PRIVACY POLICY
Brightwill Luxury Studio
Version 1.0 | Effective: 06 May 2026
─────────────────────────────────────────────
INTRODUCTION
Brightwill UAB and Brightwill LLC ("Brightwill", "we", "us", "our") are committed to protecting your personal data. This Privacy Policy explains what data we collect when you visit studio.brightwillluxury.com, why we collect it, how we use and share it, and your rights.
This Policy applies to all Website visitors, including EU residents (GDPR applies), UK residents (UK GDPR applies), California residents (CCPA/CPRA applies), and all other users.
1. WHO IS RESPONSIBLE FOR YOUR DATA
The data controller depends on your location:
EU, MENA, Asia, and all other regions:
Brightwill UAB | J. Savickio g. 4-7, LT-01108 | Vilnius, Lithuania
Governed by GDPR and Lithuanian law
North America and South America:
Brightwill LLC | 801 Brickell Avenue, Suite 800 | Miami, Florida 33131, USA
Governed by Florida law and CCPA where applicable
For all privacy questions: concierge@brightwillluxury.com
2. PERSONAL DATA WE COLLECT
Data you provide directly
When you interact with the Website we may collect:
- Name, job title, and company name
- Email address and phone number
- Content of your enquiry or message
- Property preferences or budget (if voluntarily provided)
- Call booking details including time zone and selected slot
Data collected automatically
When you visit the Website, the following is collected automatically:
- IP address and approximate geolocation (country/city level)
- Browser type, version, and language settings
- Device type and operating system
- Pages visited, time on page, scroll depth, and click behaviour
- Referral source (how you arrived at the Website)
- Cookie identifiers and advertising IDs
Data we do not collect
We do not collect special category data such as health information, biometric data, political views, or financial records. Please do not submit sensitive personal data through any Website form.
3. TRACKING TECHNOLOGIES AND THIRD-PARTY TOOLS
We use the following tracking and analytics tools on the Website:
Google Analytics 4 (Google LLC, USA)
Tracks visitor behaviour, traffic sources, and page performance. IP anonymisation is enabled. Requires your consent.
Meta Pixel (Meta Platforms Inc., USA)
Tracks conversions from Meta ads and enables retargeting of Website visitors on Facebook and Instagram. Requires your consent.
LinkedIn Insight Tag (LinkedIn Corporation, USA)
Tracks visits from LinkedIn campaigns and enables B2B retargeting and conversion reporting. Requires your consent.
HubSpot Tracking (HubSpot Inc., USA)
Identifies returning visitors, tracks form submissions, integrates with CRM, and enables lead scoring. Requires your consent.
Webflow (Webflow Inc., USA)
Hosts the Website and processes form submission data. Acts as our data processor. No consent required - necessary for Website operation.
All four marketing and analytics tools require your consent before any tracking data is collected. Consent is requested via our cookie banner on your first visit. You can change your preferences at any time via the cookie settings link in the Website footer.
All US-based providers transfer data to the United States under Standard Contractual Clauses approved by the European Commission.
4. LEGAL BASES FOR PROCESSING (EU - GDPR)
Responding to contact form submissions: Legitimate interest (Art. 6(1)(f))
Booking and confirming calls: Pre-contractual steps (Art. 6(1)(b))
Delivering downloaded resources: Legitimate interest (Art. 6(1)(f))
Sending newsletter and marketing emails: Consent (Art. 6(1)(a))
Analytics cookies (Google Analytics, HubSpot): Consent (Art. 6(1)(a))
Marketing cookies (Meta Pixel, LinkedIn): Consent (Art. 6(1)(a))
Website hosting and essential functionality: Legitimate interest (Art. 6(1)(f))
Legal compliance and record-keeping: Legal obligation (Art. 6(1)(c))
5. COOKIES AND CONSENT
We use four categories of cookies:
Strictly necessary - No consent required. Used for Website functionality and security. Cannot be disabled without breaking the Website.
Analytics (Google Analytics 4, HubSpot) - Consent required. Used to understand traffic and usage patterns. Opt out via cookie settings or tools.google.com/dlpage/gaoptout.
Marketing and retargeting (Meta Pixel, LinkedIn Insight Tag) - Consent required. Used to show Brightwill advertising on other platforms after you visit the Website. Opt out via cookie settings, facebook.com/adpreferences, or linkedin.com/psettings.
Functional (HubSpot CRM identification) - Consent required. Used to remember your preferences and identify returning visitors.
Consent is collected via our cookie banner on first visit and can be updated at any time via Cookie Settings in the footer. Cookie consent records are stored for 12 months.
6. HOW WE USE YOUR DATA
Responding to enquiries
We use your contact form data to assess your enquiry and respond with relevant information about our services.
Call booking
Your booking details are used to schedule the call, send confirmation and reminder emails, and add the appointment to our calendar.
Resource downloads
When you download a guide, we deliver it to your email address. If you opted in to marketing at the point of download, we may send follow-up emails with related content. If you did not opt in, we will only email you to deliver the resource.
Newsletter
We send marketing emails only to subscribers who have actively opted in. Every email contains an unsubscribe link.
Retargeting
If you consent to marketing cookies, the Meta Pixel and LinkedIn Insight Tag allow us to show Brightwill advertising to you on Facebook, Instagram, and LinkedIn after you leave the Website.
HubSpot CRM
When you submit a form or book a call, your data is stored in our HubSpot CRM to manage our relationship with you and track communication history.
7. WHO WE SHARE YOUR DATA WITH
We share personal data only in the following circumstances:
Sub-processors (data processors acting on our instructions):
- Webflow Inc. (USA) - Website hosting and form data
- Google LLC (USA) - Analytics and advertising
- Meta Platforms Inc. (USA) - Conversion tracking and retargeting
- LinkedIn Corporation (USA) - B2B conversion tracking and retargeting
- HubSpot Inc. (USA) - CRM, email marketing, and form tracking
- Call-booking tool [insert name] - Call scheduling and confirmations
Legal disclosure: We may disclose data to public authorities, courts, or regulators where required by law.
Business transfers: In the event of a merger or acquisition, personal data may be transferred as part of that transaction.
We do not sell, rent, or trade personal data to third parties for their own marketing purposes.
8. DATA RETENTION
Contact form and enquiry data: 3 years from last contact
Call booking records: 1 year from the date of the call
Resource download records: 3 years, or until deletion request
Newsletter subscriber data: Until unsubscribe, plus 1 year for compliance records
HubSpot CRM contact records: 3 years from last meaningful interaction
Analytics data (GA4): 14 months
Cookie consent records: 12 months from consent date
Legal and compliance records: 10 years (Lithuanian law) or 7 years (US IRS)
9. YOUR RIGHTS
EU and UK residents (GDPR / UK GDPR)
You have the following rights:
- Access (Art. 15): request a copy of the data we hold about you
- Rectification (Art. 16): correct inaccurate or incomplete data
- Erasure (Art. 17): request deletion where no overriding legitimate purpose applies
- Restriction (Art. 18): limit processing in certain circumstances
- Portability (Art. 20): receive your data in a machine-readable format
- Object (Art. 21): object to processing based on legitimate interest, including direct marketing
- Withdraw consent (Art. 7(3)): withdraw consent at any time for consent-based processing
To exercise any right, contact concierge@brightwillluxury.com. We will acknowledge within 5 working days and respond within 30 calendar days.
You may also lodge a complaint with your national supervisory authority. In Lithuania: State Data Protection Inspectorate (ada.lt). In the UK: Information Commissioner's Office (ico.org.uk).
California residents (CCPA / CPRA)
You have the right to:
- Know what personal information we have collected about you in the past 12 months
- Request deletion of your personal information
- Request correction of inaccurate personal information
- Opt out of sale or sharing of personal information (we do not sell your data)
- Non-discrimination for exercising your rights
To submit a California privacy request, email concierge@brightwillluxury.com with the subject line "California Privacy Request". We will respond within 45 calendar days.
All other users
Regardless of your location, you may contact us at concierge@brightwillluxury.com to request access to, correction of, or deletion of your personal data. We will respond within 30 calendar days.
10. DATA SECURITY
We implement the following security measures:
- TLS/SSL encryption for all data transmitted to and from the Website
- Webflow's enterprise-grade hosting infrastructure with DDoS protection
- Role-based access controls for systems storing personal data
- Regular review of third-party processor security standards
In the unlikely event of a data breach affecting your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
11. CHILDREN'S PRIVACY
This Website is not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has submitted data to us, contact concierge@brightwillluxury.com and we will delete it promptly.
12. CHANGES TO THIS POLICY
We update this Policy as our practices evolve or law requires. Material changes will be communicated via a notice on the Website and, where we hold your email address, by email. The effective date at the top of this document indicates when it was last updated.
13. CONTACT AND SUPERVISORY AUTHORITIES
Privacy and legal enquiries: concierge@brightwillluxury.com
Phone (US): +1 646 561 9704
Phone (EU): +370 601 26312
Brightwill UAB
J. Savickio g. 4-7, LT-01108, Vilnius, Lithuania
Brightwill LLC
801 Brickell Avenue, Suite 800, Miami, Florida 33131, USA
EU supervisory authority: State Data Protection Inspectorate (ada.lt) | Lithuania
UK supervisory authority: Information Commissioner's Office (ico.org.uk)