Personal data protection
Privacy Policy
Privacy information under Articles 12 and 13 of Regulation (EU) 2016/679. We explain in plain language what data we process, why we process it and how long we retain it.
Last updated: 29 agosto 2026
1. Data controller
The data controller is AI Arena di Raoul Ragazzi, VAT number 02950290219, Via Goethe 42, Merano e Via Settala 1, Milano. For privacy requests, the exercise of rights or reports: contatti@splendoria.vip.
2. Data we process
- account, contact, authentication and security data;
- commercial requests, orders and administrative data;
- memories, interviews, chapters, materials and editorial preferences entered by the user;
- technical data needed to protect the service;
- local backup copies of drafts stored in the browser on the user’s device to protect them against accidental loss.
Splendoria does not sell personal data and does not use it for behavioural advertising or commercial profiling.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account, Studio, writing, support and delivery of the service | Contract or pre-contractual measures, Art. 6(1)(b) GDPR |
| Contacts, quotations and requests | Pre-contractual measures and legitimate interest in responding, Arts. 6(1)(b) and 6(1)(f) |
| Invoicing and administrative obligations | Contract and legal obligations, Arts. 6(1)(b) and 6(1)(c) |
| Security, abuse prevention and protection of rights | Legitimate interest, Art. 6(1)(f) GDPR |
| Muse functions and AI tools requested by the user | Performance of the service, Art. 6(1)(b) GDPR; explicit consent where the user’s special-category data are required, Art. 9(2)(a) GDPR |
4. Sensitive memories and other people’s data
A personal story may contain special-category data, for example health information, religious or political beliefs, ethnic origin, sex life or sexual orientation. The user decides what to tell and should limit the material to what is relevant. When entering information, photographs or documents concerning third parties, the user must be entitled to use them lawfully and must respect their dignity, privacy and rights.
5. Artificial intelligence and human control
The functions called “Muse” use artificial intelligence systems to formulate questions, organise material, generate drafts and propose revisions. The user is informed when interacting with AI, may change or reject every output and retains control of the work. No solely automated decisions are made that produce legal or similarly significant effects on the person. Further details are available on the pagina AI transparency.
6. Backup copy in the browser
In the Studio, text and editorial fields may also be stored in the device’s local storage for up to 365 days after the last change. This is a technical copy, remains in the browser and is not automatically sent to Splendoria. Passwords, tokens, sessions, email addresses and files are not included. The browser or the user may delete it at any time.
7. Recipients and transfers
Data may be processed, to the extent necessary, by providers of cloud infrastructure, databases, security, email and AI, by authorised professionals carrying out editorial review and production, by advisers and by authorities where required by law. Where processing involves transfers outside the European Economic Area, the safeguards provided for in Chapter V GDPR are used, such as adequacy decisions or standard contractual clauses.
8. Retention
Accounts and projects are retained for the duration of the relationship and, where necessary, for subsequent statutory periods or for the protection of rights. Sessions last no more than 30 days, password-recovery links 30 minutes, and technical security and audit events up to 365 days. The local draft copy has a maximum application retention period of 365 days from the last change unless it is deleted earlier in the browser.
9. Security
Splendoria applies proportionate technical and organisational measures: encrypted connections, cryptographically derived passwords, HttpOnly and Secure session cookies, access separation, attempt limiting and logging of critical events. Editorial content is processed in accordance with data-minimisation and confidentiality principles.
10. Rights
The data subject may request access, rectification, erasure, restriction, portability, objection and withdrawal of consent where applicable by writing to contatti@splendoria.vip. A response is provided without undue delay and normally within one month. A complaint may always be lodged with the Italian Data Protection Authority (Italian Data Protection Authority (Garante per la protezione dei dati personali)).
11. Minors and updates
The service is intended for adults. Data concerning minors may be entered only where the user is entitled to do so and only to the extent strictly necessary. This privacy information is updated when the service, providers or applicable law changes.