Paddle verification checkpoint
Privacy notice
Last reviewed: 3 September 2026. This notice covers the live digital sale of The Raven’s Forest through Studio ErgoLub8 at studioergolub8.com. Paddle processes the live one-time payment and the protected collection is released only after signed transaction confirmation.
Controller
Panagiotis Zografos, publicly known as Panos Zografos, an individual self-published author trading under the publisher identity Studio ErgoLub8, Athens, Greece, is the data controller for the creator-side processing described here. Privacy and customer-support requests may be submitted through the secure contact form.
Data collected
The public catalogue does not require a customer account. For live checkout, the minimum necessary data may include the buyer’s email address, billing country and address, transaction identifiers, amount, currency, consent record, fraud and security signals, download entitlement, download count and technical request logs. The contact form collects the sender’s name, reply email, subject, message, language and consent record.
Purposes and legal bases
Data is processed to take steps requested by the buyer and perform the digital purchase contract; comply with tax, accounting, consumer-protection and fraud-prevention duties; protect the service and buyers from abuse; and establish or defend legal claims. Marketing use requires a separate lawful basis and is not created by purchasing this collection.
Paddle
Paddle acts as Merchant of Record and may process billing, payment, device, fraud-prevention, tax and authentication data under its own terms and privacy information. Complete payment-card details are entered into Paddle Checkout and are not stored by Studio ErgoLub8.
Storage and recipients
Necessary transaction and entitlement records are stored in the site’s protected infrastructure. The private product archive is stored separately and is not publicly listed. Data is disclosed only to service providers needed for hosting, payment, security, transactional delivery, accounting or legal compliance, and to authorities where legally required.
Retention
Download entitlements remain active for 30 days and permit up to five completed downloads. Transaction, consent, tax and accounting records are retained for the applicable statutory period, normally five years after the relevant tax year, and longer only where an authority, dispute or legal claim requires it. Contact messages are retained only for correspondence, support and related legal needs. Security logs are retained only as long as reasonably necessary for investigation and protection.
International transfers
Payment and hosting providers may process data outside the buyer’s country. Where required, the provider must use a recognised legal transfer mechanism and appropriate safeguards.
Cookies and advertising
The Shop assigns random, anonymous browser and session identifiers in first-party local and session storage. They are used only to avoid counting the same person or session repeatedly in aggregate funnel reporting; they do not create an account and can be removed through the browser’s site-data controls.
For visitors in the United States, the Shop may use the Meta Pixel and Meta Conversions API to measure a Shop visit, the opening of the secure checkout and a verified completed purchase. This measurement may use Meta browser identifiers, the referring campaign, IP address and browser information. Payment-card details are never sent to Meta. Visitors outside the United States do not receive this advertising tracking from the Shop. Technically necessary storage remains in use for security, checkout and protected delivery.
Your rights
Depending on applicable law, a buyer may request access, correction, deletion, restriction, objection or portability through the secure contact form, and may complain to a competent data-protection authority, including the Hellenic Data Protection Authority. These rights may be limited where records must be kept by law.