Privacy Policy

Contents

Last updated: 20 August 2026

This policy explains how Saad Minhas Studio handles personal data when you visit this website or contact the studio. It applies to this website only. Work carried out for clients is governed by the agreement for that engagement.

How we produce and review published content, including where AI-assisted tools are involved, is described in our Editorial Policy and AI Use.

1. Who is responsible

The controller for this website is:

Saad Masud Minhas, trading as Saad Minhas Studio
Jahnstraße 80
12347 Berlin, Germany
Email: saad@saadminhas.studio

Full identification details are in the Imprint.

A data protection officer has not been appointed. The studio does not meet the thresholds in Art. 37 GDPR or § 38 BDSG. Use the address above for any data protection matter.

2. What we collect, and why

2.1 When you use the enquiry form

The enquiry form collects your name, company, role, business email address, company website, and, optionally, your LinkedIn profile. It also collects context about your company and the work: company stage, team size, what has changed recently, where design is creating difficulty, which areas are involved, what a successful engagement would make easier, what you have already tried, who is involved in the decision, an investment range, and a start period.

We use this to assess whether a project is a fit, to reply, and to prepare a proposal where relevant.

Legal basis: Art. 6(1)(b) GDPR, steps taken at your request before entering into a contract. Where your enquiry does not lead to a contract, we continue to rely on Art. 6(1)(f) GDPR, our legitimate interest in handling and documenting business enquiries.

Providing this information is voluntary. Without a name, an email address and a description of the work we cannot respond. Submitting the form does not create a client relationship and does not oblige the studio to accept a project.

Please do not name colleagues or third parties who are not aware you are contacting us, and do not send special category data, credentials, source code, or confidential material through this form. If an enquiry requires it, we will arrange a secure channel first.

2.2 When you email us directly

We process your email address, name, and whatever you choose to include, for the same purposes and on the same bases.

2.3 When you simply visit

Our hosting provider processes technical data needed to deliver and secure the site, including IP address, browser and device information, referring page, and request timestamps.

Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in delivering the site securely and reliably.

3. Cookies and similar technologies

This site does not set advertising or profiling cookies.

Strictly necessary storage required to deliver the site, and to remember your cookie choice, is used without consent under § 25(2) Nr. 2 TDDDG.

Any optional analytics or marketing technology is loaded only after you opt in through our consent banner.

You can change or withdraw your choice at any time using the cookie settings control available on every page.

Withdrawal is as easy as giving consent and takes effect immediately, though it does not affect the lawfulness of processing before withdrawal.

Legal basis for optional technologies: § 25(1) TDDDG and Art. 6(1)(a) GDPR.

4. Website analytics

Our hosting platform provides built-in analytics that count page views and daily unique visitors. According to Framer, it does not use cookies and does not create persistent identifiers; visitors are counted within a rolling one-day window using a hashed, daily-rotating value. Nothing is stored on or read from your device, so no consent is required.

Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in understanding aggregate site usage using the least intrusive method available.

4.1 Framer Analytics, no consent required

5. Hosting

The site is built and hosted by Framer B.V., Amsterdam, Netherlands, acting as our processor. Framer hosts and secures the site, delivers content, and processes native contact form submissions.

Framer uses authorised sub-processors and may process data outside the EEA. Where that happens, Framer states that it relies on a valid Chapter V GDPR transfer mechanism such as an adequacy decision or the EU Standard Contractual Clauses. You can ask us for information on the applicable safeguards.

6. Other recipients

We share personal data only where necessary:

— Framer B.V., hosting, content delivery, security, enquiry form processing (processor).
— Professional advisers, and competent authorities where we are legally required to disclose.
— A successor, in a genuine business transfer.

We do not sell personal data.

7. Fonts

Typefaces are served from our own hosting infrastructure. No font data is requested from Google or any other third party, and no font request transmits your IP address outside our hosting arrangement.

8. International transfers

Some providers may process data outside the European Economic Area. Where that happens we rely on an adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism under Chapter V GDPR. You may request a copy of the relevant safeguards using the contact details above.

9. How long we keep data

Enquiries that do not become projects — 12 months after the last meaningful contact
Client communication and project records — Duration of the relationship, then as needed for legal, tax or contractual purposes
Invoices and accounting records — 10 years, per § 147 AO and § 257 HGB
Consent records, including cookie and marketing consent — 3 years from the consent event
Server and security logs — As configured by our hosting provider
Analytics data — Per the retention setting stated in section 4

We keep data longer only where we must, to meet a legal obligation or to establish, exercise or defend a legal claim.

10. Your rights

Under the GDPR you have the right to:

— Access your personal data (Art. 15)
— Rectification of inaccurate data (Art. 16)
— Erasure (Art. 17)
— Restriction of processing (Art. 18)
— Data portability (Art. 20)
— Object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21)
— Withdraw consent at any time, without affecting processing already carried out (Art. 7(3))

To exercise any of these, email saad@saadminhas.studio. We respond within one month, and will tell you if we need to extend that period under Art. 12(3) GDPR.

You also have the right to lodge a complaint with a supervisory authority. For this studio the competent authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin
www.datenschutz-berlin.de

You may also complain to the authority where you live or work.

11. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and limiting who can reach enquiry data. No transmission over the internet is completely secure. Please do not send confidential material through this website.

12. AI-assisted tools and your data

The studio is an AI-enabled practice. We use AI-assisted tools in parts of our own working process, and we govern that use rather than leaving it to individual habit. This section explains what that means for your data. How AI-assisted tools are used in content we publish is described separately in our Editorial Policy and AI Use.

12.1 Our role

Where we use AI systems supplied by others, we act as a deployer of those systems within the meaning of the EU AI Act. We do not develop or supply those systems, and we do not operate an AI system on this website. There is no chatbot, no AI assistant, no emotion recognition, and no biometric categorisation on this site.

12.2 What we use AI-assisted tools for

Drafting and refining written content, supporting research, strategy and concept development, exploring design directions, and producing structured brand and design documentation. Every output is reviewed by a person before it is published or delivered, and the studio holds professional and editorial responsibility for it.

12.3 Your enquiry

Submitting an enquiry is not permission to process its contents through third-party AI tools.

We do not enter the content of your enquiry into third-party AI systems in order to assess, summarise, or respond to it. Your enquiry is read and answered by a person.

12.4 Training

We do not make personal data from this website, or the content of your enquiry, available for the training of third-party AI models. Where we use commercial AI tools in our own work, we select configurations that exclude submitted content from provider training where the provider offers that option, and we do not submit personal data to tools that do not.

12.5 Client work

For client engagements, permitted AI-assisted activity, data handling, review requirements and any client restrictions are agreed in writing in the project agreement before any client confidential information or personal data is processed through an AI tool. Silence is not permission.

12.6 Transfers

If we ever process personal data through an AI provider outside the EEA, we do so only under a lawful Chapter V GDPR transfer mechanism, and we say so in section 6. As at the date above, no personal data collected through this website is processed through an AI provider.

13. Automated decision-making

We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Enquiries are assessed by a person.

14. Links to other sites

This site may link to third-party websites. We are not responsible for their content or their privacy practices.

15. Changes

We may update this policy. The current version is always published here with its date. Where a change materially affects how we process your data, we will make that clear.

16. Contact

Saad Minhas Studio

Email: saad@saadminhas.studio

Postal address: see the Imprint.