Privacy Policy
Last updated: June 25, 2026
This Privacy Policy describes how this website (lorenzocristofori.com) collects, uses and protects your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law.
Processing Summary
Below is a summary of the processing carried out by the site; each item is detailed in the following sections.
Contact form — purpose: responding to your requests; data: name, email address, message content, usage data.
AI assistant (chatbot) — purpose: answering questions about the professional profile; data: message text, usage data.
Statistics (Umami Analytics) — purpose: aggregated traffic analysis; data: anonymous usage data, without cookies.
Hosting and security (Cloudflare) — purpose: delivery, security and diagnostics of the site; data: usage data (technical logs).
Data Controller
The data controller is Lorenzo Cristofori (Italian tax code CRSLNZ96M18I348L), a natural person residing in Ala (TN), Italy, operator of the website lorenzocristofori.com.
For any request regarding your data you can write to info@lorenzocristofori.com or use the contact form on the site.
Data Collected
Contact form data: name, email address and the content of the message you voluntarily send us.
Chatbot data: the text of the messages you type into the AI assistant. Please do not enter personal or sensitive data in the chat.
Technical data: IP address, browser type, operating system, language and time zone, collected automatically during browsing.
Provision of data: name, email and message are required in order to respond to your requests; failure to provide them prevents the form from being sent but does not prevent browsing the site. Technical data is collected automatically and is strictly necessary for the operation, security and diagnostics of the site.
Purposes of Processing
Responding to requests sent through the contact form.
Providing the answers of the AI assistant (chatbot).
Ensuring the security of the site, preventing abuse and performing diagnostics.
Analysing site usage in aggregated and anonymous form to improve content and features.
Complying with legal obligations and, in the event of disputes or abuse, defending the Controller's rights in or out of court.
Legal Basis
Performance of pre-contractual measures and handling of your requests (Art. 6(1)(b) GDPR): for the contact form and the AI assistant.
Legitimate interest (Art. 6(1)(f) GDPR): for site security and aggregated traffic analysis.
Legal obligation (Art. 6(1)(c) GDPR): to comply with legal requirements.
Data Retention
Messages sent through the contact form are kept for as long as necessary to handle the request and for any period required by law or for legal defence.
Technical browsing logs (IP address, user-agent, URL) are kept for a limited period, in line with the policies of our hosting providers (in particular Cloudflare), after which they are deleted or aggregated anonymously.
Messages sent to the AI assistant are not stored by OpenRouter by default (content logging is opt-in and disabled); OpenRouter does, however, retain some technical request metadata (token count, latency, model). The content is also processed by the provider of the selected model according to its own policies.
Traffic statistics are kept solely in aggregated and anonymous form.
Sharing with Third Parties
We do not sell your personal data and do not transfer it to third parties for direct marketing or advertising profiling. Data is shared only with the technical providers listed below, appointed as data processors under Art. 28 GDPR, and in cases required by law or by requests from the competent authorities:
Cloudflare, Inc.: provides the site hosting (Workers), the CDN/edge network and the Turnstile service for anti-bot protection of forms. It processes technical access logs (IP, user-agent, URL) and, for Turnstile, technical browser signals to verify that the visitor is a human, without visual CAPTCHAs and without collecting identifiable personal data.
Resend: used to send the emails generated by the contact form. Only the email address and the message content are transmitted to Resend.
OpenRouter: routes the messages sent to the AI assistant to the model provider to generate the replies (provider based in the United States). The content is not stored by OpenRouter by default; it is, however, processed by the provider of the selected model according to its own policies.
Umami Analytics: a traffic analytics tool in aggregated form, free of cookies and not collecting identifiable personal data. More information at umami.is/privacy.
Authorities: in case of legal obligation or request from law enforcement.
International Data Transfers
Some providers used have their registered office in the United States (in particular Resend, Cloudflare, Inc. and OpenRouter). For such transfers we rely on the safeguards put in place by the providers themselves under the GDPR, namely the Standard Contractual Clauses (SCC) approved by the European Commission and, where available, the provider's adherence to the EU-US Data Privacy Framework.
These safeguards are made available directly by the providers: for example, Cloudflare publishes its Data Processing Addendum (DPA), which incorporates the SCCs, on its website. For the other providers, please refer to their respective privacy policies.
Cookies and Local Storage
This site does not use cookies of any kind (neither technical, analytical nor profiling).
We only use the browser's localStorage to remember your theme preference (light/dark). This data stays on your device and is not transmitted to third parties; you can delete it at any time by clearing the site data in your browser settings.
For aggregated traffic analysis we use Umami Analytics, which is cookie-free, does not collect personal data and does not require consent under the GDPR.
Your Rights
Under the GDPR you have the right to: access your data; rectify inaccurate or incomplete data; erasure ("right to be forgotten"); restriction of processing; data portability; object to processing based on legitimate interest; withdraw consent, where processing is based on it, without affecting the lawfulness of prior processing (Art. 7(3) GDPR).
Requests are free of charge and will be handled as soon as possible and in any case within one month of receipt, save for a justified extension of a further two months in cases of particular complexity (Art. 12(3) GDPR). To exercise your rights, write to info@lorenzocristofori.com.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali, www.garanteprivacy.it).
Security
We adopt appropriate technical and organisational measures to protect your data from unauthorised access, loss or destruction. Communication with the site always takes place via the HTTPS protocol.
In the event of a personal data breach involving a risk to users' rights and freedoms, we will notify the breach to the supervisory authority within 72 hours of becoming aware of it and, where required, inform the affected users, in accordance with Arts. 33 and 34 GDPR.
Minors
The site is not intended for children under 14 (the threshold set by Art. 2-quinquies of Legislative Decree 196/2003, as amended by Legislative Decree 101/2018). We do not knowingly collect personal data of children under 14. If you believe a minor has provided data without the consent of the person holding parental responsibility, contact us at info@lorenzocristofori.com to request its deletion.
Automated Decisions and Profiling
We do not carry out solely automated decision-making or profiling within the meaning of Art. 22 GDPR. The AI assistant generates text answers but does not produce decisions with legal or similarly significant effects on users. We do not use data for direct marketing purposes.
Changes to this Policy
We reserve the right to update this Policy. Changes will be published on this page together with the update date.
Definitions
Personal Data — any information that allows a natural person to be identified, directly or indirectly.
Usage Data — information collected automatically by the site or third-party services (IP address, browser type, operating system, pages visited, times and session duration).
User — the individual using this site.
Data Subject — the natural person to whom the Personal Data refers.
Data Processor — the entity that processes Personal Data on behalf of the Controller.
Data Controller — the entity that determines the purposes and means of processing.
Cookies and Trackers — technical tools that allow information to be stored or Users to be tracked. This site does not use cookies or trackers for analytics or profiling purposes.