PERSONAL DATA

Privacy policy

How personal information, choices and privacy rights are handled on this website.

This policy explains the information a visitor may choose to provide, how website features should handle it and the controls that remain available to the individual.

1. Purpose and scope

This document sets out the rules that apply when using Fresh Step Studio and should be read with any specific conditions shown before an interaction.

Published information is general. Decisions involving safety, payment, rights or contracts should use current facts and the terms of the specific situation.

2. Responsible owner

Responsibility for freshstepstudio.com, required registration details and a verified written contact route must be stated wherever the applicable law requires them. A visitor should use only a contact method displayed on this domain and should ask for confirmation when identity or authority is material to the request.

Visitors should never send passwords, authentication codes, identity documents or payment credentials through a general channel.

3. Accuracy and updates

Content is prepared with care, but services, availability, interfaces and third-party rules may change.

Information that materially affects a decision should be confirmed with the relevant primary source.

4. Permitted use

Public pages may be read and linked for lawful purposes. Users must not interfere with security, attempt unauthorised access or infringe another person’s rights.

Automated access may be limited when it affects privacy, availability or security.

5. Intellectual property

Text, marks, images and graphic elements remain the property of their respective rights holders. Access does not transfer ownership or grant a commercial licence.

Third-party names are used only where needed for identification and do not imply sponsorship.

6. External links

External links provide context, but Fresh Step Studio does not control their availability, security or policies.

Check the destination domain and its current terms before providing information.

7. Availability and security

Continuous, error-free access cannot be guaranteed. Maintenance, network incidents and protective measures may temporarily affect service.

Visitors should keep devices and browsers updated and preserve copies of important information.

8. Information supplied

If a form is enabled, only information necessary for the stated purpose should be submitted.

Third-party information may be shared only with proper authority and a legitimate basis.

9. Retention and access

Personal information should not be kept for longer than the stated purpose requires. Access should be restricted to people who need it.

Relevant retention periods and recipient categories must be tied to each real purpose and service rather than applied as one arbitrary period across the website.

10. Rights and choices

People may exercise rights available under applicable law through the written contact route displayed on the contact page. Requests should be handled proportionately and identity checks should collect no more information than necessary.

Optional cookie choices should be as easy to withdraw as they were to provide.

11. Responsibility

Guides and articles do not replace official support, professional assessment or contractual terms.

Nothing in this document limits rights that cannot lawfully be excluded.

12. Changes and contact

Policies may change when the website, law or operating practices change. Material changes should be reflected consistently in the interface, forms, consent controls and this document.

Questions should use the written route available on the contact page. Sensitive credentials and confidential documents should not be included in a general enquiry.

13. Providers and responsibilities

Providers involved in hosting, security, communications, measurement or content delivery require a defined purpose, documented instructions, confidentiality and safeguards appropriate to the service. Appointing a provider does not remove the responsibility to select, direct and monitor that provider with reasonable care.

Before enabling an integration, the owner should understand which information leaves the website, where it is processed, how long it remains and how it can be deleted or exported. Material provider changes require coordinated updates to policies, settings, choices and internal records.

14. Transfers and data location

When information is processed outside a visitor’s country or region, applicable safeguards and categories of recipients must be explained. The global availability of a tool does not replace a proper assessment of the transfer or careful use of location options offered by the provider.

Data flows should be mapped from collection to deletion, including backups, security logs and technical support. That view supports accurate answers, risk assessment and removal of information from retired services after a platform change.

15. Incidents and continuity

The responsible owner needs a process to detect, contain, investigate and document incidents affecting availability, confidentiality or integrity. The plan should name responsible people, communication routes, evidence handling and the criteria for notifying individuals, authorities or providers when required by law.

Continuity also includes backups, tested restoration and a safe way to publish information if the primary channel becomes unavailable. A public policy does not replace these procedures; it should describe only commitments that the operation can genuinely support.

16. Children and vulnerable people

The website should not intentionally request information from children or vulnerable people without a legitimate purpose, suitable explanation and any required authority. Educational content must avoid language that pressures people to send documents, images, location or other information that could increase risk.

If such information is received without request, access should be restricted and the material assessed for secure deletion unless a different legal duty applies. Any service specifically directed to these groups requires clearer information and additional safeguards.

17. Complaints and resolution

A written route should be available for questions, rights requests and complaints relating to the website. Each request should receive sufficient identification, proportionate handling and a response within the applicable period without demanding information that is unnecessary to verify identity or understand the issue.

Where a disagreement cannot be resolved directly, any authority, consumer body or resolution mechanism must genuinely apply to the visitor and situation. A jurisdiction clause cannot remove mandatory protections available to the visitor.

18. Change control and accountability

Identity, website purpose, contact routes, providers, cookies, legal bases, retention, rights, intellectual property and applicable law must remain consistent with the real operation. Forms, integrations, structured data and footer copy should never contradict the policy that explains them.

Accountability requires comparing policy with technical configuration, recording material decisions and assigning responsibility for updates whenever a service, provider, purpose or legal requirement changes.