Privacy

Privacy and cookie policy

Last updated: 4 October 2026

This is an English translation of our Italian privacy policy. If the two versions differ, the Italian version prevails.

This notice explains how we handle the personal data of people who visit gelustudio.com, email us, book a call or contact us by phone, text message or WhatsApp. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the 'GDPR') and Italian Legislative Decree 196/2003 (the 'Italian Privacy Code'). It also contains the site's cookie policy (section 6).

In short

  • The site uses no profiling, advertising or analytics cookies and doesn't track visitors. That's why there's no cookie banner.
  • Visitor statistics are aggregated and cookie-free (Cloudflare Web Analytics): we can see how many visits a page gets, not who is visiting it.
  • We use the information you give us (your email, your booking, your phone number) only to get back to you and, if you become a client, to carry out the work we've agreed and meet our legal obligations.
  • We don't sell your data, we don't do any marketing or profiling, and we don't record calls.

1. Data controller

Gelu Studio di Gentian Lushaj
Via Madonna del Bosco 67, 17014 Cairo Montenotte (SV), Italy
VAT no. IT01948050099
Email: [email protected]

If you have any questions about this notice or about your data, please email us at the address above. We have not appointed a data protection officer (DPO), as our activities do not require one (Art. 37 GDPR).

2. What data we process

a) Browsing data

The site is hosted and protected by Cloudflare. When you open a page, Cloudflare's servers automatically receive the technical data that your browser sends to every website: your IP address, browser and device type, operating system, the page requested, the page you came from, the date and time of the request and whether it succeeded. This data is used to display the site, to protect it from attacks and automated traffic, and to fix technical problems. We do not use it to identify you.

b) Visitor statistics

To find out how many people visit the site and which pages they read, we use Cloudflare Web Analytics. A small Cloudflare script (loaded from static.cloudflareinsights.com) records the page visited, the page you came from, your browser and device type, your country and how long pages take to load. It sets no cookies, stores nothing on your device, does not fingerprint your browser and does not follow you to other sites. We only ever see aggregated figures, which cannot be used to identify you.

c) Email

If you write to [email protected], we process your email address and whatever you choose to tell us. Our email runs on Google Workspace.

d) Booking a consultation

The 'Book a free call' buttons open a page on Cal.com, an external booking service. There we ask for your name, the name of your business and what it does, your city and country, your phone or WhatsApp number (with country code), your work email and any notes you would like to add (optional). When you book, we also record the date and time of the appointment. Cal.com sends you a confirmation and reminders by email and adds the appointment to our Google Calendar, together with the link to the video call.

e) Phone and WhatsApp

If you give us your number, we may contact you on WhatsApp or by text message (SMS), or call you, to arrange the appointment and to follow up after the call. WhatsApp is provided by WhatsApp Ireland Limited, which processes message data under its own privacy policy. If you would rather we contacted you only by phone or by email, just let us know.

f) Video calls

Our video calls take place on Google Meet (Google Workspace). We do not record or transcribe calls. If we ever wanted to, we would ask you first: we would only do so with your consent, and you are free to say no without any consequences.

g) If you become a client

We process the data needed for the contract and the work we have agreed (for example, the names and contact details of the people we work with) and the data required for invoicing (company name, address, VAT number or tax identification number).

Where the agreed work requires us to access data for which your business is the controller (for example, the emails, documents or calendar on which we set up AI), we do so as a processor on your behalf, under a separate written agreement (Art. 28 GDPR). That data is not covered by this notice.

Please do not send us, in your messages or in the booking notes, special categories of data (for example, health information) or information about other people that isn't needed for your request.

3. Why we process data and on what legal basis

PurposeLegal basis
Displaying the site, keeping it secure and fixing technical problemsLegitimate interest in the site working properly and securely (Art. 6(1)(f) GDPR)
Aggregated visitor statisticsLegitimate interest in understanding how the site is used and improving it (Art. 6(1)(f) GDPR)
Replying to your emails and enquiriesSteps taken at your request before entering into a contract (Art. 6(1)(b) GDPR)
Managing your booking, the call and any follow-up, including by phone, text message or WhatsAppSteps taken at your request before entering into a contract (Art. 6(1)(b) GDPR)
Recording or transcribing a call, only if we ask and you agreeConsent, which you can withdraw at any time (Art. 6(1)(a) GDPR)
Carrying out the work agreed with our clientsPerformance of a contract (Art. 6(1)(b) GDPR)
Invoicing, and tax and accounting obligationsLegal obligation (Art. 6(1)(c) GDPR)
Defending our rights in the event of a disputeLegitimate interest (Art. 6(1)(f) GDPR)

We do not use your data for marketing, newsletters or profiling, and we do not make decisions based solely on automated processing (Art. 22 GDPR).

4. Do you have to give us your data?

Browsing data is needed to show you the site. Whether you email us or book a call is up to you: we need the required fields on the booking form (name, business and what it does, city and country, phone number, email) to arrange and prepare for the call, and we cannot book it without them. Notes are optional.

5. Who we share data with

Your data is processed by us and by the providers of the technical services we use, who act as our processors (Art. 28 GDPR) under their data processing agreements:

ProviderServiceBased in
Cloudflare, Inc.Website hosting, content delivery network, security, cookie-free visitor statisticsUnited States, with servers worldwide
Google Ireland LimitedEmail, calendar and video calls (Google Workspace: Gmail, Google Calendar, Google Meet)Ireland (EU)
Cal.com, Inc.Booking page and booking managementUnited States

If we use WhatsApp, WhatsApp Ireland Limited (Ireland) processes the data as an independent controller, under its own privacy policy. If you become a client, your invoicing details are passed to our tax adviser so that we can meet our legal obligations. Data may be disclosed to public authorities only where the law requires it.

We do not sell your data or make it public.

Cookies are small files that a website stores in your browser. This site sets no cookies of its own and uses no cookies or other tools for profiling, advertising or analytics. It stores nothing on your device (neither cookies nor your browser's local storage). Fonts, icons and animations are hosted on our own site: there are no requests to Google Fonts, social networks or any other external service, apart from the cookie-free statistics described in section 2(b).

The only possible exception has to do with security. If Cloudflare's protection systems need to check that a visit isn't coming from an automated program, they may set a technical cookie of Cloudflare's own:

CookieWhat it doesDuration
__cf_bmTells real visitors apart from automated traffic30 minutes
cf_clearanceRemembers that you have passed a security check, so you aren't asked to do it againUsually 30 minutes

These are technical cookies, strictly necessary to keep the site secure, so the law does not require your consent for them (Article 122 of the Italian Privacy Code and the Garante's Guidelines on cookies of 10 June 2021, in Italian). That's why the site doesn't show a cookie banner.

The booking page is on cal.com, an external site with its own cookies and its own privacy policy.

You can view, block or delete cookies at any time in your browser settings. If you block Cloudflare's technical cookies, you may have to repeat the security check.

7. Transfers of data outside the European Union

Cloudflare and Cal.com are based in the United States, and Google may also process data on servers outside the European Union. In these cases, the transfer relies on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), for certified providers, or on the standard contractual clauses approved by the Commission (Art. 46 GDPR). You can ask us for more information about the safeguards in place.

8. How long we keep data

DataHow long we keep it
Emails, bookings, messages and call notes that don't lead to an engagementAs long as needed to deal with your request, and in any case no more than 24 months after our last contact
Client data for the agreed workFor the duration of the relationship and up to 24 months after it ends
Invoices and accounting records10 years, as required by law (Article 2220 of the Italian Civil Code)
Recordings or transcripts, only if you have given your consentAs long as needed for the purpose you authorised them for, and in any case no more than 6 months or until you withdraw your consent, whichever comes first
Browsing dataFor short periods, in line with Cloudflare's technical policies, unless needed to investigate abuse or criminal offences
Visitor statisticsOnly in aggregated form, with nothing that can be linked to you

At the end of these periods, the data is deleted or anonymised.

9. Your rights

At any time, you can ask us:

  • for access to your data and a copy of it (Art. 15 GDPR);
  • to rectify inaccurate or incomplete data (Art. 16);
  • to erase your data (Art. 17);
  • to restrict processing (Art. 18);
  • for portability of the data you have given us (Art. 20).

You also have the right:

  • to object to processing based on legitimate interest, on grounds relating to your particular situation (Art. 21);
  • to withdraw your consent, where processing is based on consent, without affecting anything done before you withdrew it (Art. 7).

To exercise these rights, email [email protected]. It costs nothing, and we will reply within one month (Art. 12 GDPR).

If you believe that the way we process your data breaks the law, you can lodge a complaint with the Garante per la protezione dei dati personali, the Italian data protection authority. You can also complain to the supervisory authority in the EU country where you live or work (Art. 77 GDPR), or go to court. If you live in the UK, you can also complain to the Information Commissioner's Office.

10. Security

We take appropriate technical and organisational measures to protect data against unauthorised access, loss or disclosure: an encrypted connection (HTTPS) across the whole site, security headers that prevent the site from loading content from unauthorised sources, and restricted access to the tools that hold the data.

11. Changes to this notice

We may update this notice, for example if the services the site uses or the law change. The version in force is always the one published on this page, with the date of the latest update shown at the top. If a change affects processing based on your consent, we will ask for your consent again.