Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how Vintage Studio collects, uses, and safeguards personal data processed through this website, and sets out your rights under the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and applicable data protection law.
1. Data controller
Vintage Studio is a trading name of Ciprian Socaciu, based in Sliema, Malta. As the operator of this website, Ciprian Socaciu determines the purposes and means of the processing of personal data described in this Policy and is therefore the controller for the purposes of the GDPR. The controller may be contacted as follows:
Vintage Studio (Ciprian Socaciu)
144 Triq Manwel Dimech, Tas-Sliema SLM 1053, Malta
Phone: +356 9936 0995
Email: cipriansocaciu@yahoo.com
2. Personal data we process
This website is informational in nature. It does not use cookies, analytics, or advertising or tracking technologies, and it does not collect personal data through contact forms, account registration, or newsletter subscriptions. The personal data processed through this website is limited to the following:
- Chat messages. Where you choose to use the chat feature, the content of the messages you submit is processed in order to generate a response.
- Technical data. When your browser requests a page, the hosting infrastructure automatically processes your Internet Protocol (IP) address and standard connection data for the purpose of delivering the website and maintaining its security.
3. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases under Article 6(1) of the GDPR:
- To operate the chat feature and respond to enquiries, on the basis of our legitimate interests in answering visitors' questions and operating this website (Article 6(1)(f) GDPR).
- To deliver the website and to ensure its security and prevent abuse, on the basis of our legitimate interests in maintaining the availability, integrity, and security of the website (Article 6(1)(f) GDPR).
You are not required to submit any personal data through the chat feature. Please do not submit sensitive personal data (such as health, identity, or payment information) through the chat. To make a booking or to share confidential information, please contact us directly using the details set out above.
4. Recipients and processors
We do not sell personal data. Personal data is disclosed only to the following recipients:
- Our website provider. The website is developed and hosted on our behalf by Conversionate, which processes personal data solely on our instructions as our processor.
- Our chat technology provider. The content of chat messages is transmitted to OpenAI, a company established in the United States, which generates the automated responses.
5. International transfers
Because the chat technology provider is established in the United States, the content of chat messages is transferred outside the European Economic Area. Such transfers are made subject to appropriate safeguards within the meaning of Chapter V of the GDPR, namely the Standard Contractual Clauses adopted by the European Commission and any applicable adequacy framework for transfers to the United States. Further information about these safeguards is available on request.
6. Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy:
- chat messages are processed for the duration of your browsing session and are not stored in any database controlled by us; where a technical error occurs, a limited error record may be retained only for as long as necessary to diagnose and resolve the issue;
- technical and security data is retained only for the limited period necessary for security and abuse-prevention purposes, after which it is deleted.
7. Data security
We implement appropriate technical and organisational measures to protect personal data processed through this website. However, no method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. This does not affect your rights under the GDPR.
8. Your rights
Subject to the conditions and exceptions provided by the GDPR, you have the right to:
- request access to the personal data we hold about you (Article 15);
- request the rectification of inaccurate or incomplete personal data (Article 16);
- request the erasure of your personal data (Article 17);
- request the restriction of processing (Article 18);
- object to processing carried out on the basis of our legitimate interests (Article 21);
- request the portability of your personal data (Article 20); and
- where processing is based on your consent, withdraw that consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise any of these rights, please contact us at cipriansocaciu@yahoo.com. We will respond in accordance with applicable data protection law.
9. Complaints
If you have a concern about how we process your personal data, we ask that you contact us first so that we may address it. You also have the right to lodge a complaint with Malta's supervisory authority, the Information and Data Protection Commissioner (IDPC), which may be contacted at idpc.org.mt.
10. Changes to this Policy
We may update this Privacy Policy from time to time. The version published on this page is the version in force, and the date of the most recent update is shown at the top of this page.
11. Contact
Questions about this Privacy Policy or about how we process personal data may be addressed to us at cipriansocaciu@yahoo.com.