Privacy Policy

Last updated: 5 October 2026

  1. Controller

The person responsible for processing personal data through this website is:

João Paulo Rodrigues Andrade
Trading as Rodao Studio
Kurfürstendamm 73
10709 Berlin
Germany

Email: joao@rodao.studio

This policy explains how personal data is processed when you visit rodao.studio or contact me.

  1. Hosting and website delivery

This website is hosted by Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands.

When you access the website, technical information is processed to deliver its content and maintain the service’s security and reliability. This can include your IP address, browser and operating-system information, requested pages or files, and the date and time of access.

The legal basis is Article 6(1)(f) GDPR. My legitimate interest is to provide a functioning, secure and reliable professional website.

Framer and its authorised infrastructure providers process information as necessary for website hosting and delivery. Fonts, images and videos hosted directly in Framer are delivered through its infrastructure.

Framer’s data-processing agreement governs personal data processed on my behalf. It provides for processing during the service agreement and deletion upon written request, subject to the exceptions described in that agreement, including legally required storage and certain backups.

Further information:
https://www.framer.com/legal/data-processing-addendum
https://www.framer.com/legal/security

  1. Contact form and email

If you contact me through the website’s contact form, I process your first name, last name, email address and message. Form submissions are delivered to joao@rodao.studio.

If you contact me directly by email, I process your email address, message and any other information or attachments you provide.

I use this information to respond to enquiries, discuss potential projects and manage related correspondence.

Where an enquiry concerns entering into a contract with you, the legal basis is Article 6(1)(b) GDPR. For other correspondence, including enquiries made on behalf of an organisation, the legal basis is Article 6(1)(f) GDPR. My legitimate interest is to respond to professional enquiries and maintain relevant business communications.

Providing information is voluntary. Without sufficient contact details and information about your enquiry, I may be unable to respond.

Email is processed using Google Workspace. The provider for Germany is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland.

Further information:
https://cloud.google.com/terms/data-processing-addendum

  1. Protection against form abuse

Framer’s native forms include measures designed to prevent automated submissions and abuse. These can involve processing technical information and verification signals associated with a submission.

The purpose is to protect the contact form and maintain reliable communication. The legal basis is Article 6(1)(f) GDPR: my legitimate interest in preventing spam and misuse of the website.

  1. Retention of enquiries

Enquiries and related correspondence are retained for as long as necessary to respond, handle relevant follow-up and manage any resulting business relationship.

I delete correspondence manually when it is no longer needed. Information may be retained longer where statutory obligations apply or where necessary to establish, exercise or defend legal claims.

Processing required to meet statutory retention obligations is based on Article 6(1)(c) GDPR. Retention necessary for legal claims is based on Article 6(1)(f) GDPR.

  1. Framer analytics

This website uses Framer’s built-in analytics to understand how its content is used.

According to Framer, these analytics do not use cookies or persistent visitor identifiers. Framer uses a daily rotating hash of the IP address and browser user-agent information to calculate daily unique visitors. The information available to me consists of aggregate statistics, such as page views, traffic sources and frequently visited pages.

The purpose is to assess and improve the website. To the extent personal data is processed before anonymisation, the legal basis is Article 6(1)(f) GDPR. My legitimate interest is to understand the use of my professional website and improve its content.

I do not use additional advertising pixels or third-party analytics tools.

Further information:
https://www.framer.com/help/articles/gdpr-and-cookies/

  1. YouTube videos

Some project pages contain embedded YouTube videos. For users in the European Economic Area, the responsible provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

YouTube content is activated only after you consent to loading it. Once activated, your browser connects to Google’s servers. Google may receive your IP address, browser information, the page you are visiting and information about your interaction with the video. Google may also store or access information on your device using cookies or similar technologies.

If you are signed in to a Google account, Google may associate this activity with your account.

The purpose is to present examples of my creative work. The legal basis for processing based on your consent is Article 6(1)(a) GDPR. Consent for non-essential storage or access on your device is obtained under Section 25(1) TDDDG.

You may withdraw your consent for future loading through the website’s consent settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Google determines retention periods for data it processes for its own purposes. Information about its processing, retention and international transfers is available at:

https://policies.google.com/privacy
https://policies.google.com/technologies/retention
https://policies.google.com/privacy/frameworks

Videos hosted directly in Framer are covered by the hosting section above.

  1. Cookies and similar technologies

Framer’s built-in analytics do not use cookies. External services such as YouTube may use cookies or similar technologies when activated.

Non-essential storage or access on your device requires consent under Section 25(1) TDDDG. Associated personal-data processing based on consent is governed by Article 6(1)(a) GDPR.

Where storage or access is strictly necessary to provide a service you expressly request, Section 25(2) TDDDG applies. Any associated processing of personal data also requires an applicable GDPR legal basis.

  1. External links

This website contains links to external websites, including LinkedIn.

Following a link takes you to the external provider’s website, where its own privacy policy applies.

  1. Recipients and international transfers

Relevant recipients of personal data include Framer and its infrastructure providers, Google Workspace for email, and Google/YouTube when you activate embedded videos. Data may also be disclosed where required by law.

Some providers or their subprocessors process data outside the European Economic Area, including in the United States.

Framer and Google’s data-processing terms provide for applicable transfer safeguards, including European Commission adequacy decisions where applicable, or standard contractual clauses and supplementary safeguards where required.

Information about these arrangements is available in the provider documents linked above. You may contact me to request further information or copies of applicable safeguards.

  1. Your rights

Subject to the applicable legal conditions, you have the right to:

• Access your personal data under Article 15 GDPR.
• Correct inaccurate or incomplete data under Article 16 GDPR.
• Request deletion under Article 17 GDPR.
• Request restriction of processing under Article 18 GDPR.
• Receive eligible data in a portable format under Article 20 GDPR.

Where processing is based on consent, you may withdraw your consent at any time with effect for the future.

Right to object

Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation under Article 21 GDPR.

To exercise your rights, contact joao@rodao.studio.

  1. Complaints

You may lodge a complaint with a data protection supervisory authority, particularly in the EU country of your habitual residence, workplace or the alleged infringement.

The supervisory authority for Berlin is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Website: https://www.datenschutz-berlin.de
Email: mailbox@datenschutz-berlin.de

  1. Automated decisions

I do not use personal data collected through this website to make solely automated decisions that produce legal effects or similarly significantly affect you.

  1. Changes to this policy

This policy may be updated when the website, its services or applicable requirements change. The current version is available on this page.