← dndb.digital

Privacy Policy

DNDB Version 1.1. Last updated: 1 September 2026.

This policy explains what personal data we collect through dndb.digital, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. It covers visitors to the site, people who contact us, and people we work with on projects.

It is written to satisfy the Brazilian LGPD (Lei 13.709/2018), the GDPR (EU 2016/679), the UK GDPR, and the notice requirements of United States state privacy laws including the CCPA/CPRA. Section 12 sets out the additional rights that apply if one of those regimes covers you.


1. Who is responsible for your data

The controller is:

Viktor Fediuk, Empresário Individual, trading as DNDB (previously trading as D&D Partners) CNPJ 65.396.022/0001-68 São Paulo, SP, Brazil. The full registered address is available in the public CNPJ registry and on request by email Email: agency@dndb.digital

Contact channel for data protection. Under Brazilian law we qualify as a small scale processing agent (agente de tratamento de pequeno porte, Resolução CD/ANPD nº 2/2022) and are not required to formally appoint a Data Protection Officer. We do maintain a direct channel for everything covered by this policy: write to agency@dndb.digital with "Privacy" in the subject line, and a human reads it.

We have not appointed a representative in the European Union under Article 27 GDPR or in the United Kingdom. Our processing of EU and UK personal data is occasional, does not include large scale processing of special categories, and is unlikely to result in a risk to rights and freedoms; we rely on the exemption in Article 27(2)(a). If our processing changes in a way that requires a representative, we will appoint one and name them here.


2. What we collect, and when

2.1. When you fill in the contact form

Fields you fill in yourself:

Data Required
Name yes
Email address yes
Message about your project no
Estimated budget range no
Desired timeline yes

Collected automatically with the submission:

2.2. When you add project details

If you continue and answer the additional project questions, we receive those answers as a second message. They are business information about your project, plus the name and email you already gave.

2.3. When you book a call

We receive the time slot you selected and the timezone your browser reports, so that the confirmation matches your local time, along with your name and email.

2.4. When you email us or talk to us

We receive whatever you put in the message: your name, email address, any phone number, company details, signature block, attachments, and the content of the conversation. Calls are not recorded unless we tell you in advance and you agree.

2.5. When you simply visit the site

2.6. When you become a client

During a project we handle: your contact and billing details; the name, role and contact details of the people on your side; access credentials you give us; the content and materials you send; and correspondence. Where a project involves personal data of your users, we act as a processor on your behalf, not as a controller, and the terms in clause 25 of the Client Services Agreement apply.

We also hold the invoicing records that Brazilian law requires us to keep, including the data needed to issue a Nota Fiscal de Serviços.

2.7. What we never ask for

We do not ask for, and you should not send us through the website form: passwords, access credentials, payment card numbers, identity document numbers, health data, or any of the special categories of data listed in Article 9 GDPR and Article 5, II LGPD. If you send such data unprompted, we delete it.


3. Third-party content embedded in the site

One element loads from outside our servers. When they load, the provider receives your IP address and basic technical data, because that is how the internet delivers a file. They may also set their own cookies.

Element Provider Loads when
Showreel video player YouTube (Google Ireland Limited / Google LLC) only after you click to play the showreel, served from the privacy-enhanced youtube-nocookie.com

Fonts, the 3D scene and the 3D player software are hosted on our own server, so they generate no third-party request.

If you do not want YouTube to receive anything, do not play the showreel.


4. Analytics and your choice

4.1. We use Google Analytics 4 to count visits and understand which pages and which channels work. We also use Microsoft Clarity for aggregated heatmaps and session recordings, to see where the site is confusing and fix it, and the Meta Pixel so that our advertising can be measured and optimised. All three run behind the same choice: nothing loads until you accept.

4.2. Nothing is loaded until you choose. On your first visit a banner asks whether you accept analytics. Until you accept:

If you decline, the site makes zero third-party analytics requests. Your choice is stored on your device and you can change it by clearing your browser storage for this site.

4.3. If you accept, Google Analytics collects: pages viewed, time on page, approximate location derived from a truncated IP address, device and browser type, referring source, campaign parameters, and an identifier stored on your device. IP anonymisation is applied. We use the data only in aggregate. We do not use Google Signals, advertising personalisation or cross-device tracking.

4.4. Legal basis: your consent (Article 6(1)(a) GDPR; Article 7, I LGPD). You may withdraw it at any time, with effect for the future.


5. Who else processes your data

These are our processors. Each one only receives what it needs for its function.

Processor Function Where the data is processed
Web3Forms (Surjith S M, India) delivers the website form to our inbox servers in the United States (AWS, US East). Retains submissions for up to 3 years. Offers a data processing agreement and uses Standard Contractual Clauses for transfers from the EEA, UK and Switzerland.
Google (Google Ireland Limited / Google LLC) the mailbox behind agency@dndb.digital, and Analytics if you accept European Union and United States. Google LLC is certified under the EU-US Data Privacy Framework.
Microsoft (Microsoft Corporation) Clarity heatmaps and session recordings, only if you accept analytics United States. Microsoft Corporation is certified under the EU-US Data Privacy Framework.
Meta (Meta Platforms Ireland Ltd / Meta Platforms, Inc.) the Meta Pixel, to measure and optimise our advertising, only if you accept analytics European Union and United States. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework.
Cloudflare, Inc. serves the site, routes our incoming email, keeps server logs United States, with a global network. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework.
Our payment and invoicing providers receive and record payments from clients as stated on the relevant proposal or invoice
YouTube see section 3 United States
Contractors on our team carry out project work, under confidentiality obligations Ukraine, Brazil and elsewhere

We also disclose data where the law requires it: to the Brazilian tax authorities as part of ordinary invoicing and reporting, to a court or regulator on a valid order, or to professional advisers under a duty of confidence. If our business is transferred, data may pass to the acquirer under the same commitments, and we will tell you.

We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not trade in mailing lists.


6. Why we process your data, and on what legal basis

Purpose GDPR / UK GDPR basis LGPD basis
Reply to your enquiry, prepare an estimate or proposal Article 6(1)(b), steps at your request before a contract Article 7, V, procedimentos preliminares
Carry out a project, invoice it, support it Article 6(1)(b), performance of a contract Article 7, V
Keep tax, accounting and invoicing records Article 6(1)(c), legal obligation Article 7, II
Keep the site secure, prevent spam and abuse Article 6(1)(f), legitimate interest in protecting our service Article 7, IX, legítimo interesse
Understand which channel brought you, and improve the site Article 6(1)(a), consent, for analytics; Article 6(1)(f) for campaign parameters submitted with a form you chose to send Article 7, I and IX
Establish, exercise or defend legal claims Article 6(1)(f) Article 7, VI
Send occasional updates to existing clients about our services Article 6(1)(f), and consent where required by local law Article 7, IX

Where we rely on legitimate interest, we have considered your interests and rights against ours, and you can object at any time under section 11.


7. Marketing

We do not run a newsletter and we do not add enquirers to a mailing list. If we later start one, it will be opt-in only, and every message will carry an unsubscribe link. Existing clients may receive occasional messages about our services and can opt out at any time by replying.


8. How long we keep things

Data Retention
Enquiry that does not become a project 24 months from the last contact, then deleted
Enquiry that becomes a project for the project, then 5 years from the end of the business relationship, to cover the ordinary Brazilian limitation and tax periods
Contracts, proposals, invoices and fiscal records at least 5 years, as required by Brazilian tax and civil law
Project files and deliverables up to 24 months after delivery, so that we can help you if something breaks. After that they may be deleted without notice, so keep your own copies
Email correspondence up to 5 years
Form submissions held at Web3Forms up to 3 years, by that provider
Server logs as set by our hosting provider, typically weeks rather than months
Analytics data 14 months in Google Analytics, then aggregated; Clarity keeps individual session recordings up to 30 days and aggregated heatmaps up to 13 months
Your analytics choice on your device until you clear it

When a period ends we delete the data or irreversibly anonymise it. Backups are overwritten on their own cycle, and data can persist in them briefly after deletion from the live systems.


9. Where your data goes

We are established in Brazil. Depending on the processor involved, your data may be processed in Brazil, the European Union, the United States, India or Ukraine.

For transfers out of the EEA we rely first on the European Commission's adequacy decision for Brazil, adopted on 26 January 2026, which recognises Brazilian data protection law as providing a level of protection essentially equivalent to the GDPR. Personal data can therefore flow from the EEA to us without any further transfer mechanism. Brazil adopted a mutual adequacy decision for the EU on the same date, so the flow back is equally covered.

For transfers from the United Kingdom we rely on the UK's own transfer mechanisms, including the International Data Transfer Agreement or Addendum where required.

Where a processor is outside Brazil and the EEA, we rely on: the EU-US Data Privacy Framework where the recipient is certified; Standard Contractual Clauses with additional safeguards in every other case; and, for transfers out of Brazil, the mechanisms permitted by Articles 33 to 36 LGPD.

You can ask us for details of the safeguards applying to a specific transfer.


10. Security

We take measures appropriate to a business of our size and to the sensitivity of what we hold: HTTPS on the whole site, two-factor authentication on our accounts, a password manager, access limited to the people who need it, confidentiality obligations on every contractor, encrypted devices, and no storage of payment card data by us at any time.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the competent authority without undue delay, and within the deadlines set by the law that applies, including the ANPD in Brazil.


11. Your rights

Whoever you are and wherever you are, you can ask us to:

How to exercise them. Write to agency@dndb.digital with "Privacy" in the subject. We reply within 30 days, or within 15 days where the LGPD requires it. We may ask you to confirm your identity, and only to the extent needed. Exercising these rights is free. We may charge a reasonable fee, or decline, only for a request that is manifestly unfounded or repetitive, and we will explain why.

Complaints. You can complain to a supervisory authority: - Brazil: ANPD, https://www.gov.br/anpd - EU/EEA: the data protection authority of your country - United Kingdom: the ICO, https://ico.org.uk

We would rather you told us first, so that we can fix it.


12. Regional additions

12.1. If you are in the EU, the EEA or the UK

All the rights in section 11 apply as set out in the GDPR and the UK GDPR. We rely on Article 6(1)(b), (c), (f) and (a) as shown in section 6. We do not carry out automated decision making or profiling that produces legal or similarly significant effects.

12.2. If you are in Brazil

Your rights under Article 18 LGPD apply, including confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, and revocation of consent. We are a small scale processing agent under Resolução CD/ANPD nº 2/2022, which is why the contact channel in section 1 stands in place of a formally appointed Encarregado.

12.3. If you are in California or another US state with a privacy law

In the last 12 months we have collected the categories of personal information described in section 2: identifiers, commercial information, internet activity and, if you accept analytics, inferences drawn from it. The purposes are in section 6, the recipients in section 5, and the retention periods in section 8.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA/CPRA. We have not done so in the preceding 12 months, and we do not knowingly collect or sell the personal information of anyone under 16.

You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. We do not collect sensitive personal information as defined in that law. Use the contact in section 11, and an authorised agent may act for you with written proof.


13. Children

The site is aimed at businesses. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us data, write to us and we will delete it.


14. Automated decisions

We do not make decisions about you by automated means alone. We use AI tools in our research and production work, but the decisions that affect a person or a project are made by a human. Clause 15 of the Client Services Agreement explains how we use those tools on client projects.


15. Links to other sites

Our site links to Behance, Dribbble, LinkedIn, Clutch and Upwork. Once you follow a link, that provider's own privacy policy applies. We have no control over it.


16. Changes to this policy

We update this policy when what we actually do changes. The current version, with its number and date, is always at dndb.digital. If a change materially affects your rights, we will make it visible on the site and, where the law requires, ask for your consent again.


17. Contact

agency@dndb.digital with "Privacy" in the subject line. Postal address as in section 1.

DNDB · Viktor Fediuk, Empresário Individual · CNPJ 65.396.022/0001-68 · São Paulo, Brazil · agency@dndb.digital
The Provider previously traded as D&D Partners. This document is effective from 1 September 2026.