Privacy
What I collect, and what I do with it.
Two forms and one analytics tool, with no cookie and no recording of your visit. No advertising, no data broker, no newsletter list. This page says exactly what happens to your details.
Last updated 14 September 2026
The clauses
I am one person. The whole of this is two contact forms that email me, and one analytics tool that counts which pages were read and where the forms lose people. There is no marketing database behind it, because there is no marketing team.
Who is responsible
[[ full legal name ]], trading as Midosu Studio, working from Bangkok, Thailand. Postal address and tax details are in the legal notice on the terms page.
I decide what happens to the personal data described here, which makes me the controller under the GDPR and the data controller under Thailand's Personal Data Protection Act. Both apply: the GDPR because I offer services to clients in the EU and measure how EU visitors use this site, the PDPA because I carry out the work from Thailand.
Write to info@midosustudio.com about anything on this page. It reaches me and nobody else.
What I collect
Three things, and nothing beyond them.
- The contact form. Your name, your email address, your company website if you give one, what the enquiry is about, and what you write in the message box.
- The fit questionnaire. The eight answers you type, and the email address you leave so I can reply.
- Analytics. Which pages were opened, in what order, how long you stayed, on what kind of device, from roughly which country, how far down a page you read, which buttons and questions you pressed, how far into the fit questionnaire you got and where you stopped, and any error the page threw while you were on it.
Why, and on what legal ground
The two forms exist to answer you. That is a step taken at your request before a possible contract, which is the lawful basis under article 6(1)(b) of the GDPR, and the equivalent contractual basis under section 24(3) of the PDPA. I do not use a form address for anything else. There is no newsletter sequence and no list I add you to.
Analytics runs on legitimate interest under article 6(1)(f): I need to know which pages are read, where the two forms lose people, and which pages break. It is a list of named events rather than a recording of your visit, which is a deliberate choice and the reason the interest does not cost you anything. The next clause explains what that rules out.
I keep the emails your enquiry generates because if we end up working together, the thread is the record of what was agreed. That is legitimate interest too.
This site sets no cookies of its own and writes nothing to your browser's storage. The analytics tool, PostHog, is configured to hold its identifier in memory for the length of the tab and forget it when you close the page. Nothing survives the visit.
That is deliberate, and it is the reason you are not being asked to dismiss a consent banner to read a page. Article 5(3) of the ePrivacy Directive is about storing things on your device. A site that stores nothing has nothing to ask permission for.
What is switched off, since you have only my word for the paragraphs above. Session replay, which records a visit as a watchable recording, is off. So is autocapture, which would log every click and every field you moved through. So are heatmaps, surveys, product tours and on-page experiments. All of them are off in the site's own code rather than in a setting on PostHog's side, so none of them can be turned on from a dashboard: it takes a change to this site and a new deployment, and this page changes in the same breath if it ever happens.
One caveat, stated rather than buried. Cloudflare serves this site and may set a short lived security cookie to tell a person from a bot. That one is strictly necessary, exempt from consent, and not mine to switch off.
Four suppliers, each doing one job, none of them selling anything. I do not sell, rent or trade personal data, and there is no circumstance in which I would.
- Cloudflare. Serves the site and sends the mail the forms generate.
- PostHog. Analytics. Hosted in the EU, on their Frankfurt region.
- Google. info@midosustudio.com is a Cloudflare Email Routing address rather than a mailbox of its own: it forwards to a Gmail account, which is where your enquiry actually sits after it arrives, and therefore where it is read and kept.
- An accountant or a lawyer, if a specific matter needs one. Both are under professional confidentiality.
Where it goes
I read your enquiry in Thailand. For anyone in the EU or the UK that is a transfer to a country without an adequacy decision, so the transfer runs on the European Commission's standard contractual clauses with my suppliers, and on your explicit request that I reply to you.
Thailand's PDPA points the other way at the same problem: it restricts sending personal data out of Thailand to countries without adequate protection, and the regulator has not yet published its list of which those are. In practice the data described here travels between the EU, the United States and Thailand, and the suppliers above are the only parties involved.
If that is a problem for your own compliance position, say so in the first email and we will find another way to run the conversation.
How long I keep it
An enquiry that does not become a project is deleted after 24 months. Long enough that a reader who comes back a year later is not a stranger, short enough that it is not a filing cabinet.
An enquiry that becomes a project is kept for as long as the project runs and then for 7 years, because invoices and the correspondence behind them have to be keepable if a tax authority asks.
Analytics is kept for as long as the PostHog project holds it. It is not attached to a name or an address, and because nothing is stored on your device it is not attached to you across visits either: a second visit next week is a new anonymous row, not a continuation of this one.
What you can ask me to do
If the GDPR covers you, you can ask for a copy of what I hold, ask me to correct it, ask me to delete it, ask me to restrict what I do with it, ask for it in a portable format, and object to the analytics. If the PDPA covers you, the list is close enough to identical that I do not run two processes.
Ask by email. No form, no account, no identity check beyond replying from the address the data is attached to. I will do it inside 30 days, and in practice inside a week, because the entire operation is one person and a mailbox.
Nothing here is automated. No decision about you is made by a machine, and there is no profiling.
If I get it wrong
Tell me first. It is one email and I would rather fix it than read about it from a regulator.
You are entitled to go over my head, and you do not need my permission. In the EU, complain to the supervisory authority where you live or work. In the Netherlands that is the Autoriteit Persoonsgegevens. In the UK it is the Information Commissioner's Office. In Thailand it is the Personal Data Protection Committee.
I have not appointed a representative in the EU under article 27. The exemption for processing that is occasional, low risk and free of special category data is the ground for that, and it holds for a marketing site with two forms and a list of named events. It would stop holding if this site started recording visits, which is the second reason session replay is off in the code and not merely off today.
Changes to this page
Last updated 14 September 2026. If I change what I collect or who processes it, I change this page on the same day, and the date above moves. It has moved once: the first version of this page, on 11 September 2026, could not tell you whether session replay was on, and said so. It is off, and off in a way a dashboard cannot undo. There is no archive of old versions.
Still unclear
Ask me instead of guessing.
If a clause on this page is in the way of working together, it is a sentence in an email and not a reason to walk away. I wrote these myself and I can explain any of it.