Privacy Policy
Last updated 26 July 2026
This notice explains what personal data we collect when you visit msve.io, contact us, or engage us for a project - why we collect it, how long we keep it, who else sees it, and what you can require us to do about it.
It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679. If anything here is unclear, ask us and we will explain it in plainer terms.
Who we are
We trade as MSVE Digital. The legal entity behind that name, and the data controller for the personal data described in this notice, is KV Marketing & Design LTD. We decide why and how your data is processed.
- Trading name: MSVE Digital
- Registered name: KV Marketing & Design LTD
- Company number: 202447482
- VAT number: BG202447482
- Registered office: Floor 2, 3 Ohrid Street, 8000 Burgas, Bulgaria
- Operating office: 69 Aungier Street, Dublin 2, D02 DW30, Ireland
- Email: connect@msve.io
- Phone: +353 83 1283 399
We are not required to appoint a Data Protection Officer under Article 37, and we have not appointed one. Privacy questions go to the address above and are handled by the business owner.
What we collect
Information you give us
When you submit the contact form, request a quote, or email or call us, we receive whatever you choose to send: your name, email address, phone number, company name, and the details of the project you are describing - including any budget, timeline, or business information you include.
If we go on to work together, we also process the contact and billing details needed to run the engagement and issue invoices.
Information collected automatically
Our hosting provider keeps standard server logs, including your IP address, the pages requested, and your browser user-agent string. These are generated by the act of serving the site and exist for security and diagnostics.
If you consent to analytics cookies, Google Analytics 4 records your approximate location, device and browser, the pages you view, how you arrived, and how long you stay. We also run a cookieless traffic counter (Ahrefs Web Analytics) which produces aggregate page-view figures and does not store anything on your device or build a profile of you.
Full detail, including every cookie name and lifetime, is in our Cookie Policy.
Your cookie choice
When you accept or reject cookies we record the choice itself, the categories you allowed, the time, the page you were on, your IP address, and your user-agent. Article 7(1) requires us to be able to demonstrate that consent was given, and this record is how we do that.
We do not collect special category data (health, biometrics, political or religious views, and so on), and we ask that you do not send it to us. We do not knowingly collect data from anyone under 16.
Why we use it, and our legal basis
Every purpose below is tied to one lawful basis under Article 6. We do not process for anything else.
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry, scoping work, and preparing a quote | Art. 6(1)(b) - steps taken at your request before entering a contract |
| Delivering a project, managing the engagement, and supporting what we build | Art. 6(1)(b) - performance of our contract with you |
| Issuing invoices and keeping accounting and tax records | Art. 6(1)(c) - compliance with our legal obligations |
| Analytics and marketing measurement cookies | Art. 6(1)(a) - your consent, which you can withdraw at any time |
| Aggregate, cookieless visitor counts | Art. 6(1)(f) - our legitimate interest in knowing whether the site works, balanced against a measurement method that cannot identify you |
| Recording your cookie choice so we can prove it and honour it | Art. 6(1)(c) - our obligation under Art. 7(1) to demonstrate consent |
| Server logs, spam filtering, and protecting the site from abuse | Art. 6(1)(f) - our legitimate interest in keeping the service secure and available |
| Establishing, exercising, or defending legal claims | Art. 6(1)(f) - our legitimate interest in protecting our legal position |
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that the processing is proportionate and would not surprise you. You can object to any of it - see Your rights below - and we will stop unless we can show compelling grounds that override your objection.
How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become projects | 12 months from our last exchange, then deleted |
| Client project records, contracts and correspondence | For the life of the engagement, then 7 years |
| Invoices and accounting records | 7 years, as required by tax law |
| Cookie consent records | 24 months from the date of the choice |
| Google Analytics event data | 14 months, then deleted by Google automatically |
| Server access logs | Up to 30 days |
Where a limitation period for a legal claim runs longer than the periods above, we may keep the minimum necessary for as long as that claim remains possible. When a retention period ends we delete the data or irreversibly anonymise it.
Who else sees it
We never sell personal data, and we do not share it for anyone else’s marketing. We use the following processors, each under a written Article 28 agreement that permits them to act only on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Hostinger International Ltd | Website and application hosting, server logs | EU |
| Neon Inc. | Application database (content, form submissions, consent log) | United Kingdom (London) |
| Google Ireland Ltd / Google LLC | Google Tag Manager, Google Analytics 4, and our email | EU and United States |
| Ahrefs Pte Ltd | Cookieless aggregate traffic measurement | Outside the EEA |
We may also disclose data to our accountants and professional advisers where they need it to advise us, and to a court, regulator, or law enforcement body where the law requires it. If the business is ever sold or restructured, client data may transfer to the acquirer, who would remain bound by this notice until they lawfully replace it.
Sending data outside the EEA
Two of the transfers above leave the European Economic Area. Both are covered:
- United Kingdom. Our database is hosted in London. The European Commission renewed its adequacy decision for the UK on 19 December 2025, so no additional safeguard is required.
- United States.Analytics and email data may be processed by Google LLC. Google is certified under the EU-US Data Privacy Framework, and its terms also incorporate the Commission’s Standard Contractual Clauses as a second layer.
- Other third countries. Any remaining transfer is made under Standard Contractual Clauses together with a transfer risk assessment.
You can ask us for a copy of the safeguards that apply to any specific transfer.
Your rights
Under Articles 15 to 22 you can require us to do the following, free of charge:
- Access - get confirmation of whether we hold data about you, and a copy of it.
- Rectification - have inaccurate data corrected and incomplete data completed.
- Erasure - have data deleted where we no longer have a good reason to hold it.
- Restriction - have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability - receive the data you gave us in a structured, machine-readable format, or have it sent directly to another controller.
- Objection - object to processing based on legitimate interests, and object to direct marketing at any time, with no reason needed and no exceptions.
- Withdraw consent - withdraw analytics or marketing consent whenever you like, via Manage cookies in the footer. Withdrawal does not affect processing carried out before you withdrew.
Email connect@msve.io to exercise any of these. We respond within one month. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if we do. We may ask you to confirm your identity before we release data.
Automated decisions
We do not make decisions about you by automated means, and we do not carry out profiling that produces legal effects for you or similarly significantly affects you.
Do you have to give us your data?
No. There is no statutory obligation to give us anything. If you use the contact form we need enough to reply - realistically a name and an email address - and without those we cannot respond. Once we are working together, some data is a contractual necessity: we cannot invoice a client we cannot identify. Everything else, including analytics, is optional.
Keeping it secure
The site is served over HTTPS. Access to the CMS and the database is restricted to named accounts with individual credentials, our database is managed by a provider with encryption at rest and in transit, and consent records capture IP and user-agent server-side so they cannot be forged by a browser. No system is perfectly secure, but if a breach ever puts your rights at risk we will notify the supervisory authority within 72 hours and tell you directly where the law requires it.
Complaints
Raise it with us first - connect@msve.io - and we will try to resolve it. You do not have to, and your right to complain to a supervisory authority is unconditional. You may complain to the authority in the EU country where you live or work, where the alleged infringement happened, or to either of ours:
- Ireland - Data Protection Commission, dataprotection.ie
- Bulgaria - Commission for Personal Data Protection, cpdp.bg
You also have the right to an effective judicial remedy against us or against a supervisory authority.
Changes to this notice
We update this notice when what we do with data changes. The date at the top always reflects the current version. Where a change materially affects your rights we will say so prominently on the site rather than quietly editing the page, and where the change concerns cookies we will re-ask for your consent.
Contact
MSVE Digital
69 Aungier Street, Dublin 2, D02 DW30, Ireland
connect@msve.io
+353 83 1283 399