Privacy Policy
for Website and Online Shop
We appreciate your interest in our website and services. Protecting your personal data is of utmost importance to us. Below, we provide detailed information on how we process your data, in compliance with the General Data Protection Regulation (GDPR) and applicable national laws.
1. Data Controller
The entity responsible for processing personal data within the meaning of the GDPR and other applicable data protection laws is:
📍 Kollektiv Lumen - Mayrl & Colin GbR
Im Rödelbach 2
34537 Bad Wildungen
📞 Phone: +49 (0) 151 20687915
đź“§ Email: post@irisphoto.art
2. Data Processing on Our Website
2.1. Accessing Our Website (Server Log Files)
When you visit our website, certain technical data is automatically collected and stored in server log files. This includes:
- The website visited
- Date and time of access
- Amount of data transferred
- Source/referring URL
- Browser type and version
- Operating system used
- IP address (anonymized where possible)
This data is collected based on our legitimate interest (Art. 6(1)(f) GDPR) in ensuring the stability and security of our website. It is not used to identify individuals. However, we may review log data in cases of suspected unlawful activity.
3. Cookies and Tracking Technologies
3.1. Use of Cookies
We utilize cookies to optimize website functionality and enhance your browsing experience. Cookies are small text files stored on your device.
- Essential cookies: Required for basic website functions (e.g., login, shopping cart).
- Performance cookies: Help us analyze site usage.
- Marketing cookies: Used for personalized advertising (only with your consent).
The legal basis for setting cookies:
✔ Essential cookies → Art. 6(1)(f) GDPR (Legitimate Interest)
✔ All other cookies → Art. 6(1)(a) GDPR (User Consent)
Managing Cookies:
You can adjust your cookie settings in your browser:
đź”— Instructions for different browsers
For detailed information, refer to our Cookie Policy.
4. Contacting Us
If you reach out via contact form or email, we will process the information provided to handle your inquiry.
âś” Legal basis: Art. 6(1)(b) GDPR (contractual/pre-contractual inquiries) or Art. 6(1)(f) GDPR (legitimate interest in responding to requests).
âś” Storage duration: Data is deleted once it is no longer needed, unless legal retention obligations apply.
5. Order Processing & Customer Accounts
5.1. Customer Accounts
When creating an account, we store the following:
- Name
- Address
- Order history
Legal basis: Art. 6(1)(b) GDPR (necessary for contract fulfillment).
You can delete your account at any time. We will retain only legally required data for tax and commercial purposes.
5.2. Order Fulfillment
For processing purchases, we share necessary information with:
- Payment providers (PayPal, Stripe, etc.)
- Shipping partners (DHL, UPS, etc.)
Legal basis: Art. 6(1)(b) GDPR (contractual necessity).
6. Email Marketing & Direct Advertising
6.1. Newsletters
If you subscribe to our newsletter, we will use your email for promotional messages.
âś” Consent-based (Art. 6(1)(a) GDPR).
âś” You can unsubscribe at any time via the link in our emails.
6.2. Existing Customers
We may send promotional emails about similar products based on previous purchases. You can opt out at any time.
âś” Legal basis: Art. 6(1)(f) GDPR (legitimate interest in direct marketing).
7. Data Processing for Analytics & Marketing
7.1. Google Ads & Conversion Tracking
We use Google Ads to measure the effectiveness of our advertisements. When you interact with an ad, Google may set tracking cookies.
âś” Legal basis: User consent (Art. 6(1)(a) GDPR).
❌ No tracking occurs without prior user approval.
For details, see: Google Privacy Policy
8. Your Rights Under GDPR
As a data subject, you have the following rights:
✔ Access (Art. 15 GDPR) – Request details about your stored data.
✔ Correction (Art. 16 GDPR) – Request updates to incorrect data.
✔ Deletion (Art. 17 GDPR) – Request erasure of your data.
✔ Restriction (Art. 18 GDPR) – Request limited processing in certain cases.
✔ Objection (Art. 21 GDPR) – Object to processing based on legitimate interest.
✔ Data portability (Art. 20 GDPR) – Receive a copy of your data in a structured format.
Contact us at post@irisphoto.art to exercise your rights.
9. Data Retention Periods
We store personal data only as long as necessary for the purpose collected:
- Customer account data → Stored until account deletion.
- Order data → Retained per tax & commercial law (6-10 years).
- Marketing data → Until consent is revoked.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in legal requirements or business practices. The latest version will always be available on our website.
đź“… Last updated: 07.02.2025