Privacy policy
This policy explains what personal data is collected on this website, why, and what rights you have. It is written to be read, not to hide behind legalese.
01Who is responsible for your data
The data controller is Thomas Nicoli, operating as Thomas Nicoli Consulting, based in Madrid, Spain. You can reach the studio through the contact form on this site or via LinkedIn for any privacy question.
02What data is collected
Only what you choose to send: when you use the contact form, the details you enter (name, email, business name, project details) are processed to reply to your enquiry. This site does not use analytics cookies, advertising trackers or behavioural profiling.
03Legal basis and retention
Enquiry data is processed on the basis of your explicit request (pre-contractual measures, GDPR art. 6.1.b). Enquiry emails are kept only as long as needed to handle your request and any resulting project, then deleted.
04Who receives your data
No one, beyond the email service provider used to deliver your enquiry (currently Resend, processed under their data-processing terms). Your details are never sold, rented or shared with third parties for marketing.
05Your rights
You may request access, rectification, deletion, portability or restriction of your personal data at any time, and lodge a complaint with the Spanish data protection authority (AEPD). Write via the contact form to exercise any of these.
06Project Clarity diagnostic data
Project Clarity collects answers to six questions about project type, the blockage, existing systems, the observable outcome, constraints and response language. It also requests a name and email so a reply is possible; website and location are optional. Turnstile and an idempotency reference help limit abuse and duplicates.
07Transit and storage
Cloudflare validates and temporarily stores the request in a bounded queue. Resend may carry an owner notification. Sanitised fields and the validated report are stored in a separate lead vault, never in the owner's personal vault.
08Local inference and human review
The Gemma-assisted first read will run asynchronously on the owner's computer, not in the visitor's browser. The model receives only sanitised fields and approved public knowledge. No commercial decision or email is sent autonomously: Thomas reviews the report and every draft before replying.
09Project Clarity retention and deletion
The planned operational retention period is 30 days from receipt. Expired Cloudflare queue records can be purged through the private worker; expired local notes first move to recoverable trash and permanent deletion requires human confirmation. You can request earlier deletion at bonjour@thomas-nicoli.com.
010Intelligent chat and email summaries
Cloudflare places the message and a bounded amount of recent context in a secure queue. An open-source Gemma model running locally through Ollama on Thomas's computer generates the reply; no paid AI provider receives the content. After every processed turn, an interaction summary is automatically emailed to Thomas through Resend. The chat does not request the visitor's email and warns against sharing sensitive data.
011Chat session and retention
Turnstile opens an anonymous two-hour session limited to twelve turns. The IP address is used only as a hash for security and usage limits. The message, reply, summary and minimal metadata are retained for 30 days and can be deleted earlier on request to bonjour@thomas-nicoli.com.
This page is a template provided for convenience and does not constitute legal advice. Confirm the final wording with your legal advisor before launch.