The short version
This site sets no cookies, runs no analytics, and loads nothing from a third party. The fonts are served from this domain rather than from Google, so no outside company learns that you visited.
The only personal data actively collected is what you type into the contact form, and it is used for one thing: answering you. Nothing is sold, shared for marketing, or added to a mailing list. There is no consent banner because there is nothing here to consent to.
The rest of this page is the detail behind that.
Who is responsible
The controller of any personal data described here is:
- Company
- SpearLight OÜ
- Registry code
- 14523090
- Address
- Sepapaja tn 6, Lasnamäe, 15551 Tallinn, Estonia
- hello@spearlight.co
Full company details are on the legal notice. No data protection officer has been appointed, as the company is not required to appoint one.
What is collected
The contact form
When you send the form on the homepage, the following is collected: your name, your email address, your company or project name, the kind of organisation you work for, a rough budget band, your timeline, and the message you write. Only the name, email and message are required; the rest can be left blank.
It is used to answer your enquiry and, if we go on to work together, to scope and quote the project. The legal basis is Article 6(1)(b) GDPR, taking steps at your request before entering into a contract. Where an enquiry does not lead to a contract, the basis is Article 6(1)(f), the legitimate interest in responding to people who contact the business.
The form sends the message to the studio mailbox and also stores a copy in a file on the same server, so an enquiry is not lost if an email fails to arrive. That file is not reachable from the web.
Server logs
The web host records standard access logs: your IP address, the page requested, the date and time, the referring page, and your browser's user agent string. This happens for every website and is needed to operate the server, diagnose faults and detect abuse. The legal basis is Article 6(1)(f), the legitimate interest in keeping the site running and secure.
Spam prevention
A few small technical measures protect the contact form. The page records the moment the form loaded, so a submission completed in under three seconds can be rejected as automated. To limit how many messages arrive from one connection per hour, a one-way cryptographic hash of the IP address is stored with a timestamp; the hash cannot be turned back into an IP address, and entries older than an hour are deleted automatically. A hidden field invisible to people catches automated form-fillers.
Message content is also scored against a short list of patterns common in unsolicited sales mail, such as embedded links and stock sales phrases. This never blocks or deletes anything. A message that scores highly still arrives and is still stored; it simply carries a marker so it can be filed. No profile is built, and the score is not kept beyond the enquiry itself. The legal basis for all of this is Article 6(1)(f), the legitimate interest in preventing abuse of the form.
What is not collected
- No cookies. The site sets none, of any kind, including functional ones.
- No analytics or statistics. No Google Analytics, no Plausible, no Fathom, nothing.
- No tracking pixels and no advertising or remarketing tags.
- No browser storage. Nothing is written to localStorage or sessionStorage.
- No third-party fonts, embeds, maps or video players. Everything the page needs is served from this domain.
- No profiling and no automated decision-making within the meaning of Article 22 GDPR.
- No newsletter or mailing list. Contacting the studio does not sign you up to anything.
- No special category data is requested. Please do not put any into the form.
The links to Instagram, LinkedIn and Behance in the footer, and the project links in the work section, are ordinary hyperlinks rather than embedded widgets. Those companies receive nothing about you unless you click through, at which point their own privacy policies apply.
Who else handles it
DreamHost provides the web hosting and the email service for this domain, which means enquiries pass through and are stored on their infrastructure. DreamHost is based in the United States, so this involves a transfer of personal data outside the European Economic Area. That transfer is covered by the data processing agreement and the European Commission's Standard Contractual Clauses.
Nobody else receives your data. It is not passed to advertisers, data brokers, or any other third party.
How long it is kept
- Enquiries that do not lead to work: 12 months, then deleted from both the mailbox and the server file.
- Enquiries that become projects: kept for the duration of the work and afterwards for as long as accounting and tax law requires, which under the Estonian Accounting Act is 7 years after the end of the financial year.
- Server access logs: kept for the period set by the hosting provider, typically a few weeks.
- Spam-prevention hashes: deleted automatically after one hour.
Your rights
Under the GDPR you can ask for any of the following, free of charge:
- Access. A copy of the personal data held about you.
- Rectification. Correction of anything inaccurate or incomplete.
- Erasure. Deletion of your data, where there is no legal reason to keep it.
- Restriction. A pause on processing while a dispute is resolved.
- Portability. Your data in a structured, machine-readable format.
- Objection. To any processing based on legitimate interest, including everything described above under that basis.
To use any of these, email hello@spearlight.co. You will get an answer within one month. No special form is needed and no reason has to be given for an erasure or objection request.
Complaints
If you think your data has been handled improperly, you are entitled to complain to a data protection supervisory authority. The competent authority for this company is:
- Authority
- Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
- Address
- Tatari 39, 10134 Tallinn, Estonia
- Phone
- +372 627 4135
- info@aki.ee
- Website
- aki.ee
You may also complain to the supervisory authority in the EU country where you live or work, if that is easier.
Changes to this policy
If what this site does with data changes, this page changes with it and the date below is updated. Adding analytics, a newsletter, an embedded video player or a booking widget would all be such a change, and any of them would be reflected here before going live.
Last updated 22 August 2026