Privacy statement
This privacy statement explains which personal data we process through pagewren.com and the PageWren client portal (portal.pagewren.com), why we process it, and which rights you have. We handle your data with care and comply with the General Data Protection Regulation (GDPR).
1. Who is responsible for your data?
PageWren is a service of Picazzo Research & Development, which is the controller for the personal data processed through this website and the client portal.
- Legal name: Picazzo Research & Development
- Trade name: PicazzoLabs (PageWren is a PicazzoLabs service)
- Address: Zinkstraat 24, Box C4687, 4823 AD Breda, the Netherlands
- Dutch Chamber of Commerce (KvK) number: 42060545
- VAT identification number: NL005464235B85
- Email: [email protected] (legal and privacy matters: [email protected])
We have no telephone contact channel; all contact runs by email.
2. Which personal data do we process?
The public website at pagewren.com is an informational site. It sets no cookies, runs no analytics and uses no tracking pixels. We process only the data described below.
- Contact by email — the "Request your page" button opens your own email program with a message draft; you send it yourself and it arrives directly in our mailbox. The website does not store your message on a server. We process the email address, name and message content you send us, in order to answer your question or prepare your website.
- Client portal account — if you are a PageWren client, we process your email address and the one-time login codes we send you, plus a session token, so you can sign in to the portal securely. There are no passwords.
- Uploads and change requests — files you upload in the portal (images and PDF documents) and the change requests you submit, so we can carry out the work on your website.
- Billing — your name, business details and subscription status. Payments run through Stripe; card and payment details are handled by Stripe only — we never see or store your card data (see section 4).
- Technical server logs — when you visit the website or portal, our hosting infrastructure (Cloudflare and our own servers in the Netherlands) automatically records your IP address, user-agent (browser and device type) and the referring page in short-lived server logs. This happens only for the ordinary technical handling of your request and for security and abuse prevention (for example DDoS mitigation), based on our legitimate interest (art. 6(1)(f) GDPR). These logs are kept for approximately 24–72 hours and then deleted automatically; we do not use them for profiling, marketing or to identify you personally.
Websites we host for our clients: for the visitor data of the client websites we build and host, the client business is the controller and we act only as a processor within the meaning of art. 28 GDPR, under a written data processing agreement. That processing is described in the privacy statement of the client website concerned, not in this document.
We do not build profiles of you, do not use your data for advertising and do not sell personal data. You are not legally required to provide us with personal data; without the requested details, however, we cannot handle your request or provide the service.
3. Why and on which legal basis do we process your data?
We process your data for the purposes above, on the following legal bases (art. 6 GDPR):
- to answer your question and offer our service, based on our legitimate interest (art. 6(1)(f) GDPR) in handling enquiries about our services;
- to enter into and perform the agreement with you (art. 6(1)(b) GDPR) — the portal login, uploads, change requests, hosting and billing;
- to comply with a legal obligation (art. 6(1)(c) GDPR), for example the Dutch fiscal duty to retain invoices;
- to keep the website and portal secure (the technical server logs), based on our legitimate interest (art. 6(1)(f) GDPR).
4. Who receives your data?
We do not share your data with advertisers and do not sell it. Your data may be processed by service providers who work on our behalf:
- Cloudflare — CDN, DNS and hosting infrastructure for the website and portal. Cloudflare processes traffic data (including IP addresses) solely on our behalf, under a data processing agreement.
- Self-hosted servers in the Netherlands — the client portal, uploads and website previews run on our own servers located in the EU (the Netherlands).
- MXRoute — delivery of transactional email (such as login codes and service messages).
- Stripe — payment processing and the customer billing portal. Stripe processes your payment details as a processor for the payment itself, and additionally acts as an independent controller for its own purposes such as fraud prevention and compliance with financial regulations; see Stripe's own privacy statement for details.
- Hostinger — domain name registration, where applicable to your website's domain.
- Google Fonts — this website loads its fonts from Google's servers. When a page loads, your browser therefore sends your IP address to Google, which acts as an independent controller for that request. See the cookie policy for details.
5. Transfers outside the European Economic Area (EEA)
Where personal data is processed outside the EEA (for example by providers established in the United States, such as Cloudflare, Stripe, MXRoute or Google), this takes place under appropriate safeguards: an adequacy decision (such as the EU–US Data Privacy Framework) or the standard contractual clauses adopted by the European Commission (SCCs, art. 46 GDPR). We maintain standard contractual clauses as a fallback option.
6. How long do we keep your data?
We do not keep your data longer than necessary:
- contact emails: up to 2 years after our last contact;
- portal account data, uploads and change requests: for the duration of your subscription; after cancellation your website and data are removed after the current billing period ends;
- data we are legally required to keep (such as invoices): the statutory period (7 years for Dutch tax purposes);
- technical server logs: approximately 24–72 hours.
7. Your rights
You have the right to:
- access your data (art. 15 GDPR);
- have your data corrected (art. 16 GDPR);
- have your data erased (art. 17 GDPR);
- have the processing restricted (art. 18 GDPR);
- object to the processing (art. 21 GDPR);
- have your data transferred (data portability, art. 20 GDPR).
Send your request to [email protected]. We respond within the statutory period of one month.
8. Right to object to direct marketing
We do not use your data for direct marketing. Should that change, you have the right to object to it at any time, free of charge.
9. Automated decision-making
We do not make decisions about you based solely on automated processing (profiling) that produce legal effects for you or similarly significantly affect you (art. 22 GDPR).
10. Minors
This website is not directed at persons under 16. We do not knowingly collect data from minors without the consent of a parent or guardian. If you believe we have nevertheless processed a minor's data, please contact us at [email protected] and we will delete it.
11. Security
We take appropriate technical and organisational measures to protect your data (art. 32 GDPR), including encrypted traffic (HTTPS), HttpOnly session cookies, one-time login codes instead of passwords, access restriction, and hosting on maintained infrastructure within the EU.
12. Complaints
Do you have a complaint about how we handle your personal data? Please contact us at [email protected]. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
13. Changes
We may update this privacy statement when our website, portal or the way we process data changes. The date at the top shows the latest revision.
