This privacy policy applies to the Designeria online shop on Shopify and the associated processing of inquiries and orders.
1. Controller and Contact
Designeria e.U., Owner Theresa Thaler, Erdbrustgasse 7/9, 1160 Vienna, Austria. Please direct questions regarding data protection and requests to exercise your rights to contact@designeria.at, Phone: +43 676 432 6606.
2. Shop Visit and Technical Operation
When accessing the shop, your IP address, time of access, pages visited, device and browser information, as well as technically necessary cookie and session data are processed. This serves the provision of the website, the shopping cart, and the checkout process, as well as security and troubleshooting. The legal bases are Art. 6(1)(b) GDPR for requested contractual functions and Art. 6(1)(f) GDPR for our legitimate interest in a secure and functional shop. Access to your terminal device that is not required is subject to your consent pursuant to § 165(3) TKG 2021, where legally required.
3. Inquiries, Customizations, and Orders
We process the name, contact, billing, and delivery information you provide, details regarding products, orders, payments, and deliveries, as well as the content of your messages. If you submit images, sketches, or motifs for a customization, we use them to review and process your request. Please do not submit unnecessary personal data of third parties.
Processing is carried out for the performance of pre-contractual measures and for the fulfillment of the contract in accordance with Art. 6(1)(b) GDPR. Art. 6(1)(c) GDPR applies to bookkeeping and legal evidence. We rely on Art. 6(1)(f) GDPR for the defense against abuse and for the assertion or defense of legal claims. We cannot process the contract without the information necessary for ordering and delivery; voluntary additional information is not required for this purpose.
4. Shopify and Customer Account
We use Shopify for hosting, the shop, checkout, order management, and – if offered – the customer account. For merchants in the European region, Shopify International Limited, Ireland, is involved in particular. Shopify processes data partly on our behalf and partly under its own responsibility for certain services. Technical security checks and payment or fraud checks may also take place. Details on Shopify’s own processing and your rights can be found in the privacy notice for consumers; information on data processing is available in the Shopify Data Processing Addendum.
If you use a customer account, the identification and contact data required for this will be linked to your orders. You should treat access data and login codes confidentially.
5. Payment Processing and Shipping
Depending on the payment method you choose at checkout, the necessary payment, contact, order, and technical data will be transmitted to the respective payment service provider. If offered, these are Shopify Payments and its payment partners, PayPal, as well as the wallet and card providers involved in Apple Pay or Google Pay. In the case of bank transfers, we process the payment reference, sender, and transaction data from the banks involved. We do not receive complete credit card information. The legal basis is the performance of a contract according to Art. 6(1)(b) GDPR; independent legal verification obligations of the payment providers remain unaffected.
For shipping processing, shipping labels, and shipment tracking, we use Sendcloud B.V., Stadhuisplein 10, 5611 EM Eindhoven, Netherlands, as a data processor. In this process, the order, contact, and address data required for delivery are processed and transmitted to the respective commissioned shipping service provider. The legal basis is Art. 6(1)(b) GDPR. Further information: Sendcloud Privacy Policy and PayPal Privacy Policy.
6. Withdrawal, Return, and Warranty
In the event of a withdrawal or complaint, we process your identification and contact data, contract and article data, your declaration, any voluntarily submitted photos, as well as receipt, processing status, and refund information. The legal bases are Art. 6(1)(b) and (c) GDPR; we process necessary evidence for legal claims pursuant to Art. 6(1)(f) GDPR. These data are not used for newsletters or advertising solely because of a withdrawal.
7. Newsletter, Reviews, and Optional Services
Registration for advertising is voluntary and not a condition for an order. If a newsletter is offered and you register, your email address, registration, confirmation, and unsubscription are processed for distribution and to provide evidence of your consent. The legal basis is Art. 6(1)(a) GDPR. You can revoke your consent at any time for the future via the unsubscribe link or by email. Necessary order and contract notifications are independent of this.
A Trustpilot review counter from Trustpilot A/S, Pilestræde 58, 5., 1112 Copenhagen K, Denmark, is integrated into the footer. When the widget loads, IP address, browser and device information, the page visited, and the time of access, in particular, may be transmitted to Trustpilot. We base the display of independent reviews on our legitimate interest in accordance with Art. 6(1)(f) GDPR. Insofar as Trustpilot uses non-essential cookies or comparable technologies, this is done only based on your consent pursuant to Art. 6(1)(a) GDPR and § 165(3) TKG 2021; you can revoke your consent via the cookie settings.
For the online withdrawal form, we use the "Revoq EU Withdrawal Button" app integrated into Shopify. When you submit the form, your name, email address, order and article data, as well as voluntary messages, are processed for the processing and documentation of your withdrawal. The legal bases are Art. 6(1)(b) and (c) GDPR; the technical service provider is involved as a data processor to the extent necessary.
A simple link to a social network only leads to its website when clicked. No registration for review invitations follows from such a link. For other embedded analysis, advertising, or review services, the specifications and selection options of the provided consent management tool are decisive.
8. Recipients and Data Transfers
Recipients are, to the extent necessary, our shop, IT, communication, payment, and shipping service providers, as well as commissioned tax and legal advisors and, in the case of a legal obligation, public authorities. Data processors are involved based on Art. 28 GDPR.
Shopify and other service providers may process data outside the European Economic Area. Transfers take place in accordance with Art. 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses and, if necessary, additional protective measures. Information on Shopify’s recipients and safeguards can be found in the Data Processing Addendum linked above. Further information and details on obtaining a copy of the relevant safeguards can be obtained via our data protection contact.
9. Storage Duration
We only store data for as long as it is needed for the respective purpose. Bookkeeping and accounting documents are generally kept for seven years; longer legal periods may apply in the case of ongoing proceedings. Inquiries without a subsequent contract are deleted after completion as soon as they are no longer needed for the purpose or for necessary legal evidence. Contract, complaint, and withdrawal data are kept in accordance with legal retention obligations and the relevant limitation periods. Evidence of consent can also be stored after unsubscription for the necessary documentation. Regarding service providers, technical storage periods are additionally based on their required security and operational processing.
10. Your Rights
In accordance with the legal requirements, you have the right to access, rectification, erasure, restriction of processing, and data portability. You can revoke consent at any time for the future; the lawfulness of the processing performed to date remains unaffected.
Right to Object: If processing is based on Art. 6(1)(f) GDPR, you may object for reasons arising from your particular situation. You can object to processing for direct marketing at any time; this also applies to related profiling.
You can file a complaint with a data protection supervisory authority, in particular with the Austrian Data Protection Authority. Please direct requests to us at contact@designeria.at. To prevent unauthorized disclosure, reasonable proof of identity may be required.
11. Automated Decisions and Changes
Information about any automated decisions by a payment service provider you have chosen can be found in their privacy notice. If you have questions about an automatic rejection, contact us and the relevant provider. We update this policy in the event of changes to the services used or processing procedures.
