Privacy Policy
This policy explains how personal data is handled when you visit the iKloot online gallery or contact us about an artwork, exhibition or collaboration.
Who is responsible for your data
The data controller is ZIZULA CARDS SRL, Str. 1 Decembrie nr. 94, Timișoara, Romania. VAT / company identification number: RO35590842.
Privacy questions and rights requests may be sent to contact@ikloot.com.
Personal data we process
When you use the contact form, we may process:
- your name and email address;
- the subject and message you provide;
- an optional artwork ID when you enquire about a specific work;
- the server-generated date and time of your submission; and
- your IP address temporarily for abuse prevention and rate limiting.
The hosting and content-delivery infrastructure also processes standard technical request data needed to deliver and protect the website, including an IP address, browser and request headers, and requested URLs.
We do not use browser fingerprinting, location tracking, profiling or behavioural monitoring. Please avoid including unnecessary sensitive personal data in the free-text message.
How a contact enquiry is handled
The form is processed server-side. The application does not save contact-form submissions in the website database. If an artwork ID is supplied, it is checked server-side against the published artwork data so purchase wording is used only for an available, published work.
The form data is sent through Resend for delivery. The resulting email is delivered to contact@ikloot.com and stored in Microsoft 365. Contact-form content is not used for marketing.
No automated decision-making or profiling is performed.
Why we process personal data
Purchase and transaction-related enquiries
For an enquiry about purchasing an artwork, or another request that may lead to a transaction, the legal basis is Article 6(1)(b) GDPR — taking steps at the visitor’s request before entering into a contract.
General correspondence
For general questions, correspondence and managing legitimate communications, the legal basis is Article 6(1)(f) GDPR — the controller’s legitimate interest in receiving and responding to enquiries concerning iKloot and its artworks.
Security and abuse prevention
For spam prevention, rate limiting, security and reliable website delivery, the legal basis is Article 6(1)(f) GDPR — the controller’s legitimate interest in protecting the website and communications from abuse and maintaining a secure service.
Temporary rate limiting
The raw IP address is used only as a temporary in-memory rate-limit identifier. It is not written to the website database or to application logs. Rate-limit entries expire after approximately 10 minutes and may disappear sooner when the server instance restarts or is redeployed.
Service providers and recipients
- Lovable / Lovable hosting and CDN — website delivery and technical request processing.
- Lovable Cloud / managed Supabase infrastructure — database, authentication and private artwork-image storage. The configured project region is AWS eu-west-1, Ireland.
- Resend — transmission of contact-form email. The configured sending region is Ireland, eu-west-1.
- Microsoft 365 — receipt and storage of enquiries in the contact@ikloot.com mailbox.
These providers may use their own infrastructure and subprocessors. Their processing may involve international transfers depending on their infrastructure and arrangements; this policy does not state that data always remains within the EEA.
How long data is kept
- The application itself does not retain contact-form submissions in a website database.
- Enquiry emails are kept in the Microsoft 365 mailbox for a maximum of 12 months after the last communication.
- A message may be retained longer when it becomes part of an artwork transaction, when necessary to establish or defend legal claims, or when a legal accounting or record-keeping obligation applies.
- Resend retains email data for approximately 30 days under its standard service retention.
- Rate-limit IP data remains only in server memory for approximately 10 minutes.
- Hosting and CDN providers may keep technical access and security logs according to their own operational retention schedules.
Your rights
Depending on the circumstances and the legal requirements that apply, you may have rights to information, access, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, and data portability. These rights do not apply unconditionally in every situation.
To make a request, email contact@ikloot.com. You may also lodge a complaint with a supervisory authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
Marketing, sale of data and automated processing
The website does not use contact details for newsletters or direct marketing. It does not sell personal data, conduct profiling, or make decisions producing legal or similarly significant effects through automated processing.
Changes to this policy
This policy may be updated if the website’s services or data practices change.