PRIVACY POLICY (Datenschutzerklärung)
Last Updated: December 3, 2024
1. Controller and Contact Information
Funking Kunst
Tutzinger Str. 10
81369 Munich, Germany
Email: [email protected]
As a Kleinunternehmer (small business) under §19 UStG, we are exempt from charging VAT.
2. General Information About Data Processing
We take the protection of your personal data very seriously. We process your data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telemedia Act (TMG).
3. What Data We Collect and Why
3.1 Order Processing
When you place an order, we collect:
- Name
- Email address
- Billing address
- Shipping address
- Payment information (processed by PayPal)
Legal basis: Contract fulfillment (Art. 6(1)(b) GDPR)
Storage duration: 10 years (German tax law requirements)
Purpose: To process and fulfill your order, send order confirmations, and comply with legal obligations
3.2 Email Communications
We use Brevo (formerly Sendinblue) as our SMTP service provider to send transactional emails (order confirmations, shipping notifications).
Data shared with Brevo: Your email address
Legal basis: Contract fulfillment (Art. 6(1)(b) GDPR)
Brevo’s privacy policy: https://www.brevo.com/legal/privacypolicy/
3.3 Payment Processing
We use PayPal Payments for secure payment processing. When you choose PayPal, you will be redirected to PayPal’s platform to complete your payment.
Data shared with PayPal: Order amount, billing information
Legal basis: Contract fulfillment (Art. 6(1)(b) GDPR)
PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
3.4 Order Fulfillment
We use Gelato for print-on-demand production and shipping. Your shipping address and order details are shared with Gelato to fulfill your order.
Data shared with Gelato: Name, shipping address, order details
Legal basis: Contract fulfillment (Art. 6(1)(b) GDPR)
Gelato’s privacy policy: https://www.gelato.com/privacy-policy
4. Cookies
Our website uses only essential cookies required for the shopping cart and checkout process. We do not use analytics, tracking, or marketing cookies.
5. Your Rights Under GDPR
You have the following rights:
- Right of access (Art. 15 GDPR): Request information about your stored data
- Right to rectification (Art. 16 GDPR): Correct inaccurate data
- Right to erasure (Art. 17 GDPR): Request deletion of your data
- Right to restriction (Art. 18 GDPR): Limit how we process your data
- Right to data portability (Art. 20 GDPR): Receive your data in a structured format
- Right to object (Art. 21 GDPR): Object to data processing
- Right to withdraw consent (Art. 7(3) GDPR)
To exercise these rights, contact us at: [email protected]
6. Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant data protection supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach, Germany
Phone: +49 (0) 981 180093-0
Email: [email protected]
7. Data Security
We use technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access. Our security measures are continuously improved in line with technological developments.
8. Third-Party Services
We do not use analytics tools, social media plugins, or marketing tracking on our website.
9. Automated Decision-Making
We do not use automated decision-making or profiling as defined in Art. 22 GDPR.
10. Data Transfer Outside the EU
Some of our service providers (PayPal, Brevo, Gelato) may process data outside the European Union. These transfers are secured through:
- EU Standard Contractual Clauses
- Adequacy decisions by the EU Commission
- Other appropriate safeguards under GDPR
11. Changes to This Privacy Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. The “Last Updated” date at the top indicates when changes were last made.