Privacy Policy
107.design ("107", "we", "us", "our") is a sole proprietorship operated by Vlad Bubenko, running a portfolio and studio website at https://107.design (the "Site") for an independent design and engineering practice based in San Francisco, California, United States.
We built this site to show work and start conversations — not to collect data. This policy explains what little information we do process, why, and the rights you have under the laws that apply to you, including the EU/UK General Data Protection Regulation (GDPR / UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other US state privacy laws.
1. Who is responsible for your data
107.design (operated by Vlad Bubenko, sole proprietor) is the data controller for the personal information described in this policy. Because this is a small practice, questions about privacy go straight to the person who runs it:
- Email: work@107.design
- Studio location: San Francisco, California, United States
- Site: https://107.design
We aim to respond to every privacy request within 30 days, as the GDPR requires.
2. Information we collect
We deliberately collect very little:
a) Information you send us directly
When you email us through the links on the Site (e.g. work@107.design, or a "request access" email), we receive your email address, your name if you include it, and whatever you wrote. We use that information to reply to you, discuss potential work, and — where you request access — to send you the passphrase for our gated case studies.
b) Analytics information (region-dependent)
The Site uses Google Analytics 4 to understand aggregate usage — which pages get visited, roughly where visitors come from, what device and browser they use, and how long they stay.
- Visitors outside the United States (EU/EEA/UK and elsewhere): analytics runs only after you click "Accept analytics" on the cookie banner. If you decline, it is never loaded.
- Visitors in the United States: analytics loads automatically — US privacy law (including CCPA/CPRA) uses an opt-out model, not opt-in consent. If your browser sends a Global Privacy Control or Do Not Track signal, analytics is never loaded, and no banner is shown.
c) Information stored only in your browser
Two small items are stored in your browser's local storage, never on our servers:
107.consent— your cookie consent choice, so we don't ask twice.107.access.key— only if you choose "remember me" when unlocking a gated case study; it stores the passphrase locally in your browser so you don't have to re-enter it. It is never sent to our servers.
d) Information we do NOT collect
We do not collect account data, payment card data, billing addresses, phone numbers, or any sensitive categories of personal data. We do not run ads on this site. We do not sell, rent, or share personal information with anyone for money — and we never have.
3. How we use information
- To respond to your inquiries and requests (including portfolio access requests);
- To negotiate and deliver our design and engineering services;
- To understand how the Site is used, so we can improve it;
- To protect the Site and our systems against abuse and security incidents;
- To comply with legal obligations.
4. Legal bases for processing (GDPR / UK GDPR)
If the GDPR or UK GDPR applies to you, we rely on the following legal bases:
- Consent (Article 6(1)(a)) — for analytics cookies and similar tracking, which we only run after you opt in.
- Legitimate interests (Article 6(1)(f)) — for replying to inquiries, running the Site securely, and improving it. We weigh your privacy rights against our interests and keep what we process to a minimum.
- Contract (Article 6(1)(b)) — where you engage us for services, to perform that engagement.
- Legal obligation (Article 6(1)(c)) — where we must keep records for tax, accounting, or other legal requirements.
5. Cookies and similar technologies
We use cookies and browser storage as described in our Cookie Policy. In short: analytics cookies run only with consent for visitors outside the US, and automatically for US visitors (who can opt out via Global Privacy Control / Do Not Track or by email); local storage only remembers your choices and (optionally) your passphrase preference. You can change or withdraw consent at any time via the "Cookie preferences" link in the footer, or by clearing your browser storage.
6. Third-party services and international transfers
The Site loads a small number of third-party services. Where those services process personal data, they do so under their own policies:
- Google Analytics 4 (Google LLC, United States) — usage analytics, only after consent. Data may be processed in the United States. Google is certified under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF for transfers from the EEA, the UK, and Switzerland. Google also offers its own privacy controls.
- Google Fonts (Google LLC) — font files requested by your browser when you load the Site. Google documents its handling of these requests in its privacy policy.
- Fontshare (ITF — Indian Type Foundry) — the Clash Display typeface served from
api.fontshare.com. - jsDelivr — an open-source CDN that hosts the Lenis smooth-scroll library.
- Hostinger — our hosting provider, which operates the servers the Site is stored on and may keep standard server logs.
Because we are based in the United States, information processed on our behalf is generally stored in the United States. Where we transfer personal data from the EEA, the UK, or Switzerland to the US or other countries, we rely on adequacy decisions, the EU-U.S./UK/Swiss Data Privacy Frameworks, or standard contractual clauses as applicable. We don't have enough of your data for this to get complicated — but the safeguards are in place.
7. How long we keep information
- Email correspondence: kept for as long as needed to handle your inquiry or engagement, and then deleted when it no longer has a legitimate purpose (typically no more than a few years, and sooner on request).
- Analytics data: retained by Google according to your chosen GA4 retention settings; aggregate reports don't identify you.
- Browser local storage: kept on your device until you clear it, or until you withdraw consent.
8. Your rights
Under the GDPR / UK GDPR (EEA, UK)
You have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing in certain circumstances;
- Data portability — receive your data in a machine-readable format;
- Object to processing based on legitimate interests;
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- Lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the data protection authority of the country where you live or work.
Under the CCPA/CPRA (California residents)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose;
- Delete personal information we hold about you;
- Correct inaccurate personal information;
- Opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information, and we never have;
- Limit the use of sensitive personal information — we do not collect sensitive personal information;
- Non-discrimination — we will never treat you differently for exercising your rights.
Do Not Sell or Share My Personal Information: we do not sell, share, or trade your personal information with any third party for money or for cross-context behavioral advertising. Because we don't sell or share, there is no opt-out switch to flip — but if that ever changes, this page will be updated and you will be able to opt out here.
California residents may also request disclosure of the categories of personal information we've shared with third parties for their direct marketing purposes under California Civil Code § 1798.83 ("Shine the Light"). We have not shared any such information.
Under other US state privacy laws
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Montana, Oregon, Texas, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, and others with laws in effect) have similar rights to know, access, correct, delete, and opt out of the sale or processing of personal data for targeted advertising and profiling. We do not engage in those practices. If one of these laws applies to you, email work@107.design and we will honor your request.
Under other international laws
If you are in Canada (PIPEDA), Australia (Privacy Act / APPs), Brazil (LGPD), Japan (APPI), South Korea (PIPA), or another jurisdiction with a privacy law, we will honor your requests to access, correct, or delete your personal information. Email us and we'll take care of it.
9. Children
The Site is a professional portfolio for a design studio and is not directed at children. We do not knowingly collect personal information from anyone under the age of 16, and we do not offer content, products, or services aimed at children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Security
The Site is served over HTTPS with HSTS, strict security headers (Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), and protection against directory listing and known scraper traffic. We store almost no personal data, which is the best security measure of all. No method of transmission is 100% secure, but we take reasonable and proportionate steps to protect what we process.
11. Changes to this policy
We may update this policy as the Site or the law changes. The "Last updated" date at the top of this page will always reflect the most recent version. Where a change is material, we'll also note it on the homepage for a reasonable period.
12. Contact & complaints
For any privacy question, request, or complaint — including exercising any of the rights above — email work@107.design. We will respond within 30 days (or sooner).
If you're in the EEA or UK and believe we haven't resolved your concern, you can complain to your local data protection authority — in the UK, the ICO (ico.org.uk). We'd appreciate the chance to fix the problem first.
13. Legal notice (Imprint)
107.design is an independent design practice operated by Vlad Bubenko as a sole proprietor from San Francisco, California, United States. For purposes of EU/EEA transparency requirements (including the German Digital Services Act, § 5 DDG):
- Service provider: Vlad Bubenko (trading as 107.design)
- Location: San Francisco, California, United States
- Contact: work@107.design
- Website: https://107.design
The practice does not currently maintain a physical office outside the United States. Full business registration details are available on request by email.
107.design — independent design studio. We make brands impossible to ignore.