Privacy Policy
How personal data is handled on okarostudio.com, and what rights you have under the GDPR.
1. Who is responsible
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:
Okaro Studio OG
Nordbahnstraße 8/1/9, 1200 Vienna, Austria
FN 634257g (Handelsgericht Wien) · VAT ID ATU81080018
Nordbahnstraße 8/1/9, 1200 Vienna, Austria
FN 634257g (Handelsgericht Wien) · VAT ID ATU81080018
Email: [email protected] · Phone: +43 676 650 2828
Full company details are in our Imprint.
We have not appointed a data protection officer, because the conditions in Article 37 GDPR do not apply to us: we are not a public authority, we do not monitor individuals on a large scale, and we do not process special categories of data on a large scale.
2. What this site does and does not do
This is a portfolio site. It carries no analytics, no advertising pixels and no social media tracking, and it embeds no third-party content — no social feeds, no video players, no maps. We do not build visitor profiles and we do not sell or share data for advertising.
The only third-party code that runs in your browser is the spam protection on our contact form, described in section 7. Everything else is served from our own infrastructure.
The site sets no cookies at all unless you make a choice in the cookie banner, in which case a single record of that choice is stored. Everything else described below is either technically necessary to deliver the page to you, or something you actively start by contacting us.
3. Hosting and server log files
This website runs on a server we operate ourselves, housed at Scaleway SAS, 8 rue de la Ville l’Évêque, 75008 Paris, France. The server and the data on it are located in the European Union.
Requests reach that server through Cloudflare, Inc. (USA), which we use as a content delivery network and to filter malicious traffic. Cloudflare acts as our processor and necessarily sees the connection data of every request.
When you open a page, the server logs: your IP address, the date and time of the request, the page requested, the amount of data transferred and the HTTP status code, the referring URL where applicable, and your browser type, version and operating system.
Purpose: delivering the site, keeping it secure and diagnosing faults. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating the site reliably and securely. These logs are not combined with other data and are not used to identify individual visitors.
Retention: access logs are rotated automatically once a log file reaches 10 MB, and only the ten most recent rotated files are kept — older ones are deleted. How much calendar time that covers therefore depends on how much traffic the site receives.
4. Media and script delivery
Video, images, stylesheets and scripts for this site are served from cdn.avinii.com, storage we operate ourselves on Cloudflare R2 through Cloudflare, Inc. (USA), acting as our processor. The storage bucket is located in the European Union.
Loading these files transmits your IP address and the usual request headers, which is unavoidable for any file to reach your browser. We deliberately host these files ourselves rather than pulling them from public third-party script CDNs, so that opening the page does not disclose your IP address to providers you have no relationship with.
Purpose: delivering the site’s media and code. Legal basis: Article 6(1)(f) GDPR — legitimate interest in a fast, reliable and privacy-preserving delivery of our own content.
5. Cookies and consent management
We use cookies and comparable storage only where they are strictly necessary to operate the site, or where you have given your prior consent (§ 165(3) TKG 2021 in conjunction with Article 6(1)(a) GDPR).
The consent banner itself is provided by Finsweet Cookie Consent, which runs entirely in your browser from our own server. It records your decision in two first-party cookies:
fs-cc — stores which categories you allowed. Lifetime: up to 180 days.
fs-cc-updated — notes that a decision has been made, so the banner is not shown again.
fs-cc-updated — notes that a decision has been made, so the banner is not shown again.
Legal basis: § 165(3) TKG 2021 and Article 6(1)(c) in conjunction with Article 7(1) GDPR — we are required to be able to demonstrate your consent. These two cookies are set regardless of which choice you make, including refusal, because refusal is itself the decision that has to be remembered.
You can change or withdraw your choice at any time using the privacy button at the bottom left of every page. Withdrawal does not affect the lawfulness of processing carried out before it.
6. The consent categories, and what is actually in them
The preferences panel offers four categories. We list them honestly, including the ones that are currently empty, because they exist so that anything added later cannot run before you agree to it.
Essential — always active. Delivering the pages, images and video you requested, protecting the contact form from automated abuse, and remembering your consent decision. This cannot be switched off, because without it the site cannot be shown to you at all.
Functional — optional convenience features. Currently empty. No functional third-party tool is loaded on this site.
Statistics — measurement of how the site is used. Currently empty. No analytics or tracking product is installed — no Google Analytics, no Tag Manager, no comparable tool.
Marketing — advertising and third-party embedded content. Currently empty. No advertising pixel and no embedded social or video player is present.
If we ever add something to one of these categories, it will be blocked until you allow that category, and this policy will be updated to name the provider and say what it transmits.
7. Contacting us
Our contact form is handled by Formspark, a service of Trampoline Software SRL (Belgium). When you submit the form, its contents are transmitted to Formspark, stored on infrastructure in Ireland, and forwarded to us by email. Typically that means your name, your email address or phone number, your company, and whatever you write in the message.
To keep the form usable we protect it with Botpoison, from the same company. Botpoison is a proof-of-work check: your browser solves a small computational puzzle before the form can be submitted. It sets no cookies, and the token it produces records only a one-time reference and the moment the page was opened — it is not an identifier and cannot be linked to you or to your activity on other sites. Loading the check does transmit your IP address to Botpoison.
Our mailbox is hosted on Google Workspace, provided to customers in the EEA by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Messages sent to us therefore rest on Google’s infrastructure.
Purpose: receiving and answering your enquiry, and preventing automated abuse of the form. Legal basis: Article 6(1)(b) GDPR where the contact concerns a contract or steps taken prior to one; otherwise Article 6(1)(f) GDPR — our legitimate interest in responding to enquiries and in protecting our systems from spam.
If you write or call us directly instead, we simply receive what you choose to tell us.
Retention: until your enquiry is dealt with and it is clear no further questions will arise. Where the correspondence becomes part of a business relationship, statutory commercial and tax retention periods apply — in Austria seven years under § 132 of the Federal Fiscal Code (BAO).
8. Links to social platforms
We link to our profiles on Instagram, LinkedIn, YouTube and Behance. These are ordinary links, not embedded widgets or players: no content is loaded from those platforms while you are on our site, and no data reaches them until you deliberately click through. Once you do, that platform’s own privacy policy governs what happens next.
9. Who receives your data
We do not sell personal data and we do not pass it to third parties for their own purposes. Data is disclosed only to processors acting on our instructions, and to public authorities where we are legally obliged to do so.
Our processors are: Scaleway SAS (France — the server this site runs on), Cloudflare, Inc. (USA — content delivery, traffic filtering, and the cdn.avinii.com media storage, whose bucket is located in the EU), Trampoline Software SRL (Belgium — contact form handling via Formspark and spam protection via Botpoison, with data stored in Ireland), and Google Ireland Limited (Ireland — our email).
10. Transfers outside the EU
We have deliberately kept this site’s processing inside the European Union. The server is in France, the media storage bucket is in the EU, contact form submissions are stored in Ireland by a Belgian company, and our email is contracted with an Irish entity.
Two providers are nevertheless part of US-headquartered groups whose networks are global, so a transfer to a third country cannot be excluded: Cloudflare, Inc. and Google. Those transfers are based on an adequacy decision of the European Commission — in particular the EU–US Data Privacy Framework, under which both are certified — or otherwise on the Standard Contractual Clauses under Article 46(2)(c) GDPR.
Despite these safeguards it cannot be entirely excluded that US authorities may access transferred data.
11. How long we keep things
We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as a statutory retention period requires. Specifically: consent records up to 180 days; enquiries until they are resolved; documents relevant to accounting and tax for seven years under § 132 BAO. After that the data is deleted or irreversibly anonymised.
12. Your rights
In relation to the personal data we hold about you, you have the right to:
Access — obtain confirmation of whether we process your data and, if so, a copy of it (Article 15 GDPR).
Rectification — have inaccurate data corrected and incomplete data completed (Article 16).
Erasure — have your data deleted where one of the grounds in Article 17 applies.
Restriction — require that we only store your data while a dispute about it is resolved (Article 18).
Data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller (Article 20).
Objection — object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Article 21).
Withdrawal of consent — withdraw consent at any time with effect for the future, without affecting the lawfulness of what was done before (Article 7(3)).
Rectification — have inaccurate data corrected and incomplete data completed (Article 16).
Erasure — have your data deleted where one of the grounds in Article 17 applies.
Restriction — require that we only store your data while a dispute about it is resolved (Article 18).
Data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller (Article 20).
Objection — object at any time, on grounds relating to your particular situation, to processing based on legitimate interest (Article 21).
Withdrawal of consent — withdraw consent at any time with effect for the future, without affecting the lawfulness of what was done before (Article 7(3)).
To exercise any of these, write to [email protected]. We may need to ask for proof of identity where we cannot otherwise be sure who is asking.
13. Your right to complain
If you believe we are handling your data unlawfully, you can lodge a complaint with the supervisory authority. In Austria this is:
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0 · Email: [email protected] · dsb.gv.at
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0 · Email: [email protected] · dsb.gv.at
You may also complain to the supervisory authority of the EU member state where you live or work.
14. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Article 22 GDPR. Nothing on this site makes decisions about you.
15. Security
The site is served over HTTPS, so traffic between your browser and our servers is encrypted in transit. Scripts loaded from our own CDN carry Subresource Integrity hashes, which means your browser refuses to run them if the file has been altered. We apply appropriate technical and organisational measures under Article 32 GDPR, though no method of transmission over the internet can be guaranteed absolutely secure.
16. Changes to this policy
We update this policy when the site changes — for example if we add a measurement tool or an embedded service. The version in force is always the one published here, with the date shown at the top.


