Privacy Policy
Last updated: August 28, 2026
Applies to: judemichael.me and the branding, web design and development, and custom solutions work delivered through it.
This page explains what personal information I collect when you visit this site, send an inquiry, or start a project, what I do with it, who else handles it, and what you can ask me to do about it. It's written in plain language on purpose. If anything here is unclear, ask me directly at privacy@judemichael.me and I'll explain it.
1. Who is responsible for your data
This site is operated by Jude Michael Panotes, working with small businesses, startups, and solo founders on branding, web design and development, and (soon) custom software projects, plus optional ongoing plans like website care, hosting, and email.
For the information described on this page, I'm the data controller — I decide what gets collected and why.
Projects are delivered remotely to clients in several countries. This policy is written to meet UK and EU GDPR standards for everyone, including visitors outside those regions.
2. What I collect
Information you give me
Inquiry details. Name, email address, business name, phone number if you provide one, and whatever you write in the message field when you use the contact form or email me.
Project details. Once a project starts, an intake covers what's needed to deliver it: business information, target audience, brand references, and similar inputs specific to the work.
Project content. Copy, photos, logos, brand files, and any other material you send for use in your project.
Billing records. What you're being billed for, project or plan status, order history, and payment status. Full card numbers are never included; see Section 5.
Correspondence. Emails, messages, and support requests relating to your project.
Information collected automatically
Usage data. Pages viewed, time on page, referring site, approximate location at city level, device type, browser, and operating system.
Server logs. IP address, request time, and requested URL, recorded by the web host for security and troubleshooting.
Cookies and similar technologies. Covered in Section 7.
What I do not collect
I don't ask for special category data such as health, biometric, political, or religious information — there's no reason a design or development project needs it. I don't knowingly collect information from anyone under 16. I don't buy contact lists or scrape contact details to add people to my email list.
3. Why I use it, and the legal basis for each purpose
| Purpose | What it uses | Legal basis |
|---|---|---|
| Reply to an inquiry and scope a project | Inquiry details, correspondence | Steps taken at your request before a project starts |
| Deliver your project | Project details, project content, correspondence | Performance of a contract |
| Bill your project or a recurring plan | Name, email, billing records, order history | Performance of a contract |
| Keep tax and accounting records | Order and payment records | Legal obligation |
| Send project and billing emails | Name, email, project status | Performance of a contract |
| Send marketing emails and newsletters | Name, email, engagement records | Your consent, withdrawable at any time |
| Understand how the site is used and improve it | Usage data, cookies | Consent where a cookie banner applies; otherwise legitimate interest in running a functioning website |
| Protect the site against abuse, spam, and fraud | Server logs, IP address, form submissions | Legitimate interest in site security |
| Feature your results as a work sample | Project outcomes, business name, visuals | Your consent |
Where the basis is legitimate interest, I've weighed my interest against your privacy and use the least intrusive option available. You can object to any of it using the process in Section 11.
4. Automated decisions and profiling
I don't make automated decisions that produce legal or similarly significant effects about you. Email tools may score engagement to decide send frequency, and analytics tools may group visitors into segments. None of that decides what you're offered or charged without a person involved.
5. Payments
I collect the billing information needed to invoice you for a project or a recurring plan: billing name, email, and payment status. I don't store full card numbers, CVCs, or bank credentials directly — where a third-party payment tool is used to process a charge, that tool handles the card data itself under its own security standards, and what comes back to my records is limited to the outcome (amount, date, and whether it succeeded).
If a chargeback or payment dispute is raised, I may need to share evidence of the project and what was delivered with the payment provider or card network. The basis is my legitimate interest in defending a disputed payment and, where applicable, a legal obligation to respond to that process.
6. Tools that process data on my behalf
Running this practice means using third-party software. Each of the companies below processes some of your data on my instructions, under a data processing agreement, and is contractually barred from using it for its own purposes. This list is kept current — if you're reading it and something looks out of date, tell me.
| Provider | What's it used for | Data involved | Where processed |
|---|---|---|---|
| HubSpot — CRM and marketing | Managing contact and client records, tracking inquiries and project stages, communications, automated onboarding and marketing emails | Name, email, phone number, project/plan status, inquiry details, message history, email engagement data | United States and other locations depending on HubSpot's infrastructure |
| Notion — internal workspace and operations | Managing projects, client information, service documentation, internal notes, business operations | Client and project information, notes, correspondence, service details, operational records | United States and other locations depending on Notion's infrastructure |
| Proton Services — email, storage, and communications | Business email, file storage, document exchange, business communications | Email correspondence, contact information, project files, shared documents, account information | Switzerland, European Union, and other locations |
| Google Workspace — alternative email and storage provider | Business email, Drive storage, document sharing, file delivery, where used instead of Proton | Email correspondence, contact information, project files, shared documents, account information | Global, depending on Google's infrastructure |
| Web hosting providers — website and service hosting | Hosting websites, databases, and related web services | Server logs, IP addresses, website content, form submissions, account data, database contents | Varies by hosting provider and selected data centre |
| Google Analytics and Search Console — analytics and search performance | Understanding website traffic, user behaviour, search performance, technical search visibility | Usage data, cookie identifiers, device and browser information, IP-related data, search performance data | Global, including the United States and European Union |
Delivery collaborators. Some projects are fulfilled with the help of specialist designers or developers. They receive only the material needed for their part of the work, are bound by confidentiality terms, and aren't permitted to reuse your material or contact you directly.
When I am the processor rather than the controller. If your project includes a website with its own contact forms or analytics, personal data belonging to your customers may pass through it. For that data, you're the controller and I act as your processor — I use it only to support the project you engaged me for, don't use it for my own purposes, and return or delete it when the engagement ends. If you need a signed data processing agreement covering that relationship, ask and I'll provide one.
7. Cookies and analytics
Cookies are small files stored by your browser. This site uses three kinds:
Necessary cookies that keep the site working, hold your cookie preference, and protect forms against spam. Set without consent because the site can't function without them.
Analytics cookies that count visits and show which pages get read. IP addresses are truncated before storage where the tool supports it.
Marketing cookies, where used, that measure whether an ad or campaign led to an inquiry.
Visitors in the UK, EU, and other regions requiring prior consent are shown a banner before any analytics or marketing cookie is set, and nothing beyond the necessary category loads until a choice is made. You can change your choice at any time through the cookie settings link in the site footer, or clear cookies in your browser settings. Declining non-essential cookies doesn't restrict any part of the site.
Browser Do Not Track signals aren't standardised and aren't honoured individually. Global Privacy Control signals are treated as a valid opt-out of sale or sharing where the law requires it.
8. Email
Project and billing email. If you have an open inquiry or an active project, I'll email you about it — onboarding, project updates, and billing. These are part of running your project and can't be unsubscribed from while it's active, though you can ask to move a conversation to another channel.
Marketing email. Marketing and newsletter emails go only to people who opted in, or to existing clients about services similar to what they already engaged me for, where local law allows it. Every marketing email has a working unsubscribe link, effective immediately and permanently, with no penalty and no effect on an active project.
Email tracking. Marketing emails include a tracking pixel and tagged links that record whether the message was opened and which links were clicked. That's stored against your contact record in the CRM and used to decide how often to email and what to send. Block remote images in your email client if you'd rather not be tracked, or tell me and I'll flag your record to exclude tracking. Project and billing emails aren't used to build an engagement profile.
Email security. I will never ask you for a password, a full card number, or banking credentials over email. If you receive a message that appears to come from me asking for any of that, don't respond to it — contact me at a number or address you already have on file.
9. How long data is kept
| Record | Retention period |
|---|---|
| Inquiries that never turn into a project | 24 months from last contact, then deleted |
| Active client project and order records | Duration of the engagement plus 6 years, to cover tax and dispute limitation periods |
| Billing and tax records | The period required by tax law in the Philippines, typically 6 to 7 years |
| Completed or cancelled project records | 24 months after completion or cancellation, then deleted or anonymised unless a legal retention reason applies |
| Project files delivered as part of a project | 24 months after delivery as a working archive, then deleted unless you ask me to hold them longer |
| Marketing email subscribers | Until you unsubscribe, plus a suppression record kept indefinitely so you're not re-added |
| Website analytics | 14 months |
| Server logs | Per the host's rolling retention, typically 30 to 90 days |
When a period ends, records are deleted or anonymised. A minimal suppression entry — a hashed email with no other detail — is kept after an unsubscribe or deletion request so the same address isn't added back to a list later.
10. International transfers
Several of the providers in Section 6 are based in the United States, so your data may be transferred outside the UK and the European Economic Area. Where that happens, the transfer relies on one of: the EU-US Data Privacy Framework and its UK extension where the provider is certified, Standard Contractual Clauses approved by the European Commission together with the UK International Data Transfer Addendum, or your explicit consent where no other basis applies. Ask me which mechanism covers a specific provider and I'll tell you.
11. Your rights
If you're in the UK or EU, you have the right to: access a copy of the personal data I hold about you; correct anything inaccurate or incomplete; delete your data where I have no overriding legal reason to keep it (such as a tax record); restrict how I use it while a dispute or accuracy question is resolved; object to processing based on legitimate interest, and to direct marketing at any time with no exceptions; port your data to another provider in a structured, machine-readable format; and withdraw consent at any time where consent is the basis, without affecting anything done before you withdrew it.
If you're in California, you have the right to know what's collected and why, request deletion, correct inaccurate information, opt out of the sale or sharing of personal information, limit the use of sensitive personal information, and not be discriminated against for exercising any of these. I don't sell your personal information, and I don't share it for cross-context behavioural advertising. An authorised agent may submit a request on your behalf with proof of authorisation.
Other regions. Similar rights exist under laws in Canada, Australia, Brazil, and elsewhere. Rather than sorting requests by geography, I apply the same process to everyone.
How to make a request. Email privacy@judemichael.me with what you want done. I'll confirm receipt, may ask a question to verify you are who you say you are, and will respond within 30 days. Complex requests may take longer, and I'll tell you before that happens, not after. There's no charge unless a request is repetitive or excessive, in which case I'll tell you the cost before doing the work.
If you're not satisfied. Come back to me first — most issues are a misunderstanding I can fix quickly. If that doesn't resolve it, you can complain to your data protection authority: in the UK, the Information Commissioner's Office at ico.org.uk; in the EU, the supervisory authority in the country where you live or work.
12. Security
Reasonable technical and organisational measures protect your data, including HTTPS across the site, encryption in transit and at rest with the providers listed above, multi-factor authentication on business accounts, access limited to the people who need it for a specific task, and credentials stored in access-controlled storage rather than in email or chat. No system is completely secure, and I won't claim otherwise. If a breach occurs that's likely to affect your rights, I'll notify the relevant regulator within 72 hours where required and tell you directly what happened, what was affected, and what to do about it.
13. Children
This site and these services are for businesses and adults. I don't knowingly collect personal information from anyone under 16. If you believe a child has provided information here, email me and I'll delete it.
14. Links to other sites
This site links to portfolio pieces, client sites, and third-party tools. Once you follow a link, the destination's privacy policy applies, not this one. I have no control over how those sites handle your data.
15. Changes to this policy
This policy is updated when the tools, services, or applicable law change. The date at the top always shows the current version. For a change that materially affects how your data is used, I'll contact active clients and email subscribers directly rather than relying on you noticing an updated date. Past versions are available on request.
16. Contact
Privacy questions, rights requests, and anything else about this page:
Jude Michael Panotes Privacy: privacy@judemichael.me General: hey@judemichael.me