Privacy & Compliance
Last updated: 2026. This page explains, in plain terms, how Mehvar ("we") handles personal data across the markets we serve.
What we collect
Only what you give us: names and work emails from contact forms, brief submissions and booking calls, plus standard server logs (IP, user-agent) for security and analytics.
Legal bases (EU / UK — GDPR & UK GDPR)
- Contract: processing needed to deliver the work you asked for.
- Consent: non-essential cookies and marketing contact — granted via the consent banner.
- Legitimate interest: securing the site and preventing abuse.
US — CCPA / CPRA & state laws
We honor "Do Not Sell or Share My Personal Information" and the opt-out rights under California, Virginia, Colorado, Connecticut, Texas and Utah privacy laws. We do not sell personal data. To exercise rights, email hello@mehvar.store.
Russia — Federal Law 152-FZ
For Russian users' personal data we follow 152-FZ, including the data-localization requirement to record and store Russian citizens' personal data in databases located in Russia where applicable. Contact us for the specific DPA terms.
Your rights
Access, rectification, erasure, restriction, portability and objection — exercised by emailing hello@mehvar.store. We respond within statutory timeframes (generally 30 days under GDPR).
Sub-processors
We use a small set of processors (form handling, booking, hosting). A current list is available on request. Each is bound by a Data Processing Agreement.
Data Processing Agreement (DPA)
A standard DPA is available for every engagement that processes personal data on your behalf. Request it when you start a project.