Privacy policy
Last updated 19 July 2026
Progresso is an internal workspace operated by Rritje Sade (“we”, “us”) for authorized studio members. This policy explains what personal data we process, why, and your rights under the EU General Data Protection Regulation (GDPR) and similar laws.
1. Who is responsible
Controller: Rritje Sade. For privacy requests, contact the studio owner via your usual studio channel or the email on rritjesade.com.
2. What we process
- Account data — Google account identity (name, email, profile photo) used to sign in and provision your Progresso profile.
- Work data — tickets, comments, time entries, check-ins, documents, and notifications you create or are assigned to.
- Lead / CRM data — contact details and notes about prospective or current clients entered by members (name, company, email, phone, deal status, estimated value).
- Technical logs — authentication and security-related events needed to operate and protect the service.
3. Why we process it (legal bases)
- Legitimate interests / employment & contract — run the studio workspace, track time and delivery, and manage client relationships.
- Consent — where you choose optional features that require it (e.g. connecting a personal calendar if offered).
- Legal obligation — where we must retain records for tax or other law.
4. How we share data
We do not sell personal data. We use processors that host and secure the app under contract:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and delivery.
- Google — sign-in (OAuth) and, when connected, Calendar for studio scheduling.
Access inside Progresso is limited to allowlisted studio accounts. Lead contact data is visible to members so the team can follow up — treat it as confidential client information.
5. Retention
Account and work records are kept while you are a member and as long as needed for studio operations, audits, and legal retention. When access is revoked, login is blocked; owners may delete or anonymize records on request where law allows.
6. Your rights
Depending on applicable law, you may request access, correction, erasure, restriction, portability, or object to certain processing. Members can update profile fields in-app; for broader requests contact the controller above. You may lodge a complaint with your local supervisory authority (in the EU, your national DPA).
7. Security
Access requires Google sign-in and an allowlisted account. Data is protected with TLS in transit, row-level security in the database, and role-based access in the product. No method is perfectly secure; report suspected incidents to an owner immediately.
8. Cookies
Progresso uses essential cookies only (session / authentication). We do not use advertising or third-party analytics cookies on the login or app surfaces covered by this policy.
9. Changes
We may update this policy as the product or law changes. The “Last updated” date above will change when we do. Material changes will be communicated to members when practical.
See also our Terms of use.