privacy.sajw-group.com
Privacy
policy
We collect the minimum needed to run a design studio, we tell you exactly what that is, and we make it straightforward to get it back or have it deleted. This document explains all of it in plain language.
- Effective
- 12 January 2026
- Version
- 1.0
01Who we are
SAJW Group ("SAJW Group", "the studio", "we") is an independent visual design studio registered in the Netherlands, with its studio at Studio 04, Da Costakade, 1053 WL Amsterdam.
For the purposes of the EU General Data Protection Regulation (GDPR) and the Dutch UAVG, SAJW Group is the data controller for personal data collected through sajw-group.com and its subdomains.
Our data protection contact is reachable at privacy@sajw-group.com. We respond to all rights requests within one calendar month.
02What this policy covers
This policy applies to sajw-group.com and to every subdomain we operate, including privacy., tos., nexus., clients. and management.sajw-group.com.
It does not apply to third-party sites we link to. Once you follow an external link, that operator’s policy governs.
Restricted subdomains (nexus, clients, management) additionally process account and project data described in section 04.
03Data we collect
We collect as little as possible, and only where there is a clear reason for it.
- —Enquiry data — the name, email address, company, indicative budget and message you submit through our contact form.
- —Correspondence — emails you send us and our replies, retained so we can pick up a conversation where it left off.
- —Account data (restricted subdomains only) — the username, hashed password, role and access log of authorised client and staff accounts.
- —Project data (client portal only) — milestones, deliverables, files and comments relating to your engagement.
- —Technical data — IP address, user agent, requested URL and timestamp, written to server logs for security and diagnostics.
We do not run analytics of any kind on this site. There is no tracking, no advertising profile, and no third-party pixel on any page you have visited here.
We do not collect special category data.
04Why we process it, and our lawful basis
Under Article 6 GDPR, every processing activity we carry out relies on one of the following bases:
- —Legitimate interests (Art. 6(1)(f)) — responding to enquiries and keeping our systems secure. We have assessed that these interests do not override your rights.
- —Contract (Art. 6(1)(b)) — administering an engagement, providing the client portal, delivering work and invoicing.
- —Legal obligation (Art. 6(1)(c)) — retaining financial records for the seven-year period required by Dutch tax law.
- —Consent (Art. 6(1)(a)) — optional studio updates by email, where you have explicitly opted in. Consent can be withdrawn at any time.
07How long we keep it
- —Unsuccessful enquiries — 12 months from last contact, then deleted.
- —Client records and correspondence — for the duration of the engagement plus 24 months.
- —Invoices and financial records — 7 years, as required by Dutch tax law.
- —Server logs — 30 days, then automatically purged.
- —Portal accounts — deleted within 30 days of an engagement ending, unless you ask us to retain access.
Retention periods are reviewed annually. Anything past its period is deleted, not archived.
08Your rights
Under the GDPR you have the following rights over your personal data, exercisable free of charge:
- —Access — obtain a copy of the personal data we hold about you.
- —Rectification — have inaccurate or incomplete data corrected.
- —Erasure — have your data deleted where we have no overriding obligation to keep it.
- —Restriction — have processing paused while a dispute is resolved.
- —Portability — receive your data in a structured, machine-readable format.
- —Objection — object to processing based on legitimate interests, including any direct marketing.
- —Withdraw consent — at any time, without affecting processing already carried out.
To exercise any of these, email privacy@sajw-group.com. We may ask you to verify your identity. We reply within one month, and will tell you if a request will take longer and why.
If you are unhappy with our response, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority in your country of residence.
09How we protect it
- —TLS encryption in transit on every domain and subdomain we operate.
- —Encryption at rest for all stored project and account data.
- —Passwords stored only as salted hashes — never in plain text, never recoverable.
- —Role-based access, granted on a least-privilege basis and reviewed quarterly.
- —Two-factor authentication required on all internal and management accounts.
No system is perfect. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you directly without undue delay.
10Children
Our services are directed at businesses and are not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact privacy@sajw-group.com and we will delete it.
11Changes to this policy
We update this policy when our practices change. The version number and effective date at the top of this page always reflect the current text.
For material changes affecting how we use your data, we will notify affected clients directly by email at least 14 days before the change takes effect.
This document is provided as a production-ready template. Have it reviewed by qualified counsel in your jurisdiction before publication.
Questions about this document? Write to legal@sajw-group.com.