Privacy policy

This policy explains what personal data studiolocal.ai collects when you use this website, why, on what legal basis, and what you can do about it.

Last updated: 11 August 2026

Who is responsible

The controller for the processing described here is:

Bilal Ashour Hauschildstraße 2 04177 Leipzig Germany Email: [email protected]

We have not appointed a data protection officer; we are not required to under Art. 37 GDPR or § 38 BDSG. Write to the address above with any data protection question.

Visiting this website

Every request to this site is logged with your IP address, the approximate location derived from it (country, region, city and timezone), your browser and device type, and the page you came from. This is used to keep the site secure, to understand which pages and campaigns bring visitors, and to detect abuse.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure and functioning website and in understanding how it is used.

IP addresses recorded against a contact are kept for 365 days from their last use and then deleted automatically. You can object to this processing at any time using the contact details above.

Creating an account and buying

When you register or buy, we process the name and email address you give us, your order and invoice details, and the licence issued to you. We need this to create your account, to deliver what you bought, to send your invoice, and to meet our record-keeping obligations.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (legal retention obligations — invoices and accounting records are kept for the statutory period, generally ten years under German law).

Payments are processed by Stripe. Your card details are entered directly with Stripe and never reach our servers.

Email we send you

Transactional email — order confirmations, invoices, licence keys, password resets — is sent because you asked for something that requires it. Legal basis: Art. 6(1)(b) GDPR.

The newsletter is sent only after you confirm your address by clicking a link we email you (double opt-in). Legal basis: Art. 6(1)(a) GDPR — your consent, which you can withdraw at any time using the unsubscribe link in any newsletter or by writing to us. Withdrawing consent does not affect mail sent before it.

We record whether an email was delivered, opened, or a link in it was clicked, so we can tell whether our mail is arriving and remove addresses that bounce.

Who processes data on our behalf

We use the following processors, each under a data processing agreement (Art. 28 GDPR):

Fly.io — application hosting and database, in the Frankfurt region (Germany). Cloudflare — DNS, TLS and protection against attacks; requests to this site pass through their network. Mailgun — sending and delivery tracking of email, on their EU infrastructure. Stripe — payment processing.

Cloudflare and Stripe are US companies that may process data outside the EU. Those transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Cookies

We set the cookies this site needs in order to work — keeping you signed in, remembering your language, and holding your cookie choices. These do not require consent.

Anything beyond that is set only if you agree to it in the cookie banner, and you can change or withdraw your choice at any time.

Software updates

This installation checks for new versions of the software it runs. That check requests a static file and sends nothing that identifies this site, its visitors, or its data — no address, no counts, no identifier.

How long we keep things

Account and order data is kept for as long as you have an account with us, and afterwards for as long as tax and commercial law requires us to keep it.

Newsletter subscriptions are kept until you unsubscribe. We keep a record of the unsubscribe itself so we do not mail you again by mistake.

IP addresses recorded against a contact are deleted 365 days after they were last seen.

Your rights

Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16), to have it deleted (Art. 17), to restrict how we use it (Art. 18), to receive it in a portable form (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you may withdraw that consent at any time.

To exercise any of these, write to [email protected].

You also have the right to complain to a supervisory authority. For us that is the Saxon Data Protection and Transparency Officer (Sächsischer Datenschutz- und Transparenzbeauftragter), but you may complain to the authority where you live or work instead.