Legal Information

Privacy Policy

Transparent data processing, service security, and privacy protection

Your privacy is our priority

This Privacy Policy describes how the web development studio SiteLab Studio collects, uses, protects, and processes information about users of our website and web services. We are committed to processing personal data transparently and securely in compliance with applicable data protection laws.

Effective Date: July 25, 2026 Scope: Main website and web services of the Studio
01

General Provisions and Data Controller

The website sitelab-studio.com (hereinafter referred to as the "Website") is owned and operated by the web development studio SiteLab Studio (hereinafter jointly referred to as the "Studio" or the "Controller"). We provide website and online store design and development services, build Telegram bots, and create modern AI tools and business automation solutions.

Data Controller: SiteLab Studio.
Country of operation: Ukraine.
Email for data protection inquiries: info@sitelab-studio.com.

By using the Website, you acknowledge that you have read and understood this Privacy Policy. Where data processing requires explicit consent, such consent is requested prior to collecting or using the relevant data.

Legal Bases for Processing:

  • User consent, for example, for using analytics cookies, processing contact form submissions, or utilizing specific interactive features of the Website;
  • Fulfillment of a user request or preparation of a service agreement;
  • Legitimate interest of the Controller (ensuring website security, preventing failures, and optimizing user experience);
  • Compliance with legal obligations under applicable law.
02

Data Collection and Processing

We process two primary categories of data depending on which sections of the Website you interact with:

✦ User Data

  • Name and contact information (Email, phone number)
  • Verified Google email, account identifier, and avatar URL when a service request is submitted
  • Messenger usernames (Telegram)
  • Message text and technical specifications
  • Data entered into forms and AI chats

✦ Automatically Collected Data

  • IP address and approximate country or city of access
  • Browser type, operating system, and device information
  • Visited pages and time of visit
  • Technical cookie and analytics data
03

Use of Cookies, Local Storage (localStorage), and Web Analytics

To improve user experience, analyze traffic, remember preferences, and optimize performance, we use Cookies, browser local storage (localStorage), and the Google Analytics (gtag.js) web analytics system.

We adhere to Google Consent Mode v2 standards. Prior to obtaining your consent, analytics cookies are not set, and Google Analytics operates in a restricted mode in accordance with Google Consent Mode v2 settings. You may accept or reject analytics at any time via the interactive Cookie banner, which provides equal "Accept All" and "Necessary Only" buttons. Declining analytics does not prevent full use of the Website.

We collect aggregated and pseudonymized statistics about website interactions to help us improve structure and content.

Identifier (Key) Provider Purpose Technology & Duration Type
XSRF-TOKEN / laravel_session SiteLab Studio Form CSRF protection and browser session maintenance Session Cookie (2 hours) Necessary
sitelab_cookie_consent SiteLab Studio Saving user analytics consent status in banner localStorage — until user preference changes or browser data is cleared Necessary
_ga / _gid Google Analytics Pseudonymized visit counting and traffic sources Analytics Cookie (up to 2 years) Analytics
04

Interaction with AI Forms, Chats, and Voice Input

The Website may utilize intelligent assistants, contact forms, and voice input features for consultation and project cost estimation.

To generate automated responses, the content of your inquiry may be transmitted to the OpenAI service. Such transmission is carried out strictly to the extent necessary to process the request. We do not use the content of user inquiries to train publicly available AI models. An up-to-date list of the AI service providers we use is available upon request.

Voice Messages: When using voice input, the audio recording, text transcription, language, and duration may be processed. The audio recording is used for speech recognition and may be temporarily stored during technical processing. It is not intended for permanent storage and is deleted in accordance with the settings of the respective workflow and established retention schedules.

⚠️ Security Warning: Do not submit passwords, payment information, medical records, identity document copies, or other confidential data through AI forms and chats unless explicitly required for an agreed-upon service.
05

Identity Verification with Google and Internal Automation Systems

ℹ️ For Website Visitors: when a service request is submitted, we use Google OAuth 2.0 only to verify the Google Account and its email address. We do not request access to Gmail, Google Drive, Google Calendar, or the content of other Google services.

Google OAuth 2.0 is used in two separate scenarios: to verify a visitor’s email before a service request is submitted, and to allow authorized personnel to connect work Google accounts to private automation systems. In both cases, authorization takes place directly through Google, and SiteLab Studio does not receive Google Account passwords.

1. Request verification: before submitting the form, a visitor selects a Google Account. We receive a stable account identifier, verified email address, name, and avatar URL. This data is used to verify the source of the request, protect the form from spam, and contact the requester.
2. Request data storage: the verified Google email, account identifier, and verification time are stored with the request. Google access and refresh tokens for visitors are not stored and are not used to access Google APIs after identity verification.
3. Internal integrations: separately, authorized SiteLab Studio personnel may connect work accounts to private automation systems. Depending on the permissions granted, those systems may process business Gmail messages and Google Drive, Docs, and Sheets documents solely for internal workflows.
4. Security and purpose: Google data is not published, is not used for advertising, and is processed only for the stated purpose of verifying a request or executing an authorized internal workflow.
5. Deletion and revocation: visitors may request deletion of request data using the contact details in this Policy. The owner of a connected work account may also revoke access in Google Security Settings.
🛡️ Compliance with Google Limited Use Requirements:
The use of information received through Google Identity and Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is not sold, shared for advertising purposes, used to determine creditworthiness, or used to train public artificial intelligence models.
06

Data Protection, Retention Periods, and Transfers to Third Parties

We do not sell users’ personal data or disclose it to third parties for their own advertising or marketing purposes.

To ensure the operation of the Website and services, data may be processed by our technical providers strictly to the extent necessary to deliver the respective services:

  • Cloudflare — network protection, traffic filtering, and CDN;
  • Hosting Provider — server and database hosting in a secure data center;
  • Google Identity / Google Analytics / Google Workspace API — Google Account verification, pseudonymized analytics, and internal API integrations;
  • Telegram — delivery of notifications about new inquiries to internal staff chats;
  • AI Provider (OpenAI) — automated response generation in interactive chats and speech recognition for voice input;

International Data Transfer: Some technical providers may process data outside the user's country of residence (including countries outside the EU/EEA). In such cases, we implement reasonable safeguards to ensure an appropriate level of protection in accordance with applicable data protection laws.

Data Retention Periods:

  • Inquiries, including the verified Google email and account identifier — up to 24 months after the last interaction;
  • Server technical logs — from 30 to 90 days;
  • GA4 web analytics data — up to 14 months in accordance with our Google Analytics property retention settings;
  • OAuth tokens of internal accounts — until access is revoked by the respective account owner, the integration is removed, or the automation ceases operation;
  • Backups — up to 30 days after deletion of the primary record in the system;
  • Active client data — for the duration of the agreement and statutory document retention periods.

Security Measures: We apply reasonable technical and organizational security measures, including HTTPS encryption, access restrictions, Cloudflare DDoS network protection, and backups. However, no method of data transmission over the Internet can guarantee absolute security.

07

Your Rights Regarding Personal Data

Under applicable data protection legislation, including the GDPR where applicable, you may have the following rights:

🔍 Right of Access Request information about what personal data we store and process.
✏️ Right to Rectification Request updates or corrections to your contact or project data.
🗑️ Right to Erasure Request deletion of personal data in cases provided by law (except for data retained under statutory obligations).
🚫 Withdrawal of Consent Revoke your consent to data processing at any time (for example, by disabling analytics cookies).
⏸️ Restriction and Objection Request restriction of processing, object to data processing, and request human review of a decision if it was made solely by automated means and significantly affects you.
⚖️ Right to Lodge a Complaint File a complaint with the authorized data protection supervisory authority in your jurisdiction.
08

Changes and Updates to the Privacy Policy

We may periodically update this Privacy Policy due to changes in legislation, the development of our web services, or the addition of new integrations.

The current version of this Privacy Policy is always available on this page together with its effective date. If there is a material change in data processing methods or Google API usage terms, we will post an additional notice on the Website or request renewed consent if required by applicable law.

Still Have Questions About Privacy?

If you have any suggestions or questions, or wish to exercise your rights regarding your personal data, please contact us using any convenient contact method.