Privacy notice
Updated 4 October 2026. Controller: Lorenzo Colombani, trading as Lorenzo’s AI Studio, Hildesheimer Str. 248, 30519 Hannover, Germany. Contact lorenzo.colombani@live.fr or +49 178 6376825 for privacy questions and rights requests.
1. What the storefront does
The shop displays services, supports catalogue search and local cart/saved selections, prepares email enquiries and directs purchasers to Stripe-hosted payment pages. It does not itself send your enquiry email or collect your full card number. It does not call an AI-model API to answer your searches or read your draft.
2. Data, purposes and legal bases
- Browsing and security: IP address, requested URLs, timestamps, browser/device information and technical/security logs are processed to deliver and protect the site. The basis is the legitimate interest in a reliable, secure service (GDPR Article 6(1)(f)).
- Requested cart, shortlist and draft functions: selections, quantities, preferred dates and text you choose to enter are stored in sessionStorage in your browser. They are not uploaded to the studio merely by typing or saving them. Storage supports the function you request. Closing a tab usually ends its session, but browser restoration can retain it. You can remove items, clear fields or clear this site’s browser data.
- Enquiries and service delivery: when you send an email, its sender details, message and any attachments reach my mailbox. Order details, contact information, scheduling preferences and relevant correspondence are used for requested pre-contract steps and performance of the contract (Article 6(1)(b)). Do not send unnecessary sensitive information or passwords.
- Payments and accounting: Stripe collects payment, identity and billing details on its own page. I can access necessary transaction, contact and billing records in Stripe and retain records needed for performance and legal accounting/tax duties (Articles 6(1)(b) and (c)). The site’s live-payment log retains provider reference IDs, offer, amount, payment state and scheduling preference; it does not store full card numbers or security codes.
- Withdrawal requests: the online function processes your name, purchase email, order identification, declaration, selected receipt channel, reference and timestamp to receive and evidence a withdrawal and fulfil related legal duties (Articles 6(1)(b) and (c)). Review uses a short-lived token and declaration fingerprint. Confirmation is stored before the receipt is returned. The function does not itself decide refund entitlement or automatically issue a refund.
3. Browser history, cookies and analytics
The studio uses no advertising pixels or optional audience-analytics service. This site does not persist search history or automatically collected recently viewed history. Cart, deliberately saved offers and enquiry drafts use the requested browser-session functions described above. Cloudflare may use security cookies if a challenge or security feature is needed. These are distinct from optional advertising tracking.
4. Cloudflare and retained portfolio pages
Cloudflare provides hosting, proxying, security and the D1 database. It necessarily receives network/request information when you visit. Covered customer personal data is processed under its applicable data-processing terms; its own service/security processing may have a different role. The live database is configured for EU jurisdiction, but Cloudflare operates a global network and that database setting does not restrict all traffic processing to the EU.
Cloudflare may obfuscate email addresses and deliver a small decoding script to deter scraping. That feature does not send your enquiry. Some retained portfolio/project paths use GitHub Pages as an origin behind Cloudflare. Those pages and demos may load external libraries/fonts or, when activated, third-party media and demonstrations. Their providers can receive connection data; the shop’s no-advertising statement is not a claim that every externally hosted demo has identical functionality.
Provider information: Cloudflare privacy, Cloudflare data-processing terms, GitHub privacy.
5. Stripe and payment-method providers
Stripe provides the separate hosted checkout. Depending on the function, it acts as a processor for merchant services and as an independent controller for purposes such as payment processing obligations, fraud prevention and regulatory compliance. Its banks, card networks and payment-method partners may also process transaction information under their own obligations. The storefront’s privacy notice does not replace theirs.
Stripe may process data internationally using applicable contractual and transfer safeguards. Read Stripe’s privacy policy and data-processing terms. Methods shown depend on eligibility; each payment provider applies its own terms and privacy notice. The studio never receives your payment-account password.
6. Email, AI applications and other external services
An enquiry’s Open email app action uses your chosen mail application and provider. A sent message reaches my published Microsoft-hosted mailbox (live.fr); both providers process mail under their respective terms. See Microsoft privacy. Social/profile links take you to the selected service. External services have their own account, cookie and privacy settings.
During training we may separately use ChatGPT, Claude, Grok or another agreed application. Use only an account you are authorised to use. Its provider’s terms, employer/account settings, retention and any model-improvement choices govern data you supply there; these vary by product and plan. No promise is made that every third-party tool never retains data or never uses it for model improvement. We agree before introducing another service or uploading your material from an account I control. Bring redacted examples wherever possible.
Relevant policies: OpenAI, Anthropic, xAI/Grok. We each remain responsible for our own legal obligations. If I process business-client personal data on documented instructions, any required processing agreement is arranged separately; these general terms do not substitute for it.
If you authorise a compatible browser assistant, it may read the public catalogue and perform supported local shortlist/cart actions. Those actions do not authorise a payment or send an enquiry. Your assistant provider may process what you allow it to access under its own terms.
7. Recipients, transfers and retention
Access is limited to what is needed by the service providers above, professional accounting/legal advisers where engaged, and authorities or payment partners where disclosure is required. I do not sell enquiry or customer data. Transfers outside the EEA must rely on an applicable legal mechanism, such as an adequacy decision or appropriate contractual safeguards. You can request information about safeguards relevant to your transaction.
Unsuccessful enquiries are ordinarily reviewed for deletion within 12 months of the last substantive contact unless you request continuing discussions. Contract and dispute evidence is kept for the applicable limitation/defence period, commonly three years after the relevant year ends, with longer retention where a legal duty or active claim requires it. Invoice/accounting records are retained for the statutory period, generally eight years for invoices. Browser storage follows your browser session and settings. These are retention rules for review and deletion, not a claim that every provider automatically deletes on the same date.
8. Your rights and choices
Subject to the legal conditions, you may request access, correction, deletion, restriction and portability, and object to processing based on legitimate interests. Where consent is used, you may withdraw it for the future without affecting prior lawful processing. You may complain to a competent data-protection authority, including the Lower Saxony authority, or the authority in your country where competent.
Required checkout/contract fields are needed to process the purchase and meet related duties; if you do not provide them, I may be unable to complete that transaction. Optional enquiry context and preferred dates may be omitted. The studio does not make decisions with legal or similarly significant effects solely through automated profiling; Stripe or another provider may perform its own automated fraud/security assessment under its notice.
9. Changes
This notice describes the services identified above. Material changes to processing will be reflected here; any legally required additional information or consent will be provided before the new use.
