This Privacy Policy explains how AI Merge Studio LTD (Company No. 16370224, Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom), trading as Areza (“we”, “us”, “our”), collects and processes personal data. This policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679).

We are the data controller for personal data collected through this website (areza.digital) and our services.

1. Data we collect

Information you provide directly

  • Contact form submissions: your name, email address, company (optional), the service you are interested in (optional), and your message. Submitted via the form on our contact page.
  • Email correspondence: anything you send to [email protected] or any team email address.
  • Service onboarding: when you become a client, we collect business contact details, billing information, and any data you share with us as part of the project.

Information collected automatically

  • Connection data: our web server keeps no access logs. Cloudflare, which delivers and protects the site, processes your IP address, user agent, and requested URL to do so.
  • Abuse protection for the contact form: to limit repeated submissions, our server keeps a one-way hash of your IP address in memory for ten minutes. It is not written to disk or sent anywhere.
  • Storage in your browser: we do not use analytics, advertising, or tracking cookies. See our Cookie Policy for the small amount of storage the site uses.

Information from third parties

We do not buy or receive personal data from third-party data brokers.

  • Responding to enquiries via the contact form: legitimate interest (UK/EU GDPR Art. 6(1)(f)), replying to people who contact us.
  • Delivering services after you become a client: contract (Art. 6(1)(b)).
  • Sending invoices and meeting tax obligations: legal obligation (Art. 6(1)(c)).
  • Site security, fraud, and abuse prevention: legitimate interest (Art. 6(1)(f)).

We do not use your data for marketing, analytics, or profiling.

3. How long we keep it

  • Contact form enquiries: kept in our CRM for as long as we need them to reply and to manage any work that follows. Ask us at any time and we will delete them.
  • Client project files and correspondence: 6 years after the engagement ends (UK statutory limitation period for contract claims).
  • Invoices and accounting records: 6 years (UK Companies Act and HMRC requirement).

4. How contact form enquiries are handled

When you send the contact form, your details go to our own server, which does two things:

  1. Records the enquiry in our CRM. We run Twenty, an open-source CRM, on our own server hosted by Hetzner in Germany (EU). Your name and email address are saved as a contact, and your company, chosen service, and message are saved as a follow-up task for our team. No third-party CRM provider has access to this data.
  2. Notifies our team on Telegram. A copy of your name, email address, company, chosen service, and message is sent to a private Telegram group that only our team can read, so we can reply quickly.

If you would rather not have your enquiry pass through Telegram, email us directly at [email protected].

5. Who we share data with (processors)

We share personal data only with the processors listed below. We do not sell personal data.

  • Hetzner Online GmbH (Germany, EU): hosts our website server and our self-hosted CRM.
  • Cloudflare, Inc. (US/EU): DNS, content delivery (CDN), proxy, and DDoS protection. Every request to the site passes through Cloudflare, which processes your IP address and request details on our behalf.
  • Telegram FZ-LLC (UAE): delivers contact form notifications to our private team group, as described above.
  • Email providers: operational email is delivered via standard email providers (e.g. Google Workspace, Microsoft 365). The provider in use at any time is disclosed on request.
  • Accounting and invoicing software: invoicing and bookkeeping providers used to meet UK statutory obligations. Disclosed on request.

We do not transfer personal data to other third parties without your consent or a legal basis.

6. International data transfers

Some processors are located outside the UK and the European Economic Area (EEA). For each transfer, we rely on either an adequacy decision (e.g. UK / EU adequacy regulations), the UK International Data Transfer Addendum, or the EU Standard Contractual Clauses. A copy of the relevant transfer mechanism is available on request.

7. Your rights

Under UK and EU GDPR you have the right to:

  • Access: get a copy of the personal data we hold on you.
  • Rectify: ask us to correct inaccurate or incomplete data.
  • Erase: ask us to delete your data, subject to lawful retention obligations.
  • Restrict: ask us to limit how we process your data.
  • Object: object to processing based on legitimate interest.
  • Portability: receive your data in a structured, machine-readable format.
  • Withdraw consent: at any time, where processing is based on consent. This does not affect prior lawful processing.
  • Lodge a complaint: with the UK Information Commissioner’s Office (ico.org.uk) or your local EU data-protection authority.

To exercise any right, email [email protected]. We respond within 30 days; if more time is needed we will tell you why and give a clear timeline.

8. Security

We protect personal data with industry-standard measures: TLS encryption in transit, encrypted storage at rest where applicable, principle of least privilege on access, MFA on administrative accounts, and regular review of processor security posture. No system is perfect. If a personal data breach occurs that is likely to result in risk to you, we will notify you and the relevant authority within 72 hours as required by GDPR.

9. Children

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe we hold data on a minor, contact [email protected] and we will delete it.

10. Changes to this policy

We may update this policy. Material changes are noted on this page with a new “last updated” date. If changes affect rights or use of data already collected, we will notify you in advance where reasonably practical.

11. Contact

Data controller: AI Merge Studio LTD, Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom (Company No. 16370224)

Contact: [email protected]
Phone: +370 658 56543

We do not currently have a designated Data Protection Officer because we do not meet the GDPR thresholds requiring one. Privacy enquiries are handled directly by company management.