Legal
What we collect, why, who helps us handle it, how long we keep it, and the choices you have. Written plainly, and kept in step with how the site actually works.
Effective: [Effective date pending: set on sign-off]
[Draft pending review by counsel and Baha]
Who we are
This website and the client portal are run by baa atelier, the studio of Baha Irs ([Legal entity name and state of formation pending: Baha to confirm]), referred to here as “we” or “the studio”. We are responsible for the personal information described below.
Contact for anything in this policy: info@atelierbaa.com, (323) 497-3794, or by post at [Business mailing address pending: Baha to confirm].
The short version
- We do not sell or share your personal information.
- There are no analytics, advertising or social media trackers on this site, and no third-party scripts or embeds.
- Public pages set no cookies. The only cookie is a sign-in cookie, and only for clients who sign in to the portal.
- We use what you send us to answer your enquiry and to run your project, and for nothing else.
What we collect
When you visit the site. Like any website, the servers that deliver these pages receive technical information with each request, such as your IP address, browser type and the page asked for. Our hosting provider uses it to deliver the site and protect it from abuse. We do not use it to build a profile of you.
When you send an enquiry. The contact form asks for your name and email (required) and, if you choose to give them, your phone number, project location, project type, estimated budget range, timeline, how you heard about us, and your message. We also record the date and time and the IP address the enquiry came from. The IP address is used to stop spam and repeated automated submissions.
When you email or call us. Whatever you choose to tell us, held in our email and phone records.
When you are a client using the portal. If you work with us, we may give you an account in the client portal. To run it we keep:
- Your account: your email address, your name, and your password, stored only as a one-way hash that nobody, including us, can read back.
- Sign-in security records: your active sessions (with IP address, browser and expiry), failed sign-in attempts, password reset requests (with IP address), and a log of account and portal actions (what was done, by which account, from which IP address, and when).
- Your project: your contact details and the project address, the plan, phases and schedule, messages between us, invoices and a record of payments received, site photographs, designs and their versions, and which members of our crew are visiting and when.
- Files you upload: photos (JPEG, PNG, WebP, HEIC) and PDF documents, up to 25 MB each, with a note if you add one.
- Approvals and signatures: when you approve or sign something in the portal, we record your decision, any comment, the name you typed, the signature you drew, the date and time, your IP address and browser, the account that was signed in, and a fingerprint (a SHA-256 hash) of exactly what you were shown. This is the record that shows what was agreed.
We do not take card or bank details through the site or the portal. Payments are made outside it, and the portal only shows a record of them.
How we use it
- To reply to your enquiry, prepare samples and quotes, and decide together whether to work together.
- To plan, carry out, invoice and document your project, and keep you up to date through the portal.
- To keep a reliable record of what was approved and signed, and when.
- To keep accounts secure and the site free of spam and abuse.
- To meet our legal, tax, licensing and accounting obligations, and to establish or defend legal claims.
We do not use your information for advertising, we do not send marketing email, and we do not make automated decisions about you.
Who helps us handle it
We use a small number of service providers who process information on our behalf and under our instructions, not for their own purposes:
- Vercel: hosts the website and portal, and stores portal files and photos.
- Neon: hosts the database that holds enquiries and portal records.
- Resend: sends the email that tells the studio a new enquiry has arrived, and password reset emails.
- [Email provider pending: Baha to confirm, DNS points to Microsoft 365]: our email mailbox.
These providers are based in, or store data in, the United States. Inside the studio, portal information is visible only to the people working on your project, according to their role. Crew members appear to you in the portal only when the studio chooses to show them. We may also disclose information when the law requires it, to protect our rights or someone’s safety, or to a successor if the business is ever transferred.
How long we keep it
- Enquiries: kept so we can pick up the conversation if you come back to us. They are not deleted automatically. How long we keep them: [Retention period pending: Baha to confirm]. You can ask us to delete yours at any time.
- Project records, invoices, payments, approvals and signatures: for as long as needed for the project, its warranty, our tax and licensing obligations and the period in which a legal claim could be brought: [Retention period pending: Baha and counsel to confirm]. Signed records are kept even if a portal account is closed, because they are evidence of what was agreed.
- Files you uploaded: until you delete them in the portal, or until the project record is deleted.
- Sign-in sessions: the sign-in cookie expires after 30 days, or at once when you sign out. The session record we keep (with its IP address and browser) is deleted 7 days after the session expires or is signed out.
- Password reset requests (with the IP address they came from): deleted 30 days after the reset link expires.
- Failed sign-in attempts (including the email address that was typed): deleted after 90 days.
- Counters that slow down repeated sign-in and form attempts (keyed to an email address or IP address): short-lived, deleted once they are more than a day old and no lock is in force.
- The log of other account and portal actions (such as sign-ins, accounts issued, passwords changed, files uploaded or removed, designs issued and payments recorded): not deleted automatically, because it is part of the record of who did what in a project. How long we keep it: [Retention period pending: counsel to confirm].
How we protect it
Passwords are stored as salted one-way hashes, sign-in cookies are protected from scripts and sent only over encrypted connections, every portal page shows a client only their own project, uploaded files are checked and kept private, and repeated sign-in or form attempts are slowed down. No system is perfectly secure; if something goes wrong that affects your information, we will tell you as the law requires.
Your choices and rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you, and give you a copy;
- correct anything that is wrong;
- delete it, except where we must keep it (for example, signed records, invoices and tax records);
- stop using it for a particular purpose.
California residents. California law (CalOPPA) requires this policy. The California Consumer Privacy Act applies to larger businesses than ours, but we offer its core rights voluntarily: to know what we collect and why, to access, correct and delete it, and not to be treated differently for asking. We do not sell or share personal information, as those terms are defined in that law, and do not use sensitive personal information to infer anything about you. Under California’s “Shine the Light” law, you may also ask whether we disclosed personal information to third parties for their direct marketing; we do not.
Visitors from Turkey and the European Union. If Turkey’s Personal Data Protection Law (KVKK, Law No. 6698) or the EU or UK GDPR applies to you, we process your information because you asked us to (to answer an enquiry or perform our contract with you), because the law requires it, or for our legitimate interest in keeping the site secure and keeping a reliable record of what was agreed. You have the rights listed above, and also the right to object, to restrict use, to receive your data in a portable form, and to complain to your data protection authority (in Turkey, the KVKK Authority). Your information is stored in the United States through the providers listed above. Our operations in Istanbul: [Istanbul operations and Turkish entity pending: Baha to confirm].
To make any request, email info@atelierbaa.com or call (323) 497-3794. We will confirm who you are (usually by replying to the email address we already have for you), and answer within [Response time pending: Baha to confirm, proposed 45 days]. You can ask someone to make a request for you; we may ask for proof that they are authorised.
Children
This site is for adults arranging work on their homes and businesses. It is not directed at children, and we do not knowingly collect information from children.
Changes to this policy
When we change this policy, we will update the effective date at the top of this page, and, if the change matters to clients with portal accounts, tell them in the portal or by email.
Using the client portal is also covered by the Client Portal Terms, and the website by our Terms of Use.
See also: Privacy · Terms · Client Portal Terms · Accessibility