Privacy policy

1. Overview and Controller Details

General Information

The following notice provides a simple overview of what happens to your personal data when you visit our website. Personal data refers to any data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy below.

Data Controller

The responsible party (controller) for data processing on this website pursuant to the General Data Protection Regulation (GDPR) is:

Boaz Eapen

Barbarossastraße 57

10781, Berlin

Germany

Phone: +49 1799008891

Email: bibleartlab@gmail.com


2. E-Commerce Platform (Shopify) and Automated Cookies

We host our online shop on Shopify, provided by Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

Shopify automatically sets essential and functional cookies that are strictly necessary for store operations, shopping cart management, session security, and checkout processing. These technical cookies are deployed without requiring prior consent pursuant to Section 25 (2) of the German Telecommunications and Telemedia Data Protection Act (TDDDG) and Art. 6 (1) (f) GDPR, as the website cannot function technically without them.

Shopify processes customer and order data on our behalf as a data processor. We have concluded a Data Processing Addendum (DPA) with Shopify in accordance with Art. 28 GDPR.

3. Data Collection on Our Website

3.1 Server Log Files

Shopify automatically collects and stores information in server log files, which your browser automatically transmits to us:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address (anonymized where applicable)

The collection of this data is based on Art. 6 (1) (f) GDPR for our legitimate interest in technical error-free presentation, stability, and optimization of the website. All server log files are automatically deleted after a maximum of 7 days.

3.2 Contact Form & Email Contact

If you send us inquiries via the contact form or email, your details and inquiry data will be stored for the purpose of processing the request on the basis of Art. 6 (1) (b) GDPR (contract performance or pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in effective handling of customer communications).

4. Locally Hosted Fonts (Google Fonts)

To ensure uniform display of fonts, this site uses Google Fonts, which are hosted locally on our own server. When you access a page, your browser loads the required fonts directly from our server into your browser cache. No connection is established with Google servers, and your IP address is not transmitted to Google.

5. Order Processing, Print-on-Demand (POD) & Statutory Retention

5.1 POD Fulfillment with WhiteWall

To produce and ship our physical print products (fine-art prints, canvases, framed art), we transmit necessary customer order data (recipient name, shipping address, order contents, artwork specifications) to our external print-on-demand fulfillment partner:

  • WhiteWall Media GmbH, Europa-Allee 59, 50226 Frechen, Germany.

This data transfer is strictly necessary for contract performance pursuant to Art. 6 (1) (b) GDPR. Data processing takes place within Germany/EU. WhiteWall is bound by a Data Processing Agreement pursuant to Art. 28 GDPR and processes data strictly according to our instructions.

5.2 Statutory Retention & Automatic Deletion

Following complete contract execution, your order data is restricted from active operational use and retained for 6 to 10 years to comply with statutory German tax and commercial preservation obligations (§ 147 AO, § 257 HGB; Art. 6 (1) (c) GDPR). Upon expiration of these statutory retention periods, your data will be automatically deleted, unless you have granted explicit consent for further data processing.

6. Shipping Service Providers

6.1 Delivery Address Processing

To fulfill our contractual obligations (Art. 6 (1) (b) GDPR), we pass delivery address details to appointed shipping partners (e.g., DHL Paket GmbH, DPD, UPS) to the extent required for physical delivery.

6.2 Email Transfer for Delivery Notifications

If you grant us explicit consent during or after your order pursuant to Art. 6 (1) (a) GDPR, we pass your email address to the shipping provider so they can contact you with delivery tracking updates. You may revoke this consent at any time with future effect.

7. Payment Methods and Payment Processing

To process payments in our online shop, we integrate secure payment service providers. When you select a payment method, your payment details (e.g., bank details, credit card numbers, transaction amounts) are processed directly by the provider. The legal basis is contract fulfillment pursuant to Art. 6 (1) (b) GDPR.

We support the following payment methods and providers:

  • Shopify Payments / Credit Cards: Processed via Shopify Payments (integrated with Stripe Payments Europe, Ltd., Ireland), supporting major credit cards (Visa, Mastercard).
  • PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-28 Boulevard Royal, L-2449 Luxembourg.
  • Klarna: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Offers invoice purchases (Rechnungskauf), instant bank transfers (Sofortüberweisung), and direct debit (Lastschrift).
  • SEPA Direct Debit (SEPA-Lastschrift): Processed via our payment gateways for direct bank account debits within the Single Euro Payments Area.
  • Apple Pay / Google Pay: Mobile payment services provided by Apple Inc. or Google Ireland Limited.

8. Web Analytics, Consent Management & Device Privacy

8.1 Cookie Consent & Opt-In (§ 25 (1) TDDDG & Art. 6 (1) (a) GDPR)

Essential storefront analytics are managed natively through Shopify’s infrastructure. Any non-essential tracking cookies, marketing pixels, or optional analytics tools are strictly controlled via Shopify’s Customer Privacy API or an integrated Consent Management Platform (CMP). Optional scripts are loaded only after you grant explicit consent via our cookie banner pursuant to Section 25 (1) TDDDG and Art. 6 (1) (a) GDPR. You may alter or revoke consent at any time via the cookie settings link in our website footer.

8.2 Consent Audit Log & Automatic Deletion

To document and provide evidence of granted consents pursuant to Art. 7 (1) GDPR and Art. 6 (1) (c) GDPR, your consent log is stored. This log is retained for 3 years (in accordance with the standard statutory limitation period under § 195 BGB) and automatically deleted thereafter.

9. Social Media Links and Profiles

We maintain public profiles on various social media networks. Social media icons on our store function as simple external hyperlinks. No data is transmitted to these platforms upon visiting our store until you actively click on an icon.

The following networks are integrated or linked on our website:

  • Instagram: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. Embedded content loads upon consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Joint controller agreement under Art. 26 GDPR.
  • YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Embedded video content is loaded only after obtaining your cookie consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).
  • Pinterest: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (Art. 6(1)(a) GDPR / § 25(1) TDDDG).
  • LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (Art. 6(1)(a) GDPR / § 25(1) TDDDG).
  • Mastodon & Bluesky: Decentralized open-source social networks accessed via direct external links. Visiting our site transmits no data to these networks.
  • Substack: Substack Inc., 111 Town Square Place, Suite 1203, Jersey City, NJ 07310, USA, for newsletter and publication updates (Art. 6(1)(a) GDPR). Data transfers to the USA are safeguarded via Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (DPF).

10. Third-Country Data Transfers (USA)

Transfers to third countries outside the European Economic Area (e.g., USA) rely on EU-US Data Privacy Framework adequacy decisions, Standard Contractual Clauses (SCCs), or explicit consent pursuant to Art. 49 (1) (a) GDPR. Without an adequacy decision, foreign government access risks may exist without effective legal remedies.

11. Your Rights as a Data Subject

Under applicable European data protection provisions (GDPR), you hold the following statutory rights:

  • Right of Access (Art. 15 GDPR)
  • Right to Rectification (Art. 16 GDPR)
  • Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
  • Right to Restriction of Processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Withdraw Consent (Art. 7 (3) GDPR)
  • Right to Object (Art. 21 GDPR)

12. Right to Lodge a Complaint

Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. German authority listings are published by the Federal Officer for Data Protection and Freedom of Information (BfDI):

https://www.bfdi.bund.de/