01.Data Philosophy & Guest-First Model
At Grafiesto, we believe digital exploration should respect user agency. Our interactive digital world is engineered to be guest-first. Visitors can explore technology realms, view interactive capability demonstrations, and create custom journey summaries without registering an account, providing an email address, or submitting personal identifiers.
When you interact with the Grafiesto platform, we collect only the minimal data required to render the experience, ensure platform security, and respond to explicitly requested inquiries.
02.Information We Collect
A. Information You Voluntarily Provide
When you use our Contact Form or subscribe to our insights newsletter, we collect the details you submit—such as your name, work email address, company name, scope budget, and message content. This information is used exclusively to fulfill your request and communicate regarding prospective engagements.
B. Technical & Device Data
Like most web services, our servers automatically log basic technical requests, including IP address (anonymized where applicable), user agent, browser type, operating system, timestamp, and referring URL. This diagnostic data is retained solely for infrastructure maintenance, abuse prevention, and network optimization.
03.Local Journey Storage
Grafiesto utilizes standard browser client-side storage (such as localStorage) to persist your progress across realms, preferred color theme (light or dark), and interactive Bravery Map milestones.
This data remains strictly local to your client browser device. It is never transmitted to or synchronized with central user profiling databases. You may clear your local journey state at any time via your browser clearing options.
04.Analytics & Cookies
We employ privacy-preserving performance telemetry to understand aggregate visitor patterns, page performance (Core Web Vitals), and interactive realm engagement.
We do not use invasive cross-site tracking cookies, behavioral ad-targeting pixels, or third-party fingerprinting scripts. Any analytics event triggers are anonymized and aggregated.
06.Security & Encryption
We deploy multi-layered defense-in-depth technical controls to protect data in transit and at rest. All web communications enforce modern TLS 1.3 encryption. Lead inquiries are processed through isolated, access-controlled enterprise infrastructure.
07.Global Rights (GDPR / CCPA)
Regardless of your geographic location, Grafiesto aligns its data protection practices with the principles of the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). This policy is not a legal certification — it describes how we actually handle data.
You have the right to request access to, correction of, or deletion of any personal information you have explicitly submitted to us (e.g., via contact submissions).
08.Contact Privacy Office
For privacy inquiries, data deletion requests, or data governance questions, reach our dedicated Data Protection lead directly:
Grafiesto Data Governance Office
Email: privacy@grafiesto.com