Privacy Policy
How SmallFix Studio collects, uses, and protects personal data on this website and in the course of client work.
How SmallFix Studio collects, uses, and protects personal data on this website and in the course of client work.
SmallFix Studio is operated by Zoltan Zakany, registered as a sole trader (Person Fizik) in Albania. We provide operational workflow services, automation, data work, and related consultancy for small teams and businesses.
For any questions about this policy or about how your data is handled, contact us at zoltan@smallfixstudio.com.
This policy explains:
We use Google Analytics to understand how visitors use this website. Google Analytics may process technical information such as approximate location, device and browser type, pages visited, and session activity. Google states that IP addresses are not logged or stored in GA4. This data is processed and stored by Google LLC on our behalf.
Google Analytics places cookies in your browser. If you are located in the European Economic Area (EEA), Switzerland, or the United Kingdom, we request your consent before these cookies are placed. You can opt out of Google Analytics tracking at any time using the Google Analytics Opt-out Browser Add-on or by adjusting your browser's cookie settings.
When you contact us through the contact form on this website or by emailing zoltan@smallfixstudio.com, we receive your name, email address, and any details you include in your message. Form submissions are processed by Formspree (USA), a form handling service. We use this information to respond to your enquiry and, if a project follows, to manage that working relationship.
If you are located in the EEA or United Kingdom, we rely on the following legal bases:
We use the following types of browser storage:
| Type | Purpose | Duration |
|---|---|---|
| Google Analytics cookies | Usage analytics: pages visited, session length, device and browser type | Up to 2 years |
| Local storage (consent preference) | Stores your analytics consent choice (accepted or declined) | Until you clear browser data |
We do not use advertising cookies or any tracking beyond Google Analytics.
We do not sell personal data. We share data only with the following third parties in connection with website operations:
No other third parties receive personal data collected through this website.
Note on GDPR Article 28: When project work involves personal data, we act as a processor on your behalf. You remain the data controller. If you need a signed Data Processing Agreement (DPA), we can provide one. Contact us at zoltan@smallfixstudio.com.
When you engage SmallFix Studio for operational, CRM, data, or automation work, you may share files, system access, or records that contain personal data belonging to your customers, staff, or contacts.
In those situations, you are the data controller and we act as your data processor. We process personal data only to the extent necessary to complete the agreed work. We do not use client data for any other purpose.
Depending on the project, this may include:
In carrying out client work, we may use the following tools, which may process personal data on our behalf:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Drive / Google Workspace | File storage and sharing | USA (SCCs apply) |
| Zapier | Workflow automation | USA (SCCs apply) |
| Make (formerly Integromat) | Workflow automation | EU / USA |
| n8n | Workflow automation | EU / self-hosted |
| Anthropic (Claude) | AI-assisted work tasks | USA (SCCs apply) |
| OpenAI (ChatGPT) | AI-assisted work tasks | USA (SCCs apply) |
We do not use AI tools with client personal data unless it is necessary for the agreed work, appropriate for the project, and permitted by the client. Before using any of these tools with personal data from a specific project, we assess whether it is appropriate and proportionate. If your project has restrictions on sub-processors, please tell us before work begins.
If your project involves personal data of EEA or UK residents and you require a formal Data Processing Agreement (DPA) under GDPR Article 28, we can sign one. Reach out at zoltan@smallfixstudio.com to request this.
We use reasonable technical and organisational measures to protect personal data, including access controls, limited sharing, password-protected accounts, and only using project data for the agreed work. We limit access to personal data to the people and tools that need it to carry out the work.
No system is completely secure, but we take care to reduce risk and respond promptly if we become aware of any issue affecting data we hold.
| Data type | Retention period |
|---|---|
| Website analytics (Google Analytics) | Up to 26 months |
| Email enquiries and contact messages | Up to 2 years from last contact |
| Project contracts, invoices, and financial records | Up to 5 years from project close (for accounting and legal compliance) |
| Project correspondence and notes | Up to 5 years from project close |
| Client data files shared for project work | Retained only as long as needed to complete the project, unless otherwise agreed. Normally deleted or returned within 30 to 90 days after project completion. |
If you are located in the EEA or United Kingdom, you have the right to:
To exercise any of these rights, email us at zoltan@smallfixstudio.com. We will respond within 30 days.
You also have the right to lodge a complaint with your national supervisory authority if you believe we are processing your personal data in breach of applicable law.
SmallFix Studio is based in Albania. Albania has adopted a personal data protection framework aligned with GDPR principles. Where required for international transfers, we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.
When we use third-party tools based in the United States (such as Google Analytics or AI services), personal data may be transferred internationally. Where required, such transfers are covered by Standard Contractual Clauses or other appropriate safeguards.
We may update this policy from time to time. The effective date at the top of this page shows when it was last revised. For material changes, we will update the date and may notify relevant parties directly.