Legal

PRIVACY
POLICY

Effective date: 28 August 2026  ·  Version 1.1
Entity: Samuel Moreno Mendoza, sole proprietor  ·  Jurisdiction: Florida, USA
← Home Terms of Service →
01

Who we are

Unrealville Studio is the trading name of Samuel Moreno Mendoza, sole proprietor ("Unrealville Studio", "we", "us"), operating from 12951 Biscayne Blvd, North Miami, Florida 33181, United States. We design, build and operate marketing, content and commerce systems for a portfolio of brands and for a limited number of associated clients.

This policy explains what personal data we handle, why, on what legal basis, and what rights you have. It applies to our website, to our commercial relationships, and to the systems we operate on behalf of clients.

Contact for privacy matters: privacy@unrealvillestudio.com

02

Our two roles, and why the distinction matters

We handle personal data in two distinct capacities, and your rights differ depending on which applies.

As a controller. When we decide why and how data is processed — visitors to our website, prospects who contact us, our own client contacts, and our internal business records — we are the controller.

As a processor. When we operate systems on behalf of a client — their store, their mailing list, their customer records, their mailbox — the client is the controller and we act on their documented instructions. If you are an individual whose data we hold in that capacity, your request is best directed to that client; if you contact us instead, we will forward it to them and assist.

Where we act as a processor for a client established in the European Economic Area or the United Kingdom, we enter into a data processing agreement meeting the requirements of Article 28 GDPR. A copy is available on request.

03

What we collect, and why

3.1 Website visitors

DataPurposeLegal basis (GDPR)
IP address, browser and device data, pages viewedServing and securing the site, aggregate analyticsLegitimate interests (Art. 6(1)(f))
Information you submit through a contact formResponding to your enquirySteps prior to a contract (Art. 6(1)(b))

We do not use advertising cookies on our own website, and we do not sell personal data.

3.2 Prospects and clients

Business contact details, correspondence, contract and billing records, and the operational data needed to deliver the engagement. Legal bases: performance of a contract (Art. 6(1)(b)), compliance with legal obligations such as tax and accounting (Art. 6(1)(c)), and our legitimate interests in operating and securing our business (Art. 6(1)(f)).

3.3 Data we process on a client's behalf

Depending on the engagement, this may include customer and order records from a client's e-commerce store, subscriber lists, CRM and enquiry records, property-owner records in the case of property-administration clients, and — where separately authorised — the contents of a client mailbox. We process this only on the client's instructions and only for the purposes of the engagement.

04

Access to client email accounts

Where a client authorises it in writing, we access a designated mailbox in read-only mode, in order to identify communications relevant to the services we provide, to diagnose email delivery or classification problems, and to detect and address situations affecting those services.

The following limits apply and are technical, not merely contractual:

  • Access is limited to the Inbox, Sent and Spam folders. The Trash folder is excluded.
  • We cannot send, reply, forward, delete, move, archive or label messages, nor change account settings. The permission granted does not include those capabilities.
  • We do not store the content, subject line, sender, recipient, attachments or message identifiers of any message accessed. Access is exercised at the moment of consultation and nothing is retained.
  • We retain only the access credential and the signed authorisation document.
  • The account holder may revoke the authorisation at any time, in writing to us or directly from the security settings of the account. Revocation takes effect immediately.

Google API Services. Where the mailbox is a Google account, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the narrowest scope that permits reading messages, we use the data solely to provide the features described above, we do not transfer it except as required to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with the account holder's affirmative agreement, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.

05

Artificial intelligence and automated processing

Our systems use large language models and generative models to research topics, draft content, evaluate it against editorial and compliance rules, and produce images. You should know three things about how we use them.

Human approval. Content produced by our systems is not published automatically without passing an automated quality and compliance review and, where the engagement provides for it, human approval.

Third-party processing. Prompts and the material needed to produce a result are transmitted to the model providers listed in section 6. We use these providers under commercial terms that exclude the use of customer content to train their models.

No automated decisions with legal effect. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

06

Who we share data with

We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose personal data to the following categories of recipients, each engaged under contract and processing only on our instructions:

CategoryProvidersLocation
Database, application platform and CDNSupabaseUnited States
Hosting, deployment and edge functionsVercelUnited States
DNS and email routingCloudflareUnited States
Source controlGitHubUnited States
Generative AI modelsAnthropic, GoogleUnited States
Transactional emailResendUnited States
Marketing email and automationKlaviyoUnited States
E-commerce platformShopifyCanada / United States
Advertising and social platformsMeta Platforms, TikTokUnited States / Ireland
Voice and media generationElevenLabs and equivalent providersUnited States

An up-to-date list of sub-processors is available on request. We notify clients of material changes to the list before they take effect, so that they may object.

We also disclose data where required by law, to enforce our agreements, or in connection with a merger, acquisition or sale of assets — in which case we will give notice before your data becomes subject to a different privacy policy.

07

International transfers

We are established in the United States. Where we receive personal data from the European Economic Area, the United Kingdom or Switzerland, that data is transferred to and processed in the United States and in the other locations listed above.

For those transfers we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we carry out transfer impact assessments where required. Where a provider is certified under the EU–US Data Privacy Framework, we may rely on that certification instead. A copy of the relevant transfer mechanism is available on request.

08

How long we keep data

CategoryRetention
Website analyticsAggregated; raw logs no longer than 12 months
Enquiries that do not become engagements24 months from last contact
Client contract, billing and tax records7 years, as required by US and EU accounting rules
Operational data processed for a clientFor the duration of the engagement, then deleted or returned within 90 days of termination, unless retention is legally required
Content of client mailboxesNot retained. Consultation only
Signed mailbox authorisationsFor the duration of the authorisation plus 5 years
09

Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, credential storage in a dedicated encrypted vault rather than in application tables, least-privilege database roles scoped to the data a given service needs, schema-level isolation for sensitive credentials, access review, and versioned, peer-reviewed changes to production systems.

No system is perfectly secure. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will notify you and any affected client without undue delay where the risk is high.

10

Your rights

If you are in the EEA, the UK or Switzerland, you have the right to access your personal data; to rectify inaccurate data; to erasure; to restriction of processing; to data portability; to object to processing based on our legitimate interests, including profiling; and to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local supervisory authority.

If you are in Panama, Law 81 of 2019 grants you rights of access, rectification, cancellation, opposition and portability, exercisable through the contact address below.

If you are a United States resident, depending on your state you may have the right to know what personal data we hold, to request deletion or correction, to obtain a portable copy, and to opt out of sale or sharing. We do not sell or share personal data as those terms are defined in US state privacy laws. We will not discriminate against you for exercising these rights.

To exercise any right, write to privacy@unrealvillestudio.com. We respond within 30 days, extendable by a further 60 days for complex requests, and we will tell you if we need the extension. We may ask for information sufficient to verify your identity; we use it only for that purpose.

11

Cookies

Our website uses cookies that are strictly necessary for it to function, and — where you consent — analytics cookies that help us understand aggregate usage. You can withdraw consent at any time through the cookie controls on the site or your browser settings. We do not use advertising or cross-site tracking cookies on our own website.

12

Children

Our services are directed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.

13

Changes to this policy

We may update this policy. When we make a material change we will update the version and effective date above and, where the change affects an active engagement, notify the client directly. The current version always governs.

14

Contact

Unrealville Studio — Samuel Moreno Mendoza, sole proprietor 12951 Biscayne Blvd, North Miami, Florida 33181, United States privacy@unrealvillestudio.com

Privacy Policy v1.1 · Unrealville Studio · 28 August 2026