Legal
Privacy Policy
Last updated 13 August 2026
This policy explains what personal data is collected through ainsleyy.com, why it is collected, how long it is kept, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act.
Who is responsible for your data
The controller of personal data collected through this site is Ainsley Fagerström Studio, Stockholm, Sweden.
For any question about this policy or your data, contact ainsley.fagerstrom@gmail.com.
What is collected, and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email address, company or project, the help you need, and the message you write in the contact form | To read and reply to your enquiry, and to discuss possible work | Legitimate interest in responding to enquiries (Art. 6(1)(f)); steps prior to entering a contract where relevant (Art. 6(1)(b)) | 24 months from last contact, unless we begin working together |
| Technical data automatically logged when you visit (IP address, browser, device type, pages viewed, referring page) | Serving the site securely and keeping it available | Legitimate interest in operating and securing the site (Art. 6(1)(f)) | Kept by the hosting provider for a short rolling period |
| Correspondence you send by email or on LinkedIn | Managing the conversation and any resulting work | Legitimate interest, or contract where we work together | As long as needed for the relationship and any legal or accounting obligation |
No special categories of data are requested, and the site is not intended for children under 16. Please do not include sensitive personal information in the contact form.
Who else processes your data
A small number of service providers process data on my behalf, under data processing agreements:
- Netlify — website hosting and contact form submissions.
- Email provider — receiving and storing correspondence.
Your data is not sold, rented, or used for advertising. It is shared with others only where required by law.
Transfers outside the EU/EEA
Some providers process data in the United States. Where that happens, transfers rely on the EU Standard Contractual Clauses and, where applicable, the provider's certification under the EU–US Data Privacy Framework, together with appropriate technical safeguards.
Your rights
Under the GDPR you have the right to:
- access the personal data held about you, and receive a copy of it;
- have inaccurate data corrected;
- have your data erased where there is no continuing reason to keep it;
- restrict or object to processing based on legitimate interest, including at any time for direct marketing;
- receive your data in a portable, machine-readable format;
- withdraw any consent you have given, without affecting processing carried out before withdrawal.
To exercise any of these, email ainsley.fagerstrom@gmail.com. You will receive a response within one month. If you believe your data has been handled improperly, you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se) or the supervisory authority where you live.
Security
The site is served over HTTPS. Access to submissions and correspondence is limited to me, protected by strong authentication. No method of transmission is completely secure, but data is kept only as long as it is needed and only where it needs to be.
Changes to this policy
If this policy changes, the updated version will be posted here with a new date at the top. Material changes will be flagged on the site.
