Compliance Protocol

Legal Framework

Chronological compliance timeline governing data handling, security audits, and client rights for OrbitCanvasStudio.

Stage 01 — 25 May 2018

Privacy Policy

1.1 Data Controller. OrbitCanvasStudio, Rua de Santa Catarina 312, 4000-443 Porto, Portugal, is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).

1.2 Data We Collect. When you submit a contact form, we collect: your full name, email address, project details, and any information voluntarily provided in your message. We do not collect sensitive categories of data (health, biometric, political, or religious data).

1.3 Legal Basis for Processing. We process your data based on: (a) your consent (Art. 6(1)(a) GDPR) — given when you submit the contact form; (b) legitimate interest (Art. 6(1)(f) GDPR) — for responding to business inquiries and maintaining communication records.

1.4 Data Retention. Contact form submissions are retained for a maximum of 24 months from the last interaction. After this period, data is permanently deleted from all systems. You may request earlier deletion at any time.

1.5 Data Sharing. Your data is not sold, rented, or shared with third parties for marketing purposes. Data may be shared with: (a) our email service provider (solely for delivering responses); (b) hosting infrastructure providers (solely for site operation); (c) legal authorities when required by applicable law.

1.6 International Transfers. Data is processed within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

Stage 02 — Continuous

Security & Encryption

2.1 Encryption in Transit. All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security). HTTP Strict Transport Security (HSTS) headers are enforced to prevent downgrade attacks.

2.2 Encryption at Rest. Data stored on our servers is encrypted using AES-256. Database backups are encrypted with separate key management. Access to production data is restricted to authorized personnel only.

2.3 Access Controls. We implement role-based access control (RBAC) with principle of least privilege. All administrative access requires multi-factor authentication (MFA). Access logs are maintained and reviewed quarterly.

2.4 Vulnerability Management. Automated security scanning runs on every deployment. External penetration testing is conducted annually by independent security auditors. Critical vulnerabilities are patched within 48 hours of discovery.

2.5 Incident Response. In the event of a data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by Art. 33-34 GDPR. Breach records are maintained for 5 years.

Stage 03 — Your Rights

Terms of Service & Client Rights

3.1 Right of Access (Art. 15 GDPR). You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data in a structured, commonly used, machine-readable format.

3.2 Right to Rectification (Art. 16 GDPR). You have the right to request correction of inaccurate personal data and completion of incomplete data without undue delay.

3.3 Right to Erasure (Art. 17 GDPR). You have the right to request deletion of your personal data when: (a) the data is no longer necessary for its original purpose; (b) you withdraw consent; (c) you object to processing and no overriding legitimate grounds exist; (d) the data has been unlawfully processed.

3.4 Right to Restriction (Art. 18 GDPR). You may request restriction of processing when: accuracy is contested, processing is unlawful, we no longer need the data but you require it for legal claims, or you have objected to processing pending verification.

3.5 Right to Data Portability (Art. 20 GDPR). You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance.

3.6 Right to Object (Art. 21 GDPR). You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

3.7 Right to Lodge a Complaint. You have the right to lodge a complaint with the Portuguese supervisory authority: Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134-1.°, 1200-651 Lisboa, Portugal. Website: www.cnpd.pt.

Stage 04 — Consent Management

Cookies Policy

4.1 What Are Cookies. Cookies are small text files placed on your device when you visit a website. They help us understand how you interact with our site and improve your experience.

4.2 Essential Cookies. We use strictly necessary cookies for site functionality: (a) session cookies for form state persistence; (b) localStorage for cookie consent preference (set only after you click "IGNITE_BOOSTERS"); (c) security cookies for CSRF protection.

4.3 No Analytics or Tracking. OrbitCanvasStudio does not deploy Google Analytics, Facebook Pixel, or any third-party tracking cookies. We do not engage in behavioral advertising or cross-site tracking.

4.4 Managing Cookies. You can control and delete cookies through your browser settings. Disabling essential cookies may impair site functionality. Cookie consent is stored in localStorage and persists until you clear browser data.

4.5 Third-Party Embedded Content. The Google Maps iframe on our contact page may set cookies per Google's own policy. These are loaded only after user interaction and are not set by OrbitCanvasStudio directly.

Stage 05 — Financial Terms

Refund Policy

5.1 Scope. This refund policy applies to all copywriting services provided by OrbitCanvasStudio. By engaging our services, you agree to the following terms.

5.2 Project Deposit. A 50% non-refundable deposit is required before work begins. This deposit covers initial research, strategy development, and resource allocation. The deposit becomes refundable only if OrbitCanvasStudio fails to deliver the agreed scope without valid justification.

5.3 Milestone-Based Payments. Remaining payments are tied to project milestones (draft delivery, revision rounds, final delivery). Each milestone payment is non-refundable once that milestone has been delivered and approved, even if the project is subsequently cancelled.

5.4 Revision Policy. Each service includes up to 2 rounds of revisions at no additional cost. Additional revision rounds are billed at €75/hour. Revision requests must be submitted within 14 days of delivery.

5.5 Cancellation. You may cancel a project at any time by written notice. If cancelled before draft delivery: 50% deposit is retained, no further charges apply. If cancelled after draft delivery: the full amount for completed milestones is due. If cancelled after final delivery: no refund is available.

5.6 Dispute Resolution. Refund disputes shall first be addressed through direct negotiation. If unresolved within 30 days, disputes shall be submitted to mediation under Portuguese law, with the competent courts of Porto, Portugal.

Questions about our compliance framework or data handling practices?

DIAL_TELEMETRY