Privacy Policy
DNDB Version 1.0.1. Last updated: 3 September 2026.
This policy explains what personal data we collect through dndb.digital, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. It covers visitors to the site, people who contact us, and people we work with on projects.
It is written to satisfy the Brazilian LGPD (Lei 13.709/2018), the GDPR (EU 2016/679), the UK GDPR, and the notice requirements of United States state privacy laws including the CCPA/CPRA. Section 12 sets out the additional rights that apply if one of those regimes covers you.
1. Who is responsible for your data
The controller is:
Viktor Fediuk, Empresário Individual, trading as DNDB (previously trading as D&D Partners) CNPJ 65.396.022/0001-68 São Paulo, SP, Brazil. The full registered address is available in the public CNPJ registry and on request by email Email: [email protected]
Contact channel for data protection. Under Brazilian law we qualify as a small scale processing agent (agente de tratamento de pequeno porte, Resolução CD/ANPD nº 2/2022) and are not required to formally appoint a Data Protection Officer. We do maintain a direct channel for everything covered by this policy: write to [email protected] with "Privacy" in the subject line, and a human reads it.
We have not appointed a representative in the European Union under Article 27 GDPR or in the United Kingdom. Our processing of EU and UK personal data is occasional, does not include large scale processing of special categories, and is unlikely to result in a risk to rights and freedoms; we rely on the exemption in Article 27(2)(a). If our processing changes in a way that requires a representative, we will appoint one and name them here.
2. What we collect, and when
2.1. When you fill in the contact form
Fields you fill in yourself:
| Data | Required |
|---|---|
| Name | yes |
| Email address | yes |
| Message about your project | yes |
| Estimated budget range | yes |
| Desired timeline | yes |
Collected automatically with the submission:
- Campaign parameters in the link you arrived through (
utm_source,utm_campaign,ad_id) and which offer on the page you were looking at, so that we know which advertisement or channel brought you. - A hidden anti-spam field, which a human never sees and never fills in. It exists so that automated submissions can be discarded.
2.2. When you add project details
If you continue and answer the additional project questions, we receive those answers as a second message. They are business information about your project, plus the name and email you already gave.
2.3. When you book a call
We receive the time slot you selected and the timezone your browser reports, so that the confirmation matches your local time, along with your name and email.
2.4. When you email us or talk to us
We receive whatever you put in the message: your name, email address, any phone number, company details, signature block, attachments, and the content of the conversation. Calls are not recorded unless we tell you in advance and you agree.
2.5. When you simply visit the site
- Server logs. Our hosting provider, Cloudflare, Inc. (United States, with a global network), records technical data for every request: IP address, date and time, the page requested, the referring page, browser and operating system. This is standard for any web server and is used for security, abuse prevention and diagnostics.
- Local storage on your device. The site stores two small items in your browser's local storage, not in cookies: your analytics choice (
dd_consent), so we do not ask again on every visit, and the section you were on, so that a reload returns you to the same place. Both stay on your device, are never sent to us, and can be cleared at any time in your browser settings. These are strictly necessary for functions you asked for, so we do not ask consent for them. - Analytics, only if you accept. See section 4.
- Embedded third-party content. See section 3.
2.6. When you become a client
During a project we handle: your contact and billing details; the name, role and contact details of the people on your side; access credentials you give us; the content and materials you send; and correspondence. Where a project involves personal data of your users, we act as a processor on your behalf, not as a controller, and the terms in clause 25 of the Client Services Agreement apply.
We also hold the invoicing records that Brazilian law requires us to keep, including the data needed to issue a Nota Fiscal de Serviços.
2.7. What we never ask for
We do not ask for, and you should not send us through the website form: passwords, access credentials, payment card numbers, identity document numbers, health data, or any of the special categories of data listed in Article 9 GDPR and Article 5, II LGPD. If you send such data unprompted, we delete it.
3. Third-party content embedded in the site
One element loads from outside our servers. When they load, the provider receives your IP address and basic technical data, because that is how the internet delivers a file. They may also set their own cookies.
| Element | Provider | Loads when |
|---|---|---|
| Showreel video player | YouTube (Google Ireland Limited / Google LLC) | only after you click to play the showreel, served from the privacy-enhanced youtube-nocookie.com |
Fonts, the 3D scene and the 3D player software are hosted on our own server, so they generate no third-party request.
If you do not want YouTube to receive anything, do not play the showreel.
4. Analytics and your choice
4.1. We use Google Analytics 4 to count visits and understand which pages and which channels work. We also use Microsoft Clarity for aggregated heatmaps and session recordings, to see where the site is confusing and fix it, and the Meta Pixel so that our advertising can be measured and optimised. All three run behind the same gate, described in 4.2 and 4.3.
4.2. Where consent is the legal basis, nothing is loaded until you choose. On a first visit from the European Economic Area, the United Kingdom or Switzerland, a banner asks whether you accept analytics. Until you accept:
- the Google, Microsoft and Meta scripts are not downloaded at all, so none of them receives anything;
- no analytics storage is written;
- Google Consent Mode is set to denied for every category.
If you decline, the site makes zero third-party analytics requests. Your choice is stored on your device and you can change it by clearing your browser storage for this site.
4.3. Everywhere else there is no banner. Asking permission before measuring an audience is a European rule, from the ePrivacy Directive together with the GDPR. Brazilian law allows audience measurement on legitimate interest, and United States state privacy laws work by opt-out rather than opt-in. Visitors outside Europe therefore get analytics, including the Meta Pixel, without being interrupted, on the legitimate interest basis in section 6, and can turn them off at any time with the control below, or by sending Global Privacy Control, which we honour in every country.
4.4. Which country you are in is read from your browser's own timezone setting. We do not look up your IP address for this and we do not call any geolocation service, because doing so would be exactly the kind of request the banner exists to prevent. The check is approximate, so it errs toward asking: anything it cannot place is treated as European.
4.5. If you accept, Google Analytics collects: pages viewed, time on page, approximate location derived from a truncated IP address, device and browser type, referring source, campaign parameters, and an identifier stored on your device. IP anonymisation is applied. We use the data only in aggregate. We do not use Google Signals, advertising personalisation or cross-device tracking.
4.6. Legal basis where a banner is shown: your consent (Article 6(1)(a) GDPR; Article 7, I LGPD). You may withdraw it at any time, with effect for the future.
5. Who else processes your data
These are our processors. Each one only receives what it needs for its function.
| Processor | Function | Where the data is processed |
|---|---|---|
| Web3Forms (Surjith S M, India) | delivers the website form to our inbox | servers in the United States (AWS, US East). Retains submissions for up to 3 years. Offers a data processing agreement and uses Standard Contractual Clauses for transfers from the EEA, UK and Switzerland. |
| Google (Google Ireland Limited / Google LLC) | the mailbox behind [email protected], and Analytics if you accept | European Union and United States. Google LLC is certified under the EU-US Data Privacy Framework. |
| Microsoft (Microsoft Corporation) | Clarity heatmaps and session recordings, only if you accept analytics | United States. Microsoft Corporation is certified under the EU-US Data Privacy Framework. |
| Meta (Meta Platforms Ireland Ltd / Meta Platforms, Inc.) | the Meta Pixel, to measure and optimise our advertising, only if you accept analytics | European Union and United States. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework. |
| Cloudflare, Inc. | serves the site, routes our incoming email, keeps server logs | United States, with a global network. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework. |
| Our payment and invoicing providers | receive and record payments from clients | as stated on the relevant proposal or invoice |
| YouTube | see section 3 | United States |
| Contractors on our team | carry out project work under confidentiality obligations. The team is public: we formed the agency on Upwork and our people are listed there by name | Ukraine, Brazil and elsewhere |
We also disclose data where the law requires it: to the Brazilian tax authorities as part of ordinary invoicing and reporting, to a court or regulator on a valid order, or to professional advisers under a duty of confidence. If our business is transferred, data may pass to the acquirer under the same commitments, and we will tell you.
We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not trade in mailing lists.
6. Why we process your data, and on what legal basis
| Purpose | GDPR / UK GDPR basis | LGPD basis |
|---|---|---|
| Reply to your enquiry, prepare an estimate or proposal | Article 6(1)(b), steps at your request before a contract | Article 7, V, procedimentos preliminares |
| Carry out a project, invoice it, support it | Article 6(1)(b), performance of a contract | Article 7, V |
| Keep tax, accounting and invoicing records | Article 6(1)(c), legal obligation | Article 7, II |
| Keep the site secure, prevent spam and abuse | Article 6(1)(f), legitimate interest in protecting our service | Article 7, IX, legítimo interesse |
| Understand which channel brought you, and improve the site | Article 6(1)(a), consent, for analytics; Article 6(1)(f) for campaign parameters submitted with a form you chose to send | Article 7, I and IX |
| Establish, exercise or defend legal claims | Article 6(1)(f) | Article 7, VI |
| Send occasional updates to existing clients about our services | Article 6(1)(f), and consent where required by local law | Article 7, IX |
Where we rely on legitimate interest, we have considered your interests and rights against ours, and you can object at any time under section 11.
7. Marketing
We do not run a newsletter and we do not add enquirers to a mailing list. If we later start one, it will be opt-in only, and every message will carry an unsubscribe link. Existing clients may receive occasional messages about our services and can opt out at any time by replying.
8. How long we keep things
| Data | Retention |
|---|---|
| Enquiry that does not become a project | 24 months from the last contact, then deleted |
| Enquiry that becomes a project | for the project, then 5 years from the end of the business relationship, to cover the ordinary Brazilian limitation and tax periods |
| Contracts, proposals, invoices and fiscal records | at least 5 years, as required by Brazilian tax and civil law |
| Project files and deliverables | up to 24 months after delivery, so that we can help you if something breaks. After that they may be deleted without notice, so keep your own copies |
| Email correspondence | up to 5 years |
| Form submissions held at Web3Forms | up to 3 years, by that provider |
| Server logs | as set by our hosting provider, typically weeks rather than months |
| Analytics data | 14 months in Google Analytics, then aggregated; Clarity keeps individual session recordings up to 30 days and aggregated heatmaps up to 13 months |
| Your analytics choice | on your device until you clear it |
When a period ends we delete the data or irreversibly anonymise it. Backups are overwritten on their own cycle, and data can persist in them briefly after deletion from the live systems.
9. Where your data goes
We are established in Brazil. Depending on the processor involved, your data may be processed in Brazil, the European Union, the United States, India or Ukraine.
For transfers out of the EEA we rely first on the European Commission's adequacy decision for Brazil, adopted on 26 January 2026, which recognises Brazilian data protection law as providing a level of protection essentially equivalent to the GDPR. Personal data can therefore flow from the EEA to us without any further transfer mechanism. Brazil adopted a mutual adequacy decision for the EU on the same date, so the flow back is equally covered.
For transfers from the United Kingdom we rely on the UK's own transfer mechanisms, including the International Data Transfer Agreement or Addendum where required.
Where a processor is outside Brazil and the EEA, we rely on: the EU-US Data Privacy Framework where the recipient is certified; Standard Contractual Clauses with additional safeguards in every other case; and, for transfers out of Brazil, the mechanisms permitted by Articles 33 to 36 LGPD.
You can ask us for details of the safeguards applying to a specific transfer.
10. Security
We take measures appropriate to a business of our size and to the sensitivity of what we hold: HTTPS on the whole site, two-factor authentication on our accounts, a password manager, access limited to the people who need it, confidentiality obligations on every contractor, encrypted devices, and no storage of payment card data by us at any time.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the competent authority without undue delay, and within the deadlines set by the law that applies, including the ANPD in Brazil.
11. Your rights
Whoever you are and wherever you are, you can ask us to:
- confirm whether we hold data about you, and get a copy of it;
- correct anything inaccurate or incomplete;
- delete it, where we have no overriding legal reason to keep it;
- restrict or object to processing based on legitimate interest;
- port it, receiving it in a structured, commonly used, machine readable format, or having it sent to another provider where technically feasible;
- withdraw consent at any time, without affecting what was lawful before;
- know with whom we have shared it;
- be told the consequences of refusing to give consent, where consent is the basis.
How to exercise them. Write to [email protected] with "Privacy" in the subject. We reply within 30 days, or within 15 days where the LGPD requires it. We may ask you to confirm your identity, and only to the extent needed. Exercising these rights is free. We may charge a reasonable fee, or decline, only for a request that is manifestly unfounded or repetitive, and we will explain why.
Complaints. You can complain to a supervisory authority: - Brazil: ANPD, https://www.gov.br/anpd - EU/EEA: the data protection authority of your country - United Kingdom: the ICO, https://ico.org.uk
We would rather you told us first, so that we can fix it.
12. Regional additions
12.1. If you are in the EU, the EEA or the UK
All the rights in section 11 apply as set out in the GDPR and the UK GDPR. We rely on Article 6(1)(b), (c), (f) and (a) as shown in section 6. We do not carry out automated decision making or profiling that produces legal or similarly significant effects.
12.2. If you are in Brazil
Your rights under Article 18 LGPD apply, including confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, and revocation of consent. We are a small scale processing agent under Resolução CD/ANPD nº 2/2022, which is why the contact channel in section 1 stands in place of a formally appointed Encarregado.
12.3. If you are in California or another US state with a privacy law
In the last 12 months we have collected the categories of personal information described in section 2: identifiers, commercial information, internet activity and, where analytics are running, inferences drawn from it. The purposes are in section 6, the recipients in section 5, and the retention periods in section 8.
The Meta Pixel runs on this site, and this is plainly why. It measures whether our advertising works: which advertisement brought a visitor, and whether that visit turned into an enquiry. Two things could restrict that, and neither one bites here. The first is selling personal information: we have never been paid for anyone's data and we do not trade in lists, so no sale takes place. The second is what the CCPA/CPRA calls sharing for cross-context behavioural advertising, which advertising measurement can amount to, and we would rather name it than pretend otherwise. But that law binds a business only above a threshold: more than US$25 million in annual revenue, or the data of 100,000 Californians in a year, or half its income earned from selling data. We are far below all three, so the obligation does not attach to us.
We give you the off switch regardless. What matters to you is whether you can say no, not whether a statute happens to oblige us to offer it. To opt out, use the control in section 4.3: it switches analytics and the Pixel off in the browser you are using. We also honour the Global Privacy Control browser signal as an opt-out, in every country, without being asked and whether or not any law requires it.
We do not knowingly collect or sell the personal information of anyone under 16, and we do not collect sensitive personal information as that law defines it. You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. For the rights other than opting out, use the contact in section 11, and an authorised agent may act for you with written proof.
13. Children
The site is aimed at businesses. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us data, write to us and we will delete it.
14. Automated decisions
We do not make decisions about you by automated means alone. We use AI tools in our research and production work, but the decisions that affect a person or a project are made by a human. Clause 15 of the Client Services Agreement explains how we use those tools on client projects.
15. Links to other sites
Our site links to Behance, Dribbble, LinkedIn, Clutch and Upwork. Once you follow a link, that provider's own privacy policy applies. We have no control over it.
16. Changes to this policy
We update this policy when what we actually do changes. The current version, with its number and date, is always at dndb.digital. If a change materially affects your rights, we will make it visible on the site and, where the law requires, ask for your consent again.
17. Contact
[email protected] with "Privacy" in the subject line. Postal address as in section 1.
DNDB · Viktor Fediuk, Empresário Individual · CNPJ 65.396.022/0001-68 · São Paulo, Brazil · [email protected]
The Provider previously traded as D&D Partners. This document is effective from 1 September 2026.
Also: Terms of Service · Privacy Policy · Client Agreement