Privacy
Privacy
What this studio collects, why, who else touches it, and how to make us stop. Written from the code that does it rather than from a template.
Last updated: 16 August 2026
Who this is
Thalos Design is a web design studio in London, working across London, Los Angeles and Cyprus. For everything described on this page, the studio is the data controller: it decides what is collected and why.
Write to alex@thalosdesign.com about anything on this page, including a request to see, correct or delete what is held about you. It reaches one person and it is answered by one person. The registered address is Edgware, London HA8.
The short version
The longer sections below are the accurate ones. This is what they add up to.
- This site sets no cookies of its own, and shows no consent banner because it has nothing to ask permission for.
- Reading this site sends nothing about you anywhere that could identify you.
- If you fill in the form, we get what you typed, plus one line about how you first arrived.
- The booking calendar comes from Cal.com and does set cookies, so it only loads when you press the button that says it will.
- Businesses we email cold are on the list because their details are published. One reply saying no removes them permanently.
- Nothing here is sold, and nothing here is used for advertising.
When you send an enquiry
The form asks for your name, your email address and your message, and offers a project type and a budget range you can leave blank. If you write from the Cyprus page, the form also notes which language you filled it in, so the reply comes back in that language rather than the wrong one.
What you send goes to two places at once. It is emailed to the studio inbox through Resend, which is the service that delivers our mail, and it is written as a row in the studio's own client system. That system runs on Supabase, on a database hosted in London.
We use it to answer you, and then to remember the conversation if you become a client. In the language the law uses, that is taking steps at your request before entering a contract, and a legitimate interest in keeping a record of who has asked us for work.
The form is protected against scripts by a hidden field that people never see and bots fill in, and by a limit on how often one connection may submit. That limit reads the network address the request arrives from and holds it in the memory of the server handling it for ten minutes. It is never written to a database, never stored with your message, and it is gone when that server is recycled.
How your visit is remembered
When you arrive, this site writes one entry into your browser's session storage recording how the visit started: the first page you landed on, the site that linked you here if one did, and the tag the link carried if it carried one. It is read once, when you press send on the form, so that an enquiry arrives saying where it came from.
Session storage is not a cookie. It is never attached to a request, so it is not sent to this site's server or anybody else's until you submit something you typed. It is per tab, and your browser throws it away when you close that tab. It holds no identifier, no timestamp and no history of the pages you read, so it cannot be built into a profile of you, and a visitor who reads this site and leaves has sent nothing anywhere.
If your browser refuses to store it, which private modes often do, the enquiry simply arrives saying the source is unknown, and everything else works exactly the same.
Visitor numbers
We count visits using Vercel Web Analytics, which is the analytics built into the platform this site is hosted on. It sets no cookies, follows you to no other site, and is not connected to any advertising network. It tells us how many people read a page, not who they are.
This is why the site has no cookie banner. A banner exists to ask permission for the things this site does not do.
The booking calendar
The contact page can show a calendar for booking an intro call. It comes from Cal.com, and like most embedded third-party tools it sets its own cookies as soon as it loads.
So it does not load until you ask for it. The page shows a button instead, and says what pressing it will do. Nothing reaches Cal.com before you press it. If you do book a call, the time you pick and the details you give go to Cal.com as well as to us, under their privacy policy as well as this one.
If you become a client
Paying for a package creates a client record: your name and email as the payment collected them, which package you bought, and the currency you paid in. Payment itself is handled by Stripe. Card details are given to Stripe and never reach this studio's systems.
You then get a private link to your own project page. Behind it is a questionnaire about your business, anything you upload for the build such as your logo and photographs, the stage the project is at, and the messages between us about it. That is the working material of the job, and it is held for as long as we are working together and afterwards as the record of a project we delivered.
The link is the key: there is no password and no account, so anybody holding the link can open the page. Treat it the way you would treat a key. If you lose it, the login page will email it back to the address on your record, and nowhere else.
Reviews
Clients whose project has been delivered are invited to leave a review from inside that same private page. Leaving one is optional, and so is publishing it.
You choose how you are named: your business name, your first name, or anonymously. You tick a box to say it may be published, and if you do not tick it, the review is not published. That is not a promise about how carefully we work: the database refuses to mark a review approved unless the consent box was ticked, so there is no path through the system that publishes an unconsented review.
Nothing appears on the site until it has been approved, and a published review can be taken down at any time by writing to alex@thalosdesign.com.
If we wrote to your business first
This studio approaches businesses directly. If an email from us was the first you had heard of us, this section is the one that concerns you.
What we hold is business contact information collected from public sources: the business name, its category and area, its website, a business email address and phone number where those are published, and notes from looking at the existing website. For limited companies, that includes the public record at Companies House. It is information about a business, not about a private individual, and we do not buy lists.
The basis is legitimate interest: offering a relevant service to a business whose published details say it is likely to want it. The rules on marketing email distinguish a company from a sole trader, so every business on our list carries a marker saying whether the public record shows it is a limited company or whether that is simply unknown, and a person reads that marker before any email is approved to send. Nothing is sent automatically without somebody approving it.
Every email we send says who we are, gives the studio's address, and tells you how to stop. Reply saying no, in any words, and that address goes on a suppression list. That list is permanent and it is checked before anything is ever sent, so the answer holds for good rather than for a season. You can also just write to alex@thalosdesign.com and ask to be removed, and the same thing happens.
Some approaches are a printed letter carrying a short code or a QR square. Scanning it records that the code was used and when, so we know a letter was worth sending. That record holds no cookie, no address, no device and no browser: the table it is written to has a column for the letter and a column for the time, and nothing else.
Who else handles it
The studio is small, so this list is short and it is complete. Each of these is a company that processes something on our behalf, under its own terms.
- Supabase: the database holding enquiries, clients and projects, hosted in London.
- Vercel: hosting for this site and the studio's own systems, and the visitor counts described above.
- Resend: delivery of email the site and studio send.
- Stripe: payments. Card details go to Stripe, never to us.
- Cal.com: the booking calendar, and only once you have loaded it.
- Google: the studio's own mailbox, so any email you send us sits there as email does.
How long it is kept
An enquiry that goes nowhere is kept for two years and then deleted. Client records and project material are kept for seven years after the last work, because tax and accounting records have to be. Business contact details on the outreach list are kept while they stay accurate, and reviewed at least once a year.
A suppression is the exception, and deliberately so. When somebody asks not to be contacted, the record of that request is kept indefinitely, because the only way to honour it is to remember it. It holds the address and nothing else.
Stated plainly: these periods are the studio's policy and are applied by hand today. There is no automatic deletion job yet, and saying otherwise on this page would be the kind of claim that is easy to write and impossible to keep.
Your rights
You can ask what is held about you, ask for it to be corrected, ask for it to be deleted, ask us to stop using it, and ask for a copy in a portable form. Where we rely on legitimate interest, which is the outreach list and our record of enquiries, you can object and we will stop unless there is a reason we can show that overrides that, which for marketing there is not.
Write to alex@thalosdesign.com. There is no form to fill in and no template to follow. We will answer within one month.
If you are not satisfied with how we answer, you can complain to the Information Commissioner's Office at ico.org.uk, and in Cyprus to the Office of the Commissioner for Personal Data Protection at dataprotection.gov.cy.
Changes
When this page changes, the date at the top changes with it. There is no archive of previous versions, so if a change matters to you, keep a copy of what you read.