Privacy Policy
Who We Are
House of JARRD is a founder-led house of brand, culture and digital intelligence, operating between Barcelona, London and Porto.This policy explains what personal data we collect when you visit this site, use our services, or get in touch, and what rights you have over it.
Data Controller: JÄRRD OÜ
Registered address: Harju maakond, Tallinn, Põhja-Tallinna linnaosa, Tööstuse tn 75-71, 10416
Registry Code: 17520790
Contact: contact@houseofjarrd.com
As an Estonian-registered company, our processing of personal data is governed by the EU General Data Protection Regulation (GDPR), and we fall under the supervision of the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon / AKI).
Where we process data belonging to individuals based in the UK, UK GDPR applies in parallel to that processing. Where the two frameworks differ, we apply whichever standard gives you stronger protection.
What We Collect
We collect personal data in the following ways:
When you contact us (including via Decode)
-
Name
-
Email address
-
Company name
Any information you choose to share about your brand, business, or project
When you browse the site
-
IP address
-
Browser and device type
-
Pages visited and time spent
-
Referral source
-
Cookie data (see Cookies section below)
When you engage us as a client
-
Billing and contact details
-
Communications related to project delivery
-
Any brand, business, or commercially sensitive information shared in the course of work
We do not knowingly collect any special category data (health, religion, political opinion, etc.) and ask that you don't send us any unless it's directly relevant to a project and necessary for us to deliver it.
Why We Collect It (Legal Basis)
Responding to Decode enquiries and general contact — legitimate interest, and pre-contractual steps taken at your request.
Delivering client services — performance of a contract.
Sending updates or marketing (only if you've opted in) — consent.
Website analytics and performance — legitimate interest, or consent where cookies require it.
Invoicing and legal compliance — legal obligation.
You can withdraw consent at any time where consent is the basis for processing — this doesn't affect the lawfulness of anything processed before withdrawal.
How Long We Keep It
-
Enquiry/contact data: retained for as long as it remains relevant to a potential or ongoing relationship with us. We don't apply an automatic deletion timeline to this data — it stays on file so we can pick up a conversation where it left off, even if that's months or years later. You can request deletion at any time (see Your Rights, below).
-
Client data: retained for the duration of the engagement, in line with our legal and tax obligations.
-
Analytics data: retained per the settings of the tools listed below (typically 14–26 months).
Exceptions to these timelines: We may retain data beyond the periods above where:
-
We're required to by law (e.g. Estonian tax and accounting retention rules, typically 7 years for financial records).
-
Data is subject to a legal claim, dispute, or investigation, until that matter is resolved.
-
Data exists in secure backup systems with limited retention cycles, and is not actively used, until those backups naturally expire or are overwritten.
-
Data has been anonymised or aggregated to the point it no longer identifies you — anonymised data isn't subject to GDPR retention limits and may be kept indefinitely for analytics or reporting.
If you request deletion under your GDPR rights, we will delete or anonymise your data across our active systems within one month, except where one of the above exceptions applies — in which case we'll tell you which one, and for how long.
Who We Share It With
We don't sell personal data. We share it only with:
-
Service providers who help us operate - Each is bound by data processing agreements consistent with GDPR.
-
Freelancers and partners engaged on client delivery, only where necessary and under confidentiality terms.
-
Legal or regulatory authorities, where required by law.
As an EU-based controller, any transfer of personal data outside the European Economic Area (EEA) — including to the UK, which is a "third country" under EU GDPR post-Brexit, or to US-based tools without adequacy coverage — requires an appropriate safeguard. Where our service providers process data outside the EEA, we rely on mechanisms such as the EU–US Data Privacy Framework (where the provider is certified) or Standard Contractual Clauses (SCCs).
Cookies
This site uses cookies to:
-
Understand how visitors use the site (analytics)
-
Remember preferences
-
At times track pixels (including [Meta Pixel / LinkedIn Insight Tag / Google Ads]) to show relevant advertising to visitors on other platforms and measure campaign performance.
You can manage or withdraw cookie consent at any time via [cookie banner / settings link]. Essential cookies required for the site to function are not subject to consent under GDPR.
Your Rights
Under GDPR / UK GDPR, you have the right to:
Access the personal data we hold about you
-
Rectify inaccurate dataErase your data ("right to be forgotten")Restrict or object to processing
-
Data portability (receive your data in a portable format)
-
Withdraw consent at any time, where consent is the basis for processing
-
Lodge a complaint with a data protection authority — as our lead supervisory authority, the Estonian Data Protection Inspectorate (AKI), or your own local authority: the ICO in the UK (ico.org.uk), the AEPD in Spain, or the CNPD in Portugal.
To exercise any of these rights, contact us at contact@houseofjarrd.com. We'll respond within one month, as required by law.
Changes to This Policy
We may update this policy as our tools, services, or legal obligations change. Material changes will be reflected with an updated "Last updated" date at the top of this page.