Privacy notice
What we do with your data
This notice says what we collect, why we use it and how to have it deleted. It is short because we collect very little: there is no form on this site other than the contact one.
Draft — pending legal review
This is written to the GDPR, but no lawyer has reviewed it yet, and one thing the law requires — the controller's registered name and address — does not exist yet: it is marked as a gap, in braces, so you can see what is missing. It is published in this state on purpose: collecting a name and an email address with no notice at all, which is what happened until today, is worse than publishing an honest one that says it is a draft.
What this notice does not cover
This notice covers the website mansio.studio and the email that reaches Mansio through it. It is short because Mansio collects very little: there are no accounts, no registration, no basket, no analytics, and the only form on the site is the contact one.
Who the controller is
The controller is {{JURIDISCHE_NAAM}} ({{RECHTSVORM}}), trading as Mansio, established at {{VESTIGINGSADRES}}, the Netherlands. Chamber of Commerce (KvK): {{KVK_NUMMER}} · VAT: {{BTW_NUMMER}}. Contact for anything in this notice, including your rights: info@mansio.studio.
- The gaps in braces are real gaps. Mansio is not yet incorporated, and the registration details the law requires it to publish do not exist yet. They are left visible and unfilled rather than invented. They are completed on the day of incorporation, and this document goes up a version that day. Until then, the person answering is whoever operates
mansio.studio, at the address above. - There is no Data Protection Officer, and none is required: Mansio does not process personal data on a large scale, nor special categories as a matter of course.
What is collected, and when
Only what you type. There are two ways Mansio ends up holding data about you. a) The contact form. Six fields, three of them required:
- Your name — yes
- Your hotel's name — yes
- The town or city — no
- How many rooms it has — no
- Your email address — yes
- Your message — no
- b) An email you send us directly, containing whatever you choose to put in it.
- In both cases the free-text field is yours: if you write a phone number, a colleague's name or a personal detail into it, Mansio will receive it. Please do not include sensitive data (health, beliefs, trade union membership and the other Article 9 GDPR categories): we do not need it and we do not want to hold it.
How that data reaches us
The form is sent from this website itself. When you press the button, what you wrote travels to an address on mansio.studio — a Cloudflare Pages function, on the same domain and in the same project that serves these pages — and two things happen there, in this order:
- It is stored in a Cloudflare database (D1) hosted in the European Union.
- A notification is sent to
info@mansio.studiothrough Zoho Mail, carrying your address in the «Reply-To» field so that a reply reaches you. - Storing comes first on purpose: if the mail failed, your enquiry is not lost and you are answered anyway. If you would rather not leave anything stored, write to us directly at
info@mansio.studio— the address is on every page and works just as well. - No third-party form service reads the message along the way, and there is no CRM behind it: the address it is sent to is ours, the database is ours and the mailbox is ours.
- Your IP address is not stored as such. Stopping a robot from submitting automatically requires telling two visitors apart, not knowing who either one is: what is stored is a cryptographic digest of the IP (SHA-256) computed with a secret key, from which the address cannot be recovered — not even by us — plus the country code Cloudflare derives from it.
Why it is used, and on what legal basis
Each purpose Mansio uses your data for, with the legal basis it rests on under Article 6 GDPR:
- Replying to you and carrying on the conversation — Steps taken at your request before entering into a contract, Art. 6(1)(b)
- Preparing the free OTA dependency audit, if you ask for it — Art. 6(1)(b)
- Making you a proposal and, if you accept, delivering the service — Art. 6(1)(b)
- Security and availability of the site — Legitimate interests, Art. 6(1)(f)
- Keeping accounts and invoices — Legal obligation, Art. 6(1)(c)
- What is not done: no newsletters, no advertising, no selling of data, no sharing with third parties for commercial purposes, no profiling and no automated decision-making. Your data is used to talk to you and for nothing else. Tell us to stop and we stop.
Who else sees it
Nobody who does not have to. It is not sold and it is not shared. The only third parties involved are the ones that carry the mail and serve the pages:
- Cloudflare, Inc. — Serves the
mansio.studiopages (Pages), runs the function that receives the form and stores the enquiries (D1, European Union) — Your IP address, your browser and the page you request; and everything you write into the form — Global network · established in the USA · the D1 database, in the EU - Zoho Corporation B.V. — The
info@mansio.studiomailbox: it receives the notification for each enquiry and is where the email conversation lives — The whole email, for as long as it is kept — European Union (European data centre) - Cloudflare is outside the European Economic Area (established in the USA), even though the D1 database holding the enquiries is hosted in the European Union. For that transfer Mansio relies on the European Commission's Standard Contractual Clauses and on the EU–US Data Privacy Framework. Zoho provides the service from its European data centre.
- Your email is not shared with any Mansio client, with any hotel, or with anyone else.
How long it is kept
Each thing Mansio holds is kept for the period beside it:
- The enquiry stored in the database (D1), if we do not end up working together — Up to 24 months from the last message, then deleted
- Your message and the conversation, if we do not end up working together — Up to 24 months from the last message, then deleted
- The conversation, if we do work together — For the duration of the engagement plus 24 months
- Invoices and accounts — 7 years, because Dutch tax law requires it
- You can ask for it to be deleted sooner: the thread is deleted and you get written confirmation that it has been. The only thing that cannot be deleted early is what tax law obliges us to keep.
Your rights
You exercise them with a single email to info@mansio.studio. No form, no lawyer and no particular wording: write what you want and who you are.
- Access: a copy of what Mansio holds about you.
- Rectification: correct it if it is wrong or incomplete.
- Erasure: have it deleted.
- Restriction: have us stop using it while something is disputed.
- Portability: receive it in a machine-readable file.
- Objection: object to processing based on legitimate interests.
- Withdraw consent at any time, where consent is the basis relied on.
- Mansio replies within one month. If more time is needed, you are told within that month and why. You can also lodge a complaint with a supervisory authority: in the Netherlands, the Autoriteit Persoonsgegevens. If you live outside the European Union you may also approach the authority in your own country; either way, you can exercise every right on this list with Mansio.
Cookies, tracking, and what your browser stores
This site does not set a single cookie, first-party or third-party. That is why there is no cookie banner: there is nothing to consent to.
- There is no analytics. No Google Analytics, no Plausible, none at all. Mansio does not know how many people visit the site or where they go.
- No pixels, no social buttons, no Google Fonts. The typeface is served from the domain itself.
- The only thing stored in your browser is the language you choose, in a
localStoragekey calledmansio.taal, holdingen,esornl. It exists so you are not sent back to English when you return. It stays on your device, travels in no request, and never reaches Mansio. You can clear it by clearing your browser's storage. - There is one exception, and it is told in full, because until today it was not declared. It is set out in the Cookie notice, and in short: the Cloudflare network adds a standard header (
NEL) to every response, asking your browser to send a technical report toa.nel.cloudflare.com, a Cloudflare server, if a request to this site fails. Successful visits are not reported — only errors — and it carries no content of yours, but it does carry the address requested and your IP address. Mansio did not add it and does not read it; it is declared because it leaves your browser.
Security
The site is served over HTTPS only, with HSTS and a Content Security Policy that permits loading resources from the domain itself and nowhere else. The domain's mail is protected with SPF, DKIM and DMARC. Access to the mailbox is limited to the people at Mansio who have to answer you. If a security breach nevertheless occurred that posed a high risk to you, Mansio will tell you without undue delay, and will notify the Autoriteit Persoonsgegevens within 72 hours where required.
Changes to this notice
When it changes, it changes here, and the date below changes with it. If the change is substantial — another purpose, another recipient, another country — the people in conversation with Mansio at that moment are told by email. On 3 September 2026 two substantial things changed, and they are reflected above: the form is now sent from the website itself — it used to open the visitor's own mail programme — and the mailbox moved from Google to Zoho Mail (European Union).
Last updated: 30 August 2026. This document is a draft (v0.1 CONCEPT) and has not been reviewed by a lawyer.