0
Last updated: 25 July 2026
1. About this Privacy Policy
This Privacy Policy explains how The Facade Collective OÜ, trading as Fools for Façades® (“FFF”, “we”, “us” or “our”), collects, uses, discloses and protects personal data when you visit www.foolsforfacades.com, create an account, subscribe to The FFF Journal, purchase a digital or printed publication, join our mailing list, submit editorial material, register for an event, contact us or otherwise interact with our services.
This Policy is intended to provide the information required by applicable data-protection law, including the EU General Data Protection Regulation (“GDPR”), where applicable.
2. Data controller and contact details
The controller responsible for the processing described in this Policy is:
The Facade Collective OÜ
Trading name: Fools for Façades®
Registered office: Järvevana tee 9, Kesklinna linnaosa, Tallinn 11314, Harju maakond, Estonia
Company registration number: 17368951
Country of establishment: Estonia
Privacy contact: s.mighali@foolsforfacades.com
3. Personal data we collect
Depending on how you use the website, we may collect:
• Identity and contact data, such as your name, job title, company, country, postal address, email address and telephone number.
• Account data, such as login credentials, subscription status, account settings and purchase history.
• Order and subscription data, such as products ordered, billing and delivery details, tax information, transaction references, renewal and cancellation history.
• Payment-related data. Payments are handled by Stripe. We generally receive transaction status, payment method type, billing identifiers and limited card information such as the last four digits, but we do not normally receive or store complete card details.
• Newsletter and marketing data, such as subscription status, consent records, email opens, link clicks, campaign interactions and communication preferences, where supported by the chosen email platform and permitted by law.
• Technical and usage data, such as IP address, browser type, device information, operating system, referring pages, pages viewed, approximate location, timestamps, cookie identifiers and diagnostic data.
• Communication data, including emails, enquiries, partnership discussions, customer-support requests, survey responses and records of your interactions with us.
• Editorial and contributor data, such as biographies, professional information, photographs, article drafts, interview responses, rights-clearance information, credits and publication preferences.
• Event data, such as registration details, attendance, dietary or accessibility information you choose to provide, professional profile and event communications.
• Social-media data, when you interact with our pages, posts or embedded social features, subject to the privacy practices of the relevant platform.
Please do not provide sensitive personal data unless it is genuinely necessary and we have specifically requested it.
4. How we obtain personal data
We collect data directly from you, automatically through the website, from organisations purchasing or arranging access on your behalf, from contributors and business contacts, from publicly available professional sources, and from service providers that support payments, fulfilment, analytics, email communications and account management.
5. Purposes and legal bases
We process personal data for the following purposes:
• To provide the website, accounts, digital access, printed publications, subscriptions and customer support. Legal basis: performance of a contract or steps requested before entering a contract.
• To process payments, invoices, taxes, fraud checks, shipping, returns and accounting. Legal basis: contract, legal obligation and legitimate interests in operating a secure business.
• To send service communications, such as order confirmations, access instructions, delivery updates, renewal notices, policy changes and security messages. Legal basis: contract, legal obligation and legitimate interests.
• To send newsletters, editorial updates and promotional communications. Legal basis: consent where required. In limited business-to-business circumstances, we may rely on legitimate interests where permitted by applicable law, always offering a clear opt-out.
• To understand how the website and content perform, improve usability, measure campaigns and develop our editorial and commercial strategy. Legal basis: consent for non-essential analytics where required; otherwise legitimate interests for strictly necessary operational measurement.
• To manage editorial submissions, contributors, interviews, corrections, licensing and publication. Legal basis: contract, consent where relevant, and legitimate interests in operating an editorial publication.
• To manage sponsors, advertisers, partners, suppliers and professional contacts. Legal basis: contract and legitimate interests in conducting and developing our business.
• To protect the website, users and our rights; prevent misuse, fraud and security incidents; establish or defend legal claims. Legal basis: legitimate interests and legal obligation.
• To comply with legal, tax, accounting, regulatory and law-enforcement requirements. Legal basis: legal obligation.
Where we rely on legitimate interests, we consider the impact on your rights and use that basis only where our interests are not overridden by your interests or fundamental rights.
6. Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy. Strictly necessary technologies may operate without consent where permitted by law. Analytics, advertising, profiling and certain third-party media technologies are activated only after consent where consent is required.
You can change your preferences at any time through the cookie-preference control available on the website.
7. Marketing communications
You may unsubscribe from marketing emails at any time by using the unsubscribe link in the message or contacting s.mighali@foolsforfacades.com. Unsubscribing from marketing does not stop essential service communications relating to an active order, account or subscription.
We may retain a minimal suppression record to ensure that we respect your opt-out and do not re-add you accidentally.
8. Recipients and service providers
We may share personal data, only as necessary, with:
• Webflow and CartGenie for hosting, content management, accounts and commerce functions;
• Stripe for payment processing, fraud prevention and transaction management;
• the email delivery and marketing provider used by FFF for newsletters and transactional communications;
• Google Analytics and consented analytics or campaign-measurement providers;
• Printers, fulfilment partners, postal operators and carriers selected for the destination for printed orders;
• event venues, registration providers and production partners where you participate in an event;
• IT, security, cloud, design, accounting, tax, legal and other professional advisers;
• authorities, courts or regulators where disclosure is required or legally justified;
• a buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate safeguards.
These recipients may act as processors, independent controllers or joint controllers depending on the service and applicable law. Their own privacy notices may also apply.
9. International transfers
Some providers may process personal data outside the European Economic Area. Where the GDPR applies and a destination does not benefit from an adequacy decision, we use an appropriate transfer mechanism, such as European Commission Standard Contractual Clauses, together with supplementary measures where required.
You may contact s.mighali@foolsforfacades.com for further information about the safeguards relevant to your data.
10. Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose, including legal, accounting and dispute-resolution requirements. Indicative periods are:
• Account data: for the life of the account and for up to 24 months after closure, unless a longer period is required.
• Orders, invoices and transaction records: for the statutory tax and accounting period applicable in Estonia, generally at least seven years after the end of the relevant financial year for accounting records.
• Customer-service records: generally three years after the matter is closed.
• Newsletter data: until you unsubscribe or consent is withdrawn, with a minimal suppression record retained for as long as necessary to honour the opt-out and demonstrate compliance.
• Contributor and publication records: for the duration of the publication archive and as needed to evidence permissions, authorship, licences and corrections.
• Cookie and analytics data: for the durations stated in the Cookie Policy and provider settings.
• Legal claims and security logs: for the relevant limitation period or as necessary to investigate and defend claims.
We may anonymise data so that it can no longer identify you and retain the anonymised information for statistical or archival purposes.
11. Security
We use appropriate technical and organisational measures designed to protect personal data, including access controls, encryption where appropriate, backups, vendor due diligence and procedures for managing incidents. No internet service can guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of suspected unauthorised access.
12. Your rights
Subject to applicable law, you may have the right to:
• obtain access to your personal data;
• correct inaccurate or incomplete data;
• request deletion;
• restrict processing;
• object to processing based on legitimate interests or to direct marketing;
• receive certain data in a portable format;
• withdraw consent at any time, without affecting processing carried out before withdrawal;
• lodge a complaint with a competent supervisory authority;
• receive information about safeguards used for international transfers.
We do not currently use solely automated decision-making that produces legal or similarly significant effects on users.
To exercise your rights, contact s.mighali@foolsforfacades.com. We may need to verify your identity. We will respond within the period required by law.
13. Supervisory authority
You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, or with the data-protection authority in the EU/EEA country where you live, work or believe an infringement occurred. We encourage you to contact us first so that we can try to resolve the issue, but doing so is not a condition of filing a complaint.
14. Children
The website and paid services are not directed to children. We do not knowingly collect personal data from children under 16 through the website. If you believe a child has provided personal data without appropriate authorisation, contact s.mighali@foolsforfacades.com.
15. Third-party websites and embedded services
The website may link to or embed services operated by third parties, including social networks, video platforms and payment services. Those parties process data under their own terms and privacy policies. We are not responsible for their independent practices.
16. Changes to this Policy
We may update this Policy to reflect changes in our services, vendors or legal obligations. We will post the revised version with a new “Last updated” date and, where appropriate, provide additional notice.
17. Contact
For privacy questions or rights requests, contact:
s.mighali@foolsforfacades.com
The Facade Collective OÜ
Järvevana tee 9, Kesklinna linnaosa, Tallinn 11314, Harju maakond, Estonia