Privacy policy

Last updated: July 13, 2026

Privacy at a glance

Inquiry information and images are used to evaluate and respond to your project. Temporary uploads are not a public gallery, and the site does not sell personal data or use it for third-party advertising.

This notice applies when you visit etedebring.com, submit an inquiry, upload reference or placement images, use the private artwork area, or contact the studio. It is an explanation of processing, not a request for blanket consent.

Controller and contact

The controller is Edvin Tedebring / etedebring.com, based in Zürich, Switzerland. Swiss data protection law is the baseline for this processing. The GDPR, UK GDPR, or other local privacy rules may also apply depending on your location and where a service is offered.

For privacy questions or requests, email info@etedebring.com.

Personal data we process

Depending on how you use the site, this may include:

  • Inquiry details: name, email, phone number, Instagram handle, requested location, travel information, height, referral source, collector status, project description, and related correspondence.
  • Images and attachments: reference images, placement photos, file type and size, temporary storage keys, and attachment names.
  • Technical and security data: request and network metadata, short-lived hashed rate-limit identifiers, anti-bot verification data, security logs, page path, timestamps, and limited error or upload diagnostics.
  • Website measurement data: page views, referrer, general location, device, browser, and performance data used in aggregated analytics.
  • Private artwork access: whether a signed first-party access cookie has been granted.

Images and sensitive information

Placement photos may show body areas, scars, health-related details, or other sensitive information. Upload only what is needed to evaluate the project. Do not include identity documents, medical records, unrelated people, or more body detail than necessary.

If you voluntarily include sensitive details in photos or text, you explicitly consent to their limited use for evaluating and responding to the inquiry where consent is required. You can withdraw that consent by contacting the studio; withdrawal does not affect processing already completed before the request.

Purposes and legal grounds

Personal data is processed to:

  • review inquiries, assess project fit, communicate, arrange bookings, and provide an agreed service;
  • receive temporary uploads, assemble inquiry emails, and remove those uploads after the submission flow;
  • prevent abuse, verify that a submission is likely human, rate-limit requests, troubleshoot failures, and protect the site;
  • understand aggregate traffic and performance so the website can be maintained and improved; and
  • meet accounting, tax, legal, insurance, and record-keeping duties or protect legal rights.

Where GDPR or UK GDPR applies, the usual legal grounds are steps before a contract, performance of a contract, legal obligations, and legitimate interests in operating a secure and effective website. Consent is used only where required, including for sensitive details voluntarily included in an inquiry.

Providers and recipients

Access is limited to the studio and service providers that are needed for the purposes above. The current provider categories include:

  • Vercel for website hosting, Web Analytics, and performance measurement;
  • Cloudflare for temporary R2 object storage and Turnstile anti-bot verification;
  • Resend and the studio mailbox provider for inquiry email;
  • Sanity for website content management; and
  • Upstash for short-lived distributed rate-limit counters when that service is configured.

Data may also be disclosed to advisers, insurers, courts, regulators, or public authorities when required by law or necessary to protect legal rights. Personal data is not sold or shared for third-party advertising.

International transfers

The studio works internationally and its providers operate across multiple regions. Processing may therefore take place in Switzerland, the EU/EEA, the United Kingdom, the United States, and other countries used by a provider or its subprocessors. Exact locations can depend on account settings and infrastructure availability.

Where required for a destination without an officially recognised adequate level of protection, contractual safeguards such as approved standard data-protection clauses and supplementary measures are used. Contact the studio if you want more information about a particular transfer.

Retention

  • Temporary uploaded images are normally deleted after the inquiry submission attempt. If the normal cleanup does not complete, stale inquiry uploads become eligible for best-effort cleanup after two days by default.
  • Inquiry emails and correspondence are kept while needed to respond, manage a booking, provide the service, maintain business records, or protect legal rights. Inactive or declined inquiries should normally be reviewed for deletion within 24 months of the last contact; booking, tax, or legal records may require longer retention.
  • Rate-limit counters last only for the relevant protection window, generally 10 to 15 minutes.
  • The private artwork access cookie expires after 14 days. Turnstile verification tokens are short-lived and used for one submission check.
  • Analytics, hosting, email, security, and diagnostic records follow the shortest practical period under the relevant account settings, operational needs, and legal duties.

Cookies, analytics, and anti-bot checks

The private artwork area uses a necessary first-party cookie named void-study-access. It is HTTP-only, same-site, secure in production, restricted to the private artwork path, and expires after 14 days.

Vercel Web Analytics and Speed Insights are used for aggregated site and performance measurement. Web Analytics is designed without third-party advertising cookies and does not provide the studio with a cross-site profile of an identified visitor.

Cloudflare Turnstile runs on the inquiry form to distinguish legitimate submissions from automated abuse. It evaluates browser and interaction signals, produces a short-lived token, and may receive the requester's IP address during server verification. This check can reject or delay a submission; if it fails incorrectly, contact the studio by email.

Browser settings can be used to clear or block storage. Blocking necessary storage or anti-bot resources may prevent protected pages or the inquiry form from working correctly.

Security

Measures include HTTPS, short-lived signed upload URLs, signed upload receipts, private object keys, file type and size limits, rate limits, anti-bot verification, temporary-upload cleanup, restricted access, escaped email content, and security response headers. No internet service can be guaranteed completely secure, but proportionate steps are taken to reduce unauthorised access, disclosure, and abuse.

Your rights

Under Swiss data protection law, you may request information about whether personal data concerning you is processed and, where applicable, ask for correction, deletion, or restriction. Where GDPR or UK GDPR applies, you may also have rights to access, rectification, erasure, restriction, portability, and objection. Consent can be withdrawn at any time where processing relies on it.

Email info@etedebring.com to make a request. You may also contact the Swiss Federal Data Protection and Information Commissioner or, where applicable, your competent EU/EEA or UK supervisory authority. Swiss guidance is available at edoeb.admin.ch.

Children

This website and inquiry form are not directed to children. Do not submit an inquiry if you are under 18 unless the request is lawful in the relevant jurisdiction and any required guardian involvement has been arranged.

Changes to this notice

This notice may be updated when the website, inquiry process, providers, locations, or legal requirements change. The latest version and update date are published on this page.