Drafted 1 September 2026. Not yet in force.
Draft. Not reviewed, not in force. This notice was written from what the website actually does, so the description of the data flow is accurate. It has not been reviewed by a lawyer, and it is not legal advice. Every [TO BE COMPLETED: …] mark below is a real-world fact the studio still has to supply or a decision an adviser still has to confirm. Nothing on this page has been filled in with a guess.
We are a two-person studio. The only personal data this website collects is what you type into the enquiry form, and we collect it for one reason: to read your enquiry and reply to it.
Applied Luck Department operates this website at www.appliedluckdept.com and is the controller of the personal data described here, in the sense of Article 4(7) GDPR.
The entity is in the process of being filed, which is why those lines are still pending. The same details appear, and will be completed, in the imprint.
Data protection officer: [TO BE COMPLETED: whether Article 37 GDPR requires a DPO for a studio of this size and activity, and if so their name and contact details. If none is required, say so here plainly.]
Two things: what you send us through the enquiry form, and the technical record our host keeps of requests reaching the site. Nothing else.
The enquiry form. The form at the bottom of the home page is the only place on this site where we collect personal data. It asks for:
We use all of it for a single purpose: to understand your enquiry, reply to it, and carry on the conversation about an evaluation if there is one. We do not use it for marketing, we do not add you to a mailing list, we do not sell or rent it, and we do not profile you or make automated decisions about you.
The form also contains one field that is hidden from people and left out of the keyboard order and the accessibility tree. It exists to catch automated submissions. If it arrives with anything in it, the submission is discarded and nothing is stored.
A word about the free-text fields. Send only what you want us to have. Please do not put classified, export-controlled or otherwise restricted information into a web form — describe your system in general terms and keep the detail for the intake call, which is what it is for.
Technical records. Our host records the requests our site receives: the time, the path, the response status, the browser's user agent and the IP address the request came from. That is ordinary server logging, used to operate and secure the site. Our own form code does not read your IP address, and the contents of your enquiry are not written into these logs. [TO BE COMPLETED: how long the host retains runtime logs on the plan in use, stated here as a number.]
Under Article 6(1) GDPR we rely on:
[TO BE COMPLETED: adviser to confirm which of these two is the primary basis, and whether both should be cited. Consent is a weak basis for processing we cannot do without, and citing it alongside a second basis is often criticised; relying on pre-contractual steps alone would make the tick-box a courtesy rather than a legal requirement. As currently built, the site asks for consent and the form will not submit without it.]
We do not sell your data and we do not share it for anyone else's marketing. It passes through three service providers, who process it on our instructions and for no purpose of their own:
Both the email and the sheet exist on purpose. An email can be deleted or land in a spam folder, and then your enquiry is simply lost; the sheet is the record, the email is the notification. If one of the two fails we still have the other.
[TO BE COMPLETED: the provider of the [email protected] mailbox, which receives and stores the notification email and so is a fourth processor this list does not yet name. Name it above. Then a signed Article 28 data processing agreement on file for each of Resend, Google, Vercel and that provider, and a record of processing activities listing them. Add any further processor before it goes live, and update this section when you do.]
We may also disclose data where the law requires it of us.
The server function that receives the form is pinned to our host's Frankfurt region, so the submission is handled inside the European Union rather than in the platform's default US region.
Two things we would rather state than gloss over:
[TO BE COMPLETED: the transfer mechanism relied on for each of the three processors — an adequacy decision, an EU-US Data Privacy Framework certification, or standard contractual clauses plus a transfer impact assessment — documented before launch and summarised here in plain words.]
[TO BE COMPLETED: retention period. A suggested starting point for the adviser, not a decision: enquiries deleted or anonymised 24 months after our last contact with you, unless the enquiry became a client engagement, in which case the statutory retention that applies to contract and tax records takes over.]
We have not fixed this period yet, and we would rather say so than print a number we do not actually follow. Whatever it turns out to be, it applies to both copies of your enquiry — the notification email and the row in the sheet — and we will state it here before the form goes live.
Under the GDPR you can ask us to:
Email [email protected] and we will act on it. There is no charge, and we aim to reply within one month, which is the period Article 12(3) allows.
You can also complain to a data protection supervisory authority — in the member state where you live, where you work, or where you believe the problem happened. Ours is [TO BE COMPLETED: lead supervisory authority — the data protection authority of the member state in which the entity is registered, with its website].
This site sets no cookies. It runs no analytics, no tag manager, no advertising or social pixels, no session recording and no A/B testing. It stores nothing in your browser. There is no consent banner because there is nothing to consent to.
It also makes no third-party requests at all. The typefaces are served from this domain rather than a font network, nothing is pulled from another company's CDN, there is no embedded video and no framework loaded from someone else's server. The only JavaScript is a small script written into the page itself. While you read this site, nothing on it talks to another company about you.
The single exception is the thing you deliberately do: when you submit the form, that submission reaches the processors named in section 4.
This is a deliberate design rule of the site, not an accident. If it ever changes, this notice changes with it.
The site is served over HTTPS, and the form endpoint rejects submissions that do not originate from this site. Access to the notification mailbox and to the sheet is limited to the two of us.
We will not overstate this. We are a two-person studio using ordinary commercial services, and section 4 names every one of them so you can judge them for yourself.
If we change how any of this works, we will change this page and update the date below. Where a change is material we will say what changed rather than quietly reissuing the page.
Last updated: [TO BE COMPLETED: the date this notice is published, once it has been reviewed]