1. Overview
N2K Labs (“we”, “us”, or “our”) is a digital studio operated by an individual freelancer based in the South Pacific, Fiji. We are currently operating as an unregistered sole proprietor and are in the process of formalising our business registration. We operate the website at https://n2klabs-4vh9w5pq5-n2-k1.vercel.app (the “Site”).
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over it. By using the Site, you agree to the practices described here.
We are committed to protecting your privacy and complying with all applicable data protection and privacy laws, including:
- Fiji Constitution 2013, Clause 24 — the right to personal privacy, including confidentiality of personal information.
- Fiji Online Safety Act 2018 (Act No. 8 of 2018) — promotes responsible online behaviour and a safe online environment, administered by the Online Safety Commission Fiji (OSC).
- EU General Data Protection Regulation (GDPR) — for visitors in the European Economic Area.
- California Consumer Privacy Act (CCPA) — for residents of California, USA.
Note: Fiji does not currently have a standalone comprehensive data protection statute. A Data Protection Bill is under development. In the interim, privacy protections derive from the constitutional right to privacy and the Online Safety Act 2018. We have voluntarily adopted GDPR-aligned practices to ensure strong protection regardless of the visitor’s location.
2. Data We Collect
2.1 Data you provide directly
When you submit our contact form, we collect:
- Your name
- Your email address
- The service you’re interested in (optional)
- Your approximate budget (optional)
- Your project message or inquiry
This data is stored in our database so we can respond to your inquiry and reference it if we begin a working relationship.
2.2 Data collected automatically
When you visit the Site, we automatically collect limited technical data through Vercel Analytics:
- Page views and visit timestamps
- Approximate geographic region (country-level, derived from IP)
- Referrer (the page you came from)
- Browser and device type
Vercel Analytics is privacy-friendly and does not use cookies or collect personally identifying information. IP addresses are not stored — only country-level geography is derived and the raw IP is discarded.
2.3 Admin authentication data
When an N2K Labs administrator logs in to the dashboard, a session cookie (n2k_session) is set. This cookie contains a cryptographic hash of the admin password — it does not contain the password itself and cannot be used to recover it. The cookie expires after 7 days.
3. How We Use Your Data
We use the data we collect for the following purposes:
- Responding to inquiries — to reply to your contact form submission and discuss potential projects.
- Providing services — if we begin a working relationship, your contact details are used for project communication and delivery.
- Improving the Site — aggregated, anonymized analytics help us understand which content is useful and how the Site performs.
- Legal compliance — retaining records as required by law or for legitimate business purposes.
We do not use your data for targeted advertising, profiling, or sale to third parties.
Legal basis (GDPR)
For visitors in the European Economic Area, our lawful bases for processing are:
- Consent (Article 6(1)(a)) — you voluntarily submit your contact details.
- Legitimate interests (Article 6(1)(f)) — responding to inquiries and operating the Site.
- Legal obligation (Article 6(1)(c)) — retaining records where required by law.
4. Third-Party Processors
We do not sell your data. We do share it with the following third-party service providers who help us operate the Site:
Database hosting. Stores contact form submissions and project data. Servers in AWS Tokyo (ap-northeast-1).
Website hosting and analytics. Processes HTTP requests and collects anonymized page-view data. Global edge network.
Email delivery. Used to send contact form submissions to our team inbox. Your email address is included in the message so we can reply.
Each processor is bound by data protection agreements and only handles your data to provide services on our behalf.
6. Data Retention
We retain contact form submissions for as long as necessary to fulfill the purpose for which they were collected:
- Inquiries that do not lead to a project: retained for 24 months, then deleted.
- Inquiries that lead to a project: retained for the duration of the working relationship and 7 years thereafter for record-keeping purposes.
- Analytics data: aggregated and anonymized; retained indefinitely.
You may request early deletion of your data at any time (see Your Rights below).
7. Your Rights
Depending on your jurisdiction, you may have the following rights over your personal data:
- Right of access — request a copy of the data we hold about you.
- Right to rectification — request correction of inaccurate data.
- Right to erasure — request deletion of your data (“right to be forgotten”).
- Right to data portability — receive your data in a machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — withdraw consent at any time (does not affect prior processing).
To exercise any of these rights, email us at n2k1works@gmail.com. We will respond within 30 days.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
8. International Data Transfers
Your data may be processed in countries other than your country of residence:
- Database (Turso): AWS Tokyo region (ap-northeast-1).
- Hosting (Vercel): global edge network; requests served from the nearest data center.
- Email (Resend): United States.
Where data is transferred outside your jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or the recipient’s participation in an approved certification framework.
9. Security
We take reasonable technical and organizational measures to protect your data:
- HTTPS encryption for all data in transit (enforced via HSTS).
- Content Security Policy (CSP) to prevent injection attacks.
- Rate limiting and input validation on all API endpoints.
- Admin authentication via cryptographically hashed session tokens.
- Encrypted at rest by our infrastructure providers (Turso, Vercel).
No method of transmission or storage is 100% secure. If a data breach occurs that poses a risk to your rights, we will notify you and the relevant authorities as required by law.
10. Children’s Privacy
The Site is not directed to children under 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time, particularly when Fiji’s Data Protection Bill is enacted into law. The “Last updated” date at the top of this page indicates when the policy was last revised. Material changes will be highlighted on the Site or communicated to you directly if we have your contact details.
Continued use of the Site after changes take effect constitutes acceptance of the updated policy.
12. Fiji Legal Framework
As an operator based in Fiji, N2K Labs operates within the following national legal framework relevant to privacy and data handling:
Recognises the right to personal privacy, including the right to confidentiality of personal information. This is the primary constitutional basis for privacy protection in Fiji.
Promotes responsible online behaviour and a safe online environment. Administered by the Online Safety Commission Fiji (OSC). The Act is currently under review, and we monitor amendments that affect data handling.
Provides consumer protection provisions that apply to our services when supplied to Fijian consumers. Administered by the Fijian Competition and Consumer Commission (FCCC).
Gives legal recognition to electronic contracts, electronic signatures, and digital records. This Act validates contracts formed through our Site (including the contact form and Terms of Service acceptance).
Fiji’s comprehensive Data Protection Bill is currently under development. When enacted, it will introduce formal data controller/processor obligations, breach notification requirements, and enhanced data subject rights. We are monitoring its progress and will update this Policy to achieve full compliance when it takes effect.
For cross-border visitors, we additionally comply with the EU GDPR and the California CCPA as described in this Policy. Where multiple laws apply, we apply the highest standard of protection.
13. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Questions about this document?
We’re happy to clarify anything in this policy. Reach out and we’ll get back to you within 1-2 business days.
n2k1works@gmail.com