain further details about their transfer mechanisms.
6. Retention
- Hosting and security logs are retained only for the period needed for security, diagnostics, service operation, and applicable legal obligations, according to the hosting provider's retention controls.
- Pseudonymous enquiry-form rate-limit and duplicate-prevention records become eligible for automatic deletion after 24 hours and are removed during subsequent form maintenance. They do not contain the enquiry text or email address.
- Google Analytics user- and event-level data is configured for a retention period of 14 months. Standard aggregate reports may remain available for longer.
- Email enquiries that do not lead to a project are normally deleted within 12 months after the conversation ends.
- Client portal records, project correspondence, and stored review media are retained for the project and ordinarily for up to 3 years afterwards where needed to handle follow-up work or legal claims. Media may be deleted earlier when it is no longer needed. Records subject to accounting or other statutory duties may be kept for the legally required period.
7. Your Rights
Subject to the conditions in the GDPR, you may request access to your personal data, correction, deletion, restriction, or portability. You may object to processing based on legitimate interests. Where processing is based on consent, you can withdraw that consent at any time without affecting processing that was lawful before withdrawal.
To exercise a right, email filip@krejci3d.com. I may need to verify your identity before fulfilling a request. You also have the right to complain to the Czech supervisory authority, the Office for Personal Data Protection (ÚOOÚ), or to the supervisory authority where you live or work.
8. Withdrawing Consent
Use “Cookie Settings” in the footer at any time. Withdrawing analytics consent disables further analytics collection and removes accessible Google Analytics cookies from this site. Withdrawing external-media consent unloads embedded providers; you can continue using the rest of the site.
9. Security
I use measures appropriate to this website, including HTTPS, access controls, private no-store responses for portal pages, restricted administrator sessions, security headers, one-time form tokens, rate limiting, and anti-spam checks. No internet service can guarantee absolute security. If a personal-data breach creates a risk to individuals, it will be handled and notified as required by Articles 33 and 34 GDPR.
10. Automated Decisions and Children
I do not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects. The website and services are directed to business clients and are not intentionally directed to children.
11. Changes to This Policy
I may update this policy when the website, providers, or legal requirements change. The date at the top shows the latest revision. If a change materially affects an existing consent, the website will request a new choice.