PRIVACY POLICY
Studio 23 Effective Date: January 1st, 2025 Studio 23 ("we," "our," or "us") is a service business located in Wisconsin.
This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you visit our website or use our services. By using our services, you agree to the practices described in this policy.
1. Information We Collect We collect the following categories of personal information: a. Information You Provide • Name, email address, and phone number • Appointment and booking details submitted through our scheduling system • Communications you send to us (e.g., inquiries, feedback) b. Automatically Collected Information • IP address and general location data • Browser type, device information, and operating system • Pages visited, time spent on pages, and other usage data collected via analytics tools • Cookie identifiers and similar tracking data
2. Legal Basis for Processing (GDPR — EU/UK Users) If you are located in the European Union or United Kingdom, we process your personal data under the following lawful bases: • Contract performance: To fulfill bookings and deliver our services • Legitimate interests: To analyze website usage, improve our services, and prevent fraud • Consent: For marketing communications and non-essential cookies (which you may withdraw at any time) • Legal obligation: Where required to comply with applicable law
3. How We Use Your Information We use your personal information for the following purposes: • To process and manage bookings and appointments • To communicate with you about your inquiries or services • To send marketing updates and offers, only where you have opted in • To analyze website traffic and user behavior using analytics tools (e.g., Google Analytics) • To serve interest-based or targeted advertisements • To improve our website and service offerings • To comply with legal obligations
4. Cookies and Tracking Technologies We use cookies and similar technologies for analytics, advertising, and to improve your experience. Cookies fall into the following categories: • Strictly necessary: Required for the website to function (no consent needed) • Analytics: Help us understand how visitors use our site (requires consent for EU/UK users) • Advertising/targeting: Used to serve relevant ads (requires consent for EU/UK users) EU and UK visitors will be presented with a cookie consent banner upon their first visit. You may withdraw your consent or manage cookie preferences at any time through our cookie settings link or your browser settings. Please note that disabling certain cookies may affect site functionality.
5. Sharing Your Information We do not sell, rent, or trade your personal information. We may share your data only with: • Service providers: Third-party vendors who assist us with scheduling, analytics, advertising, website hosting, and communications. These providers are contractually required to protect your data and may only use it as directed by us. • Legal authorities: When required by law, court order, or government request • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity For EU/UK users, we maintain Data Processing Agreements with all third-party processors as required by GDPR.
6. Data Retention We retain your personal information only as long as necessary for the purposes outlined in this policy, or as required by law. Specifically: • Booking and service records: Retained for up to 3 years after your last interaction with us • Marketing contact data: Retained until you opt out or withdraw consent • Website analytics data: Retained for up to 26 months in line with industry standards • Accounting and legal records: Retained for up to 7 years as required by U.S. tax law
7. Your Privacy Rights a. All Users • Opt out of marketing communications at any time by clicking "unsubscribe" in any email or contacting us directly • Request access to, correction of, or deletion of your personal information b. EU/UK Users (GDPR Rights) If you are located in the EU or UK, you have the right to: • Access the personal data we hold about you • Correct inaccurate or incomplete data • Request erasure of your data ("right to be forgotten") • Restrict or object to certain processing • Data portability — receive your data in a structured, machine-readable format • Withdraw consent at any time without affecting prior processing To exercise these rights, contact us at [your email]. We will respond within 30 days as required by GDPR. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. c. California Residents (CCPA/CPRA Rights) If you are a California resident, you have the right to: • Know what personal information we collect, use, share, or sell • Delete your personal information (subject to certain exceptions) • Correct inaccurate personal information • Opt out of the sale or sharing of your personal information • Limit the use of sensitive personal information • Non-discrimination for exercising your privacy rights We do not sell personal information as defined under the CCPA. However, our use of advertising and analytics tools may constitute "sharing" of personal information under CPRA. You may opt out by contacting us at [your email] or by using a recognized opt-out preference signal (such as the Global Privacy Control). To submit a verifiable consumer request, contact us at [your email]. We will respond within 45 days.
8. Children's Privacy Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected such information, we will delete it promptly. If you believe we have collected information from a child, please contact us immediately.
9. Data Security We implement reasonable and appropriate technical and organizational measures to protect your personal information against unauthorized access, loss, destruction, or alteration. These measures include encrypted data transmission (SSL/TLS), access controls, and regular security reviews. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security and encourage you to use strong passwords and be cautious when sharing personal information online.
10. Third-Party Links Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
11. Changes to This Policy We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. When we make material changes, we will update the effective date at the top of this page. We encourage you to review this policy regularly. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
12. Contact Us If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
Studio 23 Location: Wisconsin, USA Contact: Wendy Email: wendy@studio23co.com
For EU/UK inquiries, you may also contact your local data protection authority if you believe your rights have not been adequately addressed.