Legal / PrivacyUpdated 20 September 2026

Privacy
policy

This website sets no cookies, runs no analytics and follows no one around the internet. What we do handle, and your rights over it, is set out below.

01Who we are

WITHIN Design Lab S.L. is responsible for the personal data handled through this website.

We are a strategic innovation and industrial design studio based in Barcelona, Spain. When this policy says “we” or “us”, it means WITHIN Design Lab S.L. We handle personal data under the EU General Data Protection Regulation (GDPR) and the Spanish Organic Law 3/2018 on Data Protection and the Guarantee of Digital Rights (LOPDGDD).

Our registration details are in the legal notice. The law does not require a studio of our size to appoint a Data Protection Officer, so any question about your data comes straight to us at the address above.

02What we collect

Only what reaches us when you visit the site, or when you choose to get in touch.

  • When you visit. The technical data your browser sends with every request: your IP address, browser type and version, operating system, the page you asked for, the page you came from, and the date and time. It is recorded in server log files.
  • When you write or call. Your name, email address, phone number, company, and whatever you choose to tell us about your project.
  • When you apply to work with us. Your CV, portfolio and anything else you send with them.

There are no contact forms, user accounts or newsletters on this website, and we never ask for sensitive data such as health information or ethnic origin. Please do not send it to us.

03Why we use it

A small number of clear purposes, each with a legal basis.

  • To deliver this website and keep it secure. Basis: our legitimate interest in a reliable, secure website (Art. 6(1)(f) GDPR).
  • To answer your enquiry, and where it leads somewhere, to prepare a proposal or carry out a project with you. Basis: steps taken at your request before a contract, or the contract itself (Art. 6(1)(b) GDPR). For any other enquiry, our legitimate interest in replying (Art. 6(1)(f) GDPR).
  • To consider your application. Basis: steps taken at your request before an employment or collaboration agreement (Art. 6(1)(b) GDPR).
  • To meet our legal obligations, such as keeping accounting and tax records. Basis: Art. 6(1)(c) GDPR.

We do not sell your data, we do not use it for advertising, and we make no automated decisions or profiles about you.

04Cookies

This website sets no cookies.

It uses no analytics, advertising or tracking tools, and it keeps nothing on your device beyond one functional preference: the language you chose to read the company profile in, which your own browser stores so the profile opens the same way next time. It is not a cookie, it holds no identifier, it is never sent to us or to anyone else, and clearing your browser data removes it. That is why there is no cookie banner: there is nothing to consent to. If that ever changes, we will update this policy first, and ask for your consent before anything that needs it is used.

05Services we rely on

A few outside services help the site load. They receive only the technical data needed to deliver it.

  • Hosting. The site is served by our hosting provider, which processes the technical data described above on our behalf and only on our instructions.
  • Typefaces. None. The site’s two typefaces are served from this domain along with everything else, so reading a page sends your address to no one but us and our host.
  • Code libraries. None. The open-source libraries behind the site’s motion are served from this domain along with everything else, so no request for them goes to anyone but us and our host.
  • Email and telephone. Messages you send us are held by our email and telephone providers, who act on our behalf.

Beyond these, we share personal data only with advisers bound by confidentiality, such as our accountants and lawyers, or with public authorities where the law requires it.

06Outside Europe

Where data leaves the European Economic Area, it stays protected.

Some of the providers above may process data in the United States. Those transfers rely on the European Commission’s adequacy decision for companies certified under the EU-U.S. Data Privacy Framework or, where a provider is not certified, on the Commission’s Standard Contractual Clauses.

07How long we keep it

No longer than we need it.

  • Server log files: only as long as needed to keep the site secure, after which they are deleted.
  • Enquiries that do not become a project: until the conversation is finished, and never longer than 12 months.
  • Client and project records: for as long as we work together, and afterwards for the six years Spanish commercial law requires us to keep business records.
  • Applications: up to 12 months, so we can reach you if a suitable role opens, unless you ask us to delete yours sooner.
08Security

Appropriate care, technical and organisational.

The site is served over an encrypted connection. Messages and project files are open only to the people at WITHIN who need them, and we keep your data accurate and only for as long as it is needed. No transmission over the internet is ever completely secure, but we work to keep the risk as low as we reasonably can.

09Children

This website is not directed at children.

We do not knowingly collect personal data from anyone under 14, the age of digital consent in Spain. If you believe a child has sent us personal data, contact us and we will delete it.

10Your rights

You stay in control of your data, free of charge.

  • Access: to ask whether we hold data about you, and to receive a copy (Art. 15 GDPR).
  • Rectification: to have inaccurate or incomplete data corrected (Art. 16).
  • Erasure: to have your data deleted (Art. 17).
  • Restriction: to have its use limited (Art. 18).
  • Portability: to receive the data you gave us in a structured, machine-readable format, or have it sent to someone else (Art. 20).
  • Objection: to object at any time to processing based on our legitimate interests (Art. 21).
  • Withdrawing consent: where we rely on your consent, to withdraw it at any time, without affecting what was done before (Art. 7(3)).

To exercise any of these rights, write to hello@withindesign.pro. We may ask you to confirm your identity, and we will reply within one month.

If you are not satisfied with how we have handled your data, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan 6, 28001 Madrid, aepd.es, or to the supervisory authority where you live or work.

11Changes

We review this policy whenever the website, or the way we work, changes.

The version published on this page is always the current one, and the date at the top says when it was last updated.

Questions about your data? Write to us directly.

hello@withindesign.pro