Legal
Privacy Policy
How Benix Studio collects, uses, and protects personal data across this website and the client portal.
Who we are
Benix Studio ("we", "us") is the data controller for personal data collected through benix.studio and the client portal. You can reach us at hello@benix.studio with any question about this policy or to exercise the rights described below.
What we collect
We collect only what we need to answer an enquiry or run a project. Specifically:
- Enquiry details you submit through the contact form: your name, email address, and optionally your company, the service and industry you selected, your budget and timeline, and the message you wrote.
- Account details if you are a client with portal access: your email address, your display name, and an authentication credential managed by our authentication provider. We never see or store your password.
- Project content you or we upload to the portal: files, deliverables, messages, and notes relating to your project.
- Technical data our hosting provider records automatically as part of serving the site, including IP address and request logs, retained for security and abuse prevention.
Why we use it
Our lawful bases are your consent (enquiries you choose to send), performance of a contract (project delivery), and our legitimate interests in securing the service and keeping records of the work we have done.
- To respond to your enquiry and prepare a proposal.
- To deliver, support, and invoice work you have engaged us for.
- To operate the client portal, including authentication and notifications.
- To protect the site from abuse — rate limiting and spam filtering on the contact form rely on your IP address.
How long we keep it
- Enquiries that do not become projects: up to 24 months, then deleted.
- Client accounts and project records: for the life of the engagement and for six years afterwards, to meet contractual and tax record-keeping obligations.
- Server and security logs: retained by our hosting provider on a rolling short-term basis.
Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to the client portal is authenticated and role-based, and row-level security policies in the database mean a client account can only read its own records. Administrative access is limited to the people who need it to deliver your project.
Your rights
You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable format. Email hello@benix.studio and we will respond within 30 days. If you are not satisfied with our response, you can complain to your local data protection authority.
International transfers
Our processors may store or process data outside your country. Where that happens, transfers are covered by the standard contractual clauses or an equivalent safeguard offered by the provider.
Changes
If we change this policy we will update the date at the top of this page. Material changes affecting existing clients will be notified by email.
