Last updated 28 September 2026

Privacy Policy

This policy explains what personal data Vonary.digital (“we”, “us”) collects through this website, why we collect it, and what you can ask us to do with it. It applies to visitors from the European Union and the United States. Questions go to hello@vonary.digital.

Who we are

Vonary.digital is a digital product studio. For the purposes of the EU General Data Protection Regulation (GDPR) we are the controller of the personal data described here. You can reach us at hello@vonary.digital.

What we collect

When you send the contact form, we receive:

  • your name and email address;
  • what you tell us about your project, and the service and budget range if you choose them;
  • technical context of the request: the page you sent it from, the first page of your visit, the referring site, campaign tags (UTM) in the link you followed, device type and browser language;
  • a one-way hash of your IP address, used only to limit repeated submissions. We do not store the IP address itself.

If you accept analytics cookies, we also collect usage data described in the “Cookies and analytics” section. We do not ask for and do not want sensitive data such as health information; please leave it out of the form.

Why we use it and the legal basis

  • To answer your request and discuss a possible project — steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)).
  • To keep the site secure and filter spam — our legitimate interest (Art. 6(1)(f)).
  • To understand how the site is used, only if you accept analytics cookies — your consent (Art. 6(1)(a)). You can withdraw consent at any time through “Cookie settings” in the footer.

We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it for automated decisions that affect you.

Who receives the data

We use a small number of service providers who process data on our behalf and under our instructions:

  • hosting, database and file storage providers that run this website;
  • Telegram, where a short notification about each new request (name, email, the text of your message and its source) is delivered to our team chat;
  • if you accept analytics cookies: Google (Google Tag Manager, Google Analytics 4), Hotjar and Microsoft Clarity.

Some of these providers may process data outside the European Economic Area, including in the United States. Where this happens, the transfer relies on the EU–US Data Privacy Framework or on Standard Contractual Clauses approved by the European Commission.

Cookies and analytics

The site works without analytics cookies. Analytics and session recording tools load only after you press “Accept” in the cookie banner; “Reject” is equally available. Your choice is stored in your browser for six months and can be changed at any time through “Cookie settings” in the footer. Advertising cookies are never enabled.

To attribute a request to its source, the site keeps the first page of your visit, the referring site and UTM tags in your browser’s session storage. This data is deleted when you close the browser tab and is only sent to us if you submit the form.

How long we keep data

  • Contact requests: up to 24 months after our last contact with you, then deleted.
  • IP hashes used for spam protection: no longer than 30 days.
  • Analytics data: according to the retention settings of the analytics provider, no longer than 14 months.

If a request turns into a project, the data needed for the contract is kept for the period required by accounting and tax law.

Your rights

If you are in the EU or the EEA, you have the right to access your data, have it corrected or deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. You can also complain to your local data protection authority.

If you are a resident of California or another US state with a consumer privacy law, you have the right to know what personal information we collect and how we use it, to access and delete it, to correct it, and not to be discriminated against for using these rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA.

To use any of these rights, write to hello@vonary.digital. We will answer within 30 days and may ask you to confirm that the request comes from you.

Security

Access to requests is limited to our team. Data is transferred over encrypted connections, and credentials of connected services are stored encrypted.

Children

This site is intended for businesses and is not directed at children under 16. We do not knowingly collect their data.

Changes to this policy

When we change this policy, we update the date at the top of the page. Significant changes will be announced on the site.

Contact

Questions and requests about personal data: hello@vonary.digital.