Privacy Policy

Last updated: February 24, 2026

1. Data Controller

The data controller is lula.studio Srl, with registered office at Via XX Settembre 3/15 – 16121 Genova, Italy (hereinafter "Prootego", "we", "us").


For any privacy-related inquiry, you can contact us at: info@prootego.com.

2. Data We Collect

We collect personal data only when you voluntarily provide it or when it is automatically gathered through analytics tools. Specifically:


a) Contact / Demo Request Form

When you submit the "Book a Demo" form, we collect:

  • • Full name
  • • Work email address
  • • Company name
  • • Message / additional information

  • This data is processed by Formspree (formspree.io) for form handling and by Resend (resend.com) for email delivery to our team.


    b) Newsletter

    When you click "Subscribe to Newsletter", you are redirected to Substack (prootego.substack.com). Email collection and processing is handled entirely by Substack Inc. under their own privacy policy.


    c) Analytics & Tracking

    We use the following services to understand how visitors interact with our website:


  • Google Analytics 4 (Google LLC) – collects anonymized data about page views, interactions, device type, browser, geographic area, and referral source. Tracking ID: G-D47QJEHT9S. Google's privacy policy: https://policies.google.com/privacy

  • Visitor Tracking (visitortracking.com) – collects data about browsing behavior and sessions to help us understand user engagement.

  • d) Blog Content

    Blog articles are served via Contentful CMS (Contentful GmbH). Images are loaded from Contentful's CDN (images.ctfassets.net). No personal user data is sent to Contentful.

    3. Purpose of Data Processing

    We process your personal data for the following purposes:


  • Responding to inquiries: to reply to your demo requests and contact form submissions.
  • Analytics: to analyze website usage and improve user experience.
  • Newsletter: to allow you to subscribe to our updates (via Substack).
  • 4. Legal Basis (GDPR Art. 6)

  • Consent (Art. 6(1)(a)): for analytics cookies and newsletter subscription.
  • Legitimate interest (Art. 6(1)(f)): for analyzing website traffic and improving our services.
  • Contract performance (Art. 6(1)(b)): for processing demo requests and responding to your inquiries.
  • 5. Data Sharing

    We do not sell your personal data. Data may be shared with the following third-party processors, solely for the purposes described above:



    Data transfers to the USA are covered by the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs).

    ServicePurposeCountry
    Google AnalyticsWebsite analyticsUSA
    Visitor TrackingBehavior analyticsUSA
    FormspreeForm handlingUSA
    ResendEmail deliveryUSA
    SubstackNewsletterUSA
    ContentfulBlog CMS & CDNGermany/USA

    6. Cookies

    Our website uses cookies and similar technologies:


  • Technical cookies: essential for website functionality (session handling).
  • Analytics cookies: set by Google Analytics and Visitor Tracking to collect usage statistics.

  • You can manage or disable cookies through your browser settings. Disabling analytics cookies will not affect website functionality.

    7. Data Retention

  • Contact form data: retained for 12 months from submission, then deleted.
  • Analytics data: retained according to each provider's default retention policies (Google Analytics: 14 months).
  • Newsletter data: retained by Substack until you unsubscribe.
  • 8. Your Rights (GDPR Art. 15–22)

    As a data subject, you have the right to:


  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interest
  • Withdraw consent at any time

  • To exercise your rights, contact us at: info@prootego.com.


    You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at https://www.garanteprivacy.it.

    9. Security

    We implement appropriate technical and organizational measures to protect your personal data, including encrypted connections (HTTPS), secure hosting on Vercel, and restricted access to personal data.

    10. Changes to This Policy

    We may update this Privacy Policy from time to time. The latest version is always available at this page. We encourage you to review it periodically.