Legal

Privacy

What we collect when you write to us, why we keep it, how long for, and how to have it removed.

Last updated 12 August 2026.

Who is responsible

Corals, in Belgrade, Serbia. We decide why and how the data described here is handled, which under the General Data Protection Regulation makes us the controller.

Write to hello@corals.studio about anything on this page. You do not need a particular form of words and you will not be asked to explain why.

What we collect, and why

When you send an enquiry. Your name, your email address, your company if you give one, what you told us you need, the lines the form priced, the budget band and timeline you picked, your preferred time for a call, your time zone as your browser reports it, whether you told us you already have a brand, designs or copy, the figure the form quoted you, and whatever you wrote in the message box.

We use it to answer you and to prepare a quote. In the language of the Regulation that is Article 6(1)(b), steps taken at your request before entering a contract. We do not rely on consent for it, which also means there is no consent for you to have to manage.

When we work together. Whatever the project needs, which is normally your contact details and the material you send us. That is Article 6(1)(b) again, performing the contract, and where invoicing and accounting records are involved, Article 6(1)(c), a legal obligation we cannot contract out of.

When one of us signs in to the admin. A name, an email address and a password we never see in readable form.

What we do not collect

We do not store your IP address, your browser or your device with your enquiry. The only use your address has is counting requests, so the contact form cannot be used to flood us, and that count is held in memory rather than written down. We run no analytics, no tag manager, no advertising pixel, no session recorder and no chat widget. Nothing on this site profiles you, scores you or makes an automated decision about you.

We do not buy contact data, we do not sell yours, and we do not send marketing. Writing to us does not put you on a list, because there is no list.

Cookies

This site sets one cookie, and only for people who sign in to the admin. It is called admin_jwt, it holds a signed session token, it is marked http-only so no script can read it, and it is removed when you sign out.

A visitor reading these pages is set no cookie at all. Two small things are written to your own browser and never sent anywhere: which theme you chose, and whether you dismissed the bar at the top. Both hold a choice you made yourself, so neither needs your consent. That is why you were not asked for any: there is nothing to accept.

How long we keep it

An enquiry is deleted automatically two years after you send it. That is not a promise we remember to keep, it is a rule the database enforces on its own.

Project material is kept for the length of the work and for two years afterwards, so we can help if something breaks. Invoices and accounting records are kept for as long as the law of Serbia requires, which we cannot shorten even at your request.

Who else sees it

Only the people who need to, and only to do the job. We use a small number of suppliers, each of them a processor acting on our written instructions and none of them free to use your data for their own purposes:

A managed database service hosts the database. A hosting provider runs the site and the API. An email provider carries the email that tells us your enquiry has arrived.

Ask us and we will name any we have not, and tell you where they run.

We are established outside the European Economic Area, so handling your data involves a transfer out of it. That transfer is covered by the European Commission's standard contractual clauses. Ask us and we will send you a copy.

What you can ask us to do

You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to stop or limit what we are doing with it, ask for it in a portable form, and object to it. Where a legal obligation makes us keep something, we will say which one rather than refuse without a reason.

Email hello@corals.studio. We answer within one month, which is the deadline the Regulation sets, and normally much sooner. There is no charge.

If you think we have handled your data badly, you can complain to a supervisory authority: in your own country if you are in the European Union, or to the Commissioner for Information of Public Importance and Personal Data Protection where we are established. You are welcome to complain to us first, but you do not have to.

Keeping it safe

The connection to this site is encrypted. Admin passwords are hashed, never stored in a form anyone can read. Admin access is limited by role, so an account only reaches what its job needs. Uploaded files are checked and re-encoded before they are written, so what lands on the server is our output rather than an uploader's bytes.

No system is perfect. If something happens that puts your data at risk, we will tell the supervisory authority within 72 hours and tell you directly where the risk to you is high.

Changes

If this page changes, the date at the top changes with it. If a change matters to someone whose data we already hold, we email them rather than rely on them noticing.