Legal
Privacy policy
Last updated: 17 July 2026
This privacy policy explains, in accordance with Article 13 of the General Data Protection Regulation (GDPR), how personal data is processed when you visit asili-gifts.com or voluntarily share feedback about the ASILI concept.
1. Controller
- Telephone
Privacy enquiries can be sent to asili@raykast.com.
2. Purpose of the concept test
ASILI is not currently a shop or a bookable service. The website is intended to understand interest in a potential curated-gifting service. We do not use automated audience measurement. Interest is assessed only from messages that people choose to send.
3. Hosting and server logs
The website is hosted as an Azure Static Web App by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. When you access the website, the hosting infrastructure processes connection data required for technical operation. This may include your IP address, date and time, requested file or URL, referrer URL, browser type, operating system, amount of data transferred and HTTP status.
This processing is necessary to deliver the website, maintain its stability and security, and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of this website. Log data is not used to create visitor profiles and is retained only for as long as necessary for operation, fault analysis, attack prevention or legal evidence.
4. Contact form and direct contact
If you use the contact form or contact us by email, we process your name, email address, message and technically necessary transmission data. We use these details to evaluate interest and requirements relating to the ASILI concept, answer your questions and—only if you request it—continue the conversation.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to assess genuine demand for the product concept presented, develop the concept using voluntary feedback and respond appropriately to incoming messages. Providing your details is voluntary. Without the fields marked as required, we cannot technically transmit the form message. Your feedback is not an order and is not used to take steps before entering into a contract.
The form is processed by an Azure Function. For delivery, the message is transferred through the Microsoft Graph API to a Microsoft 365 mailbox and delivered to asili@raykast.com. The website code does not store contact enquiries in its own database and does not write names, email addresses or message content to application logs. The message is stored in the destination mailbox in the same way as a directly sent email.
We delete messages once the evaluation and any correspondence you requested have been completed and no statutory retention obligation or legitimate interest requires further retention. You may object to further processing of your feedback at any time using the email address above.
5. Cookies, analytics and marketing
asili-gifts.com currently uses no analytics, marketing or personalisation services. During a normal visit, the website code sets no non-essential cookies. We do not track visitors for advertising purposes or create visitor profiles.
6. Locally hosted fonts, icons and graphics
The Manrope and Cormorant Garamond fonts and the symbols from Bootstrap Icons are served directly by asili-gifts.com. Your browser therefore makes no connection to Google Fonts, an icon CDN or another external font or icon provider.
The interactive box studio also runs entirely locally in your browser. It uses our own graphics engine (WebGPU) served directly by asili-gifts.com, with no external libraries or CDNs. Your arrangement is processed exclusively on your device and is neither transmitted to us or third parties nor stored; only if you hand it to the contact form yourself does it become part of your message.
7. Recipients, processing and international transfers
Personal data is accessible only to people and service providers who need it for the relevant purpose. These include the website operator and Microsoft as the provider of the hosting, function and Microsoft 365 infrastructure. We do not sell personal data or disclose it for advertising purposes.
Microsoft processes data under the contractual data-protection terms for Microsoft products and services. Where data is processed outside the European Economic Area, Microsoft relies in particular on appropriate safeguards under Article 46 GDPR, including the EU Standard Contractual Clauses.
8. Retention
We retain personal data only for as long as the relevant purpose continues. It is then deleted or anonymised unless statutory retention periods, the establishment or defence of legal claims, or security requirements justify longer retention. These criteria apply alongside the contractual retention and deletion rules of the Microsoft services used.
9. Your rights
Subject to the applicable statutory conditions, you have the right to:
- access your personal data (Article 15 GDPR),
- rectify inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR).
Please use the contact options above to exercise your rights. You may also lodge a complaint with a data-protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR).
10. Automated decision-making
We do not use solely automated decision-making, including profiling, within the meaning of Article 22 GDPR.
11. Security and updates
We use appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. Data is transmitted using HTTPS encryption. We will update this policy if the website's features, service providers or legal requirements change.
