Privacy policy

What personal data I collect

In order for me to process your order, you need to provide me with certain information. This includes your name, email address, postal address, payment information and details of the product you are ordering. You also have the option to provide me with additional personal information (e.g. for a custom order) if you contact me directly.

 

Why I need your information and how I use it
I rely on a number of legal bases to collect, use and share your information. In fact:

  • where I need your information to provide my services, for example to process your order, resolve disputes, or provide customer support;
  • when necessary to comply with a legal obligation or court order, or in connection with a legal claim, such as retaining information about your purchases for tax purposes; and
  • as necessary for the purposes of my legitimate interests - unless those legitimate interests are overridden by your rights or interests - such as to provide and improve my services. I use your information to provide the services you have requested from me and in my legitimate interest to improve my services.


Sharing and Disclosure of Information
Customer data is important to my business. I will only release your personal information for specific reasons and under very specific circumstances, as follows:

  • Service Providers: I engage certain trusted third parties to perform tasks and provide services for my shop, such as parcel services. I share your personal information with these third parties, but only to the extent necessary to perform those services.
  • Compliance with Laws: I may collect, use, retain, and share your information when I have a good faith belief that doing so is reasonable and necessary to: a) respond to legal process or governmental requests; b) enforce my contracts, terms and policies; c) prevent, investigate and correct fraud and other illegal activity, security or technical issues; or d) protect the rights, property and safety of my customers or others.


Data Storage
I only store your personal data for as long as is necessary to provide you with my services and as described in my privacy policy. However, I may need to retain this information to comply with legal and regulatory obligations, resolve disputes, and enforce my agreements. In general, I keep your data for the following period: 7 years.

Transfer of personal data to countries outside the EU
I may store and process your information through third party hosting services in the US and other countries. As a result, I may transfer your personal information to countries that have data protection and regulatory surveillance laws that differ from the relevant laws in your country. If I am deemed to be transferring information about you outside of the EU, I rely on the EU-US Privacy Shield as a legal basis for the transfer because Google Cloud is EU-US Privacy Shield certified.

Your Rights
If you reside in certain regions, including the EU, you have a number of rights in relation to your personal information. Some of these rights are general and others are specific. These rights are described below:

  • Access: You have the right to access and receive a copy of the personal information I hold about you by writing to me using the contact information below.
  • Modification, Restriction, Deletion: You may also have the right to modify your personal information, limit my use of that information, or delete it. Except in exceptional circumstances (such as when I need to store data for legal reasons) I will generally delete your personal data upon request.
  • Objection: You can object to this, 1. that I process some of your data in relation to my legitimate interests and 2. that you will receive marketing messages from me after you have previously expressly consented to this. In such cases, I will delete your personal information unless I can demonstrate compelling legitimate grounds for its continued use or it is required for legal reasons.
  • Complaint: If you reside in the EU and wish to raise a concern about my use of your information - without prejudice to any other rights you may have - you have the right to raise these concerns with your local data protection authority.


How to Contact me
For the purposes of the EU General Data Protection Regulation, I, Christine Schober, am the data controller of your personal data. If you have any questions or concerns, you can contact me at hello@greatpanstudio.com. Alternatively, you can write to me at the following address: Christine Schober, Lehenau 16/2, 5325 Plainfeld, Austria