Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how personal data is collected, used, stored, and protected when you visit shestakovv.com or contact me regarding my services.
1. Data Controller
The controller responsible for processing your personal data is:
Nikolay Shestakov
Independent UX/UI and Web Designer
Based in Serbia
Email: shestakovv.design@gmail.com
Website: https://shestakovv.com
For any questions concerning this Privacy Policy or the processing of your personal data, please contact me using the email address above.
2. Scope of This Policy
This Privacy Policy applies to personal data processed through shestakovv.com and to information you provide when contacting me about my services.
It does not apply to third-party websites or services that may be linked from this website. Those services process personal data under their own privacy policies.
3. Personal Data I Collect
3.1 Information You Provide
When you contact me by email, Telegram, LinkedIn, Instagram, or another communication channel, I may receive:
– your name;
– your email address or social media username;
– your company name and professional role;
– information about your project, business, or request;
– files, links, and other information included in your message;
– correspondence and communication history.
Please do not send sensitive personal data unless it is strictly necessary for your request.
3.2 Technical and Usage Data
When you visit the website, limited technical information may be processed automatically, including:
– IP address and approximate country;
– browser, device, and operating system information;
– pages visited and navigation events;
– visit duration and approximate session information;
– referring website and UTM parameters;
– request time, error, security, and server log information.
The website uses Framer’s built-in privacy-focused analytics. It does not use cookies or persistent identifiers to recognise visitors across different days or devices. Analytics results are provided in an aggregated form and may include page views, traffic sources, approximate country, device category, browser, and operating system.
4. Purposes and Legal Bases
Personal data may be processed for the following purposes:
Responding to Enquiries
To review and respond to messages, discuss a potential project, prepare an estimate, or take steps requested before entering into a contract.
Legal basis: Article 6(1)(b) GDPR — processing necessary to take steps before entering into or performing a contract.
Providing Contracted Services
To communicate with clients, manage projects, deliver services, maintain business records, and handle payments or invoices.
Legal basis: Article 6(1)(b) GDPR — performance of a contract.
Operating, Securing, and Improving the Website
To deliver website content, maintain security, identify technical problems, prevent abuse, and understand the general performance and use of the website.
Legal basis: Article 6(1)(f) GDPR — legitimate interests in operating, protecting, and improving a professional portfolio website.
Complying With Legal Obligations
To maintain records, respond to lawful requests, and comply with applicable tax, accounting, contractual, or regulatory requirements.
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation.
Consent-Based Processing
If I introduce optional communications, marketing subscriptions, or other consent-based functionality, personal data will be processed only after receiving your consent.
Legal basis: Article 6(1)(a) GDPR. You may withdraw your consent at any time.
5. Cookies and Similar Technologies
The website does not currently use non-essential advertising or tracking cookies.
Framer Analytics does not use cookies or create persistent visitor identifiers. Therefore, a consent banner is not currently required solely for the website’s built-in analytics.
Framer may use strictly necessary, short-lived security technologies when required to protect the website from malicious traffic or attacks. These technologies are not used for advertising or cross-site tracking.
If non-essential cookies, external analytics, advertising tools, or embedded services are added in the future, this Privacy Policy will be updated and consent will be requested where required by law.
6. Google Fonts
Some fonts used on the website may be loaded from Google servers. When this happens, your browser sends a technical request to Google, which may include your IP address, browser information, and the page requesting the font.
This processing is used to display the website consistently and is based on the legitimate interest described in Article 6(1)(f) GDPR.
More information is available in the Google Privacy Policy:
https://policies.google.com/privacy
7. Service Providers and Recipients
Personal data may be processed by service providers that help operate the website or enable communication, including:
– Framer B.V., which provides website hosting, delivery, security, and privacy-focused analytics;
– email and cloud service providers used to receive and store correspondence;
– Telegram, LinkedIn, Instagram, or other communication platforms if you choose to contact me through those services;
– Google, where Google-hosted fonts are loaded;
– professional advisers, accountants, legal advisers, or public authorities where disclosure is necessary or legally required.
Framer processes website visitor data on my behalf as a data processor. More information is available in Framer’s Privacy Statement and Data Processing Addendum:
https://www.framer.com/legal/privacy-statement
https://www.framer.com/legal/data-processing-addendum
I do not sell personal data or provide it to third parties for their independent advertising purposes.
8. International Data Transfers
I am based in Serbia, and some service providers may process data in Serbia, the European Economic Area, the United States, or other countries.
Where personal data is transferred outside the European Economic Area, appropriate safeguards are used where required, such as:
– an adequacy decision adopted by the European Commission;
– Standard Contractual Clauses approved by the European Commission;
– other safeguards permitted under Chapter V of the GDPR.
Information about safeguards used by individual service providers is available in their respective privacy policies and data processing terms.
9. Data Retention
Personal data is retained only for as long as reasonably necessary for the purposes described in this Policy:
– general enquiries and correspondence: for up to 24 months after the last meaningful communication;
– unsuccessful project enquiries: for up to 24 months unless earlier deletion is requested;
– client and project information: for the duration of the project and afterwards for as long as necessary to manage the professional relationship or legal claims;
– contracts, invoices, and accounting records: for the period required by applicable tax, accounting, and other laws;
– website analytics accessible through the current Framer plan: generally for up to 30 days;
– technical and security logs: for as long as reasonably necessary to maintain website security and investigate incidents.
Data may be retained for a longer period where necessary to comply with a legal obligation or establish, exercise, or defend legal claims.
10. Data Security
Reasonable technical and organisational measures are used to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction.
These measures include secure website hosting, access controls, software updates, encrypted connections, and limiting access to personal data to situations where it is necessary.
No method of internet transmission or electronic storage is completely secure, so absolute security cannot be guaranteed.
11. Your Rights
Subject to the conditions established by applicable law, you may have the right to:
– request access to your personal data;
– request correction of inaccurate or incomplete data;
– request deletion of your personal data;
– request restriction of processing;
– object to processing based on legitimate interests;
– receive personal data you provided in a structured, commonly used, and machine-readable format;
– withdraw consent at any time where processing is based on consent;
– lodge a complaint with a competent data protection supervisory authority.
Withdrawing consent does not affect the lawfulness of processing performed before the withdrawal.
To exercise any of these rights, contact:
I may request limited additional information where reasonably necessary to verify your identity. Requests will normally be handled within one month, subject to any extensions permitted by applicable law.
You may also lodge a complaint with the data protection authority in the country where you live or work, or where you believe an infringement has occurred.
12. Automated Decision-Making
Your personal data is not used for automated decision-making or profiling that produces legal or similarly significant effects.
13. External Links
The website contains links to external platforms and project websites. When you follow an external link, the destination service may collect information about you independently.
I am not responsible for the privacy practices, security, or content of third-party websites. You should review their privacy policies before providing personal data.
14. Children’s Privacy
The website and services are intended for professional and business audiences and are not directed at children.
I do not knowingly collect personal data from children. If you believe that a child has provided personal data through the website, please contact me so that the information can be deleted where appropriate.
15. Changes to This Policy
This Privacy Policy may be updated when the website, services, processing activities, or applicable legal requirements change.
The latest version will always be published at:
https://shestakovv.com/privacy
Material changes will be indicated by updating the “Last updated” date at the top of this page.