Legal · privacy
Privacy policy
We collect as little as we can get away with, we don't sell any of it, and we've written this in words you can actually read. It's still a real policy — it just doesn't need a lawyer to decode.
1. Who we are
Bolt Studio Unipessoal Lda ("Bolt Studio", "we", "us") is a product design and engineering studio registered in Portugal, at Rua da Boavista 84, 2nd floor, 1200-068 Lisbon. For anything covered by the UK and EU General Data Protection Regulation, we are the data controller for the information described below.
Questions, requests and complaints all go to the same place: privacy@boltstudio.co. A person reads that inbox; there is no ticketing system in front of it.
2. What we collect
When you contact us
If you fill in the form on our contact page or email us, we get your name, email address, and whatever you choose to tell us about your project — including the optional company name, budget range and timeline. That's it. We don't enrich it with third-party data, we don't look you up in a lead database, and we don't buy lists.
When you visit the site
Our hosting provider records standard server logs: IP address, browser user-agent, the page requested and a timestamp. These are kept for 30 days for security and debugging, then deleted automatically.
When we work together
During a project we'll hold ordinary business-contact details for the people on your team, the contents of our shared Slack channel and repositories, and whatever you send us in order to get the work done.
What we never collect: we don't run advertising pixels, we don't operate tracking across other websites, we don't build behavioural profiles, and we have never sold personal data to anyone. We'd rather not be in that business.
3. Why we're allowed to
Under the GDPR everything we do with your data needs a lawful basis. Ours are:
- Legitimate interests — replying to an enquiry you sent us, keeping the site online and secure, and keeping notes on conversations so we don't ask you the same question twice.
- Performance of a contract — everything we need to actually deliver a project you've hired us for, and to invoice you for it.
- Legal obligation — Portuguese tax law requires us to keep invoices and related accounting records for ten years, and we're not going to argue with it.
- Consent — the handful of cases where we ask first, such as naming you as a client or quoting you in a case study. Consent can be withdrawn at any time and we take the reference down.
4. Cookies and analytics
This website sets no cookies. None at all — there's no consent banner because there's nothing to consent to.
We use a self-hosted, privacy-preserving analytics tool to count page views. It does not use cookies, does not store IP addresses, does not attempt to identify individual visitors, and does not follow you to any other site. We look at it roughly once a month to see whether anyone read the case studies.
Some pages embed images from Unsplash's content delivery network. Loading an image means your browser makes a request to their servers, and their own privacy policy applies to that request.
5. Who else sees it
A short list of service providers, each with a data processing agreement in place:
- Fastmail — email hosting for our inboxes (Australia / EU).
- Hetzner — website and application hosting (Germany).
- Slack — shared client channels during a project (EU data residency).
- GitHub — code repositories, which are yours, in your organisation.
- Moloni — invoicing and Portuguese tax compliance (Portugal).
Beyond those, we share personal data only when a law or a court order requires it. We do not sell, rent or trade it, and there is no advertising network in our stack.
6. How long we keep it
- Enquiries that don't become projects — 24 months, then deleted. Founders often come back a year later, and it's useful to have the context.
- Server logs — 30 days.
- Client project records — for the duration of the engagement plus 3 years, in case of a warranty or dispute question.
- Invoices and accounting — 10 years, because Portuguese tax law says so.
Ask us to delete something earlier and, unless the law requires us to keep it, we will.
7. Data inside client projects
When we build software for you, any personal data belonging to your users is yours. You are the controller; we act as a processor and only handle it on your documented instructions. In practice that means:
- We work against seeded or anonymised data wherever it's technically possible.
- Access to production systems is granted for the shortest time that works, and revoked at handover — we'll confirm in writing when it's done.
- We never copy production databases onto a laptop.
- If you need a formal data processing agreement, ask and we'll sign one before kickoff. Most of our clients do.
8. Your rights
If you're in the UK or the EU you have the right to access your data, correct it, have it deleted, restrict or object to how we use it, and receive a portable copy. Where we rely on consent, you can withdraw it at any time.
Email privacy@boltstudio.co and we'll deal with it within 30 days, usually much sooner. We won't charge you, we won't make you fill in a form, and we won't ask why.
If we get it wrong, you can complain to the Comissão Nacional de Proteção de Dados (CNPD) in Portugal, or to the supervisory authority where you live. We'd appreciate the chance to fix it first.
9. Security
Encryption in transit and at rest, mandatory two-factor authentication on every account we own, hardware security keys for anything that touches client production systems, and a password manager that nobody is allowed to opt out of.
Access follows least privilege and is reviewed quarterly. Laptops are encrypted and can be wiped remotely. No system is perfect, so if we ever suffer a breach affecting your data, we'll tell you and the CNPD within 72 hours of finding out, with what we know and what we're doing about it.
10. International transfers
Our infrastructure sits in the EU by default. Where a provider processes data outside the EEA, that transfer is covered by an adequacy decision or by Standard Contractual Clauses, and we've done a transfer risk assessment for each one. Copies are available on request.
11. Children
Our site and services are aimed at businesses and are not directed at anyone under 16. We don't knowingly collect data about children. If you believe we have, tell us and we'll delete it immediately.
12. Changes to this policy
When we change something meaningful, we update the version and date at the top of this page and email anyone with an active project. We don't quietly rewrite history — previous versions are available if you ask for them.
13. Contacting us
Privacy questions: privacy@boltstudio.co
Everything else: hello@boltstudio.co
Post: Bolt Studio Unipessoal Lda, Rua da Boavista 84, 2nd floor, 1200-068 Lisbon,
Portugal.
The short version: we hold your name, your email and whatever you told us about your project. We use it to reply to you and to do the work. We don't sell it, we don't track you, and you can have it deleted by sending one email.
Still got a question?
Privacy, contracts, security reviews — send it over and a human will answer properly. We've been through enough procurement processes to have the documents ready.