Privacy policy
This policy describes what happens to personal data when you use this shop. It describes only processing that actually takes place.
Who is responsible
The controller for the processing described here is:
- Recherche Ventures e.U.
- Alfred-Coßmann-Gasse 14/2, 8054 Graz, Austria
No data protection officer is appointed — this business is not required to appoint one. Data protection enquiries go to the email address above, which is the contact point for everything in this policy.
What is processed, and why
Order and customer data
- Accepting your order, processing it, having it delivered, and dealing with you about it afterwards.
- Name, email address, delivery address, billing address, an optional phone number, and the contents and status of the order.
- Art. 6(1)(b) GDPR — performance of the contract you enter into when you place an order.
- For as long as the contract runs and afterwards for as long as claims arising from it can still be made; records that are accounting records are kept for the period named below.
Payment
- Taking payment for your order and keeping the accounting record of it.
- The amount, the currency, the payment status and the payment reference. Card details are entered directly into the payment provider’s own form and never reach this shop’s servers.
- Art. 6(1)(b) GDPR for taking the payment; Art. 6(1)(c) GDPR for keeping the record, which Austrian law requires.
- Seven years, the retention period Austrian accounting law imposes on records of a transaction (§ 132 BAO).
Transfer of fulfillment data to the print partner
- Having the artwork produced and shipped to the address you gave. Every piece is made to order, so it cannot be produced without this.
- The recipient’s name and postal address, and the item ordered.
- Art. 6(1)(b) GDPR — performance of the contract.
- We keep the order record as described above; the print partner keeps its production record under its own retention rules as our processor.
The shop session
- Keeping your cart and your checkout together from one page to the next.
- A session identifier held in a cookie, and the cart that belongs to it.
- Art. 6(1)(b) GDPR — without a session there is no cart and no checkout. Where you are only browsing, the same processing rests on Art. 6(1)(f) GDPR: our interest in a shop whose cart works.
- The session ends when it expires or when you close the browser. See Cookies below.
Server, proxy and security logs
- Operating the shop, finding faults, and defending it against abuse and attack.
- IP address, date and time, the address requested, the response status, the referring page and the browser’s user-agent string.
- Art. 6(1)(f) GDPR — our legitimate interest in a shop that runs and is not abused.
- Kept only as long as those purposes need and deleted afterwards; an entry needed to follow up a specific incident is kept until that incident is closed.
Who receives your data
Our own server (Germany)
- The shop application and its PostgreSQL database hold your order, customer and address data.
- This is the shop itself. The machine is operated by us in Germany.
Stripe
- The payment amount and currency, the payment status, and whatever you enter into Stripe’s own payment form.
- Stripe processes the payment. Card details are entered directly into Stripe’s hosted payment element and never reach this shop’s servers.
Prodigi
- The recipient’s name and postal address, and the item ordered.
- Prodigi is the print partner that produces the artwork to order and ships it to you. It cannot produce or ship without knowing what and where.
No one else receives personal data from this shop. A recipient is listed here only while that processing actually runs, so this list changes when a service goes live — not when it is planned.
Transfers outside the EEA
- In Germany, inside the EEA. No transfer to a third country takes place.
- The contracting entity is Stripe Payments Europe, Limited in Ireland. Stripe operates internationally, including in the United States; transfers outside the EEA rest on the European Commission’s standard contractual clauses, which form part of Stripe’s data processing agreement.
- Prodigi is based in the United Kingdom, which the European Commission has recognised as offering an adequate level of protection. Where an item is produced outside the EEA and the United Kingdom, the transfer rests on the European Commission’s standard contractual clauses.
Cookies
This shop sets one cookie: the session cookie that keeps your cart and your checkout together. It is strictly necessary for the shop to function, so it needs no consent.
There are no analytics cookies, no advertising cookies, no tracking or profiling cookies, and no third-party embeds that set cookies.
That is also why you are never asked to accept anything here: there is no consent banner because there is nothing to consent to.
Your rights
Under the GDPR you have the following rights in respect of your personal data:
- Access to the data held about you, and a copy of it — Art. 15 GDPR.
- Rectification of data that is inaccurate or incomplete — Art. 16 GDPR.
- Erasure of your data, where none of the grounds for keeping it applies — Art. 17 GDPR.
- Restriction of processing while a dispute about the data is settled — Art. 18 GDPR.
- Portability: your data in a structured, commonly used, machine-readable form — Art. 20 GDPR.
- Objection to processing that rests on our legitimate interest — Art. 21 GDPR.
To exercise any of them, write to the controller’s email address above. We answer within one month, as Art. 12(3) GDPR requires.
You also have the right to lodge a complaint with a data protection supervisory authority. The competent one for this shop is:
- Österreichische Datenschutzbehörde
- Barichgasse 40–42, 1030 Vienna, Austria
This is the data protection supervisory authority. It is a different body from the trade supervisory authority named in trade law, and has nothing to do with it.
What does not happen
Giving your order and address data is necessary to perform the contract: without them an order cannot be accepted or delivered. No law obliges you to provide them — but there is no way to buy without them.
There is no automated decision-making, and no profiling, within the meaning of Art. 22 GDPR.
We do not sell your personal data, and we do not pass it on for advertising.