Privacy Policy
Effective Date: August 2, 2026
Last Updated: August 2, 2026
1. Introduction
DREOS STUDIO LLC ("DREOS STUDIO," "the Company," "we," "us," or "our") is a Wyoming Limited Liability Company providing software engineering and artificial intelligence services to businesses. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our website, our business development process, and our delivery of Services to Clients.
Because DREOS STUDIO operates on a business-to-business (B2B) model, most of the information we handle relates to our business Clients, their authorized representatives, and, in the course of building software, the data those Clients choose to process through the systems we build. This Policy is written primarily with that business context in mind, while also covering visitors to our website.
2. Scope of This Policy
This Policy applies to:
- Visitors to our website (currently a landing page, with an expanded site — including Home, Services, About, Case Studies, Portfolio, Contact, and Blog sections — planned for the future).
- Prospective Clients who contact us through our website, email, or other channels.
- Business Clients who engage us for Services, and the individual representatives who act on a Client's behalf (such as founders, employees, or contractors of the Client).
This Policy does not govern the data processed within software products we build for Clients. Each such product may have its own privacy policy determined by the Client, who acts as the data controller for that product's end users. DREOS STUDIO's role with respect to Client end-user data is typically that of a service provider or data processor acting on the Client's instructions, as further described in Section 9.
3. Information We Collect
3.1 Information You Provide to Us
We may collect information you voluntarily provide, including:
- Contact details (name, business email address, phone number, company name, job title).
- Information submitted through contact forms, inquiry forms, or project briefs.
- Communications sent to us via email, Slack, Microsoft Teams, Discord, WhatsApp, Telegram, or during calls on Google Meet or Zoom.
- Business documents, technical specifications, credentials, API keys, cloud access details, source code, and other proprietary business information shared with us in the course of a project.
- Payment and billing information, such as invoicing details (note: DREOS STUDIO does not directly store full payment card numbers; payments are processed via third-party payment processors as described in Section 7).
3.2 Information Collected Automatically
When you visit our website, we and our service providers may automatically collect certain technical information, including:
- IP address, approximate location derived from IP address, browser type, device type, and operating system.
- Pages visited, time spent on pages, click patterns, and referring URLs.
- Cookie and similar tracking technology data, as described in our separate Cookie Policy.
3.3 Information from Third Parties
We may receive information about prospective or existing Clients from business partners, referral sources, or publicly available business information (such as company websites or professional networking platforms), which we may use to inform outreach or project scoping.
3.4 Categories We Do Not Intentionally Collect
We do not intentionally collect sensitive personal categories of information — such as health data, biometric data, or government identification numbers — through our website or general business operations. If a specific project requires processing such data on a Client's behalf (for example, building a healthcare application), any such processing is governed by the specific terms of that Project Agreement rather than by this general Policy.
4. How We Use Information
We use the information we collect for purposes including:
- Responding to inquiries and preparing proposals or quotes.
- Establishing and managing our contractual relationship with Clients.
- Delivering, maintaining, and supporting the Services described in our Terms of Service.
- Processing payments and maintaining billing records.
- Communicating with Clients about project status, Deliverables, and support.
- Improving our website, Services, and internal processes.
- Complying with legal, tax, and regulatory obligations.
- Protecting the security and integrity of our systems and the systems we manage on behalf of Clients.
- Where consented to, sending occasional updates about our Services.
We do not sell personal information to third parties, and we do not use Client business or technical information for purposes unrelated to delivering and improving our Services without your consent.
5. Legal Basis for Processing
Where applicable data protection law requires a legal basis for processing personal information, we rely on one or more of the following:
- Performance of a contract, where processing is necessary to deliver Services under a Project Agreement.
- Legitimate interests, such as operating and securing our business, responding to inquiries, and improving our Services, provided such interests are not overridden by your rights.
- Legal obligation, where processing is required to comply with applicable law, such as tax and accounting requirements.
- Consent, where you have given specific consent, such as opting in to receive marketing communications.
6. Automated Decision-Making
DREOS STUDIO does not use automated decision-making processes to make decisions about individuals that produce legal or similarly significant effects, based on the personal information described in this Policy. Where AI tools are used internally to support our own operations (for example, drafting assistance or research), such use does not involve automated decisions about you as an individual.
7. Sharing of Information
We do not sell personal information. We may share information in the following circumstances:
- Service Providers. With third-party vendors who support our operations, such as cloud hosting providers, AI infrastructure providers, payment processors, communication tools, and project management software. These providers are only given access to information necessary to perform their function and are expected to handle it in accordance with applicable law.
- Professional Advisors. With our accountants, lawyers, or other professional advisors, where necessary for legitimate business purposes.
- Legal Requirements. Where required to comply with a legal obligation, court order, or governmental request, or to protect the rights, property, or safety of DREOS STUDIO, our Clients, or others.
- Business Transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
- With Your Direction or Consent. Where you have directed or consented to the sharing of your information.
8. Third-Party Tools and Infrastructure
Delivery of our Services may involve third-party cloud providers, AI APIs, payment processors, hosting providers, open-source software, and other integrations selected in the course of a project. These third parties process data subject to their own privacy policies and terms. DREOS STUDIO carefully selects reputable providers but is not responsible for the independent data practices of third parties outside of our direct control, consistent with our Terms of Service.
9. Our Role as a Service Provider for Client Data
When we build or maintain software on behalf of a Client, that software may process personal data belonging to the Client's own customers, employees, or other end users. In this context:
- The Client is generally the data controller, responsible for determining how that end-user data is collected, used, and disclosed, and for maintaining its own privacy policy governing that data.
- DREOS STUDIO acts generally as a data processor or service provider, processing such data only as instructed by the Client, for the purpose of building, deploying, or maintaining the relevant system.
If your data has been processed by a system built by DREOS STUDIO for one of our Clients, please direct privacy inquiries to that Client directly, as DREOS STUDIO does not independently determine how that data is used. Where a specific project requires DREOS STUDIO to enter into a formal data processing agreement with the Client (for example, to meet the Client's own regulatory obligations under GDPR, CCPA, or similar frameworks), such an agreement can be executed alongside the Project Agreement.
10. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect information we handle, including Client credentials, source code, and confidential business information, against unauthorized access, alteration, disclosure, or destruction. Further detail on our security practices is available in our separate Security Policy. No system can be guaranteed 100% secure, and we cannot guarantee absolute security of information transmitted to or stored by us or our third-party providers.
11. Data Retention
We retain information for as long as necessary to fulfill the purposes described in this Policy, including for the duration of an active Client engagement and thereafter as needed to comply with legal, tax, accounting, or contractual obligations, resolve disputes, and enforce our agreements. As a general practice, billing and contractual records are retained for the period required by applicable tax and accounting law, while project-related credentials and access keys are retired or revoked at the end of an engagement unless ongoing maintenance requires continued access, consistent with the applicable Project Agreement. Website inquiry data from prospective Clients who do not proceed with an engagement is generally retained for a limited period for follow-up purposes, after which it is deleted or anonymized.
12. International Data Transfers
As a U.S.-based company, information we collect may be stored and processed in the United States or in other countries where our service providers operate. Where information is transferred internationally, we take reasonable steps to ensure it receives an adequate level of protection consistent with applicable law, such as relying on service providers that maintain appropriate contractual or certification-based safeguards for cross-border transfers.
13. Your Rights
Depending on your location and applicable law, you may have rights regarding your personal information, which may include the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information, subject to legal and contractual retention requirements.
- Object to or restrict certain processing.
- Request a copy of your information in a portable format.
- Withdraw consent, where processing is based on consent.
- Lodge a complaint with a relevant data protection authority, where applicable in your jurisdiction.
To exercise any of these rights, please contact us using the details in Section 19. We will respond to verified requests within the time frame required by applicable law. We may need to verify your identity before processing certain requests to protect against unauthorized access to your information.
14. Children's Privacy
Our Services are intended for businesses and business representatives, not for individual consumers, and are not directed to children. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected such information, we will take reasonable steps to delete it.
15. Marketing Communications
If we send marketing or promotional communications, such as updates about our Services, you may opt out at any time by following the unsubscribe instructions included in the communication or by contacting us directly. Opting out of marketing communications does not affect transactional or project-related communications necessary to deliver active Services.
16. California and Other State Privacy Rights
Depending on your state of residence, additional privacy rights may apply, such as those under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, or similar state privacy laws. Because DREOS STUDIO primarily processes business contact information rather than consumer data, many state-specific consumer privacy frameworks may not directly apply to our processing activities; however, where they do apply, we honor applicable rights requests consistent with Section 13 above, including rights related to access, deletion, correction, and opting out of the sale or sharing of personal information (noting again that we do not sell personal information).
17. European and UK Data Subject Rights
If you are located in the European Economic Area or the United Kingdom, you may have additional rights under the General Data Protection Regulation (GDPR) or the UK GDPR, including the rights described in Section 13, as well as the right to lodge a complaint with your local supervisory authority. We process personal information from individuals in these regions primarily in the context of business communications with prospective or existing Clients, relying on the legal bases described in Section 5.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. The "Last Updated" date at the top of this Policy indicates when it was last revised. Material changes will be communicated to active Clients where appropriate. Continued use of our website or Services after changes take effect constitutes acceptance of the revised Policy.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
DREOS STUDIO LLC
Wyoming, United States
Email: [Insert Contact Email]
Website: [Insert Website URL]