Legal
Privacy policy
Last updated 5 September 2026
This site is a portfolio with a contact form on it. There are no accounts, no adverts and no tracking cookies, so there is not much to tell — but what there is, is here in full.
The short version
The only personal data collected is what you type into the booking form — your name, your email and your answers about the project. It is used to reply to you and nothing else. It is never sold, and never used for marketing you did not ask for. Email info@agencyduck.com and it gets deleted.
01Who is responsible
Sleek Duck is the data controller for anything collected through this website. Sleek Duck is a creative studio based in Romania, producing 3D ads, brand visuals and websites.
Contact for anything on this page:
Email: info@agencyduck.com
Phone: +40 753 709 987
There is no separate Data Protection Officer; the studio is small enough that the contact above reaches the person who decides these things.
02What is collected
When you use the booking form
The form asks for a small, fixed set of things:
- Your name and email address — so a reply can reach you.
- Your answers about the project — what you want made, what it's for, your timeline, and the budget range you selected, in euros or dollars.
- Anything you type in the free-text box — entirely optional, and skippable.
- A record of your consent — the fact that you ticked the box, and the moment you ticked it. This exists so it can be shown that you agreed, which is itself a requirement.
- Where you arrived from — if you reached the site from an ad or a link, the campaign details in the link (utm tags, click ids) and the domain that referred you. This tells the studio which channels are worth continuing. It is read from the address bar at the moment you submit, held only in the browser's memory, and never written to a cookie or to storage.
When you just read the site
Nothing is collected by the site itself. There is no analytics script, no pixel, no session recording and no advertising tag.
The company hosting the site will keep standard server logs — typically IP address, timestamp, the page requested and your browser's user-agent string. Those logs are created by the hosting provider for security and reliability, not by this site, and are not linked to anything else about you.
If you email or call instead
Whatever you put in the message, plus your email address or phone number. Same treatment as the form.
03Why, and on what legal basis
| What | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, email, project answers | To reply to your enquiry and to prepare a quote | Steps taken at your request before entering a contract — Art. 6(1)(b); with your explicit consent recorded at the form — Art. 6(1)(a) |
| Consent record | To be able to demonstrate that you agreed | Legal obligation — Art. 6(1)(c) |
| Campaign and referrer details | To know which channels bring real enquiries | Legitimate interest in understanding where enquiries come from — Art. 6(1)(f) |
| Spam checks on the form | To keep automated submissions out of the inbox | Legitimate interest in a working contact channel — Art. 6(1)(f) |
| Server logs | Security, abuse prevention, keeping the site up | Legitimate interest in a secure service — Art. 6(1)(f) |
Your details are not used for newsletters or marketing campaigns. If a marketing list is ever added, it will be a separate, opt-in decision — not something your enquiry quietly signs you up to.
06Transfers outside the EU
Some of the providers above operate servers outside the European Economic Area, most commonly in the United States. Where that happens, the transfer relies on the safeguards those providers have in place — the EU Standard Contractual Clauses, or the EU–US Data Privacy Framework where the provider is certified under it.
In practice, the data involved is an enquiry about a video project. It is not sensitive-category data, and it is never financial or identity data.
07How long it is kept
- Enquiries that don't become projects — kept up to 12 months, then deleted. Long enough to recognise you if you come back, not long enough to be hoarding.
- Enquiries that become projects — kept for the life of the project and afterwards for as long as accounting and tax law requires records to be held.
- Consent records — kept as long as the enquiry they belong to.
- Server logs — kept for whatever period the hosting provider applies, typically a short rolling window.
You do not have to wait for any of these periods to run out. Ask, and it goes.
08Your rights
Under the GDPR you can, at any time:
- Ask what is held about you, and get a copy of it (Art. 15).
- Have mistakes corrected (Art. 16).
- Have it deleted — the right to be forgotten (Art. 17).
- Restrict how it is used while a question about it is resolved (Art. 18).
- Take it with you in a portable format (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent whenever you like, without giving a reason. Withdrawing does not undo anything done while consent was in place (Art. 7).
Exercising any of these is free, and no explanation is required. Requests are answered within one month, as the regulation requires.
If you are not happy with how a request is handled, you can complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), at dataprotection.ro — or to the authority in your own EU country.
09Deleting your data
The fastest route is one email:
Or write to info@agencyduck.com with the subject “Data deletion request”.
Say which email address you used to get in touch, so the right record can be found. You may be asked one question to confirm it is really you — that check exists to stop someone else deleting your data, and nothing more.
Everything held about you is then erased from the inbox and from any project notes, except anything that accounting or tax law requires be kept — in which case you will be told exactly what has to stay and for how long. You get written confirmation when it is done.
10If something goes wrong
If a personal data breach ever occurs and it is likely to result in a risk to your rights and freedoms, the ANSPDCP will be notified within 72 hours of the breach becoming known, as Art. 33 requires.
If the breach is likely to result in a high risk to you, you will be told directly, without undue delay (Art. 34) — in plain language: what happened, what data was involved, what is being done about it and what you should do.
This site is a set of static files with no database and no logins, which keeps the surface area small. If you spot a security problem with it, please report it to info@agencyduck.com; reports made in good faith are welcome and will not be met with legal threats.
11Children
This site is aimed at businesses and is not directed at children. Personal data is not knowingly collected from anyone under 16. If you believe a child has sent information through this site, get in touch and it will be deleted.
12Changes to this policy
If this policy changes, the date at the top changes with it. Material changes — a new processor, a new purpose, analytics being introduced — will be described here rather than slipped in quietly.
This version has effect from 5 September 2026.