01In short
This site has no forms, sign-up, accounts, or tracking, advertising or analytics cookies.
We only process the data you choose to send us by email and the minimal technical data generated when visiting any website. We do not sell or rent personal data.
This policy explains what data is processed, why, who it is shared with and how we protect the site. It applies to insidewish.com and to any communication you start from it.
02Data controller
- Controller
- Inside Wish Studio
- Website
- insidewish.com
- Privacy contact
- privacidad@insidewish.com
We process data in accordance with Argentina’s Personal Data Protection Law No. 25,326 and its supplementary regulations. Where the laws of your country require it —for example, the European Union’s General Data Protection Regulation (GDPR)— we also respect the rights those laws grant you.
03What data we process
Data you send us. If you email us, we receive your email address, your name if you include it and the content of your message, including any information about your project or company you choose to share. Please do not send us sensitive data (health, ethnic origin, political opinions, beliefs, etc.): we don’t need it.
Technical visit data. When the site loads, your browser automatically shares some technical information:
- The hosting server logs data such as your IP address, browser type, the page requested and the date and time of access. These logs are used to run the site, diagnose errors and prevent abuse.
- Fonts are loaded from Google Fonts. To deliver them, Google receives your IP address and technical browser data, under its own privacy policy.
We do not use analytics tools, social media pixels or advertising, and we do not build visitor profiles.
04How we use it
- To answer your inquiries and, if you ask, to prepare a proposal or quote. The legal basis is the consent you give by writing to us and taking pre-contractual steps at your request.
- To manage our business relationship if we work together, including meeting legal, accounting and tax obligations.
- To keep the site secure and running, based on technical logs. The legal basis is our legitimate interest in protecting the service.
We do not use your data to send you marketing you haven’t asked for.
05How long we keep it
We keep emails for as long as needed to reply and manage any resulting relationship. If we work together, we retain project records for the periods required by applicable law. Server logs are kept for short periods, according to the hosting provider’s configuration. Once those periods end, the data is deleted or anonymized.
08Your rights
You may exercise your rights to access, rectify, update and erase your data at any time, free of charge. If the GDPR applies to you, you may also request restriction of processing, object to it, request portability of your data and withdraw your consent.
To do so, email privacidad@insidewish.com from the address linked to your data, stating which right you want to exercise. We will respond within the legal deadlines: in Argentina, ten calendar days for access requests and five business days for rectification, update or erasure.
The data subject has the right to access their personal data free of charge at intervals of no less than six months, unless a legitimate interest is shown, as set forth in section 14, subsection 3 of Law No. 25,326.
The Agency for Access to Public Information, as the Supervisory Authority of Law No. 25,326, has the power to address complaints and claims filed by anyone whose rights are affected by non-compliance with personal data protection regulations.
If you live in the European Union, you may also lodge a complaint with your country’s data protection authority.
09Security
We apply reasonable technical and organizational measures, proportionate to the data we process:
- Encrypted connection. The entire site is served over HTTPS; HTTP and “www” requests are automatically redirected to the secure version.
- Minimal attack surface. The site is static: it has no forms, databases, user panel or payment processing that could be attacked.
- Security headers. The server sends policies that restrict which resources the page can load, prevent it from being embedded in other sites and limit the information leaked to third parties.
- Restricted access. Only studio staff who need it can access email and site administration, using accounts protected by strong passwords and two-step verification where the provider supports it.
- Providers with recognized security standards for hosting and email.
No system connected to the internet is completely invulnerable. If a security incident affected your data, we would investigate it, take steps to contain it and notify you and the authorities where the law requires.
Reporting vulnerabilities
If you find a potential vulnerability on the site, email privacidad@insidewish.com with the subject “Security report”, describing the issue and how to reproduce it. Please do not access third-party data, do not disrupt the site’s availability and give us reasonable time to fix it before making it public. We appreciate good-faith reports and will not take action against anyone who follows these guidelines.
10Minors
The site is aimed at companies, institutions and professionals. It is not intended for people under 18, and we do not knowingly collect their data. If you believe a minor has sent us personal data, write to us and we will delete it.
11Changes to this policy
We may update this policy if the site, the services we use or the law change. The version in force is always the one published on this page, with its update date.
This English version is provided for convenience. In case of any discrepancy, the Spanish version prevails.
12Contact
For any privacy or security question, write to privacidad@insidewish.com. See also our Terms of use.