Who we are
Unrealville Studio is the trading name of Samuel Moreno Mendoza, sole proprietor ("Unrealville Studio", "we", "us"), operating from 12951 Biscayne Blvd, North Miami, Florida 33181, United States. We design, build and operate marketing, content and commerce systems for a portfolio of brands and for a limited number of associated clients.
This policy explains what personal data we handle, why, on what legal basis, and what rights you have. It applies to our website, to our commercial relationships, and to the systems we operate on behalf of clients.
Contact for privacy matters: privacy@unrealvillestudio.com
Our two roles, and why the distinction matters
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
As a controller. When we decide why and how data is processed — visitors to our website, prospects who contact us, our own client contacts, and our internal business records — we are the controller.
As a processor. When we operate systems on behalf of a client — their store, their mailing list, their customer records, their mailbox — the client is the controller and we act on their documented instructions. If you are an individual whose data we hold in that capacity, your request is best directed to that client; if you contact us instead, we will forward it to them and assist.
Where we act as a processor for a client established in the European Economic Area or the United Kingdom, we enter into a data processing agreement meeting the requirements of Article 28 GDPR. A copy is available on request.
What we collect, and why
3.1 Website visitors
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| IP address, browser and device data, pages viewed | Serving and securing the site, aggregate analytics | Legitimate interests (Art. 6(1)(f)) |
| Information you submit through a contact form | Responding to your enquiry | Steps prior to a contract (Art. 6(1)(b)) |
We do not use advertising cookies on our own website, and we do not sell personal data.
3.2 Prospects and clients
Business contact details, correspondence, contract and billing records, and the operational data needed to deliver the engagement. Legal bases: performance of a contract (Art. 6(1)(b)), compliance with legal obligations such as tax and accounting (Art. 6(1)(c)), and our legitimate interests in operating and securing our business (Art. 6(1)(f)).
3.3 Data we process on a client's behalf
Depending on the engagement, this may include customer and order records from a client's e-commerce store, subscriber lists, CRM and enquiry records, property-owner records in the case of property-administration clients, and — where separately authorised — the contents of a client mailbox. We process this only on the client's instructions and only for the purposes of the engagement.
Access to client email accounts
Where a client authorises it in writing, we access a designated mailbox in read-only mode, in order to identify communications relevant to the services we provide, to diagnose email delivery or classification problems, and to detect and address situations affecting those services.
The following limits apply and are technical, not merely contractual:
- Access is limited to the Inbox, Sent and Spam folders. The Trash folder is excluded.
- We cannot send, reply, forward, delete, move, archive or label messages, nor change account settings. The permission granted does not include those capabilities.
- We do not store the content, subject line, sender, recipient, attachments or message identifiers of any message accessed. Access is exercised at the moment of consultation and nothing is retained.
- We retain only the access credential and the signed authorisation document.
- The account holder may revoke the authorisation at any time, in writing to us or directly from the security settings of the account. Revocation takes effect immediately.
Google API Services. Where the mailbox is a Google account, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the narrowest scope that permits reading messages, we use the data solely to provide the features described above, we do not transfer it except as required to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with the account holder's affirmative agreement, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
Artificial intelligence and automated processing
Our systems use large language models and generative models to research topics, draft content, evaluate it against editorial and compliance rules, and produce images. You should know three things about how we use them.
Human approval. Content produced by our systems is not published automatically without passing an automated quality and compliance review and, where the engagement provides for it, human approval.
Third-party processing. Prompts and the material needed to produce a result are transmitted to the model providers listed in section 6. We use these providers under commercial terms that exclude the use of customer content to train their models.
No automated decisions with legal effect. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
Who we share data with
We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose personal data to the following categories of recipients, each engaged under contract and processing only on our instructions:
| Category | Providers | Location |
|---|---|---|
| Database, application platform and CDN | Supabase | United States |
| Hosting, deployment and edge functions | Vercel | United States |
| DNS and email routing | Cloudflare | United States |
| Source control | GitHub | United States |
| Generative AI models | Anthropic, Google | United States |
| Transactional email | Resend | United States |
| Marketing email and automation | Klaviyo | United States |
| E-commerce platform | Shopify | Canada / United States |
| Advertising and social platforms | Meta Platforms, TikTok | United States / Ireland |
| Voice and media generation | ElevenLabs and equivalent providers | United States |
An up-to-date list of sub-processors is available on request. We notify clients of material changes to the list before they take effect, so that they may object.
We also disclose data where required by law, to enforce our agreements, or in connection with a merger, acquisition or sale of assets — in which case we will give notice before your data becomes subject to a different privacy policy.
International transfers
We are established in the United States. Where we receive personal data from the European Economic Area, the United Kingdom or Switzerland, that data is transferred to and processed in the United States and in the other locations listed above.
For those transfers we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we carry out transfer impact assessments where required. Where a provider is certified under the EU–US Data Privacy Framework, we may rely on that certification instead. A copy of the relevant transfer mechanism is available on request.
How long we keep data
| Category | Retention |
|---|---|
| Website analytics | Aggregated; raw logs no longer than 12 months |
| Enquiries that do not become engagements | 24 months from last contact |
| Client contract, billing and tax records | 7 years, as required by US and EU accounting rules |
| Operational data processed for a client | For the duration of the engagement, then deleted or returned within 90 days of termination, unless retention is legally required |
| Content of client mailboxes | Not retained. Consultation only |
| Signed mailbox authorisations | For the duration of the authorisation plus 5 years |
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, credential storage in a dedicated encrypted vault rather than in application tables, least-privilege database roles scoped to the data a given service needs, schema-level isolation for sensitive credentials, access review, and versioned, peer-reviewed changes to production systems.
No system is perfectly secure. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will notify you and any affected client without undue delay where the risk is high.
Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your personal data; to rectify inaccurate data; to erasure; to restriction of processing; to data portability; to object to processing based on our legitimate interests, including profiling; and to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local supervisory authority.
If you are in Panama, Law 81 of 2019 grants you rights of access, rectification, cancellation, opposition and portability, exercisable through the contact address below.
If you are a United States resident, depending on your state you may have the right to know what personal data we hold, to request deletion or correction, to obtain a portable copy, and to opt out of sale or sharing. We do not sell or share personal data as those terms are defined in US state privacy laws. We will not discriminate against you for exercising these rights.
To exercise any right, write to privacy@unrealvillestudio.com. We respond within 30 days, extendable by a further 60 days for complex requests, and we will tell you if we need the extension. We may ask for information sufficient to verify your identity; we use it only for that purpose.
Cookies
Our website uses cookies that are strictly necessary for it to function, and — where you consent — analytics cookies that help us understand aggregate usage. You can withdraw consent at any time through the cookie controls on the site or your browser settings. We do not use advertising or cross-site tracking cookies on our own website.
Children
Our services are directed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.
Changes to this policy
We may update this policy. When we make a material change we will update the version and effective date above and, where the change affects an active engagement, notify the client directly. The current version always governs.
Contact
Unrealville Studio — Samuel Moreno Mendoza, sole proprietor 12951 Biscayne Blvd, North Miami, Florida 33181, United States privacy@unrealvillestudio.com