Privacy notice
Last updated: 2026-07-18. This is the privacy notice for flowdonia.com and the private portfolio at design.flowdonia.com and flowdonia.studio. Short version: Flowdonia uses one functional cookie for your language preference, no tracking pixels, and no third-party analytics. Otherwise anonymous traffic data only, plus any email you choose to send.
Data controller
Dylan Evans, natural person, based in Amsterdam, Netherlands. Contact: [email protected].
What is collected
- Anonymous traffic data via Cloudflare Analytics. Cookieless. Collects: page paths visited, referring URL, country (from IP), browser type, screen size. Does NOT collect: your IP address (Cloudflare anonymises it before storage), individual identifiers, cross-site tracking data.
- Aggregate scroll-depth counts across this site, via a first-party beacon to this site only. Counts how far down a page a visit scrolls, in four steps, by layout size, and how often the contact link is used. No cookies, no identifiers, nothing personal; stored as totals in Cloudflare.
- Inbound emails if you email [email protected]. Your message, sender address, and any attachments you choose to include are received via Proton Mail (Switzerland) and held in a personal inbox.
- Language-preference cookie: if you use the language switch
(EN | NL), or your browser signals a Dutch language preference, the site stores
one functional cookie (name:
flow_lang, retention: 1 year, SameSite=Lax, Secure) to remember your choice. It holds no personal data and is not shared with third parties.
What is NOT collected
- No tracking cookies, no analytics cookies, no advertising cookies.
- No tracking pixels, web beacons, or fingerprinting.
- No third-party analytics (no Google Analytics, no Hotjar, no similar).
- No advertising identifiers.
- No contact form data (the site has no contact form).
Private portfolio access
The portfolio at design.flowdonia.com and flowdonia.studio is private and sits behind a Cloudflare Access login. To enter, you give an email address and receive a one-time code. This involves:
- The email address you enter, used to send the one-time code and to check it against the list of people allowed in.
- Access logs via Cloudflare Access: email address, IP address, timestamp, approximate country, and browser type for each sign-in attempt. The basis is legitimate interest in controlling access to confidential material and keeping a security record. These logs are retained for about 24 hours.
- Two strictly necessary cookies set by Cloudflare Access after
sign-in (
CF_AppSessionandCF_Authorization). They keep you signed in for the session and are required to deliver the access you requested, so they need no consent. The portfolio uses no analytics or tracking cookies.
How long data is retained
- Analytics: per Cloudflare's standard retention (currently 6 months for detailed data, indefinitely for aggregated counts).
- Emails: retained as long as the conversation is relevant. Old correspondence is periodically reviewed and deleted.
Your rights under GDPR
You have the right to access, correct, delete, port, or object to processing of your personal data. To exercise any of these, email [email protected]. Requests are handled within 30 days.
If you believe your rights have been infringed, you may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Third-party processors
- Cloudflare (USA, with EU data presence) - hosting, anonymous analytics, and Access (authentication and access logging for the private portfolio). Cloudflare privacy policy.
- Proton Mail (Switzerland) - email handling. Proton privacy policy.
Changes to this notice
Material changes will be noted at the top of this page with the new "Last updated" date.