LAST UPDATED 17 SEPTEMBER 2026
Who is responsible for your data
Soma Design & Marketing (“Soma”, “I”, “me”) operates this website and is the data controller for personal data collected through it. The studio is based in Helsinki, Finland.
Contact for any privacy matter: somadigitalm@gmail.com
What data this website collects
This website does not use analytics, advertising pixels, or tracking scripts. The only personal data it collects is what you choose to type into the enquiry form on the contact page:
- Your name — so I know who I am replying to
- Your email address — so I can reply
- Business name — optional
- The service you are interested in
- Your timeline, if you give one — optional
- What you write in the project details field
Nothing else is requested and nothing is collected in the background. There is no newsletter signup, no account system and no profiling.
Why I process it, and on what legal basis
Your enquiry is used only to reply to you, discuss your project and prepare a quote. Under Article 6(1)(b) of the GDPR this is processing necessary to take steps at your request prior to entering into a contract. Where an enquiry does not lead to a project, any continued retention rests on legitimate interest under Article 6(1)(f) — keeping a record of business correspondence.
Your details are never sold, rented, or used for advertising.
Who else processes your data
To run this website and reply to you, a small number of service providers necessarily handle data on my behalf:
- Netlify, Inc. — hosts this website and receives enquiry form submissions. Netlify also keeps standard server logs, which include visitor IP addresses, for security and delivery purposes.
- Google (Gmail) — the studio email inbox, which receives and stores your enquiry and any correspondence that follows.
- Google Fonts — the typeface used on this site is requested from Google’s font servers when a page loads, which means your IP address is transmitted to Google in order to deliver the font file.
Netlify and Google are established in the United States, so using them involves a transfer of personal data outside the EEA. Both organisations participate in the EU–US Data Privacy Framework and offer Standard Contractual Clauses as a transfer safeguard.
A note on fonts. Loading fonts from Google’s servers is common practice, but it does transmit visitor IP addresses to Google and has attracted criticism in the EU. The fonts can instead be hosted directly on this site so that no request reaches Google at all. That change is recommended and can be made on request.
External services this site links to
The Academy pages link to Skool, where the courses are hosted, and the Work pages link to client websites. Once you follow a link to another website, that site’s own privacy policy and cookies apply. Nothing from those services is embedded in these pages, so they do not receive data about you unless you click through.
Cookies
This website sets no cookies and uses no local or session storage. There is more detail, including what third-party requests are made, in the Cookie Policy.
How long data is kept
Enquiries and the correspondence that follows are kept for as long as needed to answer you and to keep a reasonable record of business dealings. You can ask me to delete your enquiry at any time and I will do so unless I am required to keep it for accounting or legal reasons.
Your rights
Under the GDPR you have the right to request access to the personal data I hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. To exercise any of these, email me and I will respond within one month.
If you believe your data has been handled improperly, you can lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
Changes to this policy
If the website changes in a way that affects data handling — for example if analytics are added — this policy will be updated and the date at the top will change.
Let's Talk