Privacy Policy
Last updated: June 29, 2026
1. Who we are (Data Controller)
This website (victoriadlaine.com) is operated by Victoria D. Laine, author (the “Author”, “we”, “us”). For any privacy request you can contact us at privacy@victoriadlaine.com.
2. Scope
This policy explains how we process personal data when you visit this website. It is designed to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679 — “GDPR”), the ePrivacy Directive (2002/58/EC) as implemented in EU Member States, the UK GDPR and Data Protection Act 2018, and applicable U.S. state privacy laws including the California Consumer Privacy Act as amended by the CPRA (collectively “CCPA”), the Virginia VCDPA, Colorado CPA, Connecticut CTDPA and similar statutes.
3. What data we collect
- Browsing data: IP address (truncated where possible), browser/device type, language, referrer, pages visited, timestamps.
- Cookie & similar identifiers: see our Cookie Policy.
- Analytics & tag data: events collected through Google Tag Manager and Google Analytics 4 (pseudonymous identifiers, interaction events).
- Voluntary data: any information you send us by email or via social channels.
We do not knowingly collect data from children under 16 (or under 13 in the U.S.).
4. Purposes & legal bases (GDPR Art. 6)
- Operate the site (security, basic logs) — legitimate interest (Art. 6(1)(f)).
- Analytics & measurement via GA4/GTM — your prior consent (Art. 6(1)(a) and ePrivacy Art. 5(3)).
- Linking to Amazon for book sales — legitimate interest in promoting the Author’s work. Purchases happen on amazon.com under Amazon’s own policies.
- Replying to your messages — performance of pre-contractual steps / legitimate interest.
- Legal obligations — Art. 6(1)(c) where applicable.
5. Sharing & recipients
We share personal data only with:
- Hosting & CDN: Lovable / Cloudflare infrastructure providers.
- Analytics: Google LLC / Google Ireland Ltd (GA4 + Tag Manager).
- Amazon: when you click an outbound link to a book listing.
- Authorities: when legally required.
We do not sell personal information and we do not share it for cross-context behavioral advertising as defined under the CCPA.
6. International transfers
Some recipients (e.g., Google, Amazon, Cloudflare) are located in the United States. Transfers outside the EEA/UK rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses (Art. 46 GDPR) with supplementary measures.
7. Retention
- Server logs: up to 12 months.
- Analytics events: up to 14 months (GA4 default).
- Email correspondence: as long as needed to handle your request, then archived for legal limitation periods.
8. Your rights
Under GDPR / UK GDPR you can: access, rectify, erase, restrict, port, object, and withdraw consent at any time. You may lodge a complaint with your supervisory authority (e.g., the Italian Garante, the Irish DPC or the UK ICO).
Under U.S. state laws (CCPA/CPRA, VCDPA, CPA, CTDPA, etc.) you have the right to: know, access, delete, correct, opt out of sale/sharing and targeted advertising, and to be free from discrimination for exercising these rights. To exercise any right, email privacy@victoriadlaine.com. We respond within 30 days (GDPR) / 45 days (CCPA).
“Do Not Sell or Share My Personal Information”: we do not sell or share personal information. We also honor Global Privacy Control (GPC) signals.
9. Security
We apply appropriate technical and organizational measures (TLS in transit, access controls, hardened infrastructure). No method is 100% secure.
10. Changes
We may update this policy. Material changes will be highlighted at the top of this page with a new “Last updated” date.
11. Contact
Victoria D. Laine — privacy@victoriadlaine.com