Legal
Website Privacy Policy
Microdose Studio Privacy Policy
Microdose Studio is committed to protecting and respecting your privacy in compliance with the EU General Data Protection Regulation (GDPR) 2016/679. This policy explains when and why we collect personal information, how we use it, conditions for disclosure, and security measures. It applies to our website, services, client projects, marketing, and job applications.
About Microdose Studio
Microdose Studio is a boutique UX/UI design and brand strategy studio based in Warsaw, Poland.
Contact us at hello@microdose.studio or via our site at microdose.studio.
Data Collection Triggers
We collect personal data when you interact via email, phone, social media, our website forms, or in-person meetings. This includes job applications, client inquiries, newsletter sign-ups, or service requests. We may also obtain data from legitimate third-party sources like partners or public profiles, only with your consent or legitimate interest assessment.
Purposes and Legal Bases
Personal data supports client project delivery, marketing communications (with consent), contract fulfillment (invoicing, support), job processing, and legal compliance. Examples include responding to inquiries, sending project updates, surveys, or handling business transactions like mergers. Legal bases: contract performance (Art. 6(1)(b) GDPR), consent (Art. 6(1)(a)), legitimate interests (Art. 6(1)(f)), or legal obligation (Art. 6(1)(c)).
Data Types Collected
- Contact details: name, email, phone, company, address.
- Professional info: feedback, project details, job application data.
- Automatic: IP address, browser type, site usage (pages viewed, time spent).
We avoid sensitive data like health or biometrics.
The Get in touch Form
The form at microdose.studio/contact asks for three things: your name, your email address and a short description of your project. We use them for one purpose, which is to read your message and reply to it. The legal basis is our legitimate interest in answering an enquiry addressed to us, and where the enquiry concerns working together, the steps taken before entering into a contract (Article 6(1)(f) and Article 6(1)(b) GDPR).
Submitting the form places nothing on your device and sets no cookie. To keep automated submissions out we use a field that is hidden from you and completed only by software, and we check how long the form was open before it was sent. Neither asks you to prove anything and neither stores anything about you.
The message is delivered to our inbox by Resend, an email delivery provider acting as our processor and located in the United States; the transfer safeguards described under "Data Transfers Outside EEA" below apply to it. Your message then lives in our mailbox for as long as the enquiry and any resulting relationship require, and is deleted when neither does.
Choosing "Book a call" instead opens a Cal.com booking page embedded in ours. What you enter there is submitted to Cal.com under their terms, not through this form, and session recording never captures it.
You would rather not use the form at all: write to hello@microdose.studio and no third party is involved beyond our own mail provider.
Cookie Policy
Microdose Studio collects server log data solely for website administration and technical maintenance, without linking it to individuals or sharing with third parties. Logs help monitor site performance, detect errors, and generate anonymized statistics on usage patterns like popular pages and browser types.
Log Data Collected
HTTP request logs capture:
- Public IP address of the visitor.
- User agent (browser, device info).
- Request timestamp and response details (e.g., bytes sent, HTTP codes).
- Referrer URL and prior page visited.
These records are retained for 24 months as administrative aids and deleted thereafter.
Cookie Types Used
Our site employs essential cookies categorized as:
- Security: Detect authentication abuse and protect against threats.
- Performance: Anonymous usage metrics (e.g., page views, load times) via Vercel Web Analytics and Speed Insights. These are cookieless services: they place nothing on your device and read nothing from it.
- Product analytics: Page views and interactions such as clicks via PostHog, hosted in the European Union. PostHog runs in cookieless mode by default, which likewise stores nothing on your device. Visits are grouped using an identifier calculated on the server from your IP address and browser type together with a secret value that is replaced every day and then destroyed, so the identifier cannot be traced back to you and does not persist from one day to the next.
- Because the two services above store nothing on your device, they run without asking permission, on the basis of our legitimate interest in understanding how the site is used (Article 6(1)(f) GDPR). You can object at any time through "Cookie settings" in the site footer, which stops all collection.
- Optional, only if you accept: choosing Accept, on the cookie banner or in "Cookie settings", additionally allows PostHog to store an identifier in a cookie and in local storage, so repeat visits are recognised as the same anonymous visitor, and to record your session. Session recordings capture on-screen interaction with this site. Text entered into form fields is masked in your browser before the recording is sent, and the booking form is an embedded Cal.com page that is not recorded at all. This takes effect from your next page view. None of this happens unless you accept, and choosing Deny later stops it and clears what was stored.
- Functional: Remember user preferences such as language, region, or interface settings (e.g., font size).
Analytics runs without cookies unless you opt in, and the optional identifier described above is randomly generated: cookies store no personal data, cannot identify users directly, and do not alter browser or device configurations. "Cookie settings" in the site footer is the control for all of it, and the only place to refuse. Deny stops every form of analytics, including the cookieless one, ends any session recording, and clears the analytics identifier. Cookies can also be managed through your browser settings.
Data Transfers Outside EEA
Microdose Studio transfers personal data beyond the European Economic Area (EEA) only when necessary for operations, such as cloud services or collaboration tools hosted abroad. Transfers comply with GDPR via:
- European Commission adequacy decisions for approved countries.
- Standard Contractual Clauses for others.
- Binding Corporate Rules where applicable.
No transfers occur without safeguards ensuring equivalent protection levels.
Contact
Microdose sp. z o.o.
NIP: 5273196246
KRS: 0001210970
REGON: 543488283
ul. Marcina Kasprzaka 31/119
01-234 Warszawa