SITEIT Studio
LEGAL & PRIVACY

PRIVACY POLICY

How SITEIT collects, processes, and protects your information with transparent, minimal data practices.

Last updated: September 2026

1. Who Operates SITEIT

SITEIT is a creative digital studio based in Cyprus, specializing in bespoke website design, on-location photography, and high-performance advertising through its integrated service, ADIT.

We operate across Nicosia, Limassol, Larnaca, and Paphos.

For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679 - 'GDPR') and the Cyprus Law Providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of Such Data (Law 125(I)/2018), SITEIT operates as the Data Controller for personal data collected through this website.

Note: Formal entity registration details and registered office identification will be published upon final commercial registry issuance.

2. Scope: No Online Checkout or Payment Processing

SITEIT currently does not take payments or process financial transactions through this website.

There is no online shopping cart, checkout, customer account registration, or recurring subscription mechanism on siteit.studio.

The website serves exclusively as a creative showcase, an automated website health check tool, and an inquiry channel for potential clients wishing to discuss tailored projects.

3. What Personal Data We Collect & Why

We adhere strictly to the principle of data minimisation (Article 5(1)(c) GDPR). We collect only information that is genuinely necessary to fulfill your direct request:

  • Direct Inquiries (Contact Form & ADIT Campaign Inquiry): When you submit an inquiry, we collect your Name, Business Name, Website URL (optional), Email address and/or Telephone number, and your project notes or campaign goals.
  • Communication Purpose: This information is used solely to assess your inquiry, review your digital presence, and communicate back with a tailored proposal or schedule a consultation.
  • Legal Basis: Processing is carried out on the basis of taking pre-contractual steps at your specific request (Art. 6(1)(b) GDPR) and our legitimate interest in responding effectively to prospective clients (Art. 6(1)(f) GDPR).
  • What We Never Collect: We never ask for or collect dates of birth, home addresses, government identification numbers, financial credentials, or sensitive categories of personal data.

4. How the Website Health Check Scanner Works

SITEIT provides an interactive Digital Health Check tool that allows business owners to preview how their website performs across mobile responsiveness, conversion architecture, and visual presentation.

When you enter a website URL into the scanner, the following technical operations occur:

  • Real-Time Public Inspection: The server initiates a direct, real-time HTTP fetch of the public website URL to analyze HTML markup, meta tags, responsive viewport declarations, OpenGraph headers, and public contact links.
  • Visual Snapshot Creation: To generate the Before / After preview, a headless browser running locally on our server captures a visual snapshot of the public page, saved temporarily to /public/screenshots/ using an MD5 hash of the URL.
  • Anonymity: The diagnostic scan is completely anonymous. We do NOT log, store, or associate your personal identity or IP address with the URL scanned.
  • No Database Storage of Scans: Scan results are assembled in-memory and returned directly to your browser session. They are not stored in any public lead database.
  • SSRF Security Controls: The scanner employs strict Server-Side Request Forgery defenses, automatically blocking private IP ranges, loopback addresses, and non-public hostnames.

5. Third-Party Services & External Connections

We do not sell, rent, or trade your personal data. External services are utilized solely for necessary technical functions:

  • WhatsApp (Meta Platforms Ireland Ltd): If you choose to initiate a chat via our floating WhatsApp buttons, you are transferred to the official WhatsApp platform (wa.me), governed by WhatsApp's own privacy policy.
  • Automattic mShots: If our local headless browser is unable to capture a website screenshot during a health check, a temporary public web thumbnail request is routed to Automattic's public mShots endpoint. No user identifiers are passed.
  • Unsplash CDN: Fictional demonstration campaigns and conceptual prototypes reference editorial photography hosted via Unsplash under standard commercial-use stock licenses.
  • No Analytics or Advertising Pixels: We do NOT use Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, or third-party behavioral profiling scripts.

6. Data Retention

Inquiry submissions received through our contact and campaign forms are stored on our secure local server in data/leads.json, accessible only to authorized studio members.

Inquiry data is retained only for the duration required to communicate with you regarding your project, typically up to 24 months, after which inactive leads are deleted unless a formal client contract has been established.

7. Data Security

We implement appropriate technical and organizational measures to safeguard your information against unauthorized access, loss, or alteration. All communication between your browser and our server is secured using Transport Layer Security (TLS / HTTPS).

8. Your Rights Under European Data Protection Law

Under the GDPR and Cyprus data protection law, you possess enforceable rights regarding your personal information:

  • Right of Access (Art. 15 GDPR): Obtain confirmation as to whether your personal data is being processed and receive a copy.
  • Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete information.
  • Right to Erasure (Art. 17 GDPR): Request the deletion of your personal data when it is no longer needed for the purposes collected.
  • Right to Restriction of Processing (Art. 18 GDPR): Request that we limit processing under specific legal conditions.
  • Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests at any time.
To exercise any of these rights, simply contact us via WhatsApp (+357 99 068395) or telephone. We respond to all verified requests promptly within 30 days without fee.

9. Complaints to the Supervisory Authority

You have the right to lodge a complaint with the competent supervisory authority if you believe that our processing of your personal data violates applicable law:

Office of the Commissioner for Personal Data Protection (Cyprus) 15 Kypranoros Street, 1061 Nicosia, Cyprus P.O. Box 23378, 1682 Nicosia Telephone: +357 22818456 Email: commissioner@dataprotection.gov.cy Website: www.dataprotection.gov.cy

SITEIT Studio · Nicosia · Limassol · Larnaca · Paphos