LEGAL

Privacy statement

Version 1.0 · INVULLEN

Draft. This text is not finished. The company details are missing and no lawyer has read it yet, so nothing here can be relied on.

This statement explains what CutLink does with personal data. It is written to be read, not to be survived. If something in it is unclear, write to privacy@cutlink.studio and we will explain it in plain words.

01Who we are

CutLink is a service of INVULLEN, registered in Nederland under Chamber of Commerce number INVULLEN, at INVULLEN, INVULLEN.

For questions about your data, or to exercise any of the rights in section 10, write to privacy@cutlink.studio.

02Two different roles

This is the part that people usually get wrong, so it comes first. CutLink handles two kinds of data and our responsibility is different for each.

Your account is ours to answer for. Your name, your email address, how you sign in, which plan you are on: we decide why we hold that and what we do with it. In the language of the GDPR we are the controller, and this statement covers it.

What you upload is yours to answer for. The films, stills, designs and audio you put in a project, the names and email addresses of the people you send a link to, and what those people write back: you decide that, not us. We only store and show it because you asked us to. There we are the processor and you are the controller. The data processing agreement sets out that side, and it applies automatically from the moment you create an account.

The practical consequence: if a client of yours asks us to delete something they appear in, we will not decide that ourselves. We pass the request to you, because it is your call.

03What we hold about account holders

As controller
WhatWhy
Name and email address To give you an account, to show who did what inside a studio, and to reach you about the service.
Password, stored as a hash To let you sign in. We never hold the password itself and cannot read it. If you sign in with Google we hold no password at all, only the account identifier Google gives us.
Profile photo and studio logo Only if you set one. If it came from your Google account we record that fact so we do not fetch it again on every sign-in.
Session records A random session identifier, when it was created, when it expires, and a shortened version of your browser's user-agent string. That last one is there so you can recognise your own sessions and so we can spot a session that does not look like you.
Your plan and payment status To know what your account may do. Card details never reach us; see section 6.
Four answers about your work Only if you give them. When you first sign in we ask what you do, what you deliver most, whether you work alone, and how you found us. It is there so we know who our makers are and build for the right people, and it may be used in aggregate to decide what to work on next. You can skip it, change it, or empty it later under your profile. We do not ask what you earn, what you charge, or who your clients are.

04What we hold about people who open a delivery link

Someone who opens a link you sent does not have an account and does not create one. What gets stored about them is limited to what the page needs to work:

For all of this you are the controller and we are the processor. We do not profile these people, we do not build a picture of them across projects, and we do not use anything they leave behind for anything other than showing it back to you inside your own project.

05Cookies and similar techniques

CutLink sets no tracking cookies, runs no analytics, and carries no advertising pixels. There are exactly two things stored in your browser:

NameWhat it doesHow long
cl_session Keeps you signed in. Marked HttpOnly, Secure and SameSite=Lax, so no script can read it and it is not sent along from other sites. 30 days
cl_lang Remembers which language you chose. Stored in the browser itself, never sent to us. Until you clear your browser data

Both are strictly necessary for a function you asked for, so under article 11.7a of the Dutch Telecommunications Act no consent is required, and that is why you will not find a cookie banner on this site. We host our own typefaces rather than loading them from a font service, so opening a page on cutlink.studio does not hand your IP address to a third party.

The sign-in page is the one exception: it loads Google's sign-in code, because that is what makes the Google button work. That page does nothing until you click something.

06Who else touches the data

We keep this list short on purpose. Every name here is a company we have to trust, so there are as few as we can manage.

WhoWhat forWhere
Cloudflare Hosting, the database, and storage of the uploaded files. Files and database in Western Europe.
Google Only for signing in with a Google account, and only if you choose that. United States, under the EU-US Data Privacy Framework.
Resend Sending the emails the service produces: an invitation to a delivery page, a notification that feedback came in. European Union.
Stripe Payment. Card details go straight to Stripe and never pass through our systems. United States, under the EU-US Data Privacy Framework.

We do not sell data, we do not trade it, and we do not hand it to anyone else unless a Dutch court or a law obliges us to.

07Where it is stored

The files you upload sit in object storage with its location set to Western Europe. The database with projects, accounts and comments runs in the same region. Neither is reachable from the public internet: a file can only be fetched through a link that our own code hands out.

08How long we keep it

09How it is protected

No system is beyond reach. If something does go wrong and your data is involved, we will tell you, and where the law requires it we will report it to the Dutch Data Protection Authority within 72 hours.

10What you can ask of us

Under the GDPR you may ask to see what we hold about you, to have it corrected, to have it deleted, to have it handed to you in a portable form, to restrict what we do with it, and to object to it. Write to privacy@cutlink.studio and you will hear from us within a month, usually a good deal sooner.

If you think we are handling this badly, we would rather hear it from you first. You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority, at autoriteitpersoonsgegevens.nl.

11Changes

If this statement changes in a way that matters, we will email account holders before it takes effect. Smaller corrections we simply make, and the version number and date at the top of this page will tell you when.