Privacy Policy

How we handle your data — transparently, minimally, and with respect.

Last updated: 25 February 2026

The short version

Data controller

Regen Studio B.V. is the data controller responsible for your personal data as described in this policy. Regen Studio is a design and innovation studio registered in The Netherlands (KVK 90337948), with activities in The Hague, The Netherlands and São Paulo, Brazil (CNPJ 57.579.114/0001-55).

This privacy policy applies to the websites at regenstudio.world and demos.regenstudio.world, and to all services offered through these domains.

Contact: info@regenstudio.world

What data we collect and why

We only collect personal data when you actively provide it, or when strictly necessary to deliver a service you requested.

Contact forms and newsletter subscriptions (regenstudio.world)

Purpose: to respond to your inquiry, send newsletters, and notify our team. Legal basis: legitimate interest (GDPR Art. 6(1)(f) / LGPD Art. 7(IX)) and consent (GDPR Art. 6(1)(a) / LGPD Art. 7(I)).

Demo access requests and magic links (demos.regenstudio.world)

Purpose: to verify your identity and grant demo access. Legal basis: performance of a contract (GDPR Art. 6(1)(b) / LGPD Art. 7(V)).

Report purchases (demos.regenstudio.world/cpr-dpp-tracker)

Purpose: to process your order, generate your report, issue an invoice, and provide download access. When accessing a report or invoice, you must verify your email address to prevent unintended data disclosure through URL sharing. Legal basis: performance of a contract (GDPR Art. 6(1)(b) / LGPD Art. 7(V)).

What we do NOT collect

On both our sites, all fonts, scripts, and stylesheets are self-hosted — zero third-party asset requests are made when you browse the page.

Third-party media embeds

A small number of blog posts contain embedded videos (Vimeo) or audio players (SoundCloud). These embeds are not loaded automatically. Instead, you will see an informed consent overlay explaining exactly what data will be shared with the third party (IP address, browser type, operating system, page URL). The embed only loads after you explicitly click “I understand.”

Once you consent and the embed loads, the third party’s own privacy policy applies to the data they receive. We do not control their processing.

Privacy-preserving analytics

On both our websites, we collect aggregate page view statistics to understand which pages are visited. This system is designed from the ground up to be privacy-preserving:

How it works

Your browser sends
page path only
Server hashes your IP
with a daily-rotating salt
Only aggregate counters
persist long-term

Your IP address is used solely to generate a one-way hash for unique visitor counting. The hash formula is: SHA-256(daily_salt + IP + UA). The raw IP is never stored. The salt is automatically rotated every 24 hours via a scheduled database function, making it impossible to track visitors across days. The raw hashes are deleted within 24 hours; only aggregate counts persist.

No session IDs, no cookies, no full URLs, and no user-agent strings are stored. Only the page path, country code (derived from Cloudflare’s edge), and referrer domain are included in aggregate counters.

Because we set no cookies and store no personal data, this analytics system does not require consent under the ePrivacy Directive (Art. 5(3)) or the Dutch Telecommunicatiewet (Art. 11.7a(3)). This architecture mirrors the approach recognized by the French CNIL as exempt from consent requirements.

Local storage

We use your browser’s localStorage in two cases:

In both cases, the stored value contains no personal data (no email, no name). All tokens are programmatically enforced to expire after 24 hours: the code checks the stored timestamp against the current time and removes expired tokens automatically.

We also use sessionStorage (tab-scoped, automatically cleared when you close the tab) to store the previous page path within the same browsing session. This is used solely to understand internal navigation patterns in aggregate analytics. No personal data is stored.

This storage is strictly necessary to provide the service you requested and is exempt from consent under ePrivacy Directive Art. 5(3).

Sub-processors and data storage

We use the following third-party services. Each is contractually bound to protect your data in accordance with applicable data protection laws.

Supabase Inc.

Database hosting, server-side functions, and authentication. All data stored in the EU (Frankfurt, Germany).

EU hosted

Mollie B.V.

Payment processing for report purchases. Dutch payment service provider regulated by De Nederlandsche Bank.

Netherlands

Lettermint

Transactional email delivery: confirmations, magic links, purchase receipts, newsletters, and internal notifications.

EU

Exact Online (Exact Group B.V.)

Accounting software used to manage invoices and financial records. Invoice data is shared with our accountant, Blended Business (The Hague), via Exact Online.

Netherlands

Proton Mail (Proton AG)

End-to-end encrypted email. Contact form submissions and business correspondence are received and stored in our Proton Mail inbox.

Switzerland

GitHub (Microsoft)

Static website hosting via GitHub Pages. Serves HTML, CSS, JS, and font files. No personal data is stored by GitHub on our behalf.

US hosted

International data transfers

Your personal data (form submissions, orders) is stored in the EU (Frankfurt, Germany) via Supabase. Payments are processed by Mollie in The Netherlands. Invoices are managed through Exact Online (The Netherlands). Email is handled by Proton Mail (Switzerland, which has an EU adequacy decision).

The static websites are hosted on GitHub Pages (United States). GitHub serves only static files and does not process personal data on our behalf; however, standard HTTP server logs (including IP addresses) may be temporarily retained by GitHub in accordance with their privacy statement.

For transfers to the United States, we rely on the EU–US Data Privacy Framework where applicable, supplemented by Standard Contractual Clauses (SCCs). For transfers from Brazil, these are covered by LGPD Art. 33 with adequate safeguards.

How we use your data

We do not use your data for marketing (beyond opted-in newsletters), profiling, or automated decision-making.

Who has access

We do not sell, rent, or share your personal data with any third parties beyond the sub-processors listed above. Below is a breakdown of exactly what each party can access:

Data retention

Your rights

Depending on where you are located, you have specific rights regarding your personal data.

GDPR (European Union)

Regulation (EU) 2016/679
  • Access your personal data
  • Rectify inaccurate data
  • Request erasure (“right to be forgotten”)
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

Supervisory authority for The Netherlands: Autoriteit Persoonsgegevens (AP)

LGPD (Brazil)

Lei 13.709/2018
  • Confirmation of the existence of processing
  • Access your personal data
  • Correct incomplete, inaccurate, or outdated data
  • Anonymization, blocking, or deletion of unnecessary data
  • Portability of your data
  • Deletion of data processed with consent
  • Information about entities with which data has been shared
  • Withdrawal of consent

Supervisory authority: ANPD

For visitors from other jurisdictions, we extend the same rights listed above as a matter of good practice, regardless of whether local law requires it.

How to exercise your rights

To exercise any of your rights, contact us at info@regenstudio.world. We will acknowledge your request within 5 business days and respond substantively within 15 days (in compliance with LGPD Art. 18 §5).

If you request deletion, we will erase all personal data we hold about you, except where retention is required by law (e.g., invoice records under Dutch tax law).

Children

Our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.

Use of AI tools

In the spirit of transparency, we disclose that AI-assisted tools (including Claude by Anthropic) are used in the development of this website and in the creation and editing of content. All AI-generated or AI-assisted content is reviewed by our team for accuracy before publication.

No personal data you provide through our forms or services is shared with AI tools. AI assistance is limited to website development, content writing, and internal research. Your data never enters AI training pipelines.

For the most current regulatory information published on our blog, we always recommend consulting official EU sources such as the Official Journal of the European Union.

Changes to this policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated date. If we make material changes that affect how we handle your personal data, we will notify existing newsletter subscribers by email.

Questions about your privacy?

We’re happy to explain anything in this policy in more detail, or to help you exercise your rights.

Contact us