Privacy Policy

Your privacy matters. This policy explains what data I collect and how I use it.

Last updated: February 15, 2026

Introduction

Thank you for visiting my personal website. I am committed to protecting your privacy and being transparent about the minimal data I collect. This website operates on a simple principle: collect only what is absolutely necessary to provide my services, and never use your data for tracking, advertising, or any purpose beyond what you explicitly consented to.

You can browse this website without providing personal data. However, if you choose to subscribe to my newsletter, contact me via my contact form, or leave comments on blog posts, processing of personal data becomes necessary. This privacy policy explains the nature, scope, and purpose of the personal data I collect, use, and process.

Data Controller

For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, the controller responsible for your personal data is:

Lorenzo Loconsole

European Union

Email: privacy@loconsole.eu

What Data I Collect

I collect minimal data necessary to provide my services. The information I process depends on how you interact with this website.

A. Server Log Data and Hosting

This website is hosted on StaticHost.eu. When you visit my website, the hosting servers automatically collect certain technical data necessary for the website to function properly, including your browser type and version, operating system, referrer, pages visited, date and time of access, IP address, and Internet service provider.

The legal basis for this processing is my legitimate interest (Article 6(1)(f) GDPR) in operating a secure and functional website.

B. Newsletter Subscriptions

If you subscribe to my newsletter, I collect your email address. The legal basis is your consent under Article 6(1)(a) GDPR. I use a double opt-in procedure and also store the IP address and timestamp of registration for legal protection.

I use Resend to manage newsletter subscriptions and send emails. Your email address is stored securely with Resend and is used only for sending you updates about new blog posts and content. I do not track email opens or link clicks in newsletters.

You can unsubscribe at any time using the link provided in each newsletter, or by contacting me at privacy@loconsole.eu. For more information, see Resend's privacy policy.

C. Contact Form

If you contact me via the contact form, the personal data you transmit (name, email, subject, and message) is stored. The legal basis is either your consent (Article 6(1)(a) GDPR) or the necessity to respond to your pre-contractual inquiry (Article 6(1)(b) GDPR).

I retain contact form messages until your inquiry is resolved or for a maximum of 2 years, whichever comes first. There is no transfer of this personal data to third parties.

D. Blog Comments (Disqus)

I use Disqus, a third-party service, to power comments on my blog. Disqus may use cookies and collect data for advertising and analytics purposes, and may track your browsing activity across websites for personalized advertising.

The legal basis is your consent under Article 6(1)(a) GDPR, provided through the cookie consent banner. Disqus comments only load after you explicitly consent to targeting/advertising cookies. For more information, see Disqus Privacy Policy.

How I Use Your Data

I process your personal data only for the specific purposes for which you provided it, and only on the following legal bases:

  • Consent (Article 6(1)(a) GDPR) — When you subscribe to my newsletter or accept cookies for Disqus comments. You can withdraw this consent at any time.
  • Contractual necessity (Article 6(1)(b) GDPR) — If processing is necessary to respond to your contact form inquiry.
  • Legal obligation (Article 6(1)(c) GDPR) — If I am required by law to process or retain certain data.
  • Legitimate interests (Article 6(1)(f) GDPR) — For server log data collection necessary for website security and functionality.

What I Don't Do

  • I do not use analytics or tracking tools beyond what is necessary for basic website functionality
  • I do not sell, rent, or share your data with third parties for marketing purposes
  • I do not use your data for any purpose beyond what is described in this privacy policy
  • I do not engage in profiling or automated decision-making
  • I do not display advertisements or participate in advertising networks (except for Disqus-related advertising, which you can opt out of)

Cookies and Third-Party Services

Cookies are small text files stored on your computer by websites you visit. They allow the website to recognize your browser and remember certain information.

A. Essential Cookies

Based on my legitimate interests under Article 6(1)(f) GDPR, I use essential cookies that are strictly necessary for the website to function properly (e.g., storing your cookie preferences). These cannot be disabled.

B. Third-Party/Targeting Cookies (Disqus)

Based on your consent under Article 6(1)(a) GDPR, Disqus sets cookies for comments and advertising purposes. These are only loaded with your explicit consent through the cookie consent banner and may track your browsing activity across websites for personalized advertising.

You can change your cookie preferences at any time by clearing your browser data and revisiting the site. You may also prevent cookies through your browser settings, though this may limit functionality.

C. Google Fonts

This website uses Google Fonts. When you visit, your browser loads font files from Google's servers, which receives technical information including your IP address and browser details.

The legal basis is my legitimate interest (Article 6(1)(f) GDPR) in providing a visually consistent website. For more information, see Google's Privacy Policy.

Your Rights Under GDPR

If you are in the European Union, you have the following rights regarding your personal data:

  • Right of access — Obtain confirmation as to whether your personal data is being processed and access the data.
  • Right to rectification — Request correction of inaccurate personal data or completion of incomplete data.
  • Right to erasure — Request deletion of your personal data ("right to be forgotten") where applicable.
  • Right to restriction of processing — Obtain restriction of processing where you contest accuracy, processing is unlawful, or data is needed for legal claims.
  • Right to data portability — Receive your data in a structured, machine-readable format and transmit it to another controller.
  • Right to object — Object to processing based on legitimate interests.
  • Right to withdraw consent — Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint — Lodge a complaint with a supervisory authority in your Member State.

To exercise any of these rights, please contact me at privacy@loconsole.eu. I will respond within 30 days.

Data Retention

I process and store your personal data only for the period necessary to achieve the purpose of storage, or as granted by applicable laws and regulations.

  • Newsletter subscriptions — Retained until you unsubscribe or request deletion.
  • Contact form messages — Retained until inquiry is resolved or for a maximum of 2 years, whichever comes first.
  • Comments (Disqus) — Managed by Disqus according to their retention policies.
  • Server log files — Anonymized data managed by StaticHost.eu according to their retention policies.

Security Measures

I have implemented technical and organizational measures to protect personal data processed through this website, including secure data transmission via HTTPS, regular security assessments, and limited access to personal data.

However, Internet-based data transmissions may have security gaps, and absolute protection cannot be guaranteed. You are free to contact me via alternative means if you have security concerns.

International Data Transfers

Some third-party service providers may process data outside the European Economic Area (EEA). Appropriate safeguards are in place:

  • StaticHost.eu — EU-based hosting provider.
  • Google (Google Fonts) — May process data in the US; relies on standard contractual clauses and the EU-U.S. Data Privacy Framework.
  • Disqus — May process data in the US; uses standard contractual clauses.
  • Resend — Implements appropriate safeguards for international data transfers.

Changes to This Privacy Policy

I may modify this privacy policy at any time to reflect changes in my practices, services, or legal obligations. When I make changes, I will update the "Last updated" date. For significant changes, I will post a prominent notice on my website and may notify newsletter subscribers by email.

Contact for Privacy Requests

If you have any questions, concerns, or requests related to this privacy policy or your personal data, please contact me:

I will respond to all legitimate requests within 30 days. Please include your full name, contact information, and the nature of your request.