Back to home
1. Introduction
CreARTive IT LLC ("we", "our", "us"), a limited liability company organized under the laws of the State of New Mexico, United States, trading as creARTive IT, is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website or use our services.
This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection legislation.
2. Data Controller
The data controller responsible for your personal data is CreARTive IT LLC. For any questions regarding this policy or your personal data, please reach us through our contact form.
3. Data We Collect
We may collect and process the following categories of personal data:
- Contact information: Name, email address and company name that you enter in our contact form, together with the message you write. Your IP address is included in the resulting email and is briefly stored on our server to limit automated abuse of the form.
- Technical data: IP address, browser type and version, operating system, referring page, requested page and timestamp, recorded automatically in our web server logs.
- Communication data: Records of correspondence when you contact us via email or other channels.
4. How We Use Your Data
We use your personal data for the following purposes:
- To respond to your inquiries and provide our IT consulting and AI services.
- To send you relevant information about our services when you have given consent.
- To improve our website, services, and user experience.
- To comply with legal obligations.
- To protect our legitimate business interests.
5. Legal Basis for Processing
We process your personal data based on one or more of the following legal grounds:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary for the performance of a contract with you.
- Legitimate interest: Where processing is necessary for our legitimate business interests, provided these do not override your rights.
- Legal obligation: Where processing is necessary to comply with a legal obligation.
6. Cookies
This website sets no cookies, stores nothing in your browser, and uses no analytics, advertising or behavioural tracking. There is consequently no consent banner, because there is nothing to consent to. For details, see our Cookie Policy.
7. Third-Party Services
We may use the following third-party services that process personal data:
- Web hosting providers: To host our website and ensure its availability.
- Email services: To manage communications with clients and prospects.
- Cloud service providers: To deliver our consulting and AI services.
All third-party processors are bound by data processing agreements and are required to protect your data in accordance with GDPR.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Contact inquiries: Up to 2 years after the last interaction. The abuse-prevention record of your IP address is discarded after one hour.
- Client data: For the duration of the business relationship and up to 5 years thereafter for legal and accounting purposes.
- Web server logs: Approximately five weeks, after which raw logs are rotated and deleted. Aggregate visitor statistics may be kept longer in a form that does not identify individuals.
9. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can request correction of inaccurate or incomplete data.
- Right to erasure: You can request deletion of your personal data under certain circumstances.
- Right to restrict processing: You can request that we limit how we use your data.
- Right to data portability: You can request your data in a structured, commonly used format.
- Right to object: You can object to the processing of your personal data.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please reach us through our contact form. We will respond to your request within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security assessments.
11. International Transfers
As an international digital company, your data may be transferred to and processed in countries outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: our contact form