Skip to content

Legal

Privacy

Version: 14 September 2026.

Identity and contact details of the data controller

Kathrin Planke
trading as „ArtistiKath"
Suderloh 17
30419 Hannover
Germany

hallo@artistikath.de

Data Protection Officer

No Data Protection Officer is appointed (sole trader below the threshold).

Page views · Legal basis for processing

Plausible counts which page someone opens. Not who. The script lives on analytics.artistikath.de — Kathi's server, not the Plausible cloud. No cookie, no banner, no ads, no profiles. Stored: page, referrer, browser, device, coarse country.

Recipients: Hetzner (hosting the Plausible instance). Retention: aggregated on my server until I delete the instance. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reach and stability). Objection: content blocker or do not visit.

Server · Recipients of personal data

The shop and Plausible run on my Hetzner server. Short access logs (IP, path, user-agent) for security and stability — journald, 14 days. Art. 6(1)(f) GDPR.

Cookies · Cart

A cookie named cart, 30 days, HttpOnly, SameSite=Lax, Secure on HTTPS. It holds an id, nothing else. That keeps the cart yours and the original held. No cookie, no checkout. Open carts are deleted after 40 days, unpaid checkout sessions after 7 days. Art. 6(1)(b) GDPR, TDDDG § 25(2).

Contact · Legal basis

Name, mail, text, optional the work. Lands with hallo@artistikath.de. You get a short confirmation to your mail — without the text of your message. I keep the inquiry until it is done, then delete it. The IP sits briefly in memory against form spam — not on disk. Art. 6(1)(b) and (f) GDPR. Contact form

Withdrawal · Legal basis

Name, mail, order number or the work. Lands with hallo@artistikath.de. You get an immediate receipt to your mail — name, order, mail and time. I keep the withdrawal with the order (bookkeeping). The IP sits briefly in memory against form spam — not on disk. Art. 6(1)(b) and (c) GDPR. Withdraw from contract

Checkout · Recipients

You pay at Stripe by card or PayPal. Card data never sits on my machine. Stripe and PayPal are payment providers with their own privacy rules: stripe.com/privacy · paypal.com/privacy. After payment I keep the order, name, mail, phone, address and the invoice — otherwise there is no bookkeeping. Eight years from year-end (German Fiscal Code § 147). No erasure of those records during that time (GDPR Art. 17(3)(b)). After that I delete the order and the PDF. The thank-you mail goes via Proton (Switzerland). Art. 6(1)(b) and (c) GDPR.

Prints · Recipients

For a print I send name, mail, phone and delivery address to Prodigi (United Kingdom) so they can print and ship. Prodigi fetches the print file from my server. Your contract is with me, not the print partner. Prodigi has its own rules: prodigi.com/privacy-and-cookie-policy. Art. 6(1)(b) GDPR.

International data transfers

Stripe and PayPal process in the US — under the EU-US Data Privacy Framework and/or standard contractual clauses. Proton Mail in Switzerland (adequacy decision). Prodigi in the UK (adequacy decision); depending on destination the print may be made in the EU or the US.

Instagram

Links on About and Contact go to Instagram. You only leave the shop when you click. No embedded feed, no tracking from me.

Data retention period

  • Plausible: until the instance is deleted
  • Server logs: 14 days
  • Cart cookie: 30 days; open carts 40 days; checkout sessions 7 days
  • Contact inquiries: until done
  • Withdrawal: with the order, 8 years from year-end (German Fiscal Code § 147)
  • Orders and invoices: 8 years from year-end (German Fiscal Code § 147)

Data subject rights · Right to lodge a complaint with a supervisory authority

Access, correction, erasure, restriction, portability, objection — including against the legitimate interest for page views: hallo@artistikath.de.

Complaint to the Lower Saxony Data Protection Authority, Prinzenstraße 5, 30159 Hanover — without going through me first. lfd.niedersachsen.de

No automated decisions including profiling (Art. 22 GDPR).