Skip to content
WorkServicesAboutContact
Start projectLog in
HomeWorkServicesAboutContact
Start projectLog ininfo@juzva.us

Have something that needs building?

Start a project

Web apps, mobile apps and business tools, designed and built end to end by Laurynas.

Studio

  • Work
  • Services
  • About

Contact

  • Start a project
  • Get support
  • info@juzva.us

Clients

  • Log in
  • Reset password
© 2026 Juzva
Privacy PolicyTerms of Service

Privacy Policy

Last updated September 27, 2026

In short

  • Juzva is run by Laurynas Juzva, a sole proprietor in California, USA. He decides how your data is used (the “controller”).
  • We collect what you send us (the contact form, your account, project files and messages) and, only if you agree, anonymous analytics.
  • We use it to reply to you, deliver and bill our work, and keep the site secure. We never sell it or use it for advertising.
  • It is stored with Google Cloud in the United States. You can see, correct, export or delete your data by emailing info@juzva.us.
  1. Who we are
  2. What we collect
  3. How we use it and why we’re allowed to
  4. Who we share it with
  5. International transfers
  6. How long we keep it
  7. Your rights
  8. California and other US states
  9. Cookies and similar storage
  10. How we protect it
  11. Children
  12. Changes to this policy
  13. Contact

1. Who we are

This policy explains how Laurynas Juzva, a sole proprietor doing business as Juzva (“Juzva”, “we”, “us”), collects and uses personal information through juzva.us, the client portal and the work we do for clients.

For the purposes of the EU and UK General Data Protection Regulation (GDPR), Juzva is the controller of the personal information described here. When we build or host an app that processes our client’s own customers’ data, we act on the client’s instructions as their processor, and the client’s privacy policy applies to that data.

Contact: info@juzva.us. We answer privacy questions ourselves; there is no separate data protection officer because we are a one-person business.

2. What we collect

Information you give us

  • Contact form: your name, email, the topic, your message and, if you add them, your company and budget.
  • Portal account: name, email, password (stored only as a secure hash by our sign-in provider) or your Google sign-in, and any profile details you add: photo, phone number, location, time zone, date of birth and a short bio.
  • Business details for clients: company name, legal name, address, tax ID, website, social links, contacts who should receive invoices, questionnaire answers and brand assets (logos, colours, fonts).
  • Project content: messages, files, feedback and anything else you share with us in the portal or by email.
  • Billing: invoices, amounts, due and paid dates. We don’t collect or store card numbers; payments are made by the methods on each invoice (such as bank transfer).

Information collected automatically

  • Security and anti-spam: when you send the contact form, a one-way hash of your IP address is kept for up to two hours to limit repeated messages. Our hosting provider keeps standard server logs (IP address, browser, time of request) for security.
  • Sign-in: when you log in, your browser stores a sign-in token so you stay signed in. This is strictly necessary for the portal to work.
  • Analytics, only with your consent: Google Analytics records pages visited, device and browser type, approximate region and how the site was reached. See Cookies.

Information from others

  • If you sign in with Google, Google shares your name, email and profile photo with us.
  • A colleague or client may add you as a contact on their account (for example to receive invoices), or refer you to us.

We don’t ask for sensitive information (such as health, religion or government ID numbers). Please don’t send it to us.

3. How we use it and why we’re allowed to

Under the GDPR every use needs a legal basis. Here is each use and the basis we rely on.

What we doLegal basis (GDPR)
Reply to your enquiry and follow up on a possible projectSteps you ask for before a contract; our legitimate interest in answering enquiries
Create and run your portal account; deliver projects, files, messages and supportPerformance of our contract with you or your company
Send invoices, record payments and keep business and tax recordsContract; legal obligation (tax and accounting law)
Send service emails: invitations, password resets, invoices, replies to your messagesContract; legitimate interest in running the service
Keep the site and portal secure, prevent spam and abuseLegitimate interest in protecting our systems and users
Understand how the site is used (analytics)Your consent, which you can withdraw at any time
Enforce our terms or respond to lawful requestsLegal obligation; legitimate interest in defending our rights

We don’t send marketing newsletters, and we don’t make decisions about you by automated means or build advertising profiles.

4. Who we share it with

We never sell your personal information or share it for cross-context behavioural advertising. We share it only with:

  • Service providers who process it for us, under contracts that limit how they can use it:
    • Google LLC — Firebase Hosting, Authentication, Cloud Firestore, Cloud SQL, Cloud Storage and Cloud Functions (hosting, sign-in, databases and files, United States);
    • Google LLC — Google Workspace (email) and, with your consent, Google Analytics.
  • People on your own account, such as colleagues your company invites to the portal.
  • Professional advisers (accountants, lawyers) where needed, under confidentiality.
  • Authorities when the law requires it, or to protect rights, safety and security.
  • A successor if the business is sold or transferred, who must keep this policy’s protections.

5. International transfers

We are based in the United States and our data is stored in the United States (Google Cloud, us-central1). If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred to the US.

Google LLC is certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, and its data processing terms include the European Commission’s Standard Contractual Clauses. We rely on these safeguards for transfers. You can ask us for more information about them.

6. How long we keep it

  • Enquiries and leads that don’t become projects: up to 3 years after our last contact, then deleted.
  • Client accounts and project content: for as long as we work together, and up to 2 years afterwards so you can still reach your files and history, unless you ask us to delete them sooner.
  • Invoices and billing records: 7 years, because tax law requires it.
  • Anti-spam IP hashes: up to 2 hours. Server logs: up to 30 days.
  • Analytics data: up to 14 months.

7. Your rights

Wherever you live, you can ask us to:

  • tell you what personal information we hold about you and give you a copy;
  • correct information that is wrong or incomplete;
  • delete your information (we may need to keep some records, such as invoices, where the law requires);
  • give you your information in a portable, machine-readable format;
  • stop or limit a use, or object to uses based on our legitimate interests;
  • withdraw your consent to analytics at any time, without affecting what happened before.

Email info@juzva.us from the address we know you by, or tell us how to reach you. We may ask you to confirm your identity before acting, and we’ll reply within one month (GDPR) or 45 days (US state laws). An authorised agent can make a request for you with your signed permission. We won’t treat you differently for using your rights.

If you are in the EEA or UK and are unhappy with our answer, you can complain to your local data protection authority (for example, in the UK the Information Commissioner’s Office). We’d appreciate the chance to fix it first.

8. California and other US states

This section applies to residents of California and of other US states with consumer privacy laws (such as Colorado, Connecticut, Oregon, Texas, Utah and Virginia), to the extent those laws apply to us.

  • Categories collected in the last 12 months: identifiers (name, email, phone, IP address); customer records (business details, billing records); commercial information (projects and invoices); internet activity (analytics, with consent); approximate location from IP; professional information; and the content of messages and files you send us. Sources and purposes are described above.
  • Sensitive personal information: we don’t collect it for inferring characteristics, and only use account passwords to let you sign in.
  • No sale or sharing: we have not sold or “shared” (for targeted advertising) personal information, including that of anyone under 16.
  • Global Privacy Control: if your browser sends a GPC signal, we treat it as a request to opt out and don’t load analytics.
  • Your rights to know, access, correct, delete and port your information, and to appeal a decision we make on your request, can be used as described in Your rights. To appeal, reply to our answer with “Appeal” in the subject.
  • California “Shine the Light”: we don’t disclose personal information to third parties for their direct marketing.
  • Do Not Track: there is no common standard for browser Do Not Track signals, so we rely on your cookie choice and GPC instead.

9. Cookies and similar storage

TypeWhat it doesNeeds consent
Sign-in (Firebase Authentication, browser storage)Keeps you signed in to the portalNo, strictly necessary
Preferences (browser storage)Remembers your cookie choice and small settings such as rows per pageNo, strictly necessary
Analytics (Google Analytics: _ga, _ga_*)Counts visits and pages anonymously; kept up to 14 monthsYes, only after you click Accept

We don’t use advertising or social media tracking cookies. You can change your choice at any time in , which is also linked at the bottom of every page.

10. How we protect it

Data is encrypted in transit (HTTPS) and at rest by Google Cloud. Access is limited by role: clients see only their own company’s data, and admin-only areas are restricted to admins. Database and file access rules are tested before each release, and passwords are never stored by us. No system is perfectly secure, but if a breach affects your information we will tell you and the authorities as the law requires.

11. Children

Our site and services are for businesses and adults. We don’t knowingly collect information from anyone under 16. If you believe a child has sent us personal information, email info@juzva.us and we’ll delete it.

12. Changes to this policy

We’ll update this page when our practices change and change the date at the top. If a change is significant, we’ll tell clients by email or in the portal before it takes effect.

13. Contact

Laurynas Juzva (Juzva), California, USA. Email info@juzva.us. Our Terms of Service explain the rules for using the site and working with us.