Privacy Policy
Effective Date: January 1, 2026 | Last Updated: September 2026
1. Data Controller Identification
This Privacy Policy explains how LazyLabs ("we", "us", "our"), an independent indie software and micro-SaaS studio operating in Belgium, European Union, collects, processes, and safeguards personal data when you access our public website (lazylabs.panicdm.com) and use our software products (including PanicDM and WanderLabs).
Controller Contact:
LazyLabs Studio
Operating Location: Ghent / Flanders, Belgium (EU)
Official Contact Email: [email protected]
Support & Privacy Inquiries: [email protected]
2. Legal Basis & Data We Collect
We process personal data strictly in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) based on consent (Art. 6(1)(a)), contractual necessity (Art. 6(1)(b)), and our legitimate interest in providing reliable, secure software (Art. 6(1)(f)):
Contact Inquiries
When you submit our contact form, we collect your name, email address, topic, and message content solely to respond to your inquiry.
Technical Server Logs
Standard diagnostic data including anonymized IP addresses, HTTP request headers, timestamps, and browser user-agent strings for security and rate-limiting.
3. Cookie & Local Storage Usage
We believe in privacy by default. LazyLabs does not employ third-party advertising cookies, cross-site behavioral tracking networks, or intrusive digital fingerprinting.
The only cookies utilized on our platform are strictly functional and necessary:
- Language Preference Cookie (e.g.
.AspNetCore.Culture/ Session): Preserves your selected UI language (English / Dutch) across navigation. - Session & CSRF Verification Cookie: Protects contact form submissions against Cross-Site Request Forgery attacks.
- Administrative Authentication Cookie (
LazyLabs.AdminAuth): A secure, HttpOnly, SameSite=Strict cookie granted exclusively to authorized studio operators.
4. Third-Party Sub-Processors
To provide high-performance digital services, we partner with vetted infrastructure providers who uphold stringent EU privacy standards:
Paddle (Merchant of Record)
Financial transactions and software license checkouts for our products are handled by Paddle.com Market Ltd (or its EU affiliate Paddle Payments Ireland Ltd) acting as Merchant of Record. Paddle processes payment instruments, invoices, and VAT calculations under their independent PCI-DSS Level 1 certified privacy architecture. LazyLabs never receives or stores your credit card details.
Groq Inc. (High-Speed AI Inference)
For our micro-SaaS application PanicDM, encounter generation prompts (e.g., party level, monster biome, tactical difficulty) are routed through Groq, Inc. via secure TLS 1.3 endpoints. Groq processes generation queries ephemerally in volatile memory. No customer prompts or outputs are retained or used to train foundational AI models.
MailerSend / MailerLite (Email Deliverability)
Transactional notification emails generated from our contact form are routed through MailerSend/MailerLite. Your email address is strictly used to deliver communications you initiated. We do not sell or rent marketing lists.
5. Data Retention Periods
Contact form inquiries and correspondence are retained for a maximum of 12 months following resolution, after which they are securely purged unless required for legal or tax compliance. Server diagnostic logs are automatically cycled and deleted every 30 days.
6. Your Rights Under the GDPR
As a European Union citizen or user within the European Economic Area, you hold extensive rights concerning your personal information:
- Right of Access (Art. 15): Request a copy of the personal data we maintain about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
- Right to Erasure (Art. 17): Request deletion of your personal data ("Right to be Forgotten").
- Right to Restriction of Processing (Art. 18): Restrict processing under contested circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing carried out under legitimate interest grounds.
To exercise any of these statutory rights, submit an email to [email protected]. We respond to verified requests within 30 days free of charge.
You also have the legal right to lodge a complaint with your local supervisory authority. For Belgium, this is the Gegevensbeschermingsautoriteit (GBA) / Autorité de protection des données (APD), Drukpersstraat 35, 1000 Brussels (gegevensbeschermingsautoriteit.be).
7. Updates to this Policy
We may revise this Privacy Policy periodically to reflect technical or regulatory developments. Any material amendments will be posted on this page with an updated revision date.