Version: 1.0 · Effective Date: 10 May 2026
This Privacy Policy explains how we collect, use, share, retain, and protect personal data in connection with the AI SaaS Financial Model and related materials. It is issued under Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree no. 196/2003, as amended by Decree no. 101/2018 (the “Italian Codice Privacy”).
In short
• We collect only what we need to deliver the Licensed Product and meet our legal obligations.
• Most of your checkout data is collected directly by the third-party platform (Gumroad or Lemon Squeezy), not by us.
• We do not sell your personal data. We do not send marketing emails without your separate consent.
• Order and transaction records are retained for ten (10) years to comply with Italian fiscal law. Other data has shorter retention.
• You have rights of access, rectification, erasure, restriction, portability, objection, and complaint — see Section 10.
• Privacy contact: aisaas@perelygin.expert.
1. Who We Are
Dmitry Perelygin (“Licensor”, “we”, “us”, “our”) is the data controller responsible for the personal data processed in connection with the AI SaaS Financial Model and related materials (collectively, the “Licensed Product”).
Controller details:
- Name: Dmitry Perelygin
- Legal form: Italian sole trader (ditta individuale)
- Partita IVA: 04180740047
- Codice fiscale: PRLDTR75S12Z154H
- Registered address: Corso Alcide De Gasperi 53, 12100 Cuneo (CN), Italy
- Contact email: aisaas@perelygin.expert
- Website: https://perelygin.expert/
For all privacy-related matters, including exercising the rights described in Section 10, contact us at aisaas@perelygin.expert.
Data Protection Officer. Given the limited nature, scope, and scale of our processing (see Section 5), we are not required to appoint a Data Protection Officer under Article 37 GDPR. All privacy-related queries are handled by the Controller directly at aisaas@perelygin.expert.
2. Scope of This Policy
Important clarification regarding the purchase flow. The purchase of the Licensed Product takes place entirely on the third-party platform (Gumroad or Lemon Squeezy). When you click “Buy” on Licensor’s website, you are redirected to the platform’s checkout, where the platform — not Licensor — collects your full checkout data (including payment card details, billing address, name, country, and tax-related information) and acts as the independent controller of that data for purposes of payment processing, tax collection, and fraud screening. Licensor receives from the platform only a limited subset of post-purchase data necessary to deliver the Licensed Product and to comply with Italian commercial and fiscal law (see Section 3). This Privacy Policy describes Licensor’s processing of that limited subset, not the platform’s own processing.
This Policy describes the personal data we process when you:
- Visit our website at https://perelygin.expert/.
- Purchase the Licensed Product through Gumroad, Lemon Squeezy, or any direct channel we operate (in which case post-purchase data is shared with us by the platform).
- Contact us by email for support, refund, or any other reason.
- Receive a copy of the Licensed Product that contains buyer-specific watermarks or tracing markers (once such markers are implemented; see Section 3(d)).
- Are otherwise in contact with us in connection with the Licensed Product.
This Policy does not describe the practices of third parties that operate their own services, including Gumroad, Lemon Squeezy, and any other linked third-party service. Those providers operate under their own privacy notices, available from their respective websites.
3. What Data We Collect
We collect the following categories of personal data:
- (a) Identification and contact data received from the platform after purchase: email address; and where you provided them to the platform at checkout, also your name and country of billing. Identification data received directly from you: where you contact Licensor by email, the email address you use and any information you choose to include in your message; where you complete a “Licensee Entity” identification field in connection with the License Agreement, the name of your Licensee Entity.
- (b) Transaction data received from the platform: order ID, date and time of purchase, currency, amount paid, payment method type, and platform identifier (Gumroad or Lemon Squeezy). We do not see or store your full payment card number or bank account details — those are processed by the platform.
- (c) Assent data received from the platform: Licensor relies on the platform’s checkout records as evidence of your assent to the License Agreement, Disclaimer, Terms of Sale, and Refund Policy. The platform records the timestamp of your acceptance and the version of the documents accepted (where its checkout flow includes a checkbox referencing Licensor’s documents). Licensor receives from the platform the order ID, timestamp, and confirmation of completed checkout, which together constitute Licensor’s record of your assent. Licensor does not directly collect your IP address or browser user-agent at the platform’s checkout.
- (d) Product-linked identifiers (where applicable): where Licensor introduces buyer-specific watermarks, licence keys, or tracing markers in future copies of the Licensed Product (License Agreement, Section 6), Licensor will retain the mapping between order ID, email address, and the identifier. As of the effective date of this Privacy Policy, such markers are not yet implemented; this subsection is forward-looking and will become operational once watermarking is introduced.
- (e) Communications data: emails you send to us and our responses, including any screenshots, descriptions, or attachments you share for support or refund purposes.
- (f) Website data: limited technical information collected automatically when you visit Licensor’s website at https://perelygin.expert/ (such as IP address, browser identifier, requested URL, and timestamp). See Section 9.
We do not knowingly collect special categories of personal data (such as health, biometric, or data revealing racial or ethnic origin, political opinions, religious beliefs, or trade union membership). Please do not share such information with us.
Providing the data described in (a)–(d) above is necessary for us to deliver the Licensed Product and to comply with our legal obligations. If you do not provide it (or if the platform does not share it with us), we cannot complete the purchase or maintain your access to the Licensed Product.
4. Where We Collect It From
We collect personal data from the following sources:
- Directly from you when you contact us by email or otherwise interact with us outside the platform’s checkout.
- Automatically when you visit our website (technical and cookie data — see Section 9).
- From Gumroad and Lemon Squeezy after you complete a purchase through them. They pass to us a limited subset of order details (as described in Section 3), but not your payment card or bank account number.
5. Why We Use Your Data and the Legal Basis
We process personal data for the following purposes, on the following legal bases under GDPR Article 6:
- (a) To deliver the Licensed Product and perform the contract you entered into with us. Lawful basis: performance of a contract (Art. 6(1)(b)). Without this data we cannot deliver the product or maintain access.
- (b) To comply with Italian tax and accounting law. Licensor operates under the regime forfettario. Under this regime, the principal retention obligation arises from Article 2220 of the Italian Civil Code (Codice civile), which requires retention of accounting records, invoices, and related correspondence for ten (10) years, and from DPR no. 600/1973 in respect of income tax records. Lawful basis: legal obligation (Art. 6(1)(c) GDPR).
- (c) To handle refund, support, and dispute requests, including chargebacks. Lawful basis: performance of a contract (Art. 6(1)(b)) and our legitimate interest in resolving customer requests and defending claims (Art. 6(1)(f)).
- (d) To embed buyer-specific watermarks and tracing markers in the Licensed Product, and to maintain the mapping between order ID, email, and identifier, in order to detect and respond to unauthorised distribution of the Licensed Product (License Agreement, Section 6). Lawful basis: our legitimate interest in protecting our intellectual property and the value of the Licensed Product for paying customers (Art. 6(1)(f)). You may exercise the right to object on grounds relating to your particular situation, as described in Section 10. As of the effective date of this Privacy Policy, watermarking is not yet implemented; this provision will become operational once it is.
- (e) To defend ourselves against chargebacks, fraud, or other legal claims. Lawful basis: legitimate interest (Art. 6(1)(f)), legal obligation where applicable (Art. 6(1)(c)), and the establishment, exercise, or defence of legal claims.
- (f) Marketing communications (future use, subject to your separate consent). Licensor does not currently send marketing emails or newsletters. In the future, Licensor may offer a separate opt-in subscription for product updates, AI SaaS finance insights, or similar communications. If such a service is launched, processing for marketing purposes will be based on your explicit consent (Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of processing before withdrawal. You may opt out by clicking the unsubscribe link in any marketing email or by emailing aisaas@perelygin.expert.
6. Who We Share It With
We do not sell personal data. We share personal data only with the following categories of recipients, all of whom are bound by appropriate confidentiality, security, and (where applicable) GDPR-compliant data processing agreements:
- (a) Payment and sales platforms acting as merchant of record and independent controllers: Gumroad, Inc. (United States) and Lemon Squeezy LLC (United States). These platforms collect your checkout data directly from you and act as the independent controllers of that data for purposes of payment processing, tax handling, refund processing, and dispute resolution. Licensor does not “share” your full checkout data with these platforms — they collect it directly at their own checkout pages. The platforms in turn share with Licensor, after a completed purchase, a limited subset of post-purchase data as described in Section 3. Each platform operates under its own privacy notice, available on its website (Gumroad: https://gumroad.com/privacy; Lemon Squeezy: https://www.lemonsqueezy.com/privacy).
- (b) Email provider: Licensor uses an email service provider to operate the address aisaas@perelygin.expert. The provider processes emails sent to and from this address as a processor on Licensor’s behalf, under the provider’s standard terms and data processing arrangements. The provider is established within the European Economic Area or in a jurisdiction recognised as providing an adequate level of data protection under Article 45 GDPR, or operates under appropriate safeguards as described in Section 7.
- (c) Operational tools used by Licensor: Licensor maintains internal records of orders (such as order ID, email, purchase date, and version of documents accepted) on Licensor’s own equipment, protected by the security measures described in Section 13. As of the effective date of this Privacy Policy, Licensor does not use external automation platforms, customer relationship management (CRM) tools, or third-party spreadsheet/database services for processing personal data of customers. Should Licensor introduce such operational processors in the future, this Privacy Policy will be updated and the changes mechanism described in Section 15 will apply.
- (d) Website hosting and infrastructure providers: the provider hosting Licensor’s website at https://perelygin.expert/ processes limited technical data as a processor.
- (e) Professional advisers and authorities: tax advisers (commercialista), legal counsel, and accounting professionals, and competent authorities (tax authorities, courts, supervisory authorities) where required by law.
- (f) Successor in interest: in the event of a merger, acquisition, or sale of substantially all of Licensor’s assets, personal data may be transferred to the successor entity, subject to this Policy or an equivalent policy.
7. International Transfers
Some of our processors, including Gumroad and Lemon Squeezy, are located in the United States. Where personal data is transferred outside the European Economic Area, transfers are made under appropriate safeguards, including:
- (a) the EU-US Data Privacy Framework, where the recipient is certified under that framework;
- (b) Standard Contractual Clauses (SCCs) approved by the European Commission; and
- (c) any equivalent safeguard required under GDPR Articles 44–49.
You may request a copy of the relevant safeguards by emailing aisaas@perelygin.expert.
8. How Long We Keep It
We retain personal data only for as long as necessary for the purposes set out in Section 5, and in any event for the longer of:
- (a) ten (10) years from the date of purchase, in line with Italian fiscal record retention requirements under Article 2220 of the Italian Civil Code; and
- (b) the period required by other applicable law or reasonably necessary for the establishment, exercise, or defence of legal claims.
Specific retention periods:
- Transaction and order records: ten (10) years.
- Email correspondence: up to five (5) years after the relevant matter is closed, longer where the matter is ongoing.
- Watermarking mapping (order ID ↔ identifier ↔ email, once implemented): retained for as long as reasonably necessary for the establishment, exercise, or defence of intellectual property and contractual claims relating to the Licensed Product, typically up to ten (10) years from the date of purchase, or longer where an active infringement matter or related legal proceeding requires it.
- Website technical data and server logs: typically twelve (12) months, unless retained for a specific security investigation.
After these periods, personal data is deleted or anonymised.
9. Cookies and Website Data
Our website at https://perelygin.expert/ may use:
- (a) Strictly necessary cookies, required for the website to function (e.g., session cookies and load-balancing cookies). These do not require consent. Lawful basis: legitimate interest in providing a functional website (Art. 6(1)(f)).
- (b) Functional, analytics, and similar cookies, where applicable. These are loaded only with your prior consent, given through the website’s cookie banner. Lawful basis: consent (Art. 6(1)(a)).
In addition to cookies, Licensor’s hosting infrastructure may automatically log technical information about visitors, such as IP address, browser user-agent, requested URL, and timestamp. This data is retained for the period stated in Section 8 (typically 12 months) for security, debugging, and abuse prevention purposes. Lawful basis: legitimate interest (Art. 6(1)(f)).
You may withdraw consent for non-strictly-necessary cookies at any time through the cookie settings on the website. Withdrawal does not affect the lawfulness of processing before withdrawal.
The product purchase flow itself takes place on the third-party platform (Gumroad or Lemon Squeezy), whose own cookie practices apply on their domains.
Further details about the categories of cookies used on Licensor’s website, their purposes, retention, and how to manage consent are set out in Licensor’s Cookie Policy.
10. Your Rights
Under the GDPR and the Italian Codice Privacy, you have the following rights with respect to your personal data:
- (a) Right of access (Art. 15 GDPR): to obtain confirmation of whether we process your personal data, and to receive a copy of it.
- (b) Right to rectification (Art. 16 GDPR): to have inaccurate personal data corrected.
- (c) Right to erasure, the so-called “right to be forgotten” (Art. 17 GDPR): to have personal data deleted. Please note that Licensor may retain certain data despite an erasure request where retention is required by Italian fiscal law (transaction records under Article 2220 of the Italian Civil Code and DPR no. 600/1973), necessary for the establishment, exercise, or defence of legal claims (Art. 17(3)(e) GDPR), or necessary to protect Licensor’s legitimate interests in intellectual property (such as the watermarking mapping described in Section 5(d), where implemented). Where Licensor cannot delete specific data, Licensor will explain why.
- (d) Right to restrict processing (Art. 18 GDPR): to limit our processing in defined circumstances.
- (e) Right to data portability (Art. 20 GDPR): to receive your personal data in a structured, commonly-used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract.
- (f) Right to object (Art. 21 GDPR): to object, on grounds relating to your particular situation, to processing based on our legitimate interests, including the watermarking processing described in Section 5(d).
- (g) Right to withdraw consent (Art. 7(3) GDPR): to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- (h) Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): see Section 14.
To exercise these rights, email aisaas@perelygin.expert with a description of your request. We will respond within one (1) month of receipt. Where the request is complex or where we receive a high number of requests, this period may be extended by up to two (2) further months, in which case we will inform you of the extension and the reasons within the first month.
11. Children
The Licensed Product is intended for use by adults in a business or professional context. Licensor does not knowingly direct its products or services to children, and does not knowingly collect personal data from children under the age of 16 (or 14 in Italy, in accordance with Article 2-quinquies of the Italian Codice Privacy). If you believe Licensor has collected data from a minor below the applicable age, please contact aisaas@perelygin.expert and Licensor will delete it.
12. Automated Decision-Making and Profiling
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. We do not engage in profiling for marketing, behavioural advertising, or similar purposes.
13. Security
Licensor implements technical and organisational measures appropriate to the limited scope and nature of personal data processed (Article 32 GDPR), including:
- Encrypted storage: Licensor’s working device on which order records are maintained uses full-disk encryption.
- Authentication: strong device login and two-factor authentication on Licensor’s email account, platform accounts (Gumroad, Lemon Squeezy), domain registrar, and other critical service accounts.
- Access restriction: access to personal data is restricted to Licensor personally. No employees, contractors, or third parties have routine access to the internal order registry.
- Encrypted backups: Licensor maintains encrypted backups of business records, including order data, in line with Italian fiscal record retention requirements.
- Processor selection: Licensor relies on established service providers (Gumroad, Lemon Squeezy, and Licensor’s email and hosting providers) that publish their own security and data protection practices, and reviews such practices periodically.
- Forward-looking measures: where buyer-specific watermarks or tracing markers are introduced in the future (License Agreement, Section 6), the corresponding mapping registry will be subject to the same access restrictions and encryption.
No system is perfectly secure. Where Licensor becomes aware of a personal data breach affecting your data, Licensor will notify the Italian Garante within 72 hours of becoming aware where required, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Articles 33 and 34 GDPR.
14. Supervisory Authority
If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the Italian supervisory authority:
Garante per la protezione dei dati personali
- Piazza Venezia 11, 00187 Roma, Italy
- Web: www.garanteprivacy.it
- Email: protocollo@gpdp.it
You also have the right to lodge a complaint with the supervisory authority of your country of habitual residence. We encourage you to contact us first at aisaas@perelygin.expert so that we can try to resolve your concern directly.
15. Changes to This Policy
Licensor may update this Privacy Policy from time to time. The current version, with its effective date, is always available at https://perelygin.expert/privacy/. Material changes will be notified in advance where reasonably practicable. Amendments do not apply retroactively to processing that has already taken place.
16. Contact Us
For any question about this Privacy Policy or about our processing of your personal data, email us at aisaas@perelygin.expert.
This Privacy Policy operates alongside the License Agreement, Disclaimer, Terms of Sale, and Refund Policy. In matters of personal data processing, this Privacy Policy is the authoritative document, complementing rather than overriding the other documents. Where any provision of another document touches personal data, this Privacy Policy controls to the extent of any inconsistency.