Legal · updated 21 August 2026
Privacy Policy
This notice explains how FairyLabs processes personal data when you visit fairylabs.io or send a message through the contact form. It applies only to this website, not to other FairyLabs products that publish their own policies.
1. Data controller
The data controller is FairyLabs, VAT IT09192731215, based in Italy.
For any request about your personal data, write to info@fairylabs.io.
2. Scope
This policy covers browsing fairylabs.io, submitting the contact form, and technical data needed to operate and secure the site.
If we later work together under a contract, that agreement (and any product-specific privacy notice) governs project data. This page does not cover accounts, dashboards, or messaging on other FairyLabs products.
3. Data we collect
Depending on how you use the site, we may process:
- Contact form: name, email address, message, and your acceptance of this policy.
- Technical data from the form request: IP address and timestamp, used only to limit abuse (rate limiting).
- Server and hosting logs that the infrastructure may generate (IP address, user agent, requested URL, date and time).
- Theme preference stored in your browser (localStorage key fairylabs-theme). It is not sent to our servers.
- We do not ask for special-category data through the form. Please do not include health, biometric, or other sensitive information in your message.
4. Purposes and legal bases
We process data for these purposes:
- Reply to your inquiry and start a possible professional relationship (Art. 6(1)(b) GDPR: steps at your request before a contract; Art. 6(1)(a) where you accept this policy).
- Send the message to our inbox through our email infrastructure (same bases as above).
- Prevent spam and abuse, including rate limiting by IP (Art. 6(1)(f) GDPR: legitimate interest in securing the site).
- Operate, host, and deliver the website (Art. 6(1)(f) GDPR: legitimate interest in making the site available).
- Remember your theme preference on this device (Art. 6(1)(f) GDPR: legitimate interest in a usable interface). This storage is strictly technical.
- Meet legal obligations if a request or correspondence must be kept (Art. 6(1)(c) GDPR).
5. Recipients
We do not sell your data. We share it only with providers needed to run the site, and only to the extent required.
- Email infrastructure (Postal at mail.fairylabs.io): delivers the contact message to info@fairylabs.io.
- Hosting and edge infrastructure that serves fairylabs.io and the form endpoint: may process connection logs.
- Fonts (Inter and Geist Mono) are self-hosted with this website. They are not loaded from Google or another third-party font CDN.
- People at FairyLabs who handle incoming inquiries.
- Authorities, if required by law.
6. Cookies and local storage
This website does not use advertising, analytics, or profiling cookies. We do not run third-party tracking pixels on the pages.
The only preference we store in your browser is the theme (light, dark, or system) in localStorage. You can clear it from your browser settings.
The hosting layer may set strictly technical cookies required to deliver the site. They are not used to build a marketing profile.
7. Retention
Contact messages are kept for as long as needed to reply and, if a project starts, for the life of that relationship. If we do not work together, we typically delete or archive inquiries within 24 months, unless a longer period is required for legal claims or accounting.
Rate-limit records (IP and timestamps) are kept in memory for about one minute.
Hosting logs follow the retention of the hosting provider, limited to security and operations.
8. Your rights
You may request access, rectification, erasure, restriction, objection, and portability of your data, where those rights apply. You may withdraw consent without affecting processing that was lawful before withdrawal.
You may lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it) or with the supervisory authority of your EU member state.
To exercise your rights, email info@fairylabs.io and include the address you used on the form.
9. Security
We use HTTPS, input validation, a honeypot field against bots, and rate limiting on the form. Access to incoming mail is limited to people who handle inquiries.
No system is risk-free. Do not send passwords, medical records, or other highly sensitive material through the public form.
10. International transfers
Hosting or CDN nodes may process connection logs outside the European Economic Area. Where that happens, we rely on the mechanisms allowed by the GDPR, such as an adequacy decision or standard contractual clauses.
Website fonts are served from this site and do not involve a transfer to Google.
11. Minors
The site is intended for businesses and professionals. We do not knowingly collect data from children under 16. If you believe a minor has sent us data, write to us and we will delete it.
12. Changes
We may update this notice when the site or the law changes. The date at the top of the page is the latest version. Material changes will be published here.
This notice is provided for transparency and does not replace tailored legal advice. For questions, write to info@fairylabs.io or go back to the homepage.