Privacy policy

Last updated: October 7, 2025

1. Controller

ART STUDIO WALDBAUER-KUNST / waldbauer-kunst.shop
Helga Waldbauer
Feldgrabenstr. 3, 79725 Laufenburg (Baden), Germany
Phone: +49 176 516 41 307
Email: helga.waldbauer@email.de

Imprint: https://waldbauer-kunst.shop

A Data Protection Officer is not appointed, as there is no legal obligation to do so.

2. Purposes, Legal Bases and Categories of Data

2.1 Provision of the Website / Hosting

When you visit our website, server log files are automatically processed (IP address, date/time, time zone, accessed URL, referrer, user agent, error codes if applicable).

Purposes: technical operation, security, stability of the website.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure web operation).
Storage duration: generally 30 days; longer storage only in case of security-relevant events.

Hosting service provider: OVHCloud (server location within the EU).
We have a data processing agreement with the hosting provider in accordance with Art. 28 GDPR.

2.2 Technically Required Cookies / Similar Technologies

We use exclusively technically required cookies, particularly for shopping cart, order and session functions in the online shop (WooCommerce).

  • woocommerce_cart_hash (session)
  • woocommerce_items_in_cart (session)
  • wp_woocommerce_session_[…] (up to 2 days)

Legal basis: § 25(2) TDDDG (formerly TTDSG) and Art. 6(1)(f) GDPR.
We currently do not use tracking or marketing cookies.

2.2a Google Tag Manager

This website uses Google Tag Manager. Google Tag Manager is a solution that allows website tags to be managed via an interface.

Google Tag Manager itself is a cookieless domain and does not collect personal data.

Google Tag Manager merely triggers other tags, which in turn may collect personal data.

Google Tag Manager does not access this data.

If a deactivation has been made at the domain or cookie level, it remains in effect for all tracking tags implemented via Google Tag Manager.

2.3 Contact

If you contact us by email, phone or contact form, we process your information (name, email, phone number, content of the inquiry).

Purposes: processing your inquiry, communication.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual) and Art. 6(1)(f) GDPR.
Storage duration: until the inquiry is completed; statutory retention obligations may apply.

2.4 Online Shop, Customer Account & Payments

When ordering in our online shop, we process inventory, contact, contract and payment data. Orders are possible with a customer account or as a guest.

Purposes: contract fulfillment, payment processing, accounting, fraud prevention.
Legal bases: Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR, Art. 6(1)(f) GDPR.

Payment Service Providers:

a) Stripe Payments Europe Ltd.
The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland
Privacy notice: https://stripe.com/de/privacy
Stripe may transfer data to Stripe Inc., USA. Appropriate safeguards exist in accordance with Art. 46 GDPR (EU Standard Contractual Clauses).

b) PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal, L-2449 Luxembourg
Privacy notice: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Storage duration: according to statutory retention periods.

2.5 Products & Artistic Services

We offer original paintings, commissioned works, printed textiles, art prints and other articles with our own designs. Personal data is processed exclusively for contract fulfillment.

2.6 Painting Courses, Workshops & Events (Adults & Children)

When booking or inquiring about painting courses, we process personal data (e.g., name, contact details, age if applicable for children’s courses).

Purposes: organization, execution and billing of courses.
Legal basis: Art. 6(1)(b) GDPR.

Data of children is processed exclusively with the consent of legal guardians.

2.7 External Links

Our website contains links to external platforms (e.g., Instagram, Facebook). When clicking these links, the privacy policies of the respective providers apply. No data transfer through embedding takes place.

3. Obligation to Provide Data

Certain information is required for orders, course bookings or inquiries. Without this data, execution is not possible.

4. Recipients / Categories of Recipients

  • IT & hosting service providers (data processors)
  • Payment service providers (independent controllers)
  • Tax consultants / accounting when legally required

5. Storage Duration

Personal data is deleted as soon as it is no longer required for the stated purposes and no statutory retention obligations exist.

Statutory retention periods are 6, 8 or 10 years depending on the document (§ 147 AO, § 257 HGB).

6. Your Rights

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)

Granted consents can be revoked at any time with effect for the future.

Right to lodge a complaint:
State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW)
Email: poststelle@lfdi.bwl.de

7. Security

We implement technical and organizational measures (TOM) to protect personal data against loss, misuse and unauthorized access.

8. Minors

Our offer is not directed at children under 18 years of age without the consent of legal guardians.

9. Changes to this Privacy Policy

This privacy policy will be updated whenever legal requirements or our data processing activities change.

Opening hours:

Tuesday: 9:00 AM – 6:00 PM
Wednesday: 9:00 AM – 6:00 PM

Friday: 9:00 AM – 6:00 PM

Saturday: by appointment

We are here:

© 2026 Copyright by WALDBAUER-KUNST. All rights reserved.

Secure payment methods:

X
Add to cart