Effective September 24, 2026. This notice explains our processing under the GDPR and applicable German data-protection law. See our Cookie & Storage Notice for device-storage details.
The controller for this storefront is Fotohaus Klinger, Schloßgasse 2-4, 04109 Leipzig, Germany. Privacy enquiries and data-rights requests may be sent to info@fotohausklinger.com or through Live Chat.
If a data-protection officer is legally appointed, their current contact details will be made available here.
Payment information is used only to process or verify the selected payment method, prevent fraud, and keep legally required transaction records. A production card payment must be handled through an appropriately compliant payment provider.
We do not ask customers to send payment-card numbers or security codes by email, chat, or return forms. Saved payment displays must be limited to non-sensitive references such as brand and last four digits.
We disclose data only as needed to operate the store, fulfil orders, comply with law, or protect rights. Recipients can include hosting and infrastructure providers, database providers, email-delivery services, search infrastructure, carriers, payment and banking providers, professional advisers, and public authorities.
The current technical stack may use Vercel for application hosting, Supabase for database services, Resend for transactional email, Cloudflare R2 for hosted product media, and Typesense for search. Each provider processes only the data needed for its service under the applicable contractual terms.
Some providers or their subprocessors may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard. Information about applicable safeguards is available on request.
We keep personal data only as long as required for the stated purpose. Account data is generally retained while the account remains active; customers may request deletion subject to legal retention duties.
Order, invoice, payment, refund, and business correspondence records are retained for applicable German commercial and tax periods, commonly between 6 and 10 years. Support, chat, return, security, and fraud-prevention records are retained according to operational need, dispute periods, and legal obligations, then deleted or anonymized.
Local storage remains on the device until it expires, is cleared through the browser, or is removed using the relevant site control.
We use access controls, encrypted transport, signed sessions, restricted administrative access, and other proportionate technical and organizational measures. No internet service can guarantee absolute security.
Contact us promptly if you believe an account or communication has been compromised.
The store is not directed to children who cannot lawfully enter a purchase contract. We do not knowingly use personal data for solely automated decisions producing legal or similarly significant effects.
We may update this notice when services, providers, or legal requirements change. The current version and effective date will remain available on this page.