Legal Information

Privacy Policy

Transparent data processing, service security, and privacy protection

Your privacy is our priority

This Privacy Policy describes how the web development studio SiteLab Studio collects, uses, protects, and processes information about users of our website and web services. We are committed to processing personal data transparently and securely in compliance with applicable data protection laws.

Effective Date: July 25, 2026 Scope: Main website and web services of the Studio
01

General Provisions and Data Controller

The website sitelab-studio.com (hereinafter referred to as the "Website") is owned and operated by the web development studio SiteLab Studio (hereinafter jointly referred to as the "Studio" or the "Controller"). We provide website and online store design and development services, build Telegram bots, and create modern AI tools and business automation solutions.

Data Controller: SiteLab Studio.
Country of operation: Ukraine.
Email for data protection inquiries: info@sitelab-studio.com.

By using the Website, you acknowledge that you have read and understood this Privacy Policy. Where data processing requires explicit consent, such consent is requested prior to collecting or using the relevant data.

Legal Bases for Processing:

  • User consent, for example, for using analytics cookies, processing contact form submissions, or utilizing specific interactive features of the Website;
  • Fulfillment of a user request or preparation of a service agreement;
  • Legitimate interest of the Controller (ensuring website security, preventing failures, and optimizing user experience);
  • Compliance with legal obligations under applicable law.
02

Data Collection and Processing

We process two primary categories of data depending on which sections of the Website you interact with:

User Data

  • Name and contact information (Email, phone number)
  • Messenger usernames (Telegram)
  • Message text and technical specifications
  • Data entered into forms and AI chats

Automatically Collected Data

  • IP address and approximate country or city of access
  • Browser type, operating system, and device information
  • Visited pages and time of visit
  • Technical cookie and analytics data
03

Use of Cookies, Local Storage (localStorage), and Web Analytics

To improve user experience, analyze traffic, remember preferences, and optimize performance, we use Cookies, browser local storage (localStorage), and the Google Analytics (gtag.js) web analytics system.

We adhere to Google Consent Mode v2 standards. Prior to obtaining your consent, analytics cookies are not set, and Google Analytics operates in a restricted mode in accordance with Google Consent Mode v2 settings. You may accept or reject analytics at any time via the interactive Cookie banner, which provides equal "Accept All" and "Necessary Only" buttons. Declining analytics does not prevent full use of the Website.

We collect aggregated and pseudonymized statistics about website interactions to help us improve structure and content.

Identifier (Key) Provider Purpose Technology & Duration Type
XSRF-TOKEN / laravel_session SiteLab Studio Form CSRF protection and browser session maintenance Session Cookie (2 hours) Necessary
sitelab_cookie_consent SiteLab Studio Saving user analytics consent status in banner localStorage — until user preference changes or browser data is cleared Necessary
_ga / _gid Google Analytics Pseudonymized visit counting and traffic sources Analytics Cookie (up to 2 years) Analytics
04

Interaction with AI Forms, Chats, and Voice Input

The Website may utilize intelligent assistants, contact forms, and voice input features for consultation and project cost estimation.

To generate automated responses, the content of your inquiry may be transmitted to the OpenAI service. Such transmission is carried out strictly to the extent necessary to process the request. We do not use the content of user inquiries to train publicly available AI models. An up-to-date list of the AI service providers we use is available upon request.

Voice Messages: When using voice input, the audio recording, text transcription, language, and duration may be processed. The audio recording is used for speech recognition and may be temporarily stored during technical processing. It is not intended for permanent storage and is deleted in accordance with the settings of the respective workflow and established retention schedules.

⚠️ Security Warning: Do not submit passwords, payment information, medical records, identity document copies, or other confidential data through AI forms and chats unless explicitly required for an agreed-upon service.
05

Internal Automation Systems and Google OAuth 2.0

ℹ️ For Website Visitors: The Google OAuth 2.0 integration and internal automation systems described in this section are not available to regular website visitors. When visiting the Website or submitting a request, SiteLab Studio does not request access to your Gmail, Google Drive, Google Calendar, or other data in your Google account.

To process inquiries and manage internal workflows, our studio uses private automation systems deployed within isolated infrastructure with restricted access. When integrating internal systems with Google services through OAuth 2.0, we follow the principles described below:

1. Access and Authorization: Google OAuth 2.0 is used exclusively by authorized SiteLab Studio personnel to connect internal Google Workspace accounts to private automation systems. Authorization is performed directly through Google’s authorization interface. SiteLab Studio does not receive or store passwords for Google accounts.
2. Data Accessed: Once an authorized employee grants the necessary permissions, SiteLab Studio's private automation systems may process the following categories of data via Google APIs:
  • Profile and Email: email address and basic Google profile information for employee identification;
  • Gmail Messages: email messages, headers, and attachments (strictly for routing operational notifications and processing client inquiries);
  • Google Drive / Docs / Sheets: spreadsheet and text documents (for maintaining project documentation and reports).
3. Use of Data: Data is used exclusively to execute internal operational workflows configured and authorized by SiteLab Studio, such as processing corporate email, saving information in internal spreadsheets, preparing documents, and sending internal notifications.
4. Data Storage: OAuth tokens are stored in a private automation system and are used solely to execute authorized operational workflows. Depending on the configuration of a specific automation, some processed data may be temporarily stored in internal execution history, technical logs, or backups. This data is not published, is not used for advertising purposes, and is deleted in accordance with established retention schedules.
5. Deletion and Revocation of Access: The owner of a connected internal Google account can revoke access at any time in their account security settings (Google Security Settings). Authorized SiteLab Studio personnel can also delete the OAuth connection and associated tokens directly from within the internal automation system.
🛡️ Compliance with Google Limited Use Requirements:
The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is not sold, shared for advertising purposes, used to determine creditworthiness, or used to train public artificial intelligence models.
06

Data Protection, Retention Periods, and Transfers to Third Parties

We do not sell users’ personal data or disclose it to third parties for their own advertising or marketing purposes.

To ensure the operation of the Website and services, data may be processed by our technical providers strictly to the extent necessary to deliver the respective services:

  • Cloudflare — network protection, traffic filtering, and CDN;
  • Hosting Provider — server and database hosting in a secure data center;
  • Google Analytics / Google Workspace API — pseudonymized analytics and API integrations;
  • Telegram — delivery of notifications about new inquiries to internal staff chats;
  • AI Provider (OpenAI) — automated response generation in interactive chats and speech recognition for voice input;

International Data Transfer: Some technical providers may process data outside the user's country of residence (including countries outside the EU/EEA). In such cases, we implement reasonable safeguards to ensure an appropriate level of protection in accordance with applicable data protection laws.

Data Retention Periods:

  • Inquiries and commercial proposals — up to 24 months after the last interaction;
  • Server technical logs — from 30 to 90 days;
  • GA4 web analytics data — up to 14 months in accordance with our Google Analytics property retention settings;
  • OAuth tokens of internal accounts — until access is revoked by the respective account owner, the integration is removed, or the automation ceases operation;
  • Backups — up to 30 days after deletion of the primary record in the system;
  • Active client data — for the duration of the agreement and statutory document retention periods.

Security Measures: We apply reasonable technical and organizational security measures, including HTTPS encryption, access restrictions, Cloudflare DDoS network protection, and backups. However, no method of data transmission over the Internet can guarantee absolute security.

07

Your Rights Regarding Personal Data

Under applicable data protection legislation, including the GDPR where applicable, you may have the following rights:

🔍 Right of Access Request information about what personal data we store and process.
✏️ Right to Rectification Request updates or corrections to your contact or project data.
🗑️ Right to Erasure Request deletion of personal data in cases provided by law (except for data retained under statutory obligations).
🚫 Withdrawal of Consent Revoke your consent to data processing at any time (for example, by disabling analytics cookies).
⏸️ Restriction and Objection Request restriction of processing, object to data processing, and request human review of a decision if it was made solely by automated means and significantly affects you.
⚖️ Right to Lodge a Complaint File a complaint with the authorized data protection supervisory authority in your jurisdiction.
08

Changes and Updates to the Privacy Policy

We may periodically update this Privacy Policy due to changes in legislation, the development of our web services, or the addition of new integrations.

The current version of this Privacy Policy is always available on this page together with its effective date. If there is a material change in data processing methods or Google API usage terms, we will post an additional notice on the Website or request renewed consent if required by applicable law.

Still Have Questions About Privacy?

If you have any suggestions or questions, or wish to exercise your rights regarding your personal data, please contact us using any convenient contact method.