Overview
Dark Water respects your privacy. We collect only the information you provide to deliver our services and communicate with you, and we never sell your data.
This policy explains what information we collect when you visit darkwater.work, contact us, or use a client portal account, how that information is used, who it is shared with, how long it is kept, and the choices available to you. It applies to this website and to the business services provided through it. It does not govern the separate websites and applications we build and hand over to clients — once a project is delivered, the client operates that property under their own privacy policy.
This document describes our current data practices in plain language. It is a description of how we operate, not legal advice, and it may be updated as our services, tools, and legal obligations change. Where a written agreement with a client covers the handling of specific data, that agreement governs for the data it addresses.
Dark Water is a studio brand operated by Dark Water Ventures Inc., a company based in the United States. References to “we,” “us,” and “our” in this policy mean that entity. References to “you” mean any visitor to this site, anyone who contacts us, and anyone who holds a client portal account.
Information We Collect
We collect three broad categories of information: what you give us directly, what is gathered automatically as you browse, and what is generated inside a client portal account. We do not attempt to collect more than we need to run the business.
Information you provide
Contact and project details you submit via forms or email. In practice this usually means your name, business name, email address, telephone number, website address, and a description of the project or question you are bringing to us. If you book a call, we also hold the time you selected and any notes you added.
If you become a client, we additionally hold the information needed to run an engagement: billing and invoicing details, the names and contact information of people on your team who work with us, and whatever project materials you choose to share with us, such as brand assets, content drafts, and access credentials for systems we are asked to work in.
Please do not send us sensitive personal information — government identifiers, health information, financial account numbers, or similar — through the contact form or by ordinary email. If an engagement genuinely requires that kind of data, we will agree on a secure channel and written terms for handling it first.
Information collected automatically
When you visit the site, our hosting and analytics infrastructure records standard technical information: your IP address, browser type and version, operating system, device category, screen dimensions, referring page, the pages you viewed, the approximate time spent on each, and the date and time of your visit. Approximate location at the city or region level may be inferred from the IP address.
This information is collected in aggregate to understand how the site performs and where visitors lose interest. We do not use it to build advertising profiles about individuals, and we do not attempt to identify individual visitors from it.
Server and security logs are also generated automatically. These record requests made to our servers, including IP addresses and error conditions, and exist so that we can diagnose outages, investigate suspicious traffic, and defend against abuse.
Contact form submissions
Submitting a form on this site sends the content of that form, along with the technical metadata described above, to our email and project intake systems. Submissions are reviewed by our team so that we can respond, scope work, and keep a record of the conversation. Form data is not used for unrelated marketing, and we do not add you to a mailing list because you filled in an enquiry form.
Client portal account data
Clients with portal access have an account record containing a name, work email address, organization, role, and an encrypted representation of the password — we do not store passwords in readable form. The portal also records activity necessary to operate it: sign-in timestamps, IP address at sign-in, project and task history, files uploaded or downloaded, comments, approvals, and invoice status.
Some of this activity data doubles as a security record. Being able to see who approved a deliverable or who last accessed a file is part of how we keep engagements accountable and how we investigate any suspected unauthorized access.
Information from other sources
Before or during an engagement we may review publicly available information about your business — your website, public search and advertising data, business listings, and similar public records — to prepare proposals and strategy. Where a client grants us delegated access to their own analytics, advertising, or content platforms, we may receive data from those platforms on the client’s behalf and under the client’s instructions.
How We Use Information
To scope projects, deliver services, and communicate. Analytics help us improve our experience.
In more detail, we use the information described above to respond to enquiries and prepare proposals; to negotiate, sign, and perform contracts; to design, build, host, and support the work we are engaged to deliver; to operate and secure the client portal; to issue invoices and collect payment; to maintain business records and meet tax, accounting, and other legal obligations; to understand how this website performs and improve it; to detect, investigate, and prevent fraud, abuse, and security incidents; and to send occasional operational or business updates to people who have an existing relationship with us.
Where we send marketing communications, they go to business contacts who have engaged with us or asked to hear from us, and every message carries a working unsubscribe link. Unsubscribing from marketing does not stop transactional messages about an active project, an invoice, or a security matter, because those are necessary to the service itself.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under California law. We do not use the information collected here to make decisions about you that produce legal or similarly significant effects, and we do not use it to train third-party artificial intelligence models.
Our legal bases
For visitors in the European Economic Area and the United Kingdom, we rely on the following legal bases. We process enquiry and client data because it is necessary to perform a contract with you or to take steps at your request before entering into one. We process analytics, security, and business-development data on the basis of our legitimate interests in running, securing, and improving our business, balanced against your rights. We rely on consent for non-essential cookies and for marketing where consent is required, and you may withdraw that consent at any time. We process certain records because we are legally obliged to keep them.
Cookies and Analytics
This site uses a small number of cookies and similar technologies such as local storage. They fall into two groups.
Strictly necessary cookies and storage keep the site working. They remember your interface preferences, hold a client portal session so you are not signed out between pages, and support security functions such as protecting forms against automated abuse. The site cannot function properly without them, so they are not optional.
Analytics cookies and storage help us understand how the site is used in aggregate: which pages are read, how far people scroll, which paths lead to an enquiry, and where the experience is failing. We configure analytics conservatively, with IP handling restricted where the provider supports it, and we use the results to improve the site rather than to profile individuals.
You can control cookies through your browser. Most browsers let you view what is stored, delete it, block cookies from specific sites, or block them entirely, and most offer a private browsing mode that discards them at the end of a session. Blocking strictly necessary cookies will break portal sign-in and some site features. Where local law requires a consent banner before non-essential cookies are set, that banner is presented and your choice is respected until you change it.
Some browsers transmit a Do Not Track or Global Privacy Control signal. There is still no single accepted standard for Do Not Track, so we do not respond to it. Where a recognized opt-out preference signal such as Global Privacy Control is received, we treat it as a valid request to opt out of the sale or sharing of personal information — which, since we do neither, means it changes nothing about how we handle your data.
Service Providers and Sharing
We rely on a small set of vendors to operate the business. We describe them by category rather than by brand name, because the specific providers change over time and naming them would make this policy stale rather than more useful. A current list is available on request from the contact address below.
The categories are: cloud hosting and content delivery providers that serve this website and the client portal; email and calendar providers that carry our correspondence and scheduling; a form and project intake system that receives enquiries; a privacy-conscious web analytics provider; error monitoring and uptime services that alert us when something breaks; a payment processor and an accounting platform that handle invoicing and bookkeeping; a customer relationship and proposal tool; secure file storage and transfer services; a password and credential management service; and professional advisers such as accountants and legal counsel.
Every provider receives only the information needed for its function. We select vendors that offer appropriate security and contractual protections, we bind them to confidentiality, and we require them to process personal information on our instructions rather than for their own purposes.
Beyond those providers, we share personal information only in narrow circumstances: when you direct us to; when a client instructs us to interact with their own platforms or partners on their behalf; when we are required to by law, subpoena, or other valid legal process; when disclosure is necessary to investigate suspected fraud or a security incident, or to protect the rights, property, or safety of Dark Water, our clients, or the public; and in connection with a merger, acquisition, financing, or sale of assets, in which case personal information may transfer to the successor entity under this policy or a successor policy with equivalent protections. We would notify affected individuals of any such transfer where notice is required.
Data Retention
We keep personal information only as long as it serves the purpose it was collected for, and then we delete it or reduce it to an anonymous form.
Enquiries that do not become engagements are generally kept for up to twenty-four months, so that we can recognize a returning prospect and honor a prior conversation, after which they are deleted. Correspondence and project records for active clients are kept for the life of the engagement. After an engagement ends, contract, invoice, and financial records are retained for the period required by applicable tax and corporate record-keeping law, which in the United States is commonly seven years.
Client portal accounts remain active while the engagement is active. On request, or within a reasonable period after an engagement closes, accounts are deactivated and account data is deleted except where a record must be kept for legal or accounting reasons. Project deliverables are handed over to the client at close, and clients are responsible for their own copies thereafter.
Aggregated analytics data, which no longer identifies any individual, may be retained indefinitely for trend analysis. Server and security logs are retained on a short rolling window — typically no more than twelve months — unless a specific log is preserved as part of an ongoing security investigation.
Security
We take reasonable and appropriate technical and organizational measures to protect personal information against loss, misuse, and unauthorized access, alteration, or disclosure.
In practice that means encryption in transit using current TLS across the site and the portal, encryption at rest for stored data where our providers support it, hashed rather than stored passwords, access granted on a least-privilege basis and reviewed periodically, multi-factor authentication on administrative and vendor accounts, dependency and vulnerability scanning on the systems we operate, monitored and regularly tested backups, and a documented process for investigating and responding to suspected incidents.
No method of transmission over the internet and no method of electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will investigate promptly and notify you and the relevant authorities where the law requires it. You also play a part: use a strong, unique password for any portal account, keep it private, and tell us immediately if you believe an account has been compromised.
Your Rights and Choices
Wherever you are located, you can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, or ask us to stop sending you marketing. Write to the contact address at the end of this policy and we will respond within a reasonable period, and within any period the law specifies. We may need to verify your identity before acting on a request, and we may decline a request where the law permits or requires us to keep the information — for example, records we must retain for tax purposes. We will not treat you differently for exercising any of these rights.
California residents
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you specific rights over your personal information.
You have the right to know what categories of personal information we have collected about you, the categories of sources it came from, the business purpose for collecting it, and the categories of third parties to whom it is disclosed. You have the right to request a copy of the specific pieces of personal information we hold. You have the right to request deletion, and the right to request correction of inaccurate information. You have the right to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information — and as stated above, we do not sell or share personal information for cross-context behavioral advertising, and we do not collect sensitive personal information for the purpose of inferring characteristics about you. You have the right not to receive discriminatory treatment for exercising any of these rights.
In the twelve months before the last update of this policy, we collected the categories of information described in this policy: identifiers such as name, email address, telephone number, and IP address; commercial information such as services enquired about and purchased; internet and network activity such as browsing behavior on this site; approximate geolocation inferred from IP address; and professional information such as job title and employer. We collected it from you directly, automatically through your use of the site, and from public sources. We disclosed it for business purposes to the categories of service providers listed above. We did not sell it and we did not share it for cross-context behavioral advertising.
To exercise a right, email us at the address below with “California Privacy Request” in the subject line and tell us which right you are exercising. An authorized agent may submit a request on your behalf with written proof of authorization, and we may still ask you to verify your own identity directly.
EU and UK visitors
If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation and equivalent UK law give you the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing carried out on the basis of legitimate interests, as well as the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
We act as a data controller for information collected through this website and for our own client relationships. Where we handle personal data inside a client’s own systems as part of an engagement, we generally act as a processor on that client’s documented instructions, and the client’s own privacy notice governs that data. We will enter into a data processing agreement where one is required.
To exercise any of these rights, email the contact address below. You also have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner’s Office — although we would appreciate the chance to resolve the matter with you first.
Other jurisdictions
Residents of other US states with comprehensive privacy laws, and of other countries with equivalent regimes, have similar rights of access, correction, deletion, and portability. We apply the same process to every request regardless of where you live, so you do not need to identify the statute you are relying on in order to be helped.
International Transfers
We are based in the United States and our infrastructure and service providers are primarily located there. If you access this site or work with us from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and potentially in other countries where our providers operate. Data protection law in those countries may differ from the law where you live.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards recognized under applicable law, including standard contractual clauses and the UK international data transfer addendum, together with contractual and technical measures with the receiving provider. By using the site or engaging our services, you understand that your information will be handled as described in this policy.
Children’s Privacy
This is a business-to-business website and our services are directed to businesses and to adults acting on their behalf. The site is not intended for children, and we do not knowingly collect personal information from anyone under the age of sixteen. If you believe a child has provided us with personal information, contact us and we will delete it promptly. We do not sell or share the personal information of minors.
Links to Other Sites
This site links to other websites, including the sites we have built for clients and the platforms our services touch. We are not responsible for the privacy practices or content of any site we do not operate. When you follow a link away from darkwater.work, read the privacy policy of the site you land on.
Changes to This Policy
We update this policy when our practices, our tools, or the law change. The current version is always published at this address and carries the date it last changed. Material changes — for example, a new category of information collected or a new purpose for using it — will be highlighted on this page and, where the law requires it or the change is significant, communicated to active clients directly. Continuing to use the site after a change takes effect means the revised policy applies to you.
Contact
Questions? Email [email protected].
Use the same address to request a copy of your data, to ask for a correction or deletion, to opt out of marketing, to request our current list of service providers, or to report a suspected security issue. Write “Privacy Request” in the subject line and tell us what you need, and a person will read it and respond. Postal correspondence for Dark Water Ventures Inc. can be arranged through the same address.
Last updated: July 2026.
Sample policy for demonstration; review with counsel before publishing.