Legal
Privacy Policy
This Privacy Policy explains how Creativo@Work LLC collects, uses, discloses, retains, and safeguards personal information in connection with the website at creativoatwork.com. It also describes the rights available to you and how to exercise them. Please read it alongside our Terms of Service, which govern your use of the Site.
01Scope and Controller
This Policy applies to personal information processed by Creativo@Work LLC (“we,” “us,” “our,” or the “Company”) through the website at creativoatwork.com and its subdomains and forms (the “Site”). For the purposes of the EU and UK General Data Protection Regulation, we act as the controller of the personal information described here.
This Policy does not apply to personal information we process on behalf of a client under a separately executed engagement, which is addressed in Section 19, nor to any third-party website or service that this Site links to.
02Information You Provide
The Site invites one deliberate act of disclosure: the contact form. When you submit it, we receive the name, email address, and message you enter. The form also contains a hidden field that is not visible to human visitors and exists solely to detect automated submissions; if it is completed, the submission is discarded and nothing is sent.
You may also contact us directly by electronic mail, in which case we receive whatever information you choose to include in that message and its headers.
Please do not transmit information you consider confidential, privileged, or sensitive through the Site. See Section 5 below, and Sections 9 and 10 of our Terms of Service.
03Information Collected Automatically
Serving a website necessarily involves processing certain technical information. We do not use it to build profiles or to track you across sites.
- Hosting logs. Our hosting provider records ordinary server request data, which may include IP address, timestamp, requested URL, HTTP status, referrer, and user-agent string.
- Contact endpoint logs. The service that processes contact submissions records diagnostic information about requests and errors. These diagnostics do not include the content of your message.
- Abuse prevention. To prevent the contact endpoint from being flooded, we apply a rate limit keyed to the requesting IP address. This involves short-lived processing of that IP address for security purposes and is not used to identify or profile you.
- Web fonts. Typefaces are loaded from Google Fonts. As a technical consequence of loading a resource from a third-party server, your IP address and user-agent are transmitted to Google. We do not control that processing; it is governed by Google's privacy policy.
04Cookies and Similar Technologies
We do not set cookies on this Site. We do not use advertising cookies, analytics cookies, session cookies, pixels, beacons, fingerprinting techniques, or cross-site tracking of any kind. We operate no analytics package and no advertising network, and we do not participate in any advertising exchange.
Because we set no cookies and run no tracking, there is no consent banner and no cookie-preference centre. Browser signals such as Global Privacy Control and Do Not Track are moot on this Site, as there is no tracking to disable; we honour such signals in any event.
05Sensitive Information
We do not request, and ask that you do not submit, special categories of personal data or sensitive personal information, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, data concerning sex life or sexual orientation, precise geolocation, government identification numbers, financial account information, or account credentials. If you submit such information voluntarily, you do so at your own initiative, and we will delete it where practicable.
06How We Use Information
We process personal information only for the following purposes:
- to receive, review, and respond to your inquiry, and to correspond with you about it;
- to evaluate and, where appropriate, negotiate and enter into a prospective engagement;
- to operate, maintain, secure, and improve the Site;
- to detect, investigate, prevent, and respond to fraud, spam, abuse, security incidents, and unlawful activity;
- to maintain ordinary business, accounting, and correspondence records; and
- to comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use your personal information for behavioural advertising, and we do not use the content of your inquiries to train machine learning models.
07Legal Bases for Processing
Where the EU or UK GDPR applies, we rely on the following legal bases under Article 6(1):
| Purpose | Legal basis |
|---|---|
| Responding to your inquiry | Steps taken at your request prior to entering a contract, Art. 6(1)(b); and our legitimate interests in conducting business correspondence, Art. 6(1)(f) |
| Negotiating an engagement | Pre-contractual steps and performance of a contract, Art. 6(1)(b) |
| Site operation and security, abuse prevention, rate limiting | Our legitimate interests in operating a secure, available service and preventing abuse, Art. 6(1)(f) |
| Record keeping and legal claims | Legal obligation, Art. 6(1)(c); and our legitimate interests in establishing, exercising, or defending claims, Art. 6(1)(f) |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights and freedoms, taking into account the limited and non-intrusive nature of the processing described in this Policy. You may object to such processing as described in Section 14.
08Service Providers and Processors
We engage a small number of third parties to operate the Site. Each processes personal information on our behalf, or as an independent controller in respect of its own infrastructure, and each is bound by its own terms and privacy commitments.
| Provider | Function | Data involved |
|---|---|---|
| Google (Firebase Hosting) | Website hosting and content delivery | Request logs, IP address, user-agent |
| Google (Google Fonts) | Delivery of typefaces | IP address, user-agent |
| Cloudflare | Processing of contact-form submissions and rate limiting at the network edge | Form contents, IP address, diagnostics |
| Resend | Delivery of contact-form submissions to our inbox by electronic mail | Name, email address, message content, delivery metadata |
We do not authorise any of these providers to use your personal information for their own marketing purposes.
09Disclosure of Information
We disclose personal information only in the following circumstances:
- to the service providers listed in Section 8, for the functions described;
- to our professional advisers, including lawyers, accountants, and insurers, where reasonably necessary and subject to duties of confidence;
- where required by applicable law, regulation, legal process, subpoena, court order, or governmental or regulatory request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or respond to a lawful request;
- in connection with, or during negotiations concerning, any merger, acquisition, financing, reorganisation, bankruptcy, receivership, dissolution, or sale of all or part of our business or assets, in which case personal information may be among the assets transferred, subject to this Policy or a successor policy providing comparable protection; and
- with your consent or at your direction.
10No Sale or Sharing
We do not sell personal information, and we have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We do not disclose personal information to data brokers. We have no financial incentive programmes relating to personal information.
11International Transfers
We are established in the United States, and our service providers operate globally distributed infrastructure. If you access the Site or contact us from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and potentially in other countries whose data protection laws may differ from those of your jurisdiction.
Where personal information is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum as incorporated into our providers' data processing terms, or on a derogation under Article 49 where applicable, including where the transfer is necessary for pre-contractual steps taken at your request. You may request further information at the address in Section 21.
12Retention
We retain personal information only for as long as necessary for the purposes described in this Policy, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements.
- Inquiries that do not lead to an engagement are ordinarily retained for up to twenty-four (24) months from the last correspondence, so that we can recognise a returning prospect and maintain a record of the exchange.
- Inquiries that lead to an engagement are retained for the duration of the engagement and thereafter for the period required by applicable contractual, tax, accounting, and limitation-period requirements.
- Technical and security logs are retained for a short period consistent with our providers' default retention settings and our security needs, and are then deleted or overwritten in the ordinary course.
You may request earlier deletion as described in Section 14, subject to our need to retain certain records.
13Security
We maintain technical and organisational measures appropriate to the limited scope of our processing, including encryption in transit (HTTPS across the Site and the contact endpoint), restriction of the contact endpoint to our own origins, input validation and escaping, rate limiting to mitigate abuse, storage of credentials as managed secrets rather than in source code, and access limited to the small number of people who require it.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You transmit information to us at your own risk. If we become aware of a personal data breach affecting your information, we will notify you and any relevant supervisory authority where required by applicable law and within the time periods it prescribes.
14Your Rights
Depending on where you live, you may have some or all of the following rights. We honour these requests regardless of your jurisdiction where it is practicable to do so.
If you are in the EEA, the United Kingdom, or Switzerland
- to be informed about, and to request access to, the personal information we hold about you;
- to request rectification of inaccurate or incomplete information;
- to request erasure of your information in certain circumstances;
- to request restriction of processing in certain circumstances;
- to receive your information in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
- to object to processing carried out on the basis of legitimate interests, including profiling, at any time on grounds relating to your particular situation;
- to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; and
- to lodge a complaint with your supervisory authority.
If you are a California resident
- to know the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties to whom it is disclosed;
- to request deletion of personal information, subject to statutory exceptions;
- to request correction of inaccurate personal information;
- to opt out of the sale or sharing of personal information — we do not sell or share, as stated in Section 10;
- to limit the use of sensitive personal information — we do not collect it, as stated in Section 5; and
- not to receive discriminatory treatment for exercising any of these rights.
Residents of other jurisdictions, including Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy statutes, have broadly comparable rights, and we will apply the standards above to such requests.
15Exercising Your Rights
To exercise any right, write to [email protected] with the subject line “Privacy Request” and describe the right you wish to exercise. We will acknowledge your request and respond within the period required by applicable law, ordinarily within thirty (30) days for United States requests and one (1) month for requests under the GDPR, and we may extend that period where permitted, in which case we will tell you.
We must be able to verify your identity before acting on a request, ordinarily by confirming that the request comes from the email address associated with the information. We will not request more information than is necessary to verify you. An authorised agent may submit a request on your behalf with written proof of authorisation. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, and will explain why.
16Automated Decision-Making
We do not engage in automated decision-making producing legal or similarly significant effects concerning you, and we do not carry out profiling. The rate limiting described in Section 3 is a purely technical control applied to request volume; it does not evaluate you as a person and produces no legal effect.
17Children
The Site is directed to businesses and professionals and is not intended for children. We do not knowingly collect personal information from anyone under the age of sixteen (16), and under the age of thirteen (13) in particular. If you believe a child has provided us with personal information, contact us at the address in Section 21 and we will take reasonable steps to delete it promptly.
18Third-Party Sites
The Site may reference or link to websites operated by others, including former and current clients. We do not control those sites and are not responsible for their content, security, or privacy practices. This Policy does not apply to them, and we encourage you to read the privacy notice of any site you visit.
19Client Data and Engagements
When we deliver professional services, we may access or process personal information belonging to a client or to that client's own users. In that context we act as a processor (or service provider) on the client's documented instructions, and the client remains the controller. That processing is governed by the applicable engagement agreement and, where required, a separate data processing agreement, and not by this Policy.
If you are an end user of a system we built for a client and wish to exercise rights over your information, please direct your request to that client, who is the controller. We will assist them in responding as our agreement with them requires.
20Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, our providers, or applicable law. The current version is always available at this URL, and the “Effective date” above records when it last changed. Where a change materially affects your rights, we will take reasonable steps to bring it to your attention. Your continued use of the Site after a revision takes effect signifies your awareness of the updated Policy.
21Contact and Complaints
Questions, requests, and complaints about this Policy or our handling of personal information should be directed to:
Creativo@Work LLC195 Plymouth Street, Suite 5/5
Brooklyn, NY 11201
United States
[email protected]
We would like the opportunity to resolve your concern directly. If you are in the EEA, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. If you are in California, you may also contact the California Privacy Protection Agency or the Attorney General.
← back to site