Privacy Policy
1. Overview
This privacy policy explains what personal data is collected when you use this website, how it’s processed and which rights you have under the GDPR.“Personal data” means any information that can identify you as an individual.
2. Controller
The controller responsible for data processing on this website is:
Wienberg Photo (Sole Proprietorship)
An der Wallhecke 12
6789 Leer, Germany
Phone: +49 (0) 172 1655661
Email: kathrin@wienberg-photo.de
3. How We Collect DataData you provide directly
For example, through email, phone, WhatsApp or the contact form (name, email, message).
Data collected automatically
When you visit the website, technical data is processed automatically by our hosting provider (e.g. browser type, operating system, IP address, date/time of access).This is necessary to ensure the secure and stable operation of the site.
4. Why We Process Your Data
We process personal data in order to:provide and maintain the websitesecure and optimise website functionalityanswer inquiriesmanage communication across platformscomply with legal obligationsLegal bases under the GDPR: Art. 6(1) lit. a (consent), lit. b (contract), lit. f (legitimate interest).
5. Your Rights Under GDPR
You have the right to:access your stored personal data (Art. 15)correct inaccurate data (Art. 16)request deletion (Art. 17)restrict processing (Art. 18)receive your data in portable format (Art. 20)object to processing based on legitimate interest or direct marketing (Art. 21)withdraw consent at any time (Art. 7(3))lodge a complaint with a supervisory authority (Art. 77)To exercise your rights, email: kathrin@wienberg-photo.de
6. Data Security (SSL / TLS)
This website uses SSL/TLS encryption.
Encrypted connections are identifiable by “https://” and the lock icon in the browser bar.
Encrypted data cannot be read by third parties.
7. Web Hosting (Webflow)
This website is hosted via Webflow, Inc., 398 11th St, San Francisco, CA 94103, USA.Webflow processes:IP addressesdate and time of accessbrowser and device informationreferrer URLsserver log dataProcessing is based on legitimate interest (Art. 6(1) lit. f GDPR) to ensure a stable and secure website.Webflow uses EU Standard Contractual Clauses to ensure GDPR-compliant data transfer.
More information: https://webflow.com/legal/privacyA Data Processing Agreement (DPA) is in place.
8. Cookies
This website uses cookies to ensure proper functionality and an optimal user experience.Types of cookies:Session cookies (automatically deleted after closing the browser)Persistent cookies (stored for up to 12 months unless deleted manually)
You can control or block cookies via your browser settings.L
egal basis:
Art. 6(1) lit. f GDPR (legitimate interest), or Art. 6(1) lit. a GDPR when consent is required (e.g. analytics cookies).
9. Server Log Files
Collected automatically by the hosting provider:browser type and versionoperating systemreferrer URLhost name of accessing devicetime of server requestIP addressLog files are processed based on legitimate interest (Art. 6(1) lit. f GDPR).
10. Contact via Email, Phone or WhatsApp
When you contact us, the transmitted data (e.g. name, message, contact info) is stored to process your inquiry.Legal basis:
Art. 6(1) lit. b GDPR (contract or pre-contractual measures)
or Art. 6(1) lit. a GDPR (consent).
Retention period:
Up to 10 years in accordance with legal requirements.
11. Google Web Fonts (Local Hosting)
This website uses Google Fonts, which are hosted locally.
No data is transferred to Google servers.
12. Social Media Profiles (LinkedIn, Instagram, TikTok)
We maintain publicly accessible profiles on social networks.
When visiting these profiles, your personal data may be processed by the respective platforms and us as joint controllers.We use these profiles to communicate with visitors and share information about our services.Full details on data processing can be found in the privacy policies of each platform:LinkedIn: https://www.linkedin.com/legal/privacy-policyInstagram: https://help.instagram.com/519522125107875TikTok: https://www.tiktok.com/legal/privacy-policy-eeaLegal basis: Art. 6(1) lit. f GDPR (legitimate interest in communication & visibility).
13. Contact via Social Media
If you contact us via social networks (comments, messages, interactions), we process the transmitted data solely to respond to your inquiry.
Legal basis: Art. 6(1) lit. a and b GDPR.Data is deleted once your inquiry is completed, unless statutory retention applies.