Who we are
Lazy Lab (“Lazy Creator AI Lab”, “we”, “us”) is an AI-native creative studio producing commercials, films, music videos, animation and digital-influencer content. This policy covers this website and enquiries made through it.
Registered entity: [legal entity name]. Registered address: [registered address]. For anything in this policy, write to [email protected].
Data we collect
We collect only what you give us and what our hosting infrastructure records automatically.
- Enquiry details you submit: name, email address, company or brand name, the type of work you’re after, and the message you write.
- Correspondence: emails, WhatsApp or call notes exchanged while scoping and running a project.
- Technical data: IP address, browser and device type, referring page, pages viewed and timestamps — logged by our host and CDN for security and to keep the site running.
- Aggregate usage data: anonymous or pseudonymous statistics about how the site is used.
We do not ask for and do not want sensitive personal data — government identifiers, financial account numbers, health or biometric data — through this website. Please don’t send it in the contact form.
How we use it
- To reply to your enquiry, quote, and scope work.
- To deliver, invoice and support projects you engage us for.
- To keep the site secure, diagnose faults and prevent abuse.
- To understand which work resonates, so we can improve the site.
- To meet legal, tax and accounting obligations.
We do not sell personal data. We do not use your enquiry to train AI models, and we do not use your business’s confidential material for anything other than your project.
Legal basis
For visitors in India, we process personal data with your consent under the Digital Personal Data Protection Act, 2023, and for the legitimate uses that Act permits — including responding to a request you voluntarily made. Submitting the contact form is your consent to be contacted about your enquiry; you can withdraw it at any time.
For visitors in the UK/EEA, we rely on consent for enquiries and marketing, contract for delivering engaged work, legitimate interests for site security and analytics, and legal obligation where records must be kept.
Cookies & analytics
This site is deliberately light. We use only what is needed to make pages work and to count visits in aggregate; we do not run third-party advertising trackers or sell audience data. Your browser can block or clear cookies at any time — the site will still work.
Videos on our Work page are served from our own storage. Where a page embeds a third-party player, that provider may set its own cookies under its own policy once you press play.
Project & client material
When you engage us, you may send us brand assets, scripts, product shots, footage, voice recordings or reference images. We treat these as confidential and use them only to produce your project.
If material features a real person’s face, voice or likeness, you confirm you hold the consents needed for us to use it in the ways your brief describes. We will ask for written confirmation before producing any work built on a real individual’s likeness. See our Terms of Service for the full position.
Retention
- Enquiries that don’t become projects: up to 24 months, then deleted.
- Project files and correspondence: for the life of the engagement and up to [3] years after, so we can support and evidence the work.
- Invoices and tax records: as long as tax and company law requires.
- Server and security logs: short rolling periods, typically under 90 days.
You can ask us to delete your data sooner — see your rights.
Your rights
Subject to local law, you can ask us to:
- Confirm what personal data we hold about you and give you a copy.
- Correct data that is wrong, incomplete or out of date.
- Erase data we no longer have a reason to keep.
- Withdraw consent — including opting out of any future emails from us.
- Restrict or object to particular processing, or ask for portability, where that right applies to you.
- Nominate someone to exercise your rights if you are unable to (an India DPDP right).
Email [email protected] and we will respond within 30 days. We may need to verify your identity first. If you’re unhappy with our response, you can complain to your data protection authority — in India, the Data Protection Board.
Security
We use access-controlled cloud storage, encrypted transport (HTTPS), limited team access on a need-to-know basis, and provider-side protections for our hosting. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
International transfers
We are based in India and use global cloud providers, so your data may be processed in other countries. Where data leaves your region, we rely on the transfer mechanisms our providers offer — such as standard contractual clauses — and on the destinations permitted by applicable law.
Children
This site and our services are for businesses and adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We may update this policy as our services or the law change. The “last updated” date at the top always reflects the current version. Material changes will be highlighted on this page.
Contact & grievances
Data protection / grievance contact: [name, title], [email protected]. Post: [postal address].
Note for Lazy Lab: items marked in orange are placeholders to fill before launch — legal entity name, registered and postal address, grievance officer, and retention period. This policy is a solid general baseline, not legal advice; have a lawyer confirm it against the DPDP Act 2023 and any client contracts that impose stricter terms.