Last modified: 2026-07-27

Summary

1. Introduction

Welcome to www.graphicatelier.com (hereinafter referred to as the “Site”), a website operated by graphicatelier (hereinafter referred to as “We”, “Our”, or “graphicatelier”). If you use this Site, you are considered a user (hereinafter referred to as “You” or “Your” or “User”). This Privacy Policy (hereinafter referred to as the “Policy”) governs how We collect, use, store, and disclose information about You when You use this Site. This Policy also applies to information collected by third-party services We use to enhance Your experience on the Site (hereinafter referred to as “Third-Party Services”).

1.1 Objectives of this Policy

The objectives of this Policy are to inform You about:

  • The types of information We collect and process
  • How We use and share this information
  • With whom We share this information and why
  • Your data protection rights under applicable regulations
  • How to exercise Your rights and manage Your privacy preferences
  • Our compliance with the General Data Protection Regulation (GDPR), the ePrivacy Directive (2002/58/EC), and applicable Austrian data protection laws

1.2 What is GDPR?

GDPR, or the General Data Protection Regulation (Regulation (EU) 2016/679), is a European Union law that came into effect on May 25, 2018. GDPR aims to give EU citizens and residents full control over their personal data and to harmonise data protection regulations within the EU. It establishes strict requirements for organisations that collect, process, and store personal data, and provides individuals with enhanced rights regarding their personal information. The Regulation applies to all organisations processing personal data of data subjects residing in the EU, regardless of the organisation’s location.

1.3 Scope of this Policy

This Policy applies to all personal data processing activities carried out by graphicatelier through the Site. It covers:

  • Data You provide directly to Us (e.g., through contact forms, comments, subscriptions)
  • Data We collect automatically (e.g., through cookies, analytics, server logs)
  • Data We receive from Third-Party Services integrated into the Site
  • Data processed by third-party service providers acting on Our behalf

This Policy does not apply to third-party websites that may be linked from our Site. We encourage You to review the privacy policies of those websites before providing them with any personal information.

1.4 What Information is Collected

We collect various types of information to provide and improve Our services. This information may include, but is not limited to:

  • Personal identification data: name, email address, phone number, postal address
  • Technical data: IP address, browser type and version, operating system, device type
  • Usage data: pages visited, time spent on the Site, referring URLs, click patterns
  • Preference data: language preferences, cookie consent choices, subscription settings
  • Communication data: message content submitted through forms, comment content
  • Transactional data: order history, purchase information (if applicable)

The specific information We collect and how We use it is detailed throughout this Policy, particularly in Section 8 – Data Collected.

2. Contact Information

If You have any questions or concerns about this Policy or how We handle Your data, please contact Our Data Protection Officer, who is the data controller for Your personal information:

Role Details
Company Name graphicatelier
Representative Name Pierre Niel
Address Wimmerfeld 27, 4492 Hofkirchen, Austria
Phone Number +43 650 956 5454
Email Address pierre@graphicatelier.com
Website www.graphicatelier.com

You also have the right to lodge a complaint with the Austrian Data Protection Authority if You believe that the processing of Your personal data infringes the provisions of the GDPR:

Role Details
Authority Austrian Data Protection Authority (Österreichische Datenschutzbehörde – DSB)
Address Barichgasse 40-42, 1030 Vienna, Austria
Phone +43 1 52 152-0
Email dsb@dsb.gv.at
Website https://www.dsb.gv.at/

3. Lawfulness of Processing

In this section, We explain the legal bases on which We rely for processing Your personal data in accordance with the provisions of the GDPR. Each processing activity carried out by graphicatelier is grounded in at least one legal basis, as required by Article 5(1)(a) of the GDPR (lawfulness, fairness, and transparency).

The processing of Your personal data is based on one or more of the following legal bases, as established in Article 6 of the GDPR:

When You use this Site, You may give Your consent to the processing of Your personal data for specific purposes. Consent must be freely given, specific, informed, and unambiguous, in accordance with Article 7 of the GDPR and the requirements of the ePrivacy Directive (Article 5(3)). You have the right to withdraw Your consent at any time by referring to Section 2 – Contact Information or through the cookie settings interface. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

3.1.2 Legitimate Interests — Article 6(1)(f) of the GDPR

We may process Your data when it is necessary for Our legitimate interests or those of a third party, provided that these interests do not override Your rights and interests. Before processing data on this basis, We conduct a Legitimate Interest Assessment (LIA) in accordance with EDPB Guidelines 3/2019 on processing of personal data through video devices to ensure a proper balance between Our interests and Your rights. Our legitimate interests include: ensuring website security, improving Our services, and protecting against fraud.

3.1.3 Contractual Necessity — Article 6(1)(b) of the GDPR

Processing of Your data may be necessary for the performance of a contract to which You are a party or for taking pre-contractual steps at Your request.

We may process Your data when it is necessary to comply with a legal obligation to which We are subject under Austrian and EU law.

3.1.5 Vital Interests — Article 6(1)(d) of the GDPR

In rare situations where a person’s life or health is at stake, We may process personal data if it is necessary to safeguard vital interests.

3.1.6 Public Interest — Article 6(1)(e) of the GDPR

We may also process Your personal data when such processing is necessary for the performance of a task carried out in the public interest.

3.2 Summary

The lawfulness of processing Your personal data by graphicatelier is established on several legal bases. For processing activities that may pose a high risk to Your rights and freedoms, We conduct Data Protection Impact Assessments (DPIAs) as required by Article 35 of the GDPR, in accordance with EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR.

4. Rights of Concerned Individuals

As a User, You have certain rights regarding the processing of Your personal data. We are committed to respecting these rights and facilitating their exercise, in accordance with the provisions of Articles 12–22 of the GDPR. We will respond to all requests without undue delay and at the latest within one month, unless the request is particularly complex or We have received numerous requests, in which case We may extend the response period by up to two additional months in accordance with Article 12(3) of the GDPR.

4.1 Right of Access — Article 15 of the GDPR

You have the right to obtain confirmation as to whether personal data concerning You is being processed, access this data, and receive additional information about its use. You may request a free copy of the personal data being processed.

4.2 Right to Rectification — Article 16 of the GDPR

You have the right to request the correction of Your personal data if it is inaccurate or incomplete.

4.3 Right to Erasure — Article 17 of the GDPR

You have the right to request the deletion of Your personal data under certain conditions. This right is not absolute and may be limited by legal obligations as provided in Article 17(3) of the GDPR.

4.4 Right to Restriction of Processing — Article 18 of the GDPR

You can request the restriction of the processing of Your personal data in certain circumstances.

4.5 Right to Data Portability — Article 20 of the GDPR

You have the right to receive Your personal data in a structured, commonly used, and machine-readable format.

4.6 Right to Object — Article 21 of the GDPR

You have the right to object to the processing of Your personal data in certain situations. Where We process personal data for direct marketing, You have an absolute right to object at any time.

4.7 Right Not to Be Subject to Automated Decision-Making — Article 22 of the GDPR

You have the right not to be subject to a decision based solely on automated processing. We do not currently make any automated decisions with legal or similarly significant effects.

4.8 Summary

If You wish to exercise any of these rights, please refer to Section 2 – Contact Information. We will respond to Your request without undue delay and at the latest within one month in accordance with Article 12(3) of the GDPR.

5. Data Collection

When You use Our Site, various categories of information may be gathered to provide You with an optimal user experience, in line with Our service objectives. This data collection is carried out in full compliance with the GDPR and the ePrivacy Directive.

5.1 Information Provided Directly by the User

When You browse the Site or use certain of Our services, You have the option to provide Us with data such as Your name, email address, phone number, and more. Examples of when You might provide this information include:

  • When filling out contact forms
  • When subscribing to newsletters or email notifications
  • When posting comments on articles
  • When participating in surveys or contests
  • When creating a user account (if applicable)
  • When placing an order or making a purchase (if applicable)

5.2 Information Automatically Collected

When You visit the Site, certain information may be automatically collected, such as Your IP address, browser details, operating system, and more. The automatically collected information includes:

  • IP address and approximate location derived from it
  • Browser type and version
  • Operating system and device type (desktop, mobile, tablet)
  • Referring website and exit pages
  • Pages visited and time spent on each page
  • Actions taken on the Site (clicks, scrolls, form interactions)
  • Date and time of visit
  • Language preferences
  • Screen resolution and colour depth

5.3 Information from Third-Party Services

We may also receive information about You from Third-Party Services We use to enhance Our Site and services. For detailed information about each Third-Party Service and the data they collect, please refer to Section 8 – Data Collected. If You have questions regarding the collection of Your personal data, please refer to Section 2 – Contact Information.

6. Use of Your Personal Data

The personal data We collect is used for various purposes, always in strict compliance with applicable laws.

6.1 Communication and Service

We process Your data, such as Your email address, to communicate with You, keep You informed of Our service updates, or respond to Your requests. This use arises from Our contractual obligation to provide You with the service for which You have registered, in accordance with Article 6(1)(b) of the GDPR.

6.2 Service Improvement

Automatically collected information helps Us understand how users interact with Our Site. This understanding allows Us to enhance Our services to better meet Your needs, in accordance with Article 6(1)(f) of the GDPR (legitimate interest).

We may also use Your data to comply with Our legal obligations, for example, to respond to a request from a judicial authority or to maintain required business records, in accordance with Article 6(1)(c) of the GDPR.

If You have questions regarding the use of Your personal data, please refer to Section 2 – Contact Information.

7. Sharing of Your Personal Data

We attach great importance to the privacy of Your data. However, in certain situations, it may be necessary to share Your personal data. Each sharing is strictly regulated by the GDPR, ensuring the highest protection of Your information.

7.1 Service Partners

We may share Your data with third-party partners who assist Us in operating the Site, providing Our services, or processing transactions on Our behalf. These third parties are required to process this data in accordance with the law and in compliance with Our commitment to protecting Your privacy, in alignment with Article 28 of the GDPR (processors). We have Data Processing Agreements (DPAs) in place with each service partner, as required by Article 28(3) of the GDPR.

We may be obligated to disclose Your data if required by law, when We believe such disclosure is necessary to protect Our rights, the safety of others, or to respond to a judicial or governmental request, in accordance with Article 6(1)(c) of the GDPR.

7.3 International Transfers

If We need to transfer Your data outside of the European Economic Area (EEA), We ensure that these transfers comply with the requirements of the GDPR, thus ensuring adequate protection of Your data, in accordance with Chapter V of the GDPR (Articles 44–49). This includes implementing appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission in accordance with Commission Implementing Decision (EU) 2021/914 (the new modular SCCs).
  • EU-US Data Privacy Framework (DPF) for transfers to participating US organisations, as established by the European Commission’s adequacy decision (EU) 2023/1795.
  • Transfer Impact Assessments (TIAs) conducted in accordance with EDPB Recommendations 01/2020.
  • Supplementary measures as necessary to ensure an adequate level of protection.

7.3.1 EU-US Data Privacy Framework (DPF)

The EU-US Data Privacy Framework (DPF) became operational in July 2023 following the European Commission’s adequacy decision (EU) 2023/1795. This framework is supported by Executive Order 14086 (October 2022) and includes a UK Extension and a Swiss-US DPF. You can verify an organisation’s participation status on the official Data Privacy Framework website.

If You have any questions regarding the sharing of Your personal data, please refer to Section 2 – Contact Information.

8. Data Collected

Our Site uses various technologies to collect and store information when You visit it. This may include the use of cookies, local storage, session storage, IndexedDB, or similar technologies. In accordance with Article 5(3) of the ePrivacy Directive (2002/58/EC) and in line with EDPB Guidelines 02/2023, We provide detailed information about each storage technology used on this Site.

8.1 Cookies

Cookies are small text files that websites place on Your device to store information about Your preferences, enhance site functionality, and collect analytics data. In addition to HTTP cookies, websites may use other storage technologies:

  • LocalStorage: Stores data persistently in the browser with no expiration date.
  • SessionStorage: Stores data for the duration of the browser session only.
  • IndexedDB: A client-side database that can store significant amounts of structured data.
  • Fingerprinting: Techniques that collect device and browser characteristics to create a unique device identifier.

Cookies serve several important functions on websites:

  • Essential cookies: Required for the website to function properly. Exempt from consent under the ePrivacy Directive.
  • Functional cookies: Help to enhance the functionality and personalisation of the website.
  • Statistics cookies: Help website owners understand how visitors interact with websites.
  • Marketing cookies: Used to track visitors across websites.

The use of cookies is primarily regulated by two key pieces of legislation in the European Union:

Cookies come in different types: First-party (issued by the site You visit), Third-party (issued by domains other than the site You visit), Session (deleted when browser closes), and Persistent (stored for a specified period).

Essential cookies are exempt from the consent requirement under Article 5(3) of the ePrivacy Directive. Functional, Statistics, and Marketing cookies require prior informed consent under Article 6(1)(a) of the GDPR.

You can manage Your cookie preferences through Our consent management tool or Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Attribute Details
Service Name Real Cookie Banner (RCB)
Provider devowl.io GmbH
Address Tannet 12, 94539 Grafling, Germany
Email support@devowl.io
Privacy Policy devowl.io/rcb/data-processing
Data Transfers None (self-hosted, all data stored locally)
DPF Status Not applicable (German provider, EEA-based)

We use Real Cookie Banner to ensure legal compliance with cookie consent regulations while providing You with a transparent way to manage Your privacy preferences. It supports IAB TCF v2.2 and uses a blocking mode that prevents third-party scripts from loading until consent has been obtained.

Real Cookie Banner processes: Your consent choices, timestamp of consent, UUID, browser type and version, anonymized IP address, language preferences, operating system, and referrer URL.

Name Host Purpose Lifetime Requires Consent Type
rcb_* graphicatelier.com Stores the UUID of the consent given 1 year No (Essential) HTTP Cookie
rcb_*-tcf graphicatelier.com Stores consent via TCF v2.2 1 year No (Essential) HTTP Cookie
rcb-test graphicatelier.com Tests if HTTP cookies can be set Session No (Essential) HTTP Cookie
rcb-*-blog graphicatelier.com Consent status for multisite network 1 year No (Essential) HTTP Cookie

Real Cookie Banner is self-hosted on Our web server. No data is transferred outside the EEA by the plugin itself. If You consent to third-party services through the banner, those services may transfer data internationally according to their own privacy policies.

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Real Cookie Banner, visit devowl.io/rcb/data-processing.

Controller: graphicatelier Processor: devowl.io GmbH
Data Categories: Consent choices, UUID, anonymized IP Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.3 WordPress Comments

8.3.1 Definition and Provider

Attribute Details
Service Name WordPress Comments (Native)
Provider Self-hosted (WordPress.org)
Data Transfers None by default (self-hosted). Gravatar requests may reach Automattic (US)

8.3.2 Purpose

WordPress Comments allows users to engage in discussions on Our published content. This helps enhance community engagement and provides valuable feedback.

8.3.3 Categories of Personal Data Processed

When You leave a comment: name, email address, website URL (optional), IP address, browser user agent string, comment content, and timestamp.

8.3.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
comment_author_[hash] graphicatelier.com Stores commenter’s name for prefilling 1 year No (Essential) HTTP Cookie
comment_author_email_[hash] graphicatelier.com Stores commenter’s email for prefilling 1 year No (Essential) HTTP Cookie
comment_author_url_[hash] graphicatelier.com Stores commenter’s website URL for prefilling 1 year No (Essential) HTTP Cookie

8.3.5 External Data Loading and International Transfers

WordPress Comments is self-hosted. However, if You use a Gravatar-linked email address, Your browser may request profile images from Automattic’s servers in the US. For more information, refer to Automattic’s Privacy Policy.

8.3.6 Data Retention

Comments and their metadata are retained indefinitely. Registered users can see, edit, or delete their personal information.

8.3.7 How to Withdraw or Object Consent

You can request deletion of Your comments by referring to Section 2 – Contact Information. You can also manage comment-related cookies through Your browser settings.

For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article
Facilitating discussions Art. 6(1)(a) of the GDPR (consent) and Art. 6(1)(f) of the GDPR (legitimate interest)

8.3.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For WordPress’s general data handling, visit WordPress Privacy Policy.

8.3.10 At a Glance

Data Categories: Name, email, IP, comment content Transfer: None (except Gravatar)
Retention: Indefinite Consent Required: Conditional

8.4 Contact Form 7

8.4.1 Definition and Provider

Attribute Details
Service Name Contact Form 7
Provider Takayuki Miyoshi (self-hosted plugin)
Plugin Privacy contactform7.com/privacy-policy
Data Transfers None by default (self-hosted)

8.4.2 Purpose

Contact Form 7 enables You to communicate with Us through forms on Our website. Form submissions are processed entirely on Our server.

8.4.3 Categories of Personal Data Processed

Name, email address, phone number (if requested), message content, subject line, IP address, timestamp, and browser user agent.

8.4.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Contact Form 7 in Our implementation

8.4.5 External Data Loading and International Transfers

Contact Form 7 is self-hosted. No data is transferred outside the EEA by the plugin itself. If reCAPTCHA is integrated with the form, please refer to the reCAPTCHA section for data transfer details.

8.4.6 Data Retention

Form submissions are retained for up to 3 years, after which they are securely deleted unless there is a legitimate business or legal reason to retain them longer.

8.4.7 How to Withdraw or Object Consent

Please refer to Section 2 – Contact Information to request access to, correction, or deletion of Your personal data submitted through the form.

For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article
Responding to inquiries Art. 6(1)(a) of the GDPR (consent), Art. 6(1)(b) of the GDPR (contract), Art. 6(1)(f) of the GDPR (legitimate interest)

8.4.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For plugin information, visit contactform7.com.

8.4.10 At a Glance

Data Categories: Name, email, message content Transfer: None (EEA only)
Retention: Up to 3 years Consent Required: Yes

8.5 Google reCAPTCHA

8.5.1 Definition and Provider

Attribute Details
Service Name Google reCAPTCHA
Provider Google LLC
Address 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Email privacy@google.com
Privacy Policy policies.google.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Google LLC may rely on the EU-U.S. Data Privacy Framework where certified, or on other documented transfer safeguards such as SCCs.

8.5.2 Purpose

Google reCAPTCHA helps prevent automated spam and abuse by verifying that the user is human.

8.5.3 Categories of Personal Data Processed

When You use reCAPTCHA: IP address, browser user agent string, anonymized IP address, and timestamp.

8.5.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by reCAPTCHA in Our implementation

8.5.5 External Data Loading and International Transfers

Google reCAPTCHA loads Google scripts and sends security and interaction signals to Google. Data may be processed outside the EEA as described in the warning below.

⚠ Data transferred outside the EEA: Google reCAPTCHA transmits data to Google’s servers in the United States. Protected by the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.5.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.5.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.5.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about reCAPTCHA, visit Google’s reCAPTCHA.

8.5.10 At a Glance

Controller: graphicatelier Processor: Google LLC
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.6 Google Fonts

8.6.1 Definition and Provider

Attribute Details
Service Name Google Fonts
Provider Google LLC
Address 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Email privacy@google.com
Privacy Policy policies.google.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Google LLC may rely on the EU-U.S. Data Privacy Framework where certified, or on other documented transfer safeguards such as SCCs.

8.6.2 Purpose

Google Fonts allows users to select and use custom fonts on Our website.

8.6.3 Categories of Personal Data Processed

When You use Google Fonts: IP address, browser user agent string, anonymized IP address, and timestamp.

8.6.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Google Fonts in Our implementation

8.6.5 External Data Loading and International Transfers

If Google Fonts is loaded from Google servers, the browser requests font resources from Google and technical data such as the IP address may be transmitted. If fonts are genuinely self-hosted, this external request does not occur; the implementation must be verified before publication.

⚠ Data transferred outside the EEA: Google Fonts loads from Google’s servers which may be located in the United States. Protected by the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.6.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.6.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.6.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Google Fonts, visit Google Fonts.

8.6.10 At a Glance

Controller: graphicatelier Processor: Google LLC
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.7 Google Maps

8.7.1 Definition and Provider

Attribute Details
Service Name Google Maps
Provider Google LLC
Address 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Email privacy@google.com
Privacy Policy policies.google.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Google LLC may rely on the EU-U.S. Data Privacy Framework where certified, or on other documented transfer safeguards such as SCCs.

8.7.2 Purpose

Google Maps allows users to view and interact with maps on Our website.

8.7.3 Categories of Personal Data Processed

When You use Google Maps: IP address, browser user agent string, anonymized IP address, and timestamp.

8.7.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Google Maps in Our implementation

8.7.5 External Data Loading and International Transfers

Google Maps is not self-hosted when an embedded map, JavaScript API, or Google map tiles are loaded. The browser connects directly to Google services and may transmit technical, location, search, and interaction data. A static, locally hosted map image would be a different implementation.

⚠ Data transferred outside the EEA: Google Maps loads map data from Google’s servers in the United States. Protected by the EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.7.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.7.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.7.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Google Maps, visit Google Maps.

8.7.10 At a Glance

Controller: graphicatelier Processor: Google LLC
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.8 Jetpack Stats

8.8.1 Definition and Provider

Attribute Details
Service Name Jetpack Stats
Provider Automattic, Inc.
Address 1355 Market Street, San Francisco, CA 94103, USA
Email privacy@automattic.com
Privacy Policy automattic.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Not applicable (US provider, EEA-based)

8.8.2 Purpose

Jetpack Stats provides analytics and insights into user engagement on Our website.

8.8.3 Categories of Personal Data Processed

When You use Jetpack Stats: IP address, browser user agent string, anonymized IP address, and timestamp.

8.8.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Jetpack Stats in Our implementation

8.8.5 External Data Loading and International Transfers

Jetpack Stats is not self-hosted. The Jetpack module sends measurement data to Automattic/WordPress.com services for analytics. The applicable transfer safeguards are described in the warning below.

⚠ Data transferred outside the EEA: Jetpack Stats transmits analytics data to Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, IP anonymization, data minimization, and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.8.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.8.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.8.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Stats, visit Jetpack Stats.

8.8.10 At a Glance

Controller: graphicatelier Processor: Automattic, Inc.
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.9 Jetpack Comments

8.9.1 Definition and Provider

Attribute Details
Service Name Jetpack Comments
Provider Automattic, Inc.
Address 1355 Market Street, San Francisco, CA 94103, USA
Email privacy@automattic.com
Privacy Policy automattic.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Not applicable (US provider, EEA-based)

8.9.2 Purpose

Jetpack Comments provides analytics and insights into user engagement on Our website.

8.9.3 Categories of Personal Data Processed

When You use Jetpack Comments: IP address, browser user agent string, anonymized IP address, and timestamp.

8.9.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Jetpack Comments in Our implementation

8.9.5 External Data Loading and International Transfers

Jetpack Comments may exchange comment and authentication data with Automattic/WordPress.com services. The native WordPress comment database remains on the Site, but the Jetpack feature itself is not self-hosted.

⚠ Data transferred outside the EEA: Jetpack Comments transmits comment data to Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.9.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.9.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.9.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Comments, visit Jetpack Comments.

8.9.10 At a Glance

Controller: graphicatelier Processor: Automattic, Inc.
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.10 Jetpack Notifications

8.10.1 Definition and Provider

Attribute Details
Service Name Jetpack Notifications
Provider Automattic, Inc.
Address 1355 Market Street, San Francisco, CA 94103, USA
Email privacy@automattic.com
Privacy Policy automattic.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Not applicable (US provider, EEA-based)

8.10.2 Purpose

Jetpack Notifications provides analytics and insights into user engagement on Our website.

8.10.3 Categories of Personal Data Processed

When You use Jetpack Notifications: IP address, browser user agent string, anonymized IP address, and timestamp.

8.10.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Jetpack Notifications in Our implementation

8.10.5 External Data Loading and International Transfers

Jetpack Notifications communicates with Automattic/WordPress.com services to generate and deliver notifications. It is not a wholly self-hosted service.

⚠ Data transferred outside the EEA: Jetpack Notifications transmits notification data to Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.10.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.10.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.10.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Notifications, visit Jetpack Notifications.

8.10.10 At a Glance

Controller: graphicatelier Processor: Automattic, Inc.
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.11 Jetpack Subscriptions

8.11.1 Definition and Provider

Attribute Details
Service Name Jetpack Subscriptions
Provider Automattic, Inc.
Address 1355 Market Street, San Francisco, CA 94103, USA
Email privacy@automattic.com
Privacy Policy automattic.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Not applicable (US provider, EEA-based)

8.11.2 Purpose

Jetpack Subscriptions provides analytics and insights into user engagement on Our website.

8.11.3 Categories of Personal Data Processed

When You use Jetpack Subscriptions: IP address, browser user agent string, anonymized IP address, and timestamp.

8.11.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Jetpack Subscriptions in Our implementation

8.11.5 External Data Loading and International Transfers

Jetpack Subscriptions sends subscription data to Automattic/WordPress.com services for subscription management and email delivery. It is not self-hosted.

⚠ Data transferred outside the EEA: Jetpack Subscriptions stores subscription data on Automattic’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.11.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.11.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.11.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Jetpack Subscriptions, visit Jetpack Subscriptions.

8.11.10 At a Glance

Controller: graphicatelier Processor: Automattic, Inc.
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.12 Akismet

8.12.1 Definition and Provider

Attribute Details
Service Name Akismet
Provider Automattic, Inc.
Address 1355 Market Street, San Francisco, CA 94103, USA
Email privacy@automattic.com
Privacy Policy automattic.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Not applicable (US provider, EEA-based)

8.12.2 Purpose

Akismet helps prevent spam and abuse by identifying and filtering out automated content.

8.12.3 Categories of Personal Data Processed

When You use Akismet: IP address, browser user agent string, anonymized IP address, and timestamp.

8.12.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Akismet in Our implementation

8.12.5 External Data Loading and International Transfers

Akismet is a cloud-based spam filtering service. Comment and form metadata may be sent to Automattic/Akismet for spam analysis; the plugin itself is installed locally but the filtering service is not self-hosted.

⚠ Data transferred outside the EEA: Akismet transmits comment data to Automattic’s servers in the United States for spam analysis. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.12.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.12.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.12.9 Contact and Documentation

For questions specific to Our implementation, please refer to Section 2 – Contact Information. For more information about Akismet, visit Akismet.

8.12.10 At a Glance

Controller: graphicatelier Processor: Automattic, Inc.
Data Categories: IP, browser user agent Transfer: None (EEA only)
Retention: 12 months or until consent withdrawal Consent Required: No (Essential)
Opt-Out Method: “Change Privacy Settings” button (finger icon, bottom-left)

8.13 Flickr

8.13.1 Definition and Provider

Attribute Details
Service Name Flickr
Provider Flickr, Inc.
Address 1355 Market Street, San Francisco, CA 94103, USA
Email privacy@flickr.com
Privacy Policy flickr.com/privacy
Data Transfers External service; data may be processed by the provider
DPF Status Not applicable (US provider, EEA-based)

8.13.2 Purpose

Flickr allows users to share and view images on Our website.

8.13.3 Categories of Personal Data Processed

When You use Flickr: IP address, browser user agent string, anonymized IP address, and timestamp.

8.13.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
No cookies are set by Flickr in Our implementation

8.13.5 External Data Loading and International Transfers

Flickr is an external image-hosting and embedding service. Embedded images, scripts, or players may cause the browser to connect directly to Flickr services and transmit technical data.

⚠ Data transferred outside the EEA: Flickr loads embedded content from Flickr’s servers in the United States. Protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and a Transfer Impact Assessment (TIA) under EDPB Recommendations 01/2020.

8.13.6 Data Retention

Consent records are stored for 12 months from the date consent was given, or until You withdraw Your consent, as required by Article 7(1) of the GDPR.

8.13.7 How to Withdraw or Object Consent

Click on the “Change Privacy Settings” button (finger icon) located in the bottom-left corner of every page. You can also clear cookies through Your browser settings. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Storing and managing cookie consent Art. 6(1)(c) of the GDPR (legal obligation) Art. 5(3) ePrivacy Directive (exemption)
Managing cookies and similar technologies Art. 6(1)(f) of the GDPR (legitimate interest)

8.13.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For more information about Flickr, visit Flickr Privacy.

8.14 WooCommerce

8.14.1 Definition and Provider

Attribute Details
Service Name WooCommerce
Provider Automattic, Inc. (self-hosted WordPress plugin)
Privacy Policy Automattic Privacy Policy
Data Transfers Core plugin is self-hosted; payment gateways, shipping providers, tax services, and extensions may make separate transfers.

8.14.2 Purpose

WooCommerce provides shopping-cart, checkout, customer-account, order-management, and product-delivery functionality where e-commerce is enabled.

8.14.3 Categories of Personal Data Processed

Depending on the checkout and account configuration: name, billing and shipping address, email address, telephone number, account credentials, order and download history, IP address, device data, and payment or transaction references. Full payment-card details should normally be processed by the selected payment provider, not stored by WooCommerce.

8.14.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
woocommerce_cart_hash graphicatelier.com Helps identify changes to the shopping cart Session No, where strictly necessary HTTP Cookie
woocommerce_items_in_cart graphicatelier.com Indicates whether the cart contains items Session No, where strictly necessary HTTP Cookie
wp_woocommerce_session_* graphicatelier.com Maintains the customer shopping session Up to 2 days No, where strictly necessary HTTP Cookie

8.14.5 External Data Loading and International Transfers

WooCommerce core is hosted on the Site. Any payment gateway, shipping, tax, email, fraud-prevention, or other extension is a separate service and may transmit data outside the EEA. The applicable provider and safeguard must be identified before activation.

8.14.6 Data Retention

Order and accounting records are retained for the period required by applicable Austrian tax and commercial law. Account data is retained while the account is active, subject to legal-hold and dispute exceptions.

8.14.7 How to Withdraw or Object Consent

You may manage or delete an account where available, and you may request access, correction, restriction, or erasure by referring to Section 2 – Contact Information. For privacy-setting instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Account, cart, checkout, and order fulfilment Article 6(1)(b) GDPR (contract or pre-contractual steps) Article 5(3) ePrivacy exemption where strictly necessary
Accounting, tax, and fraud prevention Article 6(1)(c) or (f) GDPR Conditional; consent where non-essential storage is used

8.14.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For plugin documentation, visit WooCommerce Documentation.

8.14.10 At a Glance

Controller: graphicatelier
Processor: self-hosted WooCommerce and separately configured providers
Consent Required: Conditional; strictly necessary cart and checkout storage is exempt, non-essential storage requires consent
Opt-Out: Account controls, provider controls, and Section 12.

8.15 WPForms

8.15.1 Definition and Provider

Attribute Details
Service Name WPForms
Provider WPForms LLC (self-hosted plugin)
Privacy Policy WPForms Privacy Policy
Data Transfers Form data is normally stored on the Site; integrations, email delivery, payments, and anti-spam services may transfer data.

8.15.2 Purpose

WPForms enables contact, registration, survey, quotation, and other forms configured by the Site operator.

8.15.3 Categories of Personal Data Processed

The fields You submit, such as name, email address, telephone number, message content, attachments, IP address, user agent, referrer, and timestamp. The exact fields depend on the form.

8.15.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
wpforms_* graphicatelier.com Form functionality, anti-spam, and session-related operation where configured Session or configuration-dependent Conditional HTTP Cookie

8.15.5 External Data Loading and International Transfers

The WPForms plugin is self-hosted, but configured integrations such as Google reCAPTCHA, Cloudflare Turnstile, payment providers, SMTP services, or marketing platforms may receive data. Please refer to the relevant service section.

8.15.6 Data Retention

Entries are retained only as long as necessary to respond, administer the relationship, establish or defend claims, and satisfy legal obligations. The configured retention period must be checked in WPForms and any connected storage or email system.

8.15.7 How to Withdraw or Object Consent

Do not submit optional information if You do not wish to provide it. To request access, correction, restriction, or deletion, please refer to Section 2 – Contact Information. For privacy-setting instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Responding to a request or providing a requested service Article 6(1)(b) GDPR or consent under Article 6(1)(a) Consent unless storage is strictly necessary
Security and abuse prevention Article 6(1)(f) GDPR Conditional

8.15.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For WPForms information, visit WPForms Privacy Policy.

8.15.10 At a Glance

Controller: graphicatelier
Processor: WPForms is self-hosted; integrations are separate processors
Data Categories: Form fields and technical submission data
Consent Required: Conditional
Opt-Out: Section 2 and Section 12.

8.16 WPML

8.16.1 Definition and Provider

Attribute Details
Service Name WPML
Provider OnTheGoSystems Limited
Address 22/F, 3 Lockhart Road, Wan Chai, Hong Kong
Privacy Policy WPML Privacy Policy and GDPR Compliance

8.16.2 Purpose

WPML provides multilingual content, language switching, translated URLs, and related WordPress language functionality.

8.16.3 Categories of Personal Data Processed

Language preference, browser language, IP address or approximate location only if a browser-redirection or geolocation feature is enabled, and technical request data. Translation-service features may process content sent for translation.

8.16.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
wp-wpml_current_language graphicatelier.com Stores the selected language Up to 1 day No, where strictly necessary for the requested language service HTTP Cookie
_icl_visitor_lang_js graphicatelier.com Supports language selection in JavaScript features Session Conditional HTTP Cookie
wpml_browser_redirect_test graphicatelier.com Tests browser-language redirection Session Conditional HTTP Cookie

8.16.5 External Data Loading and International Transfers

Core WPML language switching is primarily executed on the Site. Automatic translation, translation-management, license, update, or remote support features may connect to OnTheGoSystems or a selected translation provider, including outside the EEA. The specific feature and provider must be verified before publication.

8.16.6 Data Retention

Language-preference cookies expire according to the configured WPML feature. Translation content and account or license records are retained according to the relevant Site and provider retention settings.

8.16.7 How to Withdraw or Object Consent

Select a language manually, disable browser redirection, or delete the language cookie through Your browser. For data-rights requests, please refer to Section 2 – Contact Information. For privacy-setting instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Language selection and requested multilingual service Article 6(1)(b) or (f) GDPR Strictly necessary where required for the language service; otherwise consent
Optional automatic translation or remote services Article 6(1)(a) GDPR or another documented basis Consent where non-essential storage or access is used

8.16.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For provider information, visit WPML Privacy Policy and GDPR Compliance.

8.16.10 At a Glance

Controller: graphicatelier
Provider: OnTheGoSystems Limited and any selected translation provider
Transfer: Conditional; verify remote translation features
Consent Required: Conditional
Opt-Out: Language switcher, browser controls, and Section 12.

8.17 Vimeo

8.17.1 Definition and Provider

Attribute Details
Service Name Vimeo
Provider Vimeo.com, Inc.
Address 555 West 18th Street, New York, NY 10011, USA
Privacy Policy Vimeo Privacy Policy

8.17.2 Purpose

Vimeo hosts and delivers embedded video content on the Site.

8.17.3 Categories of Personal Data Processed

IP address, browser and device information, referrer URL, playback interactions, and viewing preferences. Vimeo may associate viewing activity with a Vimeo account if You are signed in.

8.17.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
vuid .vimeo.com Unique visitor and analytics identifier Up to 2 years Yes HTTP Cookie
player .vimeo.com Player preferences Configuration-dependent Yes HTTP Cookie or LocalStorage

8.17.5 External Data Loading and International Transfers

Embedded Vimeo content causes the browser to connect to Vimeo. Data may be processed in the United States or other countries under Vimeo’s documented safeguards.

8.17.6 Data Retention

Vimeo retains data according to its privacy and retention policies and the configuration of the embedded player.

8.17.7 How to Withdraw or Object Consent

Click “Change Privacy Settings” (finger icon, bottom-left) and disable the relevant category before Vimeo is loaded. For further instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Embedded video delivery and measurement Article 6(1)(a) GDPR Prior consent for non-essential access

8.17.9 Contact and Documentation

Please refer to Section 2 – Contact Information. For provider information, visit Vimeo Privacy Policy.

8.17.10 At a Glance

Controller: graphicatelier
Provider: Vimeo.com, Inc.
Transfer: Potentially outside the EEA
Consent Required: Yes for non-essential embedding
Opt-Out: Section 12.

8.18 Cloudflare Turnstile

8.18.1 Definition and Provider

Attribute Details
Service Name Cloudflare Turnstile
Provider Cloudflare, Inc.
Address 101 Townsend St, San Francisco, CA 94107, USA
Privacy Policy Cloudflare Privacy Policy
Turnstile Addendum Turnstile Privacy Addendum

8.18.2 Purpose

Turnstile helps protect forms and other interactive features against automated abuse and bots. It evaluates signals for security and bot detection; it is not used by Us to identify or advertise to visitors.

8.18.3 Categories of Personal Data Processed

Cloudflare states that Turnstile may process client IP address, TLS fingerprint, user-agent header, sitekey, associated origin, challenge timestamp, hostname, action, and security signals. The Site may also send a remote IP address for server-side validation if configured.

8.18.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
Turnstile signals and challenge token challenges.cloudflare.com Bot detection and server-side validation Token valid for 5 minutes and single-use No, where strictly necessary for security Security signal / token
cf_clearance (if configured) graphicatelier.com or Cloudflare-managed domain Records a successful security challenge where applicable Configuration-dependent Conditional HTTP Cookie

8.18.5 External Data Loading and International Transfers

Turnstile loads Cloudflare resources and may send signals to Cloudflare. Cloudflare states that transfers from the EEA may rely on the EU-U.S. Data Privacy Framework, the UK Extension, the Swiss-U.S. DPF, or Standard Contractual Clauses with supplementary measures, as applicable.

⚠ Potential transfer outside the EEA: Cloudflare Turnstile may process security signals through Cloudflare’s global infrastructure, including in the United States. See Cloudflare’s Turnstile Privacy Addendum and current transfer safeguards.

8.18.6 Data Retention

Turnstile tokens expire after five minutes and may be validated only once. Other signals and records are retained according to Cloudflare’s Turnstile Addendum and applicable customer configuration.

8.18.7 How to Withdraw or Object Consent

Turnstile may be necessary to protect forms and therefore may not be disabled while using the protected feature. You may use an alternative contact method where available. For privacy controls and rights, please refer to Section 12 – Managing Your Privacy Settings and Section 2 – Contact Information.

Processing Purpose GDPR Article ePrivacy Basis
Security and bot prevention for a requested form or feature Article 6(1)(f) GDPR (legitimate interest), or Article 6(1)(b) where necessary for a requested service Strictly necessary exemption where applicable; otherwise consent

8.18.9 Contact and Documentation

8.18.10 At a Glance

Controller: graphicatelier for Site use; Cloudflare may be processor for service delivery and controller for improvement activities
Data Categories: Security signals, IP address if supplied, user agent, sitekey and origin
Transfer: Potentially outside the EEA
Consent Required: Conditional; strictly necessary security may be exempt
Opt-Out: Alternative contact method, Section 2, and Section 12.

8.19 Google Analytics 4

8.19.1 Definition and Provider

Attribute Details
Service Name Google Analytics 4
Provider Google Ireland Limited and Google LLC
EU Address Gordon House, 4 Barrow St, Dublin D04 E5W5, Ireland
Privacy Policy Google Privacy Policy
Documentation Google Analytics data protection

8.19.2 Purpose

Google Analytics 4 measures how visitors use the Site, including page views, events, approximate location, device and browser information, and campaign attribution. We must not send directly identifying information or special-category data to Google Analytics.

8.19.3 Categories of Personal Data Processed

Online identifiers, cookie or client identifiers, IP-derived approximate location, device and browser information, page URL and referrer, event data, language, screen information, and campaign parameters. Google Analytics prohibits customers from sending personally identifiable information.

8.19.4 Cookies and Local Storage

Name Host Purpose Lifetime Requires Consent Type
_ga .graphicatelier.com Distinguishes users Up to 2 years Yes HTTP Cookie
_ga_* .graphicatelier.com Maintains Analytics session state Up to 2 years Yes HTTP Cookie
_gid or other Google measurement cookies Configuration-dependent Measurement and session attribution where configured Configuration-dependent Yes HTTP Cookie

8.19.5 External Data Loading and International Transfers

Google Analytics loads Google measurement resources and transmits measurement data to Google. Google may process data in the United States and elsewhere. The configured implementation should use consent mode and privacy controls appropriate to the Site, including disabling Google signals and advertising personalization unless separately consented.

⚠ Potential transfer outside the EEA: Google Analytics data may be processed outside the EEA. Depending on the provider and configuration, safeguards may include the EU-U.S. Data Privacy Framework, Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, and supplementary measures.

8.19.6 Data Retention

Google Analytics user-level and event-level retention is configurable. Google Analytics 4 properties generally allow two or fourteen months for user and event data, with longer options for certain Analytics 360 properties. Aggregated standard reports are not necessarily affected by this setting. The retention setting configured for this Site must be verified and recorded.

8.19.7 How to Withdraw or Object Consent

Click “Change Privacy Settings” (finger icon, bottom-left) and disable Statistics or Analytics consent. You may also use Google’s Analytics opt-out browser add-on or delete Site cookies. For detailed instructions, please refer to Section 12 – Managing Your Privacy Settings.

Processing Purpose GDPR Article ePrivacy Basis
Analytics measurement Article 6(1)(a) GDPR (consent) Prior consent under Article 5(3) ePrivacy Directive
Security and configuration Article 6(1)(f) GDPR, where documented by a balancing assessment Only where strictly necessary; otherwise consent

8.19.9 Contact and Documentation

8.19.10 At a Glance

Controller: graphicatelier; Google acts as provider and may have independent controller roles for some processing
Data Categories: Analytics identifiers, device, browser, event, and approximate location data
Transfer: Potentially outside the EEA
Consent Required: Yes for analytics cookies and non-essential measurement
Opt-Out: Section 12 and Google’s opt-out controls.

9. Third-Party Service Providers

We engage third-party service providers to assist Us in managing and improving Our website. These providers may process or store personal data as part of providing these services. We ensure that these third-party service providers adhere to the same privacy and security standards as Us and only share Your personal data with them to the extent necessary for them to provide the respective services. We have Data Processing Agreements (DPAs) in place with these providers as required by Article 28 of the GDPR.

These third parties include:

  • Web hosting and IT service providers
  • Website analytics and tracking service providers
  • Content delivery networks
  • Security service providers
  • Communication and email service providers

9.1 Web Hosting

9.1.1 Definition and Provider

Attribute Details
Service Name Web Hosting
Provider Hetzner Online GmbH
Address Industriestraße 25, 91710 Gunzenhausen, Germany
DPO Email data-protection@hetzner.com
Privacy Policy hetzner.com/legal/privacy-policy

9.1.2 Purpose

We use Hetzner Online GmbH to store, maintain, and deliver Our website content to visitors. This service is essential for making Our website accessible on the internet.

9.1.3 Categories of Personal Data Processed

IP addresses, date and time of requests, browser type, operating system, referring URLs, files accessed, form submissions, database content, and server logs. All data is processed on servers located in Germany (EEA).

9.1.4 Data Retention

Server logs retained for up to 14 days. User data retained according to the purposes described in this Policy.

9.1.5 Security Measures

ISO 27001 certified data centers, network security, firewalls, intrusion detection, regular updates, backups, access controls, and SSL/TLS encryption.

Processing Purpose GDPR Article
Website hosting and delivery Art. 6(1)(b) of the GDPR (contract) / Art. 6(1)(f) of the GDPR (legitimate interest)

9.1.7 Contact and Documentation

Please refer to Section 2 – Contact Information. For more information about Hetzner’s data processing, visit Hetzner Privacy Policy.

9.1.8 At a Glance

Data Categories: IP, server logs, database content Transfer: None (Germany, EEA)
Retention: 14 days (logs) Consent Required: No (Essential)

10. Security Measures

10.1 Technical and Organisational Measures

The security of Your personal data is of paramount importance to Us. We have implemented comprehensive technical and organisational measures in accordance with Article 32 of the GDPR. These measures include:

  • Encryption: SSL/TLS encryption for data in transit
  • Access controls: Strict authentication and authorization mechanisms
  • Regular security assessments: Periodic audits, vulnerability scans, and penetration tests
  • Staff training: Regular data protection training for employees
  • Data minimization: Collecting only necessary personal data
  • Backup procedures: Regular backups for disaster recovery
  • Incident response plan: Procedures to detect, report, and investigate breaches

10.2 SSL Encryption

SSL (Secure Socket Layer) encryption establishes an encrypted link between Our web server and Your browser, ensuring that all data transmitted remains private and integral. This complies with Article 32 of the GDPR. You can verify this by checking for the padlock icon and “https://” prefix in Your browser’s address bar.

10.3 Breach Notification Process

If We become aware of a personal data breach that is likely to result in a risk to Your rights and freedoms, We will act promptly in accordance with Articles 33 and 34 of the GDPR. Our breach notification process includes:

  • Breach identification and containment: Immediate steps to identify and contain the breach
  • Impact assessment: Assessment of nature, scope, and potential consequences
  • Notification to supervisory authority: Within 72 hours to the Austrian Data Protection Authority
  • Notification to affected individuals: Without undue delay if high risk to rights and freedoms
  • Documentation: Full documentation of all breaches and remedial actions

10.4 Data Retention Period

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law:

  • Account data: As long as account is active, plus a reasonable period afterward
  • Communication data: Up to 3 years from last interaction
  • Transaction data: 7-10 years for tax and accounting requirements
  • Consent records: As long as data is processed based on that consent, plus additional period for compliance
  • Log data: 30-90 days for security and performance analysis

At the end of the retention period, personal data is securely deleted or anonymized. You have the right to request deletion in certain circumstances, as described in Section 4.3 – Right to Erasure.

11. Changes to Our Privacy Policy

We reserve the right to modify this Privacy Policy at any time to reflect changes in Our practices, services, or legal requirements. When We make substantial changes, We will notify You through a prominently displayed notice on Our website before the changes take effect. The date of the last update is clearly indicated at the top of this Policy. We encourage You to review this Policy regularly. If You have questions or concerns about changes, please refer to Section 2 – Contact Information.

12. Managing Your Privacy Settings

This section provides a comprehensive guide to managing Your privacy settings across different tools and platforms. Instead of repeating these instructions in every service section, We centralize them here for Your convenience.

12.1 Graphicatelier Privacy Center

Our website features a dedicated privacy management interface accessible from every page:

  • Location: Look for the finger icon in the bottom-left corner of every page.
  • Action: Click the “Change Privacy Settings” button to open the consent management interface.
  • Options: You can individually enable or disable cookie categories: Essential, Functional, Statistics, and Marketing.
  • Withdrawal: You can withdraw Your consent at any time by deselecting previously accepted categories and saving Your preferences.
  • Persistence: Your preferences are stored for 12 months, after which You will be prompted again.

12.2 Browser Privacy Controls

Most browsers allow You to refuse cookies, delete existing cookies, and control site data. Here are detailed instructions for popular browsers:

12.2.1 Google Chrome

  1. Click the three dots (⋮) in the upper right corner
  2. Select “Settings”
  3. Under “Privacy and security,” click “Cookies and other site data”
  4. Choose Your preferred setting: “Allow all cookies,” “Block third-party cookies,” “Block all cookies,” or “Block third-party cookies in Incognito mode”
  5. You can also clear existing cookies by clicking “Clear browsing data”

Chrome Official Documentation

12.2.2 Mozilla Firefox

  1. Click the menu button (☰) in the upper right corner
  2. Select “Settings”
  3. Select “Privacy & Security” from the left menu
  4. Under “Enhanced Tracking Protection,” choose Standard, Strict, or Custom
  5. Under “Cookies and Site Data,” adjust Your preferences or clear data

Firefox Official Documentation

12.2.3 Microsoft Edge

  1. Click the three dots (⋯) in the upper right corner
  2. Select “Settings”
  3. Click “Cookies and site permissions”
  4. Under “Cookies and data stored,” manage Your preferences
  5. Toggle “Block third-party cookies” or clear existing cookies

Edge Official Documentation

12.2.4 Safari (macOS)

  1. Click “Safari” in the menu bar
  2. Select “Preferences” (or “Settings” on macOS Ventura+)
  3. Click the “Privacy” tab
  4. Adjust cookie preferences: “Prevent cross-site tracking,” “Block all cookies”
  5. Manage privacy report and website data

Safari Official Documentation

12.2.5 Opera

  1. Click the “O” menu (top-left) or “Settings” via the sidebar
  2. Select “Settings” then “Privacy & security”
  3. Under “Cookies and other site data,” adjust Your preferences
  4. Use “Clear browsing data” to remove existing cookies

Opera Official Documentation

12.2.6 Brave

  1. Click the menu (☰) in the upper right corner
  2. Select “Settings”
  3. Under “Shields,” adjust global privacy controls
  4. Under “Privacy and security,” manage cookies and site data
  5. Brave’s built-in Shields block trackers and ads by default

Brave Official Documentation

12.2.7 Vivaldi

  1. Click “Vivaldi” menu (top-left) then “Settings”
  2. Select “Privacy” from the left panel
  3. Under “Cookies,” adjust Your preferences
  4. Use the “Clear browsing data” button to remove cookies

Vivaldi Official Documentation

12.2.8 Arc Browser

  1. Click “Arc” in the menu bar then “Settings”
  2. Select “Privacy” from the sidebar
  3. Manage cookie preferences and tracking protection
  4. Arc uses Chrome’s underlying engine, so cookie settings work similarly

Arc Official Documentation

12.2.9 DuckDuckGo Browser

  1. Click the shield icon in the address bar
  2. DuckDuckGo automatically blocks third-party trackers and cookies
  3. Access “Settings” then “Privacy” for granular controls
  4. Use the “Fire Button” to clear all data with one click

DuckDuckGo Official Documentation

12.3 Privacy-Enhancing Extensions

The following browser extensions can help You enhance Your privacy online:

Extension Purpose Advantages Installation Official Site
uBlock Origin Efficient content blocker for ads, trackers, and malware domains Low memory usage, highly customizable, open source Available for Chrome, Firefox, Edge, Opera, Brave ublock.org
Privacy Badger Automatically learns to block invisible trackers by EFF AI-based learning, no configuration needed, open source Available for Chrome, Firefox, Edge, Opera privacybadger.org
Ghostery Blocks ads, stops trackers, and speeds up websites User-friendly interface, tracker categorization, privacy dashboard Available for Chrome, Firefox, Edge, Opera, Safari ghostery.com
Adblock Plus Blocks annoying ads and tracking Easy to use, acceptable ads program, filter lists Available for Chrome, Firefox, Edge, Opera, Safari adblockplus.org
ClearURLs Removes tracking parameters from URLs Prevents tracking via URL parameters, open source Available for Chrome, Firefox, Edge clearurls.xyz
Decentraleyes Emulates Content Delivery Networks locally Prevents CDN tracking, speeds up loading, open source Available for Chrome, Firefox decentraleyes.org

12.4 Advanced Privacy Tools

For users who want additional privacy protection, the following advanced tools are recommended:

Tool Purpose Advantages Installation Official Site
LocalCDN Emulates CDNs locally by loading resources from local copies No requests to external CDNs, better privacy, open source; fork of Decentraleyes with more resources Available for Firefox (WebExtensions) localcdn.org
Cookie AutoDelete Automatically deletes cookies when a tab is closed Granular control, whitelist support, automatic cleanup, open source Available for Chrome, Firefox, Edge cookieautodelete.com
CanvasBlocker Prevents fingerprinting via canvas, WebGL, AudioContext, and more Blocks fingerprinting techniques, configurable, open source Available for Firefox github.com/kkapsner/CanvasBlocker
NoScript Blocks JavaScript, Java, Flash, and other executable content Maximum security, per-site whitelisting, open source Available for Firefox, Chrome (limited) noscript.net

Please note that using some of these advanced tools may affect website functionality. We recommend starting with Our built-in “Change Privacy Settings” button (finger icon, bottom-left corner) before installing additional tools.

13. Conclusion

Thank you for taking the time to read Our Privacy Policy. We are committed to protecting Your privacy and maintaining the security of Your personal information. We believe in transparency and aim to empower You with knowledge about Your data and Your rights. If You have any questions, concerns, or feedback about Our Privacy Policy or data practices, please refer to Section 2 – Contact Information. We value Your input and are committed to addressing any privacy-related inquiries promptly and thoroughly.

This Privacy Policy was created by graphicatelier for use on www.graphicatelier.com. Reproduction, even in part, is prohibited without the author’s authorization under Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market.

And finally, if you’ve made it this far, congratulations! You are among the few people who read privacy policies to the end. Your dedication to understanding how your personal data is handled is commendable. Thank you for your attention and for trusting us with your information.

This is a unique website which will require a more modern browser to work!

Please upgrade today!