Privacy Policy
Last modified: 2026-07-27
Summary
-
- 1. Introduction
- 2. Contact Information
- 3. Lawfulness of Processing
- 4. Rights of Concerned Individuals
- 5. Data Collection
- 6. Use of Your Personal Data
- 7. Sharing of Your Personal Data
- 8. Data Collected
- 8.1 Cookies
- 8.2 Consent Management via Real Cookie Banner
- 8.3 WordPress Comments
- 8.4 Contact Form 7
- 8.5 Google reCAPTCHA
- 8.6 Google Fonts
- 8.7 Google Maps
- 8.8 Jetpack Stats
- 8.9 Jetpack Comments
- 8.10 Jetpack Notifications
- 8.11 Jetpack Subscriptions
- 8.12 Akismet
- 8.13 Flickr
- 8.14 WooCommerce
- 8.15 WPForms
- 8.16 WPML
- 8.17 Vimeo
- 8.18 Cloudflare Turnstile
- 8.19 Google Analytics 4
- 9. Third-Party Service Providers
- 10. Security Measures
- 11. Changes to Our Privacy Policy
- 12. Managing Your Privacy Settings
- 13. Conclusion
1. Introduction
Welcome to www.graphicatelier.com (hereinafter referred to as the “Site”), a website operated by graphicatelier (hereinafter referred to as “We”, “Our”, or “graphicatelier”). If you use this Site, you are considered a user (hereinafter referred to as “You” or “Your” or “User”). This Privacy Policy (hereinafter referred to as the “Policy”) governs how We collect, use, store, and disclose information about You when You use this Site. This Policy also applies to information collected by third-party services We use to enhance Your experience on the Site (hereinafter referred to as “Third-Party Services”).
1.1 Objectives of this Policy
The objectives of this Policy are to inform You about:
- The types of information We collect and process
- How We use and share this information
- With whom We share this information and why
- Your data protection rights under applicable regulations
- How to exercise Your rights and manage Your privacy preferences
- Our compliance with the General Data Protection Regulation (GDPR), the ePrivacy Directive (2002/58/EC), and applicable Austrian data protection laws
1.2 What is GDPR?
GDPR, or the General Data Protection Regulation (Regulation (EU) 2016/679), is a European Union law that came into effect on May 25, 2018. GDPR aims to give EU citizens and residents full control over their personal data and to harmonise data protection regulations within the EU. It establishes strict requirements for organisations that collect, process, and store personal data, and provides individuals with enhanced rights regarding their personal information. The Regulation applies to all organisations processing personal data of data subjects residing in the EU, regardless of the organisation’s location.
1.3 Scope of this Policy
This Policy applies to all personal data processing activities carried out by graphicatelier through the Site. It covers:
- Data You provide directly to Us (e.g., through contact forms, comments, subscriptions)
- Data We collect automatically (e.g., through cookies, analytics, server logs)
- Data We receive from Third-Party Services integrated into the Site
- Data processed by third-party service providers acting on Our behalf
This Policy does not apply to third-party websites that may be linked from our Site. We encourage You to review the privacy policies of those websites before providing them with any personal information.
1.4 What Information is Collected
We collect various types of information to provide and improve Our services. This information may include, but is not limited to:
- Personal identification data: name, email address, phone number, postal address
- Technical data: IP address, browser type and version, operating system, device type
- Usage data: pages visited, time spent on the Site, referring URLs, click patterns
- Preference data: language preferences, cookie consent choices, subscription settings
- Communication data: message content submitted through forms, comment content
- Transactional data: order history, purchase information (if applicable)
The specific information We collect and how We use it is detailed throughout this Policy, particularly in Section 8 – Data Collected.
2. Contact Information
If You have any questions or concerns about this Policy or how We handle Your data, please contact Our Data Protection Officer, who is the data controller for Your personal information:
| Role | Details |
|---|---|
| Company Name | graphicatelier |
| Representative Name | Pierre Niel |
| Address | Wimmerfeld 27, 4492 Hofkirchen, Austria |
| Phone Number | +43 650 956 5454 |
| Email Address | pierre@graphicatelier.com |
| Website | www.graphicatelier.com |
You also have the right to lodge a complaint with the Austrian Data Protection Authority if You believe that the processing of Your personal data infringes the provisions of the GDPR:
| Role | Details |
|---|---|
| Authority | Austrian Data Protection Authority (Österreichische Datenschutzbehörde – DSB) |
| Address | Barichgasse 40-42, 1030 Vienna, Austria |
| Phone | +43 1 52 152-0 |
| dsb@dsb.gv.at | |
| Website | https://www.dsb.gv.at/ |
3. Lawfulness of Processing
In this section, We explain the legal bases on which We rely for processing Your personal data in accordance with the provisions of the GDPR. Each processing activity carried out by graphicatelier is grounded in at least one legal basis, as required by Article 5(1)(a) of the GDPR (lawfulness, fairness, and transparency).
3.1 Legal Basis for Processing
The processing of Your personal data is based on one or more of the following legal bases, as established in Article 6 of the GDPR:
3.1.1 Consent — Article 6(1)(a) of the GDPR
When You use this Site, You may give Your consent to the processing of Your personal data for specific purposes. Consent must be freely given, specific, informed, and unambiguous, in accordance with Article 7 of the GDPR and the requirements of the ePrivacy Directive (Article 5(3)). You have the right to withdraw Your consent at any time by referring to Section 2 – Contact Information or through the cookie settings interface. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
3.1.2 Legitimate Interests — Article 6(1)(f) of the GDPR
We may process Your data when it is necessary for Our legitimate interests or those of a third party, provided that these interests do not override Your rights and interests. Before processing data on this basis, We conduct a Legitimate Interest Assessment (LIA) in accordance with EDPB Guidelines 3/2019 on processing of personal data through video devices to ensure a proper balance between Our interests and Your rights. Our legitimate interests include: ensuring website security, improving Our services, and protecting against fraud.
3.1.3 Contractual Necessity — Article 6(1)(b) of the GDPR
Processing of Your data may be necessary for the performance of a contract to which You are a party or for taking pre-contractual steps at Your request.
3.1.4 Legal Obligations — Article 6(1)(c) of the GDPR
We may process Your data when it is necessary to comply with a legal obligation to which We are subject under Austrian and EU law.
3.1.5 Vital Interests — Article 6(1)(d) of the GDPR
In rare situations where a person’s life or health is at stake, We may process personal data if it is necessary to safeguard vital interests.
3.1.6 Public Interest — Article 6(1)(e) of the GDPR
We may also process Your personal data when such processing is necessary for the performance of a task carried out in the public interest.
3.2 Summary
The lawfulness of processing Your personal data by graphicatelier is established on several legal bases. For processing activities that may pose a high risk to Your rights and freedoms, We conduct Data Protection Impact Assessments (DPIAs) as required by Article 35 of the GDPR, in accordance with EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR.
4. Rights of Concerned Individuals
As a User, You have certain rights regarding the processing of Your personal data. We are committed to respecting these rights and facilitating their exercise, in accordance with the provisions of Articles 12–22 of the GDPR. We will respond to all requests without undue delay and at the latest within one month, unless the request is particularly complex or We have received numerous requests, in which case We may extend the response period by up to two additional months in accordance with Article 12(3) of the GDPR.
4.1 Right of Access — Article 15 of the GDPR
You have the right to obtain confirmation as to whether personal data concerning You is being processed, access this data, and receive additional information about its use. You may request a free copy of the personal data being processed.
4.2 Right to Rectification — Article 16 of the GDPR
You have the right to request the correction of Your personal data if it is inaccurate or incomplete.
4.3 Right to Erasure — Article 17 of the GDPR
You have the right to request the deletion of Your personal data under certain conditions. This right is not absolute and may be limited by legal obligations as provided in Article 17(3) of the GDPR.
4.4 Right to Restriction of Processing — Article 18 of the GDPR
You can request the restriction of the processing of Your personal data in certain circumstances.
4.5 Right to Data Portability — Article 20 of the GDPR
You have the right to receive Your personal data in a structured, commonly used, and machine-readable format.
4.6 Right to Object — Article 21 of the GDPR
You have the right to object to the processing of Your personal data in certain situations. Where We process personal data for direct marketing, You have an absolute right to object at any time.
4.7 Right Not to Be Subject to Automated Decision-Making — Article 22 of the GDPR
You have the right not to be subject to a decision based solely on automated processing. We do not currently make any automated decisions with legal or similarly significant effects.
4.8 Summary
If You wish to exercise any of these rights, please refer to Section 2 – Contact Information. We will respond to Your request without undue delay and at the latest within one month in accordance with Article 12(3) of the GDPR.
5. Data Collection
When You use Our Site, various categories of information may be gathered to provide You with an optimal user experience, in line with Our service objectives. This data collection is carried out in full compliance with the GDPR and the ePrivacy Directive.
5.1 Information Provided Directly by the User
When You browse the Site or use certain of Our services, You have the option to provide Us with data such as Your name, email address, phone number, and more. Examples of when You might provide this information include:
- When filling out contact forms
- When subscribing to newsletters or email notifications
- When posting comments on articles
- When participating in surveys or contests
- When creating a user account (if applicable)
- When placing an order or making a purchase (if applicable)
5.2 Information Automatically Collected
When You visit the Site, certain information may be automatically collected, such as Your IP address, browser details, operating system, and more. The automatically collected information includes:
- IP address and approximate location derived from it
- Browser type and version
- Operating system and device type (desktop, mobile, tablet)
- Referring website and exit pages
- Pages visited and time spent on each page
- Actions taken on the Site (clicks, scrolls, form interactions)
- Date and time of visit
- Language preferences
- Screen resolution and colour depth
5.3 Information from Third-Party Services
We may also receive information about You from Third-Party Services We use to enhance Our Site and services. For detailed information about each Third-Party Service and the data they collect, please refer to Section 8 – Data Collected. If You have questions regarding the collection of Your personal data, please refer to Section 2 – Contact Information.
6. Use of Your Personal Data
The personal data We collect is used for various purposes, always in strict compliance with applicable laws.
6.1 Communication and Service
We process Your data, such as Your email address, to communicate with You, keep You informed of Our service updates, or respond to Your requests. This use arises from Our contractual obligation to provide You with the service for which You have registered, in accordance with Article 6(1)(b) of the GDPR.
6.2 Service Improvement
Automatically collected information helps Us understand how users interact with Our Site. This understanding allows Us to enhance Our services to better meet Your needs, in accordance with Article 6(1)(f) of the GDPR (legitimate interest).
6.3 Legal Compliance
We may also use Your data to comply with Our legal obligations, for example, to respond to a request from a judicial authority or to maintain required business records, in accordance with Article 6(1)(c) of the GDPR.
If You have questions regarding the use of Your personal data, please refer to Section 2 – Contact Information.
7. Sharing of Your Personal Data
We attach great importance to the privacy of Your data. However, in certain situations, it may be necessary to share Your personal data. Each sharing is strictly regulated by the GDPR, ensuring the highest protection of Your information.
7.1 Service Partners
We may share Your data with third-party partners who assist Us in operating the Site, providing Our services, or processing transactions on Our behalf. These third parties are required to process this data in accordance with the law and in compliance with Our commitment to protecting Your privacy, in alignment with Article 28 of the GDPR (processors). We have Data Processing Agreements (DPAs) in place with each service partner, as required by Article 28(3) of the GDPR.
7.2 Legal Requirements
We may be obligated to disclose Your data if required by law, when We believe such disclosure is necessary to protect Our rights, the safety of others, or to respond to a judicial or governmental request, in accordance with Article 6(1)(c) of the GDPR.
7.3 International Transfers
If We need to transfer Your data outside of the European Economic Area (EEA), We ensure that these transfers comply with the requirements of the GDPR, thus ensuring adequate protection of Your data, in accordance with Chapter V of the GDPR (Articles 44–49). This includes implementing appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission in accordance with Commission Implementing Decision (EU) 2021/914 (the new modular SCCs).
- EU-US Data Privacy Framework (DPF) for transfers to participating US organisations, as established by the European Commission’s adequacy decision (EU) 2023/1795.
- Transfer Impact Assessments (TIAs) conducted in accordance with EDPB Recommendations 01/2020.
- Supplementary measures as necessary to ensure an adequate level of protection.
7.3.1 EU-US Data Privacy Framework (DPF)
The EU-US Data Privacy Framework (DPF) became operational in July 2023 following the European Commission’s adequacy decision (EU) 2023/1795. This framework is supported by Executive Order 14086 (October 2022) and includes a UK Extension and a Swiss-US DPF. You can verify an organisation’s participation status on the official Data Privacy Framework website.
If You have any questions regarding the sharing of Your personal data, please refer to Section 2 – Contact Information.
8. Data Collected
Our Site uses various technologies to collect and store information when You visit it. This may include the use of cookies, local storage, session storage, IndexedDB, or similar technologies. In accordance with Article 5(3) of the ePrivacy Directive (2002/58/EC) and in line with EDPB Guidelines 02/2023, We provide detailed information about each storage technology used on this Site.
8.1 Cookies
8.1.1 What Are Cookies and Similar Technologies?
Cookies are small text files that websites place on Your device to store information about Your preferences, enhance site functionality, and collect analytics data. In addition to HTTP cookies, websites may use other storage technologies:
- LocalStorage: Stores data persistently in the browser with no expiration date.
- SessionStorage: Stores data for the duration of the browser session only.
- IndexedDB: A client-side database that can store significant amounts of structured data.
- Fingerprinting: Techniques that collect device and browser characteristics to create a unique device identifier.
8.1.2 Purpose of Cookies
Cookies serve several important functions on websites:
- Essential cookies: Required for the website to function properly. Exempt from consent under the ePrivacy Directive.
- Functional cookies: Help to enhance the functionality and personalisation of the website.
- Statistics cookies: Help website owners understand how visitors interact with websites.
- Marketing cookies: Used to track visitors across websites.
8.1.3 How Cookies Are Regulated
The use of cookies is primarily regulated by two key pieces of legislation in the European Union:
- GDPR: Regulation (EU) 2016/679 applies when cookies collect personal data, requiring a lawful basis for processing such data in accordance with Article 5 of the GDPR.
- ePrivacy Directive: Article 5(3) of Directive 2002/58/EC requires websites to obtain user consent before storing or accessing information on a user’s device, with exceptions for strictly necessary cookies.
- EDPB Guidelines 05/2020 on Consent: These guidelines clarify the requirements for valid consent.
8.1.4 Types of Cookies
Cookies come in different types: First-party (issued by the site You visit), Third-party (issued by domains other than the site You visit), Session (deleted when browser closes), and Persistent (stored for a specified period).
8.1.5 Legal Basis for Using Cookies
Essential cookies are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive. Functional, Statistics, and Marketing cookies require prior informed consent under Article 6(1)(a) of the GDPR.
8.1.6 In Summary
You can manage Your cookie preferences through Our consent management tool or Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.2 Consent Management via Real Cookie Banner
8.2.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Real Cookie Banner (RCB) |
| Provider | devowl.io GmbH |
| Address | Tannet 12, 94539 Grafling, Germany |
| support@devowl.io | |
| Privacy Policy | devowl.io/rcb/data-processing |
| Data Transfers | None (self-hosted, all data stored locally) |
| DPF Status | Not applicable (German provider, EEA-based) |
8.2.2 Purpose
We use Real Cookie Banner to ensure legal compliance with cookie consent regulations while providing You with a transparent way to manage Your privacy preferences. It supports IAB TCF v2.2 and uses a blocking mode that prevents third-party scripts from loading until consent has been obtained.
8.2.3 Categories of Personal Data Processed
Real Cookie Banner processes: Your consent choices, timestamp of consent, UUID, browser type and version, anonymized IP address, language preferences, operating system, and referrer URL.
8.2.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| rcb_* | graphicatelier.com | Stores the UUID of the consent given | 1 year | No (Essential) | HTTP Cookie |
| rcb_*-tcf | graphicatelier.com | Stores consent via TCF v2.2 | 1 year | No (Essential) | HTTP Cookie |
| rcb-test | graphicatelier.com | Tests if HTTP cookies can be set | Session | No (Essential) | HTTP Cookie |
| rcb-*-blog | graphicatelier.com | Consent status for multisite network | 1 year | No (Essential) | HTTP Cookie |
8.2.5 External Data Loading and International Transfers
Real Cookie Banner is self-hosted on Our web server. No data is transferred outside the EEA by the plugin itself. If You consent to third-party services through the banner, those services may transfer data internationally according to their own privacy policies.
8.2.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.2.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.2.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.2.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Real Cookie Banner, visit devowl.io/rcb/data-processing.
8.2.10 At a Glance
| Controller: graphicatelier | Processor: devowl.io GmbH |
| Data Categories: Consent choices, UUID, anonymized IP | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.3 WordPress Comments
8.3.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | WordPress Comments (Native) |
| Provider | Self-hosted (WordPress.org) |
| Data Transfers | None by default (self-hosted). Gravatar requests may reach Automattic (US) |
8.3.2 Purpose
WordPress Comments allows users to engage in discussions on Our published content. This helps enhance community engagement and provides valuable feedback.
8.3.3 Categories of Personal Data Processed
When You leave a comment: name, email address, website URL (optional), IP address, browser user agent string, comment content, and timestamp.
8.3.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| comment_author_[hash] | graphicatelier.com | Stores commenter’s name for prefilling | 1 year | No (Essential) | HTTP Cookie |
| comment_author_email_[hash] | graphicatelier.com | Stores commenter’s email for prefilling | 1 year | No (Essential) | HTTP Cookie |
| comment_author_url_[hash] | graphicatelier.com | Stores commenter’s website URL for prefilling | 1 year | No (Essential) | HTTP Cookie |
8.3.5 External Data Loading and International Transfers
WordPress Comments is self-hosted. However, if You use a Gravatar-linked email address, Your browser may request profile images from Automattic’s servers in the US. For more information, refer to Automattic’s Privacy Policy.
8.3.6 Data Retention
Comments and their metadata are retained indefinitely. Registered users can see, edit, or delete their personal information.
8.3.7 How to Withdraw or Object Consent
You can request deletion of Your comments by referring to Section 2 – Contact Information. You can also manage comment-related cookies through Your browser settings.
For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.3.8 Legal Basis
| Processing Purpose | GDPR Article |
|---|---|
| Facilitating discussions | Art. 6(1)(a) of the GDPR (consent) and Art. 6(1)(f) of the GDPR (legitimate interest) |
8.3.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For WordPress’s general data handling, visit WordPress Privacy Policy.
8.3.10 At a Glance
| Data Categories: Name, email, IP, comment content | Transfer: None (except Gravatar) |
| Retention: Indefinite | Consent Required: Conditional |
8.4 Contact Form 7
8.4.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Contact Form 7 |
| Provider | Takayuki Miyoshi (self-hosted plugin) |
| Plugin Privacy | contactform7.com/privacy-policy |
| Data Transfers | None by default (self-hosted) |
8.4.2 Purpose
Contact Form 7 enables You to communicate with Us through forms on Our website. Form submissions are processed entirely on Our server.
8.4.3 Categories of Personal Data Processed
Name, email address, phone number (if requested), message content, subject line, IP address, timestamp, and browser user agent.
8.4.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Contact Form 7 in Our implementation | — | — | — |
8.4.5 External Data Loading and International Transfers
Contact Form 7 is self-hosted. No data is transferred outside the EEA by the plugin itself. If reCAPTCHA is integrated with the form, please refer to the reCAPTCHA section for data transfer details.
8.4.6 Data Retention
Form submissions are retained for up to 3 years, after which they are securely deleted unless there is a legitimate business or legal reason to retain them longer.
8.4.7 How to Withdraw or Object Consent
Please refer to Section 2 – Contact Information to request access to, correction, or deletion of Your personal data submitted through the form.
For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.4.8 Legal Basis
| Processing Purpose | GDPR Article |
|---|---|
| Responding to inquiries | Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(b) of the GDPR (contract), Art. 6(1)(f) of the GDPR (legitimate interest) |
8.4.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For plugin information, visit contactform7.com.
8.4.10 At a Glance
| Data Categories: Name, email, message content | Transfer: None (EEA only) |
| Retention: Up to 3 years | Consent Required: Yes |
8.5 Google reCAPTCHA
8.5.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Google reCAPTCHA |
| Provider | Google LLC |
| Address | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA |
| privacy@google.com | |
| Privacy Policy | policies.google.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Google LLC may rely on the EU-U.S. Data Privacy Framework where certified, or on other documented transfer safeguards such as SCCs. |
8.5.2 Purpose
Google reCAPTCHA helps prevent automated spam and abuse by verifying that the user is human.
8.5.3 Categories of Personal Data Processed
When You use reCAPTCHA: IP address, browser user agent string, anonymized IP address, and timestamp.
8.5.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by reCAPTCHA in Our implementation | — | — | — |
8.5.5 External Data Loading and International Transfers
Google reCAPTCHA loads Google scripts and sends security and interaction signals to Google. Data may be processed outside the EEA as described in the warning below.
⚠ Data transferred outside the EEA: Google reCAPTCHA transmits data to Google’s servers in the United States. Protected by the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.5.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.5.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.5.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.5.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about reCAPTCHA, visit Google’s reCAPTCHA.
8.5.10 At a Glance
| Controller: graphicatelier | Processor: Google LLC |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.6 Google Fonts
8.6.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Google Fonts |
| Provider | Google LLC |
| Address | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA |
| privacy@google.com | |
| Privacy Policy | policies.google.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Google LLC may rely on the EU-U.S. Data Privacy Framework where certified, or on other documented transfer safeguards such as SCCs. |
8.6.2 Purpose
Google Fonts allows users to select and use custom fonts on Our website.
8.6.3 Categories of Personal Data Processed
When You use Google Fonts: IP address, browser user agent string, anonymized IP address, and timestamp.
8.6.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Google Fonts in Our implementation | — | — | — |
8.6.5 External Data Loading and International Transfers
If Google Fonts is loaded from Google servers, the browser requests font resources from Google and technical data such as the IP address may be transmitted. If fonts are genuinely self-hosted, this external request does not occur; the implementation must be verified before publication.
⚠ Data transferred outside the EEA: Google Fonts loads from Google’s servers which may be located in the United States. Protected by the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.6.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.6.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.6.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.6.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Google Fonts, visit Google Fonts.
8.6.10 At a Glance
| Controller: graphicatelier | Processor: Google LLC |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.7 Google Maps
8.7.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Google Maps |
| Provider | Google LLC |
| Address | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA |
| privacy@google.com | |
| Privacy Policy | policies.google.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Google LLC may rely on the EU-U.S. Data Privacy Framework where certified, or on other documented transfer safeguards such as SCCs. |
8.7.2 Purpose
Google Maps allows users to view and interact with maps on Our website.
8.7.3 Categories of Personal Data Processed
When You use Google Maps: IP address, browser user agent string, anonymized IP address, and timestamp.
8.7.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Google Maps in Our implementation | — | — | — |
8.7.5 External Data Loading and International Transfers
Google Maps is not self-hosted when an embedded map, JavaScript API, or Google map tiles are loaded. The browser connects directly to Google services and may transmit technical, location, search, and interaction data. A static, locally hosted map image would be a different implementation.
⚠ Data transferred outside the EEA: Google Maps loads map data from Google’s servers in the United States. Protected by the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.7.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.7.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.7.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.7.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Google Maps, visit Google Maps.
8.7.10 At a Glance
| Controller: graphicatelier | Processor: Google LLC |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.8 Jetpack Stats
8.8.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Jetpack Stats |
| Provider | Automattic, Inc. |
| Address | 1355 Market Street, San Francisco, CA 94103, USA |
| privacy@automattic.com | |
| Privacy Policy | automattic.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Not applicable (US provider, EEA-based) |
8.8.2 Purpose
Jetpack Stats provides analytics and insights into user engagement on Our website.
8.8.3 Categories of Personal Data Processed
When You use Jetpack Stats: IP address, browser user agent string, anonymized IP address, and timestamp.
8.8.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Jetpack Stats in Our implementation | — | — | — |
8.8.5 External Data Loading and International Transfers
Jetpack Stats is not self-hosted. The Jetpack module sends measurement data to Automattic/WordPress.com services for analytics. The applicable transfer safeguards are described in the warning below.
⚠ Data transferred outside the EEA: Jetpack Stats transmits analytics data to Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, IP anonymization, data minimization, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.8.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.8.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.8.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.8.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Stats, visit Jetpack Stats.
8.8.10 At a Glance
| Controller: graphicatelier | Processor: Automattic, Inc. |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.9 Jetpack Comments
8.9.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Jetpack Comments |
| Provider | Automattic, Inc. |
| Address | 1355 Market Street, San Francisco, CA 94103, USA |
| privacy@automattic.com | |
| Privacy Policy | automattic.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Not applicable (US provider, EEA-based) |
8.9.2 Purpose
Jetpack Comments provides analytics and insights into user engagement on Our website.
8.9.3 Categories of Personal Data Processed
When You use Jetpack Comments: IP address, browser user agent string, anonymized IP address, and timestamp.
8.9.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Jetpack Comments in Our implementation | — | — | — |
8.9.5 External Data Loading and International Transfers
Jetpack Comments may exchange comment and authentication data with Automattic/WordPress.com services. The native WordPress comment database remains on the Site, but the Jetpack feature itself is not self-hosted.
⚠ Data transferred outside the EEA: Jetpack Comments transmits comment data to Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.9.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.9.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.9.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.9.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Comments, visit Jetpack Comments.
8.9.10 At a Glance
| Controller: graphicatelier | Processor: Automattic, Inc. |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.10 Jetpack Notifications
8.10.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Jetpack Notifications |
| Provider | Automattic, Inc. |
| Address | 1355 Market Street, San Francisco, CA 94103, USA |
| privacy@automattic.com | |
| Privacy Policy | automattic.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Not applicable (US provider, EEA-based) |
8.10.2 Purpose
Jetpack Notifications provides analytics and insights into user engagement on Our website.
8.10.3 Categories of Personal Data Processed
When You use Jetpack Notifications: IP address, browser user agent string, anonymized IP address, and timestamp.
8.10.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Jetpack Notifications in Our implementation | — | — | — |
8.10.5 External Data Loading and International Transfers
Jetpack Notifications communicates with Automattic/WordPress.com services to generate and deliver notifications. It is not a wholly self-hosted service.
⚠ Data transferred outside the EEA: Jetpack Notifications transmits notification data to Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.10.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.10.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.10.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.10.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Notifications, visit Jetpack Notifications.
8.10.10 At a Glance
| Controller: graphicatelier | Processor: Automattic, Inc. |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.11 Jetpack Subscriptions
8.11.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Jetpack Subscriptions |
| Provider | Automattic, Inc. |
| Address | 1355 Market Street, San Francisco, CA 94103, USA |
| privacy@automattic.com | |
| Privacy Policy | automattic.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Not applicable (US provider, EEA-based) |
8.11.2 Purpose
Jetpack Subscriptions provides analytics and insights into user engagement on Our website.
8.11.3 Categories of Personal Data Processed
When You use Jetpack Subscriptions: IP address, browser user agent string, anonymized IP address, and timestamp.
8.11.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Jetpack Subscriptions in Our implementation | — | — | — |
8.11.5 External Data Loading and International Transfers
Jetpack Subscriptions sends subscription data to Automattic/WordPress.com services for subscription management and email delivery. It is not self-hosted.
⚠ Data transferred outside the EEA: Jetpack Subscriptions stores subscription data on Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.11.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.11.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.11.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.11.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Subscriptions, visit Jetpack Subscriptions.
8.11.10 At a Glance
| Controller: graphicatelier | Processor: Automattic, Inc. |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.12 Akismet
8.12.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Akismet |
| Provider | Automattic, Inc. |
| Address | 1355 Market Street, San Francisco, CA 94103, USA |
| privacy@automattic.com | |
| Privacy Policy | automattic.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Not applicable (US provider, EEA-based) |
8.12.2 Purpose
Akismet helps prevent spam and abuse by identifying and filtering out automated content.
8.12.3 Categories of Personal Data Processed
When You use Akismet: IP address, browser user agent string, anonymized IP address, and timestamp.
8.12.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Akismet in Our implementation | — | — | — |
8.12.5 External Data Loading and International Transfers
Akismet is a cloud-based spam filtering service. Comment and form metadata may be sent to Automattic/Akismet for spam analysis; the plugin itself is installed locally but the filtering service is not self-hosted.
⚠ Data transferred outside the EEA: Akismet transmits comment data to Automattic’s servers in the United States for spam analysis. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.12.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.12.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.12.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.12.9 Contact and Documentation
For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Akismet, visit Akismet.
8.12.10 At a Glance
| Controller: graphicatelier | Processor: Automattic, Inc. |
| Data Categories: IP, browser user agent | Transfer: None (EEA only) |
| Retention: 12 months or until consent withdrawal | Consent Required: No (Essential) |
| Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left) | |
8.13 Flickr
8.13.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Flickr |
| Provider | Flickr, Inc. |
| Address | 1355 Market Street, San Francisco, CA 94103, USA |
| privacy@flickr.com | |
| Privacy Policy | flickr.com/privacy |
| Data Transfers | External service; data may be processed by the provider |
| DPF Status | Not applicable (US provider, EEA-based) |
8.13.2 Purpose
Flickr allows users to share and view images on Our website.
8.13.3 Categories of Personal Data Processed
When You use Flickr: IP address, browser user agent string, anonymized IP address, and timestamp.
8.13.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| — | — | No cookies are set by Flickr in Our implementation | — | — | — |
8.13.5 External Data Loading and International Transfers
Flickr is an external image-hosting and embedding service. Embedded images, scripts, or players may cause the browser to connect directly to Flickr services and transmit technical data.
⚠ Data transferred outside the EEA: Flickr loads embedded content from Flickr’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.
8.13.6 Data Retention
Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.
8.13.7 How to Withdraw or Object Consent
Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.13.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Storing and managing cookie consent | Art. 6(1)(c) of the GDPR (legal obligation) | Art. 5(3) ePrivacy Directive (exemption) |
| Managing cookies and similar technologies | Art. 6(1)(f) of the GDPR (legitimate interest) | — |
8.13.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For more information about Flickr, visit Flickr Privacy.
8.14 WooCommerce
8.14.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | WooCommerce |
| Provider | Automattic, Inc. (self-hosted WordPress plugin) |
| Privacy Policy | Automattic Privacy Policy |
| Data Transfers | Core plugin is self-hosted; payment gateways, shipping providers, tax services, and extensions may make separate transfers. |
8.14.2 Purpose
WooCommerce provides shopping-cart, checkout, customer-account, order-management, and product-delivery functionality where e-commerce is enabled.
8.14.3 Categories of Personal Data Processed
Depending on the checkout and account configuration: name, billing and shipping address, email address, telephone number, account credentials, order and download history, IP address, device data, and payment or transaction references. Full payment-card details should normally be processed by the selected payment provider, not stored by WooCommerce.
8.14.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| woocommerce_cart_hash | graphicatelier.com | Helps identify changes to the shopping cart | Session | No, where strictly necessary | HTTP Cookie |
| woocommerce_items_in_cart | graphicatelier.com | Indicates whether the cart contains items | Session | No, where strictly necessary | HTTP Cookie |
| wp_woocommerce_session_* | graphicatelier.com | Maintains the customer shopping session | Up to 2 days | No, where strictly necessary | HTTP Cookie |
8.14.5 External Data Loading and International Transfers
WooCommerce core is hosted on the Site. Any payment gateway, shipping, tax, email, fraud-prevention, or other extension is a separate service and may transmit data outside the EEA. The applicable provider and safeguard must be identified before activation.
8.14.6 Data Retention
Order and accounting records are retained for the period required by applicable Austrian tax and commercial law. Account data is retained while the account is active, subject to legal-hold and dispute exceptions.
8.14.7 How to Withdraw or Object Consent
You may manage or delete an account where available, and you may request access, correction, restriction, or erasure by referring to Section 2 – Contact Information. For privacy-setting instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.14.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Account, cart, checkout, and order fulfilment | Article 6(1)(b) GDPR (contract or pre-contractual steps) | Article 5(3) ePrivacy exemption where strictly necessary |
| Accounting, tax, and fraud prevention | Article 6(1)(c) or (f) GDPR | Conditional; consent where non-essential storage is used |
8.14.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For plugin documentation, visit WooCommerce Documentation.
8.14.10 At a Glance
Processor: self-hosted WooCommerce and separately configured providers
Consent Required: Conditional; strictly necessary cart and checkout storage is exempt, non-essential storage requires consent
Opt-Out: Account controls, provider controls, and Section 12.
8.15 WPForms
8.15.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | WPForms |
| Provider | WPForms LLC (self-hosted plugin) |
| Privacy Policy | WPForms Privacy Policy |
| Data Transfers | Form data is normally stored on the Site; integrations, email delivery, payments, and anti-spam services may transfer data. |
8.15.2 Purpose
WPForms enables contact, registration, survey, quotation, and other forms configured by the Site operator.
8.15.3 Categories of Personal Data Processed
The fields You submit, such as name, email address, telephone number, message content, attachments, IP address, user agent, referrer, and timestamp. The exact fields depend on the form.
8.15.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| wpforms_* | graphicatelier.com | Form functionality, anti-spam, and session-related operation where configured | Session or configuration-dependent | Conditional | HTTP Cookie |
8.15.5 External Data Loading and International Transfers
The WPForms plugin is self-hosted, but configured integrations such as Google reCAPTCHA, Cloudflare Turnstile, payment providers, SMTP services, or marketing platforms may receive data. Please refer to the relevant service section.
8.15.6 Data Retention
Entries are retained only as long as necessary to respond, administer the relationship, establish or defend claims, and satisfy legal obligations. The configured retention period must be checked in WPForms and any connected storage or email system.
8.15.7 How to Withdraw or Object Consent
Do not submit optional information if You do not wish to provide it. To request access, correction, restriction, or deletion, please refer to Section 2 – Contact Information. For privacy-setting instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.15.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Responding to a request or providing a requested service | Article 6(1)(b) GDPR or consent under Article 6(1)(a) | Consent unless storage is strictly necessary |
| Security and abuse prevention | Article 6(1)(f) GDPR | Conditional |
8.15.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For WPForms information, visit WPForms Privacy Policy.
8.15.10 At a Glance
Processor: WPForms is self-hosted; integrations are separate processors
Data Categories: Form fields and technical submission data
Consent Required: Conditional
Opt-Out: Section 2 and Section 12.
8.16 WPML
8.16.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | WPML |
| Provider | OnTheGoSystems Limited |
| Address | 22/F, 3 Lockhart Road, Wan Chai, Hong Kong |
| Privacy Policy | WPML Privacy Policy and GDPR Compliance |
8.16.2 Purpose
WPML provides multilingual content, language switching, translated URLs, and related WordPress language functionality.
8.16.3 Categories of Personal Data Processed
Language preference, browser language, IP address or approximate location only if a browser-redirection or geolocation feature is enabled, and technical request data. Translation-service features may process content sent for translation.
8.16.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| wp-wpml_current_language | graphicatelier.com | Stores the selected language | Up to 1 day | No, where strictly necessary for the requested language service | HTTP Cookie |
| _icl_visitor_lang_js | graphicatelier.com | Supports language selection in JavaScript features | Session | Conditional | HTTP Cookie |
| wpml_browser_redirect_test | graphicatelier.com | Tests browser-language redirection | Session | Conditional | HTTP Cookie |
8.16.5 External Data Loading and International Transfers
Core WPML language switching is primarily executed on the Site. Automatic translation, translation-management, license, update, or remote support features may connect to OnTheGoSystems or a selected translation provider, including outside the EEA. The specific feature and provider must be verified before publication.
8.16.6 Data Retention
Language-preference cookies expire according to the configured WPML feature. Translation content and account or license records are retained according to the relevant Site and provider retention settings.
8.16.7 How to Withdraw or Object Consent
Select a language manually, disable browser redirection, or delete the language cookie through Your browser. For data-rights requests, please refer to Section 2 – Contact Information. For privacy-setting instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.16.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Language selection and requested multilingual service | Article 6(1)(b) or (f) GDPR | Strictly necessary where required for the language service; otherwise consent |
| Optional automatic translation or remote services | Article 6(1)(a) GDPR or another documented basis | Consent where non-essential storage or access is used |
8.16.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For provider information, visit WPML Privacy Policy and GDPR Compliance.
8.16.10 At a Glance
Provider: OnTheGoSystems Limited and any selected translation provider
Transfer: Conditional; verify remote translation features
Consent Required: Conditional
Opt-Out: Language switcher, browser controls, and Section 12.
8.17 Vimeo
8.17.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Vimeo |
| Provider | Vimeo.com, Inc. |
| Address | 555 West 18th Street, New York, NY 10011, USA |
| Privacy Policy | Vimeo Privacy Policy |
8.17.2 Purpose
Vimeo hosts and delivers embedded video content on the Site.
8.17.3 Categories of Personal Data Processed
IP address, browser and device information, referrer URL, playback interactions, and viewing preferences. Vimeo may associate viewing activity with a Vimeo account if You are signed in.
8.17.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| vuid | .vimeo.com | Unique visitor and analytics identifier | Up to 2 years | Yes | HTTP Cookie |
| player | .vimeo.com | Player preferences | Configuration-dependent | Yes | HTTP Cookie or LocalStorage |
8.17.5 External Data Loading and International Transfers
Embedded Vimeo content causes the browser to connect to Vimeo. Data may be processed in the United States or other countries under Vimeo’s documented safeguards.
8.17.6 Data Retention
Vimeo retains data according to its privacy and retention policies and the configuration of the embedded player.
8.17.7 How to Withdraw or Object Consent
Click “Change Privacy Settings” (finger icon, bottom-left) and disable the relevant category before Vimeo is loaded. For further instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.17.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Embedded video delivery and measurement | Article 6(1)(a) GDPR | Prior consent for non-essential access |
8.17.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For provider information, visit Vimeo Privacy Policy.
8.17.10 At a Glance
Provider: Vimeo.com, Inc.
Transfer: Potentially outside the EEA
Consent Required: Yes for non-essential embedding
Opt-Out: Section 12.
8.18 Cloudflare Turnstile
8.18.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Cloudflare Turnstile |
| Provider | Cloudflare, Inc. |
| Address | 101 Townsend St, San Francisco, CA 94107, USA |
| Privacy Policy | Cloudflare Privacy Policy |
| Turnstile Addendum | Turnstile Privacy Addendum |
8.18.2 Purpose
Turnstile helps protect forms and other interactive features against automated abuse and bots. It evaluates signals for security and bot detection; it is not used by Us to identify or advertise to visitors.
8.18.3 Categories of Personal Data Processed
Cloudflare states that Turnstile may process client IP address, TLS fingerprint, user-agent header, sitekey, associated origin, challenge timestamp, hostname, action, and security signals. The Site may also send a remote IP address for server-side validation if configured.
8.18.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| Turnstile signals and challenge token | challenges.cloudflare.com | Bot detection and server-side validation | Token valid for 5 minutes and single-use | No, where strictly necessary for security | Security signal / token |
| cf_clearance (if configured) | graphicatelier.com or Cloudflare-managed domain | Records a successful security challenge where applicable | Configuration-dependent | Conditional | HTTP Cookie |
8.18.5 External Data Loading and International Transfers
Turnstile loads Cloudflare resources and may send signals to Cloudflare. Cloudflare states that transfers from the EEA may rely on the EU-U.S. Data Privacy Framework, the UK Extension, the Swiss-U.S. DPF, or Standard Contractual Clauses with supplementary measures, as applicable.
⚠ Potential transfer outside the EEA: Cloudflare Turnstile may process security signals through Cloudflare’s global infrastructure, including in the United States. See Cloudflare’s Turnstile Privacy Addendum and current transfer safeguards.
8.18.6 Data Retention
Turnstile tokens expire after five minutes and may be validated only once. Other signals and records are retained according to Cloudflare’s Turnstile Addendum and applicable customer configuration.
8.18.7 How to Withdraw or Object Consent
Turnstile may be necessary to protect forms and therefore may not be disabled while using the protected feature. You may use an alternative contact method where available. For privacy controls and rights, please refer to Section 12 – Managing Your Privacy Settings and Section 2 – Contact Information.
8.18.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Security and bot prevention for a requested form or feature | Article 6(1)(f) GDPR (legitimate interest), or Article 6(1)(b) where necessary for a requested service | Strictly necessary exemption where applicable; otherwise consent |
8.18.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For provider information, visit Cloudflare Turnstile Privacy Addendum and Cloudflare’s DPO contact.
8.18.10 At a Glance
Data Categories: Security signals, IP address if supplied, user agent, sitekey and origin
Transfer: Potentially outside the EEA
Consent Required: Conditional; strictly necessary security may be exempt
Opt-Out: Alternative contact method, Section 2, and Section 12.
8.19 Google Analytics 4
8.19.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Google Analytics 4 |
| Provider | Google Ireland Limited and Google LLC |
| EU Address | Gordon House, 4 Barrow St, Dublin D04 E5W5, Ireland |
| Privacy Policy | Google Privacy Policy |
| Documentation | Google Analytics data protection |
8.19.2 Purpose
Google Analytics 4 measures how visitors use the Site, including page views, events, approximate location, device and browser information, and campaign attribution. We must not send directly identifying information or special-category data to Google Analytics.
8.19.3 Categories of Personal Data Processed
Online identifiers, cookie or client identifiers, IP-derived approximate location, device and browser information, page URL and referrer, event data, language, screen information, and campaign parameters. Google Analytics prohibits customers from sending personally identifiable information.
8.19.4 Cookies and Local Storage
| Name | Host | Purpose | Lifetime | Requires Consent | Type |
|---|---|---|---|---|---|
| _ga | .graphicatelier.com | Distinguishes users | Up to 2 years | Yes | HTTP Cookie |
| _ga_* | .graphicatelier.com | Maintains Analytics session state | Up to 2 years | Yes | HTTP Cookie |
| _gid or other Google measurement cookies | Configuration-dependent | Measurement and session attribution where configured | Configuration-dependent | Yes | HTTP Cookie |
8.19.5 External Data Loading and International Transfers
Google Analytics loads Google measurement resources and transmits measurement data to Google. Google may process data in the United States and elsewhere. The configured implementation should use consent mode and privacy controls appropriate to the Site, including disabling Google signals and advertising personalization unless separately consented.
⚠ Potential transfer outside the EEA: Google Analytics data may be processed outside the EEA. Depending on the provider and configuration, safeguards may include the EU-U.S. Data Privacy Framework, Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, and supplementary measures.
8.19.6 Data Retention
Google Analytics user-level and event-level retention is configurable. Google Analytics 4 properties generally allow two or fourteen months for user and event data, with longer options for certain Analytics 360 properties. Aggregated standard reports are not necessarily affected by this setting. The retention setting configured for this Site must be verified and recorded.
8.19.7 How to Withdraw or Object Consent
Click “Change Privacy Settings” (finger icon, bottom-left) and disable Statistics or Analytics consent. You may also use Google’s Analytics opt-out browser add-on or delete Site cookies. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.
8.19.8 Legal Basis
| Processing Purpose | GDPR Article | ePrivacy Basis |
|---|---|---|
| Analytics measurement | Article 6(1)(a) GDPR (consent) | Prior consent under Article 5(3) ePrivacy Directive |
| Security and configuration | Article 6(1)(f) GDPR, where documented by a balancing assessment | Only where strictly necessary; otherwise consent |
8.19.9 Contact and Documentation
Please refer to Section 2 – Contact Information. For Google’s documentation, visit Safeguarding your data in Google Analytics, Google Analytics privacy controls, and Google Analytics data retention.
8.19.10 At a Glance
Data Categories: Analytics identifiers, device, browser, event, and approximate location data
Transfer: Potentially outside the EEA
Consent Required: Yes for analytics cookies and non-essential measurement
Opt-Out: Section 12 and Google’s opt-out controls.
9. Third-Party Service Providers
We engage third-party service providers to assist Us in managing and improving Our website. These providers may process or store personal data as part of providing these services. We ensure that these third-party service providers adhere to the same privacy and security standards as Us and only share Your personal data with them to the extent necessary for them to provide the respective services. We have Data Processing Agreements (DPAs) in place with these providers as required by Article 28 of the GDPR.
These third parties include:
- Web hosting and IT service providers
- Website analytics and tracking service providers
- Content delivery networks
- Security service providers
- Communication and email service providers
9.1 Web Hosting
9.1.1 Definition and Provider
| Attribute | Details |
|---|---|
| Service Name | Web Hosting |
| Provider | Hetzner Online GmbH |
| Address | Industriestraße 25, 91710 Gunzenhausen, Germany |
| DPO Email | data-protection@hetzner.com |
| Privacy Policy | hetzner.com/legal/privacy-policy |
9.1.2 Purpose
We use Hetzner Online GmbH to store, maintain, and deliver Our website content to visitors. This service is essential for making Our website accessible on the internet.
9.1.3 Categories of Personal Data Processed
IP addresses, date and time of requests, browser type, operating system, referring URLs, files accessed, form submissions, database content, and server logs. All data is processed on servers located in Germany (EEA).
9.1.4 Data Retention
Server logs retained for up to 14 days. User data retained according to the purposes described in this Policy.
9.1.5 Security Measures
ISO 27001 certified data centers, network security, firewalls, intrusion detection, regular updates, backups, access controls, and SSL/TLS encryption.
9.1.6 Legal Basis
| Processing Purpose | GDPR Article |
|---|---|
| Website hosting and delivery | Art. 6(1)(b) of the GDPR (contract) / Art. 6(1)(f) of the GDPR (legitimate interest) |
9.1.7 Contact and Documentation
Please refer to Section 2 – Contact Information. For more information about Hetzner’s data processing, visit Hetzner Privacy Policy.
9.1.8 At a Glance
| Data Categories: IP, server logs, database content | Transfer: None (Germany, EEA) |
| Retention: 14 days (logs) | Consent Required: No (Essential) |
10. Security Measures
10.1 Technical and Organisational Measures
The security of Your personal data is of paramount importance to Us. We have implemented comprehensive technical and organisational measures in accordance with Article 32 of the GDPR. These measures include:
- Encryption: SSL/TLS encryption for data in transit
- Access controls: Strict authentication and authorization mechanisms
- Regular security assessments: Periodic audits, vulnerability scans, and penetration tests
- Staff training: Regular data protection training for employees
- Data minimization: Collecting only necessary personal data
- Backup procedures: Regular backups for disaster recovery
- Incident response plan: Procedures to detect, report, and investigate breaches
10.2 SSL Encryption
SSL (Secure Socket Layer) encryption establishes an encrypted link between Our web server and Your browser, ensuring that all data transmitted remains private and integral. This complies with Article 32 of the GDPR. You can verify this by checking for the padlock icon and “https://” prefix in Your browser’s address bar.
10.3 Breach Notification Process
If We become aware of a personal data breach that is likely to result in a risk to Your rights and freedoms, We will act promptly in accordance with Articles 33 and 34 of the GDPR. Our breach notification process includes:
- Breach identification and containment: Immediate steps to identify and contain the breach
- Impact assessment: Assessment of nature, scope, and potential consequences
- Notification to supervisory authority: Within 72 hours to the Austrian Data Protection Authority
- Notification to affected individuals: Without undue delay if high risk to rights and freedoms
- Documentation: Full documentation of all breaches and remedial actions
10.4 Data Retention Period
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law:
- Account data: As long as account is active, plus a reasonable period afterward
- Communication data: Up to 3 years from last interaction
- Transaction data: 7-10 years for tax and accounting requirements
- Consent records: As long as data is processed based on that consent, plus additional period for compliance
- Log data: 30-90 days for security and performance analysis
At the end of the retention period, personal data is securely deleted or anonymized. You have the right to request deletion in certain circumstances, as described in Section 4.3 – Right to Erasure.
11. Changes to Our Privacy Policy
We reserve the right to modify this Privacy Policy at any time to reflect changes in Our practices, services, or legal requirements. When We make substantial changes, We will notify You through a prominently displayed notice on Our website before the changes take effect. The date of the last update is clearly indicated at the top of this Policy. We encourage You to review this Policy regularly. If You have questions or concerns about changes, please refer to Section 2 – Contact Information.
12. Managing Your Privacy Settings
This section provides a comprehensive guide to managing Your privacy settings across different tools and platforms. Instead of repeating these instructions in every service section, We centralize them here for Your convenience.
12.1 Graphicatelier Privacy Center
Our website features a dedicated privacy management interface accessible from every page:
- Location: Look for the finger icon in the bottom-left corner of every page.
- Action: Click the “Change Privacy Settings” button to open the consent management interface.
- Options: You can individually enable or disable cookie categories: Essential, Functional, Statistics, and Marketing.
- Withdrawal: You can withdraw Your consent at any time by deselecting previously accepted categories and saving Your preferences.
- Persistence: Your preferences are stored for 12 months, after which You will be prompted again.
12.2 Browser Privacy Controls
Most browsers allow You to refuse cookies, delete existing cookies, and control site data. Here are detailed instructions for popular browsers:
12.2.1 Google Chrome
- Click the three dots (⋮) in the upper right corner
- Select “Settings”
- Under “Privacy and security,” click “Cookies and other site data”
- Choose Your preferred setting: “Allow all cookies,” “Block third-party cookies,” “Block all cookies,” or “Block third-party cookies in Incognito mode”
- You can also clear existing cookies by clicking “Clear browsing data”
12.2.2 Mozilla Firefox
- Click the menu button (☰) in the upper right corner
- Select “Settings”
- Select “Privacy & Security” from the left menu
- Under “Enhanced Tracking Protection,” choose Standard, Strict, or Custom
- Under “Cookies and Site Data,” adjust Your preferences or clear data
12.2.3 Microsoft Edge
- Click the three dots (⋯) in the upper right corner
- Select “Settings”
- Click “Cookies and site permissions”
- Under “Cookies and data stored,” manage Your preferences
- Toggle “Block third-party cookies” or clear existing cookies
12.2.4 Safari (macOS)
- Click “Safari” in the menu bar
- Select “Preferences” (or “Settings” on macOS Ventura+)
- Click the “Privacy” tab
- Adjust cookie preferences: “Prevent cross-site tracking,” “Block all cookies”
- Manage privacy report and website data
12.2.5 Opera
- Click the “O” menu (top-left) or “Settings” via the sidebar
- Select “Settings” then “Privacy & security”
- Under “Cookies and other site data,” adjust Your preferences
- Use “Clear browsing data” to remove existing cookies
12.2.6 Brave
- Click the menu (☰) in the upper right corner
- Select “Settings”
- Under “Shields,” adjust global privacy controls
- Under “Privacy and security,” manage cookies and site data
- Brave’s built-in Shields block trackers and ads by default
12.2.7 Vivaldi
- Click “Vivaldi” menu (top-left) then “Settings”
- Select “Privacy” from the left panel
- Under “Cookies,” adjust Your preferences
- Use the “Clear browsing data” button to remove cookies
12.2.8 Arc Browser
- Click “Arc” in the menu bar then “Settings”
- Select “Privacy” from the sidebar
- Manage cookie preferences and tracking protection
- Arc uses Chrome’s underlying engine, so cookie settings work similarly
12.2.9 DuckDuckGo Browser
- Click the shield icon in the address bar
- DuckDuckGo automatically blocks third-party trackers and cookies
- Access “Settings” then “Privacy” for granular controls
- Use the “Fire Button” to clear all data with one click
12.3 Privacy-Enhancing Extensions
The following browser extensions can help You enhance Your privacy online:
| Extension | Purpose | Advantages | Installation | Official Site |
|---|---|---|---|---|
| uBlock Origin | Efficient content blocker for ads, trackers, and malware domains | Low memory usage, highly customizable, open source | Available for Chrome, Firefox, Edge, Opera, Brave | ublock.org |
| Privacy Badger | Automatically learns to block invisible trackers by EFF | AI-based learning, no configuration needed, open source | Available for Chrome, Firefox, Edge, Opera | privacybadger.org |
| Ghostery | Blocks ads, stops trackers, and speeds up websites | User-friendly interface, tracker categorization, privacy dashboard | Available for Chrome, Firefox, Edge, Opera, Safari | ghostery.com |
| Adblock Plus | Blocks annoying ads and tracking | Easy to use, acceptable ads program, filter lists | Available for Chrome, Firefox, Edge, Opera, Safari | adblockplus.org |
| ClearURLs | Removes tracking parameters from URLs | Prevents tracking via URL parameters, open source | Available for Chrome, Firefox, Edge | clearurls.xyz |
| Decentraleyes | Emulates Content Delivery Networks locally | Prevents CDN tracking, speeds up loading, open source | Available for Chrome, Firefox | decentraleyes.org |
12.4 Advanced Privacy Tools
For users who want additional privacy protection, the following advanced tools are recommended:
| Tool | Purpose | Advantages | Installation | Official Site |
|---|---|---|---|---|
| LocalCDN | Emulates CDNs locally by loading resources from local copies | No requests to external CDNs, better privacy, open source; fork of Decentraleyes with more resources | Available for Firefox (WebExtensions) | localcdn.org |
| Cookie AutoDelete | Automatically deletes cookies when a tab is closed | Granular control, whitelist support, automatic cleanup, open source | Available for Chrome, Firefox, Edge | cookieautodelete.com |
| CanvasBlocker | Prevents fingerprinting via canvas, WebGL, AudioContext, and more | Blocks fingerprinting techniques, configurable, open source | Available for Firefox | github.com/kkapsner/CanvasBlocker |
| NoScript | Blocks JavaScript, Java, Flash, and other executable content | Maximum security, per-site whitelisting, open source | Available for Firefox, Chrome (limited) | noscript.net |
Please note that using some of these advanced tools may affect website functionality. We recommend starting with Our built-in “Change Privacy Settings” button (finger icon, bottom-left corner) before installing additional tools.
13. Conclusion
Thank you for taking the time to read Our Privacy Policy. We are committed to protecting Your privacy and maintaining the security of Your personal information. We believe in transparency and aim to empower You with knowledge about Your data and Your rights. If You have any questions, concerns, or feedback about Our Privacy Policy or data practices, please refer to Section 2 – Contact Information. We value Your input and are committed to addressing any privacy-related inquiries promptly and thoroughly.
This Privacy Policy was created by graphicatelier for use on www.graphicatelier.com. Reproduction, even in part, is prohibited without the author’s authorization under Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market.
And finally, if you’ve made it this far, congratulations! You are among the few people who read privacy policies to the end. Your dedication to understanding how your personal data is handled is commendable. Thank you for your attention and for trusting us with your information.