Privacy
Policy
Last update: September 25, 2026
1. Data Controller
The data controller is Clean Studio di Samuele Castaldo. The contacts below may be used for questions, privacy requests and withdrawal of consent.
Clean Studio di Samuele Castaldo
Circumvallazione Ovest 6, scala 4, interno 9, 80023 Caivano (NA), Italia
Email: cleanstudio.lab@gmail.com · PEC: cleanstudio@pec.it
Phone: +39 327 088 7475
2. Data we process
We process only the data needed to provide the website, purchases, accounts, Partner Program and Control:
- Account and authentication data: UID, email, name, profile picture and login provider.
- Order, delivery, payment, invoice and support communication data.
- Partner Program data: plan, Stripe status, license, credits, requests and contract dates.
- Email, date, source and privacy version when you choose to subscribe to the newsletter.
- Prompts, images and results voluntarily submitted to AI generation features.
- Data entered by the user in Control: their customers' records (name, email, phone number and addresses), products, inventory, orders, deliveries, prices, costs, recorded payments, notes, couriers and tracking codes. Control does not require or store full payment-card details.
3. Control and the user's customer data
When you use Control to manage your workshop, you may enter personal data relating to customers, contacts or recipients who have no direct relationship with Clean Studio. For this data, privacy roles depend on the activities actually performed.
- Role of the Control user: the user decides why and how the entered data is used and normally acts as data controller. The user is responsible for the legal basis, notices to their customers, data minimisation and accuracy, their own retention periods and responses to data-subject requests.
- Role of Clean Studio: for data entered in the Control workspace, Clean Studio processes it on the user's behalf solely to provide, protect, maintain and support the service and normally acts as data processor. Clean Studio remains an independent controller for account, subscription, billing, security, abuse-prevention and support data processed for its own purposes.
- Instructions and processing agreement: the user must not use Control for unlawful or incompatible purposes. Where required by the GDPR, the relationship between the user as controller and Clean Studio as processor must be governed by an agreement or other act compliant with Article 28; this notice does not replace that agreement.
- Special-category data and minimisation: Control is not designed for health, biometric, criminal-offence or other special-category data. Do not enter such data unless it is strictly necessary, lawful and supported by appropriate safeguards; use notes and free-text fields only for information relevant to workshop management.
- Automated decisions: Control calculates summaries, stock, costs, margins and operational priorities from entered data, but it does not perform profiling or make automated decisions that produce legal effects on individuals.
4. Purposes and legal bases
Each processing activity is tied to a purpose and legal basis:
- Contract performance: accounts, orders, payments, subscriptions, licenses, requests and support.
- Legal obligations: accounting, tax, disputes and requests from authorities.
- Consent: optional newsletters and promotional communications.
- Legitimate interests: security, fraud prevention, system protection and legal defence.
- Control: performance of the contract with the user to provide the workspace, synchronise and protect data, provide support and ensure operational continuity. When Clean Studio acts as processor, it processes the user's customer data on the basis of that user's documented instructions.
5. Providers and recipients
- Firebase and Google Cloud: authentication, database and storage.
- Stripe: Checkout, payments, subscriptions, invoices and fraud prevention. Clean Studio does not store full card details.
- Vercel: website hosting and delivery.
- Resend: transactional emails and, in the future, authorised newsletters.
- Leonardo AI: processing images and prompts submitted to generation features.
- Google and Apple: social authentication when selected by the user.
For Control, workspace data is stored through Firebase/Google Cloud and passes through the application infrastructure hosted by Vercel. Stripe, Leonardo AI and Resend do not receive Control workspace data unless the user separately uses a feature that requires those services or contacts support.
6. Newsletter and marketing
Subscription is optional, separate from registration and based on consent. We record the date, source and privacy version to document your choice. You may withdraw consent at any time by contacting us; an automatic unsubscribe link will also be available before campaigns are sent. Withdrawal does not affect prior lawful processing.
7. Retention
Contractual and tax data are retained for the period required by law, normally up to 10 years. Account and Partner Program data remain for the relationship and as needed to manage rights or disputes. Newsletter data remain until withdrawal or closure of the service. Content and generations remain in history until the account or content is deleted, subject to legal obligations. Control workspace data remains while the user's service or workspace is active and for as long as the user keeps individual records; after a verified deletion request or definitive closure, it is retained only for the time strictly necessary to manage closure, any export, backup rotation, security or disputes, then deleted or anonymised unless the law requires otherwise. As controller of their own customers' data, the user must define and apply retention periods proportionate to their purposes.
8. Necessary cookies and technologies
We use technical cookies and tokens required for authentication, security, cart, language and payments. No third-party advertising profiling or analytics tools are currently installed. See the Cookie Policy for details.
9. Data subject rights
You may request access, correction, deletion, restriction, portability and objection, and withdraw consent. Deletion does not apply to data we must retain by law and may close the account and end active functions or licenses. You may also lodge a complaint with the Italian Data Protection Authority.
If a request concerns a customer's data entered in Control by a professional user, the individual should first contact that user, who is normally the controller. Clean Studio assists the controller in responding and acts on workspace-data requests only after verifying the requester's identity, authority and instructions.
10. Transfers and security
Some providers may process data outside the European Economic Area under GDPR safeguards, including standard contractual clauses or other valid mechanisms. We apply reasonable technical and organisational measures, but no online system can guarantee absolute security.
Control logically separates workspaces by account and requires server-side authentication and authorisation to read or change data. Operational access is limited to providers and people who need it to deliver, protect or support the service.
This notice describes Clean Studio's personal data processing and is updated when services, providers or legal requirements change.