DATA PROTECTION PROTOCOL // GDPR & CCPA COMPLIANCE

Privacy Policy & Data Governance

EFFECTIVE DATE: MARCH 2026 · REGULATION (EU) 2016/679 (GDPR) & CALIFORNIA CONSUMER PRIVACY ACT (CCPA/CPRA)

1. Core Architectural Philosophy: Data Minimalism

Just as our desktop hardware rejects digital surveillance, microprocessors, and telemetry tracking, KURA WORKSTUDIO AG operates on a strict policy of architectural data minimization. We collect only the absolute minimum data required to verify encrypted commercial transactions, engrave individual serial records, and dispatch physical hardware via Tier-1 international couriers.

ZERO DATA BROKER CLAUSE: Under no circumstances do we sell, monetize, rent, or trade your personal data, order histories, IP addresses, or contact information to commercial data brokers, advertising exchanges, or profiling platforms.

2. Categories of Information Collected

When you interact with our digital platform or procure an instrument, we process the following discrete data categories:

  • Fulfillment & Identity Data: Full legal name, studio or company name, shipping address, contact telephone number (for courier customs clearance), and direct electronic mail address.
  • Transaction Verification: Masked payment tokens processed via PCI-DSS Level 1 certified gateway partners. We never view, ingest, or store raw 16-digit primary account numbers (PAN) or security codes (CVV) on our local edge nodes.
  • Technical Edge Telemetry: Transient server access logs including coarse IP geographic origin, request latency, and browser user-agent strings required for CDN distributed DDoS mitigation via Cloudflare Edge.

3. Legal Grounds for Processing Under GDPR (Articles 6 & 13)

For residents of the European Economic Area (EEA), United Kingdom, and Switzerland, data processing is anchored strictly in the following lawful bases:

  • Contractual Performance (Art. 6(1)(b)): Necessary to generate packing slips, laser engrave serials, and coordinate DHL Express international air transit.
  • Legal Obligations (Art. 6(1)(c)): Compliance with Swiss, EU, and US customs manifest declarations, international export control documentation, and tax auditing records.
  • Legitimate Interests (Art. 6(1)(f)): Platform security, fraud prevention, and maintaining our lifetime mechanical warranty ledger.

4. Cookie Handling & Client-Side Storage

Our web application uses lightweight client-side state storage (such as browser session memory and local storage) exclusively to preserve your active variant selection and shopping bag items during continuous navigation. We do not inject invasive cross-site advertising pixels (e.g., Meta Pixel, TikTok tracking beacons, or third-party behavioral retargeting scripts).

5. Your Statutory Rights (GDPR & CCPA/CPRA)

Regardless of your geographic location, KURA affords all clients universal privacy rights:

RIGHT TO ACCESS & PORTABILITY

Receive a complete copy of all personal records and serial ledger entries held under your name.

RIGHT TO ERASURE ("FORGOTTEN")

Request total deletion of your digital contact record, subject only to mandatory statutory tax retention.

RIGHT TO RECTIFICATION

Correct or update shipping manifests and concierge contact records at any time.

CALIFORNIA "DO NOT SELL" (CCPA)

We do not sell personal information; no opt-out is needed, but rights are formally affirmed.

6. Data Retention Protocols

Order transaction manifests are retained for seven (7) years in encrypted cold storage to comply with Swiss Federal Tax Administration (ESTV) and international commercial accounting laws. Serial number warranty registration is maintained indefinitely to honor our Lifetime Mechanical Guarantee unless a registered owner explicitly demands deletion.

7. Data Protection Officer (DPO) Contact

Office of Data Privacy // KURA WORKSTUDIO AG
Hardturmstrasse 161, 8005 Zürich, Switzerland
Official DPO Contact: privacy@kuraworkstudio.com
Response SLA: Under 48 Business Hours