Skip to main content

Maiora AI Lab

Privacy Policy

Information notice under Article 13 of EU Regulation 2016/679 (GDPR)

1. Data controller

Maiora AI Lab
Email: info@maioraailab.it

Website: www.maioraailab.it

2. Data collected

Through the booking form we collect the following personal data:

  • First and last name
  • Email address
  • Phone number (optional)
  • Goal and industry of interest (non-personal data)

Through the community testimonials form we may also collect:

  • Name
  • Role or professional industry
  • Email address
  • Instagram handle (optional)
  • Testimonial content

Browsing data (collected automatically)

During your visit, the following technical data is collected automatically, in anonymized form:

  • IP address (anonymized by Vercel Analytics)
  • User agent, browser language, referrer
  • Anonymous navigation events (pageviews, button clicks)
  • Optional analytics events (pageviews, internal search, CTA interactions and conversions) collected by Google Analytics 4 only after explicit consent
  • Core Web Vitals (anonymous performance metrics)

3. Cookies & local storage

Vercel Analytics and Speed Insights run in cookieless mode: they do not install cookies on your device.

The site may load the Google Analytics 4 tag in consent mode, with analytics storage denied by default. Only after your explicit consent do we activate full measurement with first-party analytics cookies and event data tied to your navigation.

Until you accept, the tag stays configured with consent denied and does not install analytics cookies. Your choice is stored in your browser's localStorage to remember the preference between visits.

You can update or revoke your consent at any time using the Analytics Preferences button in the footer. On revocation we stop optional tracking and attempt to remove the main analytics cookies from the browser.

For the gallery "Like" feature, we store an anonymous identifier (UUID) in your browser's localStorage only after you click a "Like" button for the first time. This lets us count one vote per visitor and remember your likes between sessions. Clicking constitutes consent to this storage.

You can delete this identifier at any time by clearing site data in your browser settings.

4. Third-party tools

  • Vercel Analytics and Speed Insights (Vercel Inc., USA): collect anonymous usage and performance metrics. Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR).
  • Google Analytics 4 (Google LLC, USA): activated only after explicit consent, measures pageviews, internal search, CTA clicks and conversion events. Legal basis: consent of the data subject (Art. 6(1)(a) GDPR).
  • Convex (cloud infrastructure): stores booking form submissions, community reviews and gallery like counts. Region: eu-west-1 (Ireland).
  • Resend (if used for email): transactional email service for replies to contact requests.
  • Sanity CMS: content management system for the site. Does not collect personal data from visitors.

5. Purposes of processing

Data is processed exclusively to respond to the consulting request sent through the form and to contact you to schedule an appointment or provide information about our services.

For community testimonials, data is processed to verify the authenticity of the contribution, moderate it and, if approved, publish it on the site as a community editorial testimonial.

Data is not used for marketing, profiling or shared with third parties.

6. Legal basis

Processing of booking form data is based on the data subject's express consent (Art. 6(1)(a) GDPR), expressed by ticking the acceptance checkbox in the form.

Processing of data sent through the review form is also based on the data subject's express consent (Art. 6(1)(a) GDPR).

Processing of data collected via Google Analytics 4 is based on the data subject's express consent (Art. 6(1)(a) GDPR) and can be revoked at any time using the Analytics Preferences button in the site footer.

For browsing data collected automatically the legal basis is the controller's legitimate interest in improving the service (Art. 6(1)(f) GDPR).

7. Processing methods & retention

Data is processed with electronic tools by authorized personnel. It is retained for the time strictly necessary to handle the consulting request and afterwards for no more than 12 months unless otherwise agreed.

Submitted reviews are retained for the time needed for moderation and, if approved and published, until consent is revoked or deletion is requested.

Data is stored on cloud infrastructure located in the European Union (Convex, eu-west-1 region — Ireland).

8. Third-party disclosure

Data is not sold, transferred or communicated to third parties for commercial purposes. It may be accessible to technical service providers (e.g. email services, cloud databases) solely for the provision of the requested service, in compliance with the GDPR.

9. Data subject rights

Under Articles 15–22 of the GDPR, you have the right to:

  • Access your personal data
  • Obtain rectification or update of your data
  • Request erasure ("right to be forgotten")
  • Object to processing or request its restriction
  • Receive data in a portable format
  • Withdraw consent at any time

To exercise these rights, write to info@maioraailab.it.

10. Complaint to the supervisory authority

You have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) if you believe the processing of your data violates the GDPR.

Last updated: April 2026