Privacy Policy
Last updated 16 June 2026
- Controller
- Xylora Studios, United Kingdom
- Regime
- UK GDPR + Data Protection Act 2018
- Marketing
- No unsolicited marketing; transactional only
- Advertising trackers
- None used on the Site
- Card data
- Handled by the regulated payment processor; we never see card numbers
- Account retention
- Duration of the account, plus 30 days after closure
- Order records
- 7 years for accounting and tax
- Rights requests
- Responded to within 1 month of receipt
This Privacy Policy describes how Xylora Studios (“the Studio”) collects, uses and discloses personal data in connection with the website at xylorastudios.com and any engagement undertaken by the Studio. It is to be read in conjunction with the Studio’s Terms of Service and Cookies Policy.
The Studio processes personal data fairly, lawfully and transparently, and in accordance with the United Kingdom General Data Protection Regulation, the Data Protection Act 2018 and any other applicable data protection legislation.
Controller and scope
- 1.1
Xylora Studios (“the Studio”, “we”, “us”) operates the website at xylorastudios.com and its sub-pages (the “Site”). For the purposes of the United Kingdom General Data Protection Regulation, the Data Protection Act 2018 and, where applicable, Regulation (EU) 2016/679 (collectively, the “Data Protection Legislation”), the Studio is the controller of personal data collected through the Site or in the course of any engagement with a client (a “Commission”).
- 1.2
This Privacy Policy describes the categories of personal data the Studio processes, the purposes for which such data is processed, the lawful bases relied upon, the recipients with whom such data is shared, the periods for which such data is retained, and the rights of data subjects in relation to such processing.
- 1.3
Where the Studio processes personal data on behalf of a client in the course of performing a Commission, the Studio shall act as a processor and the client shall act as controller. The terms of that processing are set out in the Studio’s Terms of Service and, where applicable, an executed data-processing addendum.
Categories of personal data processed
- 2.1
Identity and contact data. Name, organisation, email address, country and any further contact details voluntarily supplied through the contact form, commission form or account area.
- 2.2
Brief and project data. Project goals, references, links, files, brand materials, constraints, budget indications and any further information voluntarily supplied in support of an enquiry or Commission.
- 2.3
Transactional data. Package selections, add-ons, currency preference, payment status, amount, currency, receipt identifiers, checkout identifiers and limited billing metadata returned by the regulated payment service provider.
- 2.4
Account data. Sign-in identifiers, session metadata, one-time codes and order references associated with any customer account.
- 2.5
Technical data. Internet protocol address, request headers, approximate geographic region, device characteristics, bot-mitigation tokens, operational counters and security event logs.
- 2.6
The Studio does not collect, process or store full payment card numbers, card verification values or banking authentication secrets, all of which are handled exclusively by the regulated payment service provider.
Purposes of processing and lawful bases
- 3.1
Performance of contract. To respond to enquiries, prepare quotes, reserve studio capacity, collect deposits, perform Commissions, manage revision rounds, effect handover and maintain associated records.
- 3.2
Legitimate interests. To safeguard the security and integrity of the Site, to prevent abuse, fraud and chargebacks, to maintain operational logs and backups, to improve the Studio’s services, and to establish, exercise or defend legal claims, in each case where such interests are not overridden by the interests, rights or freedoms of the data subject.
- 3.3
Compliance with legal obligation. To retain accounting and tax records, to respond to lawful requests from regulators or law enforcement, and to comply with applicable consumer-protection requirements.
- 3.4
Consent. Where processing is based on the data subject’s consent — for example, the use of non-essential cookies, optional subscriptions and marketing communications — such consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.
Disclosures and sub-processors
- 4.1
The Studio engages a limited number of vetted sub-processors to operate the Site, process payments, secure traffic and notify production personnel. Each sub-processor is bound by written terms imposing obligations of confidentiality and security at least equivalent to those undertaken by the Studio under this Privacy Policy.
- 4.2
Current categories of sub-processor comprise: a regulated card payment service provider; an edge network and security provider responsible for traffic protection and human-verification challenges on public forms; an application platform provider responsible for authenticated account storage, application database and server-side functions; a typeface delivery provider; and an internal team communications provider used solely for operational notifications.
- 4.3
The Studio shall not sell personal data, shall not rent or hire mailing lists, and shall not disclose enquiry data to advertisers. The Studio may disclose personal data to professional advisers, insurers, regulators or law enforcement where such disclosure is required by law or is necessary to protect the Studio’s legitimate interests.
International transfers of personal data
- 5.1
Certain sub-processors may host or process personal data outside the United Kingdom and the European Economic Area. Where personal data is transferred to a jurisdiction not the subject of an adequacy regulation, the Studio relies on appropriate safeguards, including the United Kingdom International Data Transfer Agreement, the United Kingdom Addendum to the European Commission’s Standard Contractual Clauses, or any successor mechanism recognised by the Information Commissioner’s Office.
- 5.2
Copies of the relevant transfer mechanisms shall be made available to data subjects on reasonable request through the Studio’s support channel.
Retention
- 6.1
The Studio retains personal data only for so long as is necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirement.
- 6.2
Enquiry and contact records: a period of twenty-four (24) months from the date of last contact, following which the records shall be deleted or anonymised, save where retention is required for the establishment, exercise or defence of legal claims.
- 6.3
Quotes, statements of work and Commission records: for the duration of the Commission and for a further period of seven (7) years from completion, for accounting, tax and statutory purposes.
- 6.4
Payment and accounting records: a period of seven (7) years from the date of the transaction, in accordance with applicable tax legislation.
- 6.5
Customer accounts: for the duration of the account, with deletion within thirty (30) days of account closure, save where retention is required by law.
- 6.6
Operational, security and access logs: ordinarily a period of up to ninety (90) days, with longer retention where an active investigation requires it.
- 6.7
Backups are overwritten on a rolling cycle. Deletion requests shall be propagated to production systems immediately and to backup media at the next scheduled rotation.
Rights of the data subject
- 7.1
Subject to the conditions and exceptions provided by the Data Protection Legislation, the data subject is entitled to: (a) request access to personal data; (b) request rectification of inaccurate or incomplete personal data; (c) request erasure of personal data; (d) request restriction of processing; (e) object to processing carried out on the basis of legitimate interests; (f) request portability of personal data supplied by the data subject; and (g) where processing is based on consent, withdraw such consent at any time.
- 7.2
Requests should be submitted through the Studio’s support channel and should contain sufficient information to identify the relevant records. The Studio shall respond within one (1) month of receipt, which period may be extended by two (2) further months where the request is complex or numerous, in which case the data subject shall be notified of the extension and the reasons within the original one-month period.
- 7.3
The Studio may, where reasonably necessary, require verification of identity before acting on a request.
Right to lodge a complaint
- 8.1
The data subject has the right to lodge a complaint with a supervisory authority, in the United Kingdom the Information Commissioner’s Office (ico.org.uk). The Studio would, however, welcome the opportunity to address any concerns through its support channel before such a complaint is made.
Security
- 9.1
The Studio applies technical and organisational measures appropriate to the risks presented by its processing activities. Such measures include: transport-layer encryption (HTTPS) with HTTP Strict Transport Security and TLS 1.2 or later at the edge; role-segregated database access; row-level security on customer-facing tables; parameterised database queries; least-privilege service credentials; storage of secrets in the deployment platform’s secret store and not in source control; edge-level rate limiting, bot mitigation and human-verification challenges on public mutation endpoints; short-lived sign-in links rather than long-lived plaintext credentials; and documented backup, restore and credential rotation procedures subject to periodic review.
- 9.2
No system is capable of providing absolute security. The Studio shall notify the relevant supervisory authority and, where required, affected data subjects in accordance with the timeframes prescribed by the Data Protection Legislation in the event of a personal data breach giving rise to a risk to the rights and freedoms of natural persons.
Automated decision-making and profiling
- 10.1
The Studio does not take decisions producing legal effects or similarly significant effects concerning data subjects on the basis of automated processing alone. Fraud signals returned by the payment service provider and abuse signals returned by the edge network and security provider are used solely to inform manual review by Studio personnel.
Marketing communications
- 11.1
The Studio does not despatch unsolicited marketing. Where a data subject opts in to receive Studio updates, that data subject may unsubscribe at any time via the unsubscribe mechanism contained in each such communication, or by contacting the Studio through its support channel. Transactional communications necessary for the operation of an account or Commission are not marketing and shall be despatched regardless of marketing preferences.
Children
- 12.1
The Site is not directed at children under the age of sixteen (16). The Studio does not knowingly collect personal data from children. Where the Studio becomes aware that it has inadvertently collected personal data from a child, such data shall be deleted as soon as reasonably practicable.
Materials supplied by the data subject
- 13.1
Where a data subject submits logos, copy, photographs, footage, music, documents or other materials, that data subject warrants that he or she is entitled to share such materials with the Studio and to grant the Studio a licence to use them for the purpose of the relevant Commission.
- 13.2
Such materials may be retained with the project record for support, dispute handling and future revision context, save where a shorter retention period is agreed in writing.
Amendments
- 14.1
The Studio may amend this Privacy Policy from time to time. The version in force from time to time shall be the version published on the Site, together with the date of last revision shown above. Where amendments materially expand the scope of processing, the Studio shall give reasonable advance notice through the Site.
Contact
- 15.1
All enquiries, rights requests and complaints concerning this Privacy Policy should be addressed to the Studio through its support channel and should be accompanied by sufficient information to identify the relevant records (such as an order reference, account email address or Commission name).
