← Voltair Studio Portal

Privacy Policy

Effective [10 September 2026]

This policy explains how [Voltair Studio — legal entity name] (“Voltair Studio”, “we”) handles personal data in the Voltair Studio client portal — the web app at portalvoltairstudio.vercel.app and its iOS and Android apps, which load that same site.

The portal is invite-only. We create every account for a specific studio client; there is no public sign-up. We are the data controller for the personal data described here.

Data we collect

Account & contact. Your name, email address, and the password you set (stored only as a secure hash by our authentication provider). For a client company: the company name and its primary contact name and email.

Content you and we put in the portal. Project names and descriptions, milestones, deliverable files (video, image, PDF), version labels, review comments, approval and change-request decisions, and any files you attach to feedback.

Session & security data. A strictly-necessary authentication cookie (__session), your IP address (used to rate-limit sign-in attempts and recorded briefly in server logs), and basic request information (browser type, timestamps) in our hosting provider’s logs.

The portal contains a “Developer Pulse” panel showing our own build and deployment activity (commit messages, branch names, deploy status). This is our engineering metadata, not your personal data.

We do not use analytics, advertising, or third-party tracking.

Why we use it, and our legal basis

  • To provide the portal to you as part of our engagement with your company — performance of a contract (GDPR Art. 6(1)(b)).
  • To keep the service secure and prevent abuse (rate limiting, logging) — our legitimate interests (Art. 6(1)(f)).
  • To send you transactional email (account setup, “deliverable ready”, decision notifications) — contract performance.

We do not sell personal data and we do not use it for automated decision-making.

Who processes data on our behalf

  • Google Firebase (Google Ireland Ltd. / Google LLC) — authentication, database, and file storage. Account data and portal content are stored in the European Union (multi-region “eur3”).
  • Vercel Inc. (USA) — application hosting and serverless functions. Requests are processed in a United States region and appear in Vercel’s short-lived logs.
  • Resend — delivery of the transactional emails listed above (the recipient address and message content), once an email sending domain is configured.
  • GitHub and Vercel webhooks — deliver our deployment metadata to the Developer Pulse panel; no personal data of yours is sent.

Each provider acts under a data processing agreement and may only use the data to provide its service to us.

International transfers

Portal content and accounts are stored in the EU. Because our hosting provider (Vercel) is based in the United States and processes requests there, some data is transferred outside the EEA. These transfers rely on the European Commission’s Standard Contractual Clauses and the providers’ supplementary safeguards.

How long we keep it

We keep your account and portal content for as long as your company’s engagement with Voltair Studio is active. When an engagement ends, or on your request, we delete the client account — which removes the login and every associated project, deliverable, comment, and activity record. Backups and provider logs roll off on their own short schedules.

Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you (access);
  • correct data that is wrong or incomplete (rectification);
  • delete your data (erasure);
  • restrict or object to certain processing;
  • receive your data in a portable format.

Email [privacy@voltairstudio.com] and we will respond within one month. You may also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

Cookies

The portal sets one cookie: __session, which keeps you signed in. It is httpOnly, Secure, and SameSite=Lax, and is required for the app to work — so we do not show a cookie banner for it. There are no analytics or advertising cookies.

Security

All traffic is encrypted with TLS. Database and storage rules enforce that each client can only ever read or write their own company’s data. Sign-in is rate-limited, and the app runs under a strict Content Security Policy. No system is perfectly secure, but we take reasonable measures appropriate to the data involved.

Children

The portal is a business tool and is not directed to anyone under 16.

Changes

If we change this policy we will update the effective date above and, for material changes, notify the affected clients by email.

Contact

[Voltair Studio — legal entity name]
[street, postal code, city, Netherlands]
KVK [KVK number]
[privacy@voltairstudio.com]