top of page

Privacy Policy

How we collect, use, and protect your information.

CRISTINA LAROSE — PRIVACY POLICY


This Privacy Policy explains how personal data are collected, used, stored and protected in connection with the Cristina Larose website, member services, digital products and Cristina Larose Artificial Intelligence Twin (“AI Twin”).


1. DATA CONTROLLER


The data controller for the Cristina Larose service is:
WORLDCAPE INTERNATIONAL OÜ
Registry code: 14631046
Viru väljak 2
10111 Tallinn
Estonia
Consumer-facing brand: Cristina Larose
Website: www.cristinalarose.com
Business contact details are available through the website’s business-contact interface.
WORLDCAPE INTERNATIONAL OÜ determines the purposes and means of processing personal data relating to the Cristina Larose service, except where a third-party provider acts as an independent controller under applicable law.


2. SCOPE OF THIS POLICY


This Policy applies to personal data processed in connection with:
the Cristina Larose website;
member registration and account access;
purchase and administration of digital packages;
members-only digital content;
the Cristina Larose AI Twin;
customer-service and data-protection requests;
security, abuse prevention and technical operation of the service.
The Cristina Larose AI Twin is an artificial-intelligence-powered digital service. Users communicate with AI, not live with Cristina Larose personally.


3. CATEGORIES OF PERSONAL DATA WE MAY PROCESS


Depending on the services used, we may process:
Account and identity data
member/account identifiers;
account status;
contact information supplied through the website;
authentication-related technical identifiers.
AI Twin profile data
Users may voluntarily provide profile information such as:
preferred name;
preferred language;
gender description;
age range;
general location.
Conversation data
When a user communicates with the AI Twin, we may process:
messages submitted by the user;
AI-generated responses;
conversation context;
structured or derived conversational memory;
technical identifiers used to maintain conversation continuity.
Package and access data
We may process:
package type;
purchase/order identifiers;
access status;
message allowance;
message usage;
activation, expiry or entitlement information.
Transaction and accounting data
We may process information necessary to:
identify a transaction;
administer payment;
issue or maintain accounting records;
handle refunds or disputes;
comply with tax and accounting obligations.
Payment-card details are normally processed by the applicable payment provider and are not intended to be stored by the AI Twin system.
Technical and security data
We may process limited technical information such as:
timestamps;
request identifiers;
service logs;
security events;
error information;
information necessary to prevent abuse, duplicate requests, fraud or unauthorised access.


4. INFORMATION USERS SHOULD NOT SUBMIT


AI Twin conversations should be treated as communications with an online digital service.
Users should not submit information that is unnecessary for use of the service, including:
passwords;
authentication codes;
banking credentials;
complete payment-card details;
passport or national identification numbers;
government login credentials;
private encryption keys;
confidential access codes;
unlawfully obtained information;
highly confidential third-party or business information.
Users should exercise particular caution before voluntarily submitting medical, sexual, intimate, financial, family or other highly sensitive personal information.
If you would not want particular information processed by an online service, do not submit it to the AI Twin.
The AI Twin does not create doctor-patient, lawyer-client, therapist-patient or other professionally privileged confidentiality.


5. PURPOSES OF PROCESSING


We may process personal data where necessary to:
create and administer member accounts;
provide purchased digital services;
provide and personalise the AI Twin experience;
maintain conversation continuity;
administer package access and message allowances;
provide members-only content;
process and reconcile transactions;
provide customer support;
respond to privacy and legal requests;
prevent fraud, abuse and unauthorised access;
secure and troubleshoot the service;
protect legal rights and establish, exercise or defend legal claims;
comply with tax, accounting and other legal obligations.
We do not require users to disclose more personal information than reasonably necessary for the service.


6. LEGAL BASES FOR PROCESSING


Depending on the circumstances, processing may be based on one or more lawful bases under applicable data-protection law, including:
Performance of a contract
Processing may be necessary to provide an account, purchased package, members-only access, AI Twin conversation service or other digital functionality requested by the user.
Legal obligation
Certain transaction, accounting, tax, fraud-prevention or regulatory information may need to be processed or retained because the operator is legally required to do so.
Legitimate interests
Where appropriate and subject to applicable balancing requirements, processing may be necessary for legitimate interests such as:
operating and securing the service;
preventing fraud and abuse;
maintaining service reliability;
troubleshooting;
enforcing contractual rights;
defending legal claims.
Consent
Where applicable law requires consent for a specific activity, consent will be requested separately.
Consent is not treated as the sole legal basis for all processing carried out through the service.


7. AI TWIN CONVERSATION PROCESSING


The AI Twin is a generative artificial-intelligence system.
Conversation data may be transmitted to and processed by technology providers used to generate, deliver, secure or operate AI responses.
The AI Twin may use:
current user messages;
conversational profile information;
relevant prior context;
structured or derived memory;
authorised Cristina Larose persona and knowledge materials;
capabilities of the underlying AI technology.
An AI-generated response is not private correspondence personally written by Cristina Larose.


8. AUTOMATED PROCESSING


Artificial intelligence is used to generate conversational responses and may automatically analyse conversation context to produce relevant output.
This automated processing is primarily used to provide the interactive AI Twin service.
The service is not intended to use AI Twin conversation generation to make decisions producing legal effects or similarly significant effects concerning a user solely through automated decision-making.


9. DATA MINIMISATION


We aim to process only personal data reasonably necessary for the relevant service, security, contractual or legal purpose.
Users are encouraged to minimise the amount of personal information voluntarily included in AI Twin conversations.


10. DATA RETENTION — AI TWIN PROFILE AND CONVERSATION DATA


Where an AI Twin member profile has remained inactive for three consecutive months, eligible conversational profile data, conversation history and AI Twin conversational-memory data associated with that inactive profile are scheduled for deletion under the service’s retention procedures.
For this purpose, inactivity generally means that the relevant member has not actively used the AI Twin conversational service during that period.
Data scheduled for deletion may include, as applicable:
AI Twin conversational profile information;
stored conversation history;
derived conversational memory;
continuity data no longer required to provide the service.
The three-month policy does not require deletion of information that must be retained for another lawful purpose.


11. EARLY DELETION REQUESTS


Users may request deletion of eligible personal data before the normal three-month inactivity period ends.
Requests may be submitted through the administration or privacy contact method provided by the website.
We may take reasonable steps to verify the identity or account authority of the requester.
Valid requests will be handled without undue delay. Information concerning action taken will normally be provided within one month, subject to any extension permitted by applicable data-protection law for complex or numerous requests.


12. DATA THAT MAY BE RETAINED LONGER


Some information may need to be retained after conversational data have been deleted.
This may include information required for:
accounting;
taxation;
invoices;
payment reconciliation;
transaction evidence;
fraud prevention;
security investigations;
dispute resolution;
establishment, exercise or defence of legal claims;
other mandatory legal obligations.
Under Estonian accounting law, accounting source documents and certain related business records may be required to be preserved for seven years from the end of the relevant financial year.
Where information is retained solely for such purposes, it will not be retained merely for continued AI Twin conversational personalisation.


13. SERVICE PROVIDERS AND RECIPIENTS


Personal data may be processed by service providers where reasonably necessary to operate the service.
These may include providers of:
website and member infrastructure;
hosting and cloud infrastructure;
artificial-intelligence technology;
payment processing;
transaction administration;
security and technical services;
professional accounting, legal or compliance services where necessary.
Service providers are given access only as appropriate for their role and subject to applicable contractual and legal safeguards.
Some providers may act as processors on our behalf. Others, particularly payment or other regulated providers, may act as independent controllers for particular processing activities.


14. INTERNATIONAL DATA TRANSFERS


Some technology providers used by the service may process personal data outside Estonia or outside the European Economic Area.
Where personal data are transferred to a country not covered by an applicable adequacy decision, appropriate safeguards required by data-protection law will be used where applicable, such as European Commission Standard Contractual Clauses or another legally recognised transfer mechanism.
Information about applicable safeguards may be requested through the privacy contact method provided on the website.


15. SECURITY


We use reasonable technical and organisational measures intended to protect personal data against:
unauthorised access;
unlawful processing;
accidental loss;
destruction;
alteration;
misuse.
No internet-based service can guarantee absolute security.
Users are responsible for protecting their own account credentials and should not share passwords or authentication information with other persons.


16. ILLEGAL OR ABUSIVE CONTENT


The service must not be used to request, facilitate or conceal unlawful activity under applicable European Union law, Estonian law or the law applicable in the user’s jurisdiction.
Sexual exploitation or sexual content involving minors is strictly prohibited.
Safety and security systems may process, reject or record limited technical information relating to prohibited or abusive activity where reasonably necessary to secure the service, prevent abuse, comply with legal obligations or establish, exercise or defend legal claims.
Users should not submit unlawful or highly harmful material merely to test the AI.


17. USER RIGHTS


Subject to applicable law and the circumstances of the processing, users may have rights including:
the right to obtain information about processing;
the right of access;
the right to rectification;
the right to erasure;
the right to restriction of processing;
the right to data portability where applicable;
the right to object where applicable;
the right to withdraw consent where processing is based on consent, without affecting prior lawful processing;
the right to lodge a complaint with a competent data-protection supervisory authority.
These rights are not absolute. Applicable law may permit or require certain information to be retained or processing to continue in particular circumstances.


18. REQUESTS RELATING TO PERSONAL DATA


Privacy requests should be made through the privacy or business-contact method provided on the Cristina Larose website.
To protect users from unauthorised deletion or disclosure, reasonable identity verification may be required before a request is completed.


19. CHILDREN


Restricted Cristina Larose AI Twin services are intended for adults.
The service is not intended to knowingly collect personal data from children through adult-only functionality.
Users must not submit sexual content involving minors or use the service to facilitate exploitation, grooming or abuse of minors.


20. THIRD-PARTY INFORMATION


Users should avoid providing identifying, confidential or sensitive information about another person unless they have a lawful basis and appropriate authority to do so.
The availability of an AI conversation field does not authorise a user to upload unlawfully obtained information or violate another person’s privacy rights.


21. COOKIES AND WEBSITE TECHNOLOGIES


The website may use cookies or similar technologies required for:
authentication;
member sessions;
security;
website functionality;
preferences;
analytics or other functions where permitted.
Where required by law, non-essential cookies or similar technologies will be subject to the applicable consent mechanism.
Additional information may be provided through the website’s Cookie Policy or cookie settings.


22. CHANGES TO THIS PRIVACY POLICY


This Privacy Policy may be updated to reflect changes in:
the service;
technology;
legal requirements;
data-processing practices.
The current version will be made available through the website.
Material changes will be communicated where required by applicable law.


23. RELATIONSHIP WITH THE LEGAL NOTICE AND TERMS


This Privacy Policy should be read together with:
the applicable Terms & Conditions;
the Plan Policy;
the Cristina Larose AI Twin Legal Notice;
applicable checkout information.
The full AI Twin Legal Notice is available at:
www.cristinalarose.com/legal
Where mandatory law conflicts with this Policy, mandatory law prevails.


DATA CONTROLLER
WORLDCAPE INTERNATIONAL OÜ
Registry code: 14631046
Viru väljak 2
10111 Tallinn
Estonia
Consumer-facing brand: Cristina Larose
Website: www.cristinalarose.com

privacy@cristinalarose.com


Last updated: 8 August 2026

bottom of page