The short version
We collect the personal data you give us, plus standard server logs when you visit. We use it to respond to your inquiry, deliver the services you subscribed to, and run the business. We do not sell it. We do not let AI providers train their models on it. You can ask us what we have, correct it, or delete it. EU data residency by default.
What we collect
When you contact us: name, company, email, message — only what you put in the form.
When you become a client: billing details, the operational data you share with us for the engagement, and access logs for our client portal.
When you visit the site: IP address, page visited, browser, timestamp — standard server logs used for security and aggregate analytics. No tracking pixels, no third-party advertising cookies.
What we do with it
- Reply to your inquiry.
- Deliver the services you signed up for.
- Send transactional emails (billing, security notices, service updates).
- Send marketing emails — only if you explicitly opted in, with an unsubscribe link in every message.
- Meet legal obligations (tax, accounting, regulatory).
Three things we do not do: sell your data, share it with advertisers, or let our LLM providers train models on it.
Where your data lives
By default, in the European Union. We host primarily on Vercel's EU regions and route LLM calls to EU endpoints where available. If your engagement requires stricter residency, we set that up explicitly in your Data Processing Agreement.
How long we keep it
- Contact form messages: up to 24 months, or until you ask us to delete them.
- Client engagement data: through the engagement plus 90 days, then deleted (subject to legal retention rules for billing).
- Billing records: as long as tax law requires, typically 7-10 years.
- Server logs: about 30 days.
Who else sees it
Only the categories of recipients we need to deliver the service: our infrastructure providers (Vercel, Cloudflare), our LLM providers (Anthropic, OpenAI, Google — under no-training agreements), our email and scheduling tools (Resend, Cal.com), our payment processor, and our professional advisors (lawyers, accountants) when their work requires limited access.
The full list of subprocessors and their roles is in our Privacy Policy.
Your rights
If you are in the EU, UK, or another GDPR-equivalent jurisdiction, you can:
- ask what data we hold about you;
- correct it if it is wrong;
- delete it (unless we are legally required to keep it);
- get a copy in a portable format;
- object to processing based on our legitimate interest;
- withdraw consent for marketing communications at any time;
- complain to your data protection authority.
To exercise any of these, email dpo@logitelia.com. We respond within 30 days, usually sooner.
Cookies, briefly
We use one functional storage entry to remember your preferred language. We use Cloudflare Turnstile cookies to validate the contact form is filled by a human. We do not run cross-site advertising trackers. If we add analytics, it will be privacy-first tooling that does not require a cookie banner.
If we change this notice
We update this page when our practices change. For material changes that affect clients, we notify by email at least 30 days in advance. The current version is always at this URL.
Want the full version?
See our Privacy Policy for the complete, legally-precise version with all the detail GDPR requires us to publish.
Contact
For anything privacy-related: dpo@logitelia.com. For everything else: info@logitelia.com.
Questions about how this applies to your engagement with Logitelia?
Contact us