Privacy Policy GDPR / CCPA
Privacy Policy
This section explains what personal data we collect, why we use it, which providers help us process it, and the choices and rights you have under GDPR, UK GDPR and CCPA/CPRA.
- We collect account, usage, survey and communication data to operate and improve VersEngin.
- We use a small set of providers (Webflow, Cloudflare, Memberstack, Cookiebot, GA4, Google Forms, ConvertKit).
- You can control cookies, newsletters and exercise your legal privacy rights at any time.
1) Who We Are & DPO
VersEngin Studio Labs (“VersEngin,” “we,” “us”) is the controller of your personal data for the Services described here, unless stated otherwise. We have appointed a Data Protection Officer (DPO) reachable at dpo@versengin.com. Registered location: Barcelona, Spain.
2) What We Collect
- Account & Identification: name, email, password hash, Memberstack ID.
- Survey Data: responses to product-validation surveys (opinions, preferences, optional demographics where allowed).
- Usage & Device Data: pages viewed, events (e.g., sign-in, survey start/submit), timestamps, approximate location (derived from IP), device/browser metadata; collected via first-party scripts and Google Analytics 4 (only where consent is provided where required).
- Communications: messages or emails you send us; newsletter preferences (via ConvertKit or equivalent).
- Consent & Preferences: cookie and tracking permissions recorded via Cookiebot; newsletter and communication preferences; and locale choices stored in your account or browser.
- Cookies & Similar Tech: see Cookies Policy.
3) Why We Process Your Data (Legal Bases)
- Provide the Services — Contractual necessity (GDPR Art. 6(1)(b)).
- Security & abuse prevention — Legitimate interests (Art. 6(1)(f)).
- Analytics cookies & measurement — Consent (Art. 6(1)(a)) where required; withdraw anytime.
- Legal obligations — Legal obligation (Art. 6(1)(c)).
4) How We Use Data
We use data to operate the site, authenticate users, deliver surveys, analyze engagement (where consent is required and provided), detect abuse, communicate with you (with your opt-in), and improve features.
5) Sharing & Disclosure
We share personal data with trusted providers under appropriate agreements, or as independent controllers where applicable:
- Hosting & CMS: Webflow.
- Edge & Security: Cloudflare (DNS/CDN/Workers/KV).
- Auth & Membership: Memberstack.
- Analytics: Google Analytics 4 (consent-respecting).
- Consent Management: Cookiebot by Usercentrics.
- Forms/Email: Google Forms and ConvertKit.
- Embedded Media & Social: platforms you choose to interact with.
6) International Transfers
Where data is transferred outside the EEA/UK, we rely on adequacy decisions or appropriate safeguards (e.g., SCCs/UK IDTA) where applicable.
7) Retention
We keep personal data only as long as needed: account data for the life of the account; survey data for validation windows (typically up to 24 months unless aggregated/anonymized sooner); analytics data per provider configuration; and longer where required by law.
8) Children’s Privacy
The Services are not directed to children under 13. If you are under the age of digital consent in your country, you must obtain parental consent as required by law.
9) Your Choices
- Consents: manage cookie consent anytime via Cookies Policy.
- Comms: unsubscribe via links in messages.
10) Your Rights
See Data Protection & User Rights for region-specific details.
11) We Do Not Sell or Share Personal Information
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising without consent where required.
12) Changes to This Privacy Policy
We may update this Privacy Policy. We will update the “Last Updated” date and, where required, notify you and/or seek consent for material changes.
Data Protection & User Rights
This section explains your privacy rights under GDPR/UK GDPR and CCPA/CPRA, and how to exercise them with VersEngin.
- You can request access, correction, deletion or a copy of your data.
- You can object to certain uses (e.g. analytics/marketing) and withdraw consent.
- You can contact your data protection authority, but we encourage you to contact us first.
1) GDPR / UK GDPR (EEA/UK)
Subject to conditions and exemptions, you have the right to access, rectification, erasure, restriction, data portability, and to object to processing.
2) CCPA/CPRA (California)
California residents have rights to know, delete, correct, and opt out of “sale” or “sharing” where applicable. VersEngin does not sell personal information.
3) How to Exercise Your Rights
Email dpo@versengin.com with the subject line “Privacy Request” and indicate your region (e.g., EEA, UK, California). We may need to verify your identity.
4) Complaints
EEA/UK users may lodge a complaint with their supervisory authority (e.g., AEPD in Spain, ICO in the UK). We encourage you to contact us first so we can address your concerns.
Contact & Legal Notice
This section tells you who is behind VersEngin, how to contact us about privacy or legal matters, and provides service provider identification required for websites operating from Spain.
- Operated from Barcelona, Spain.
- Privacy contact: dpo@versengin.com.
- Hana Verse is a fictional digital persona, not a separate legal entity.
1) Identity & Contact
Service provider (Spain): VersEngin Studio Labs
Tax ID: Y1002511R
Address: 08019 Barcelona, Spain
Email (DPO/Privacy): dpo@versengin.com
The “Hana Verse” persona is a fictional digital character used as a brand and creative interface for VersEngin; it is not a separate legal entity.
2) Notices; Service of Process
Formal notices should be sent to the email above. For service of process, contact us by email to arrange a proper address and method consistent with applicable law.
3) Accessibility
To request an alternative format of any policy or to report an accessibility issue, contact dpo@versengin.com.
This document is provided to meet common global requirements for online services. It does not constitute legal advice.