GDPR

Last updated: April 5, 2026

This page explains how Legrand.design complies with the General Data Protection Regulation (GDPR) and outlines your rights as a data subject. For a broader overview of data handling, see the Privacy Policy.

Data controller

The data controller for this site is Matt Legrand. Contact: .

Lawful basis for processing

Consent. When you subscribe to the newsletter or submit a message through the AI chat, you provide explicit consent for processing that data for its stated purpose.

Legitimate interest. Privacy-friendly analytics may be used to understand aggregate traffic patterns and improve the site. No personally identifiable information is tracked for this purpose.

Contract. When you book a meeting through the Meet page, processing your name, email, and selected time is necessary to fulfil the scheduling request.

Data collected

Newsletter subscriptions: email address, stored until you unsubscribe.

Meeting bookings: name, email, and selected time slot, used solely to create a calendar event.

AI Chat: message content is sent to third-party AI providers (OpenAI, Anthropic) for processing. Messages are not stored long-term or linked to an identity on this site.

Authentication: if you sign in via GitHub, your GitHub profile information is used for session management only.

Data retention

Newsletter emails are retained until you unsubscribe. Meeting data is retained only as long as needed to fulfil the booking. AI chat messages are not persisted. Authentication sessions expire automatically.

International transfers

Data may be processed by third-party services (Vercel, Neon, OpenAI, Anthropic) whose servers are located outside the European Economic Area. These providers maintain their own GDPR compliance measures and data processing agreements.

Your rights

Under the GDPR, you have the right to:

Access: request a copy of any personal data held about you.

Rectification: request correction of inaccurate data.

Erasure: request deletion of your personal data.

Restriction: request limitation of processing.

Portability: request your data in a structured, machine-readable format.

Objection: object to processing based on legitimate interest.

Withdraw consent: withdraw consent at any time (e.g., unsubscribe from the newsletter).

Exercising your rights

To exercise any of these rights, us. Requests will be responded to within 30 days. You also have the right to lodge a complaint with your local data protection authority.