Skip to content
Thomas Nicoli

Privacy policy

This policy explains what personal data is collected on this website, why, and what rights you have. It is written to be read, not to hide behind legalese.

01Who is responsible for your data

The data controller is Thomas Nicoli, operating as Thomas Nicoli Consulting, based in Madrid, Spain. You can reach the studio through the contact form on this site or via LinkedIn for any privacy question.

02What data is collected

Only what you choose to send: when you use the contact form, the details you enter (name, email, business name, project details) are processed to reply to your enquiry. This site does not use analytics cookies, advertising trackers or behavioural profiling.

03Legal basis and retention

Enquiry data is processed on the basis of your explicit request (pre-contractual measures, GDPR art. 6.1.b). Enquiry emails are kept only as long as needed to handle your request and any resulting project, then deleted.

04Who receives your data

No one, beyond the email service provider used to deliver your enquiry (currently Resend, processed under their data-processing terms). Your details are never sold, rented or shared with third parties for marketing.

05Your rights

You may request access, rectification, deletion, portability or restriction of your personal data at any time, and lodge a complaint with the Spanish data protection authority (AEPD). Write via the contact form to exercise any of these.

06Project Clarity diagnostic data

Project Clarity collects answers to six questions about project type, the blockage, existing systems, the observable outcome, constraints and response language. It also requests a name and email so a reply is possible; website and location are optional. Turnstile and an idempotency reference help limit abuse and duplicates.

07Transit and storage

Cloudflare validates and temporarily stores the request in a bounded queue. Resend may carry an owner notification. Sanitised fields and the validated report are stored in a separate lead vault, never in the owner's personal vault.

08Local inference and human review

The Gemma-assisted first read will run asynchronously on the owner's computer, not in the visitor's browser. The model receives only sanitised fields and approved public knowledge. No commercial decision or email is sent autonomously: Thomas reviews the report and every draft before replying.

09Project Clarity retention and deletion

The planned operational retention period is 30 days from receipt. Expired Cloudflare queue records can be purged through the private worker; expired local notes first move to recoverable trash and permanent deletion requires human confirmation. You can request earlier deletion at bonjour@thomas-nicoli.com.

010Intelligent chat and email summaries

Cloudflare places the message and a bounded amount of recent context in a secure queue. An open-source Gemma model running locally through Ollama on Thomas's computer generates the reply; no paid AI provider receives the content. After every processed turn, an interaction summary is automatically emailed to Thomas through Resend. The chat does not request the visitor's email and warns against sharing sensitive data.

011Chat session and retention

Turnstile opens an anonymous two-hour session limited to twelve turns. The IP address is used only as a hash for security and usage limits. The message, reply, summary and minimal metadata are retained for 30 days and can be deleted earlier on request to bonjour@thomas-nicoli.com.

This page is a template provided for convenience and does not constitute legal advice. Confirm the final wording with your legal advisor before launch.