Questions about legal topics?
We are here for you.
Privacy Policy
We take the protection of your data very seriously.
Introduction and Responsibility
With this privacy policy, we inform you about which personal data we collect, how we use it, and what rights you are entitled to. This privacy policy is provided in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Controller
Ralph D. Woop
Schillerstraße 39
73635 Rudersberg
Germany
Phone: +49 7183 9 33 74 14
Email: graphische.manufaktur@gmail.com
Website: www.graphische-manufaktur.de
General Information and Security Measures
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as inquiries you send to us as the site operator via our contact form, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from 'http://' to 'https://' and by the small lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties. However, we would like to point out that data transmission over the Internet (e.g., when communicating via email) can generally have security vulnerabilities. Complete protection of data against access by third parties is not possible.
General Retention Period and Erasure
Unless a more specific retention period is specified within this privacy policy for individual data processing operations, your personal data will generally remain with us only until the purpose for the data processing no longer applies. If you assert a legitimate request for erasure or revoke consent granted for data processing, your data will be deleted immediately. An exception to this principle exists only if we have other legally permissible reasons or statutory obligations to store your personal data. This applies in particular to data that must be archived due to commercial or tax retention periods. In these cases, the statutory retention period replaces the actual purpose limitation. The erasure of data only takes place after these mandatory retention reasons no longer apply.
Your Rights as a Data Subject (Data Subject Rights)
As a data subject, you have the following rights under the GDPR:
- Right of Access (Art. 15 GDPR): You have the right to request information at any time and free of charge as to whether and which of your personal data we process. This includes, among other things, information on the purposes of processing, the origin of the data, the recipients, and the planned retention period.
- Right to Rectification (Art. 16 GDPR): You can request the immediate correction of incorrect data or the completion of your personal data stored with us.
- Right to Erasure / 'Right to be Forgotten' (Art. 17 GDPR): You have the right to request the deletion of your personal data as soon as the purpose of the data processing no longer applies, you revoke your consent, or the processing is unlawful. An exception applies in the case of statutory retention obligations.
- Right to Restriction of Processing (Art. 18 GDPR): Under certain conditions, you can request that the processing of your data be restricted.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive data that we process automatically on the basis of your consent or for the performance of a contract in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent (Art. 7 (3) GDPR): You can withdraw consent to data processing once given to us at any time with effect for the future. The lawfulness of the data processing carried out up to the withdrawal remains unaffected.
- Right to Object (Art. 21 GDPR): If the data processing is based on our legitimate interest, you have the right to object for reasons arising from your particular situation. In the case of direct marketing, you have a general right to object.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to complain to a data protection supervisory authority. The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg).
Server Log Files
With every purely informative visit to our website (i.e., if you do not register via a form or otherwise transmit information to us), our system automatically collects general data and information from the computer system of the calling computer.
Type and Purpose of Processing
Every time our website is accessed, the systems of our server infrastructure (load balancer, caching layer, and web server) automatically record technical log data. The following information is recorded in so-called server log files: the IP address of the requesting device, the date and exact time of access (timestamp), the specific target address or path called up (HTTP request), the HTTP status code, the amount of data transferred, as well as the referrer URL and the user agent (browser type and operating system). The purpose of this processing is to ensure IT security, stability, and the proper load distribution of our systems. The temporary storage of the IP address is technically mandatory in order to detect, defend against, and, in the event of an emergency, prosecute cyber attacks (e.g., DDoS attacks, automated malware access). An evaluation of this data for marketing purposes or profiling does not take place.
Legal Basis
Processing is carried out on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. Our legitimate interest lies in ensuring the permanent operational security, integrity, and availability of our web infrastructure as well as fulfilling our legal obligation to ensure data security (Art. 32 GDPR).
Recipients / Data Transfer
The recipient of the data is netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. Data-protection-compliant processing is guaranteed by a concluded contract on order processing (DPA) pursuant to Art. 28 GDPR; the service provider processes the data strictly in accordance with our instructions. The data is stored exclusively in certified data centers within Germany (European Union). A further transfer to unauthorized third parties or to insecure third countries (such as the USA) does not take place via the hosting.
Retention Period
The complete log data (including IP addresses) is stored on our server structures for a period of up to 30 days for IT security reasons and for technical error analysis, after which it is deleted fully automatically. Longer storage only takes place if a specific security incident (e.g., a cyber attack) requires further investigation and securing of evidence.
Provision Required/Voluntary
The provision of this data is not voluntary and cannot be prevented or configured in advance by the user. The collection is a mandatory, purely automatic part of Internet protocol communication. As soon as your browser initiates a connection to our server infrastructure, this data is processed system-side before the first website content is delivered. Using the website without this automated logging is technically impossible. Therefore, there is no right to object or option for an 'opt-out' for these purely operational infrastructure logs.
External Web Hosting and Infrastructure
Type and Purpose of Processing
For the provision, stable operation, and secure delivery of our website, we use the infrastructure of an external web hosting provider. All personal data collected when visiting or using our website (such as IP addresses as part of automatic network communication or data actively entered by you in forms) is processed and stored on the systems of this service provider.
Legal Basis
The use of the external hoster is based on our legitimate interest pursuant to Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technically error-free, stable, high-performance, and secure provision of our online offer.
Recipients / Data Transfer
The recipient of the data is netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany. Data-protection-compliant processing is guaranteed by a concluded contract on order processing (DPA) pursuant to Art. 28 GDPR; the service provider processes the data strictly in accordance with our instructions. The data is stored exclusively in certified data centers within Germany (European Union). A further transfer to unauthorized third parties or to insecure third countries (such as the USA) does not take place via the hosting.
Retention Period
The data remains on the hoster's servers until the purpose for the data processing no longer applies (e.g., after an inquiry from the contact form has been processed). Automatically collected system data (server log files) is - as described in the separate section on log files - stored for up to 30 days and then fully automatically deleted or anonymized, unless a specific security incident makes longer storage necessary for evidence purposes.
Provision Required/Voluntary
The processing of your data on the server structures of our partner is neither legally nor contractually required. However, it is a mandatory, automatic part of Internet protocol communication. As soon as your browser initiates a connection to our domain, the server processes this data before the actual website content is delivered. Displaying and using the website without this infrastructural processing is technically impossible, which is why no prior opt-out can be set up.
Consent Management and Use of Cookies
General Information on Cookies and Local Storage Technologies
Our website uses cookies and comparable local storage technologies (such as your browser's LocalStorage). Cookies are small text files or data fragments that your browser automatically stores on your end device (computer, tablet, smartphone) when you visit our website.
We distinguish between two categories of functions:
- Technically necessary (essential) functions: These are strictly required so that our website, its basic functions (e.g., remembering your privacy choice), and the security of the site work error-free.
- Non-necessary services (Analysis & Marketing): These services (e.g., Google Analytics 4) help us evaluate user behavior and optimize our offer. They are exclusively activated after your prior and explicit consent.
Consent Management (Consent Banner)
In order to query and manage your decisions regarding services requiring consent in a data-protection-compliant manner, we use an integrated consent management system on our website. This system is operated directly on our server infrastructure and at no time transmits data to external third-party providers of consent management platforms.
Your current Consent ID
This unique ID is stored locally in your browser and pseudonymized on our server to prove your privacy choice.
No choice made yetType and Purpose of Processing
When you access our website and make your choice in the consent banner, our system processes this decision. In order to comply with the legal obligation to provide proof, we must log that you consented or objected at a specific time. This is done via a privacy-friendly, pseudonymized proof procedure using a Consent ID. Locally in the browser: When submitting your declaration, our system generates a random, unique character string (the 'Consent ID') and stores it locally on your end device so that the page remembers your choice when you switch subpages. On the server: In parallel, this Consent ID is stored in a protected log file on our server. Linked to this ID, we log the exact timestamp, the status of your selection (allowed/rejected services), the user agent used (browser type/operating system), and your IP address exclusively in anonymized (shortened) form (e.g., 193.12.xx.xx). Re-identification of your person is impossible.
Legal Basis
Compliance with a legal obligation (Art. 6 (1) (c) GDPR): The server-side logging of your decision serves the legally required proof of consent granted. Legitimate interest (Art. 6 (1) (f) GDPR): Setting the technically necessary storage value on your end device is done in order to show you a functioning and GDPR-compliant website.
Recipients / Data Transfer
The log data of the consent management is sent encrypted to our servers in Germany (EU) and stored there. An inadmissible data transfer to unauthorized third parties or to insecure third countries (such as the USA) does not take place for this service.
Retention Period
The selection element (cookie) on your end device remains stored until you delete it manually or the maximum storage duration of 1 year is reached. The associated log data for proof (server logs) is kept independently for a fixed period of 1 year on our server in order to comply with our statutory obligation to provide proof and is then automatically deleted.
Provision Required/Voluntary
The collection of the Consent ID and the saving of your selection is technically required in order to ensure the GDPR compliance of the page. However, granting consent for optional tools (such as Google Analytics) is completely voluntary.
Contact Form, Artwork Inquiries and Communication
Type and Purpose of Processing
If you send us a message via the contact form or via an inquiry about an individual artwork ("Inquire about this work" or "Request appointment for a similar work" buttons) on our website, we process the data you enter (first and last name, email address, and — if provided — the content of your message). For an inquiry about a specific work, we additionally store the title or work number of the artwork concerned and the type of inquiry, so that our client can respond to your request personally and specifically. The purpose of the processing is the proper processing of your request, contacting you, and clarifying any follow-up questions.
Legal Basis
If your request serves the preparation of a contract or the performance of an existing contract, the legal basis is Art. 6 (1) (b) GDPR. In all other cases, processing is based on our legitimate interest in an efficient and rapid response to inquiries pursuant to Art. 6 (1) (f) GDPR.
Recipients / Data Transfer
The data you enter is transmitted encrypted to our server in Germany (EU) and stored there in a protected file. The data remains within the EU/EEA and is not passed on to unauthorized third parties or to the USA.
Retention Period
The data you transmit in the contact form remains with us until the purpose for storing the data no longer applies (e.g., after your request has been fully processed) or you request us to delete it. Mandatory statutory provisions - in particular commercial or tax retention periods for business contracts or resulting correspondence - remain unaffected.
Provision Required/Voluntary
The provision of your data is completely voluntary. Without providing your name and a valid email address, however, we cannot technically accept or reply to your request.
Google Tag Manager (GTM)
Type and Purpose of Processing
We use the Google Tag Manager on our website. This is a technical management system that itself does not set cookies and does not create independent user profiles. It serves exclusively as a tool to centrally control other analysis and statistical tools (such as Google Analytics 4). In order for the service to be loaded, your browser must establish a technical connection to Google, whereby your IP address is transmitted to Google.
Legal Basis
The Google Tag Manager is only loaded on our website after you have given us your explicit and voluntary consent via our consent banner. The legal basis is therefore your consent pursuant to Art. 6 (1) (a) GDPR.
Recipients / Data Transfer
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As a subsidiary of Google LLC (USA), it cannot be excluded that data will be transferred to the servers of the parent company in the USA and stored there. Detailed information on this third-country transfer and the technical and contractual security guarantees taken by us can be found centrally in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
Retention Period
The Google Tag Manager itself does not store personal data permanently. The processing of your IP address is transient for the pure technical connection setup and retrieval of the service.
Provision Required/Voluntary
The provision of your consent is voluntary. If you refuse consent, the Google Tag Manager will not be loaded; this will not result in any disadvantages for you when using the website.
Google Analytics 4 (GA4)
Type and Purpose of Processing
Insofar as you have given your consent, we use Google Analytics 4 for statistical evaluation and range measurement of our website. In the process, data about your user behavior is recorded via cookies or device identifiers (e.g., pages called up, duration of visit, click paths, your approximate location, and technical details about your browser and end device). We have activated IP anonymization by default, so that your IP address is shortened by Google within the EU/EEA before a data transfer takes place.
Legal Basis
Processing is carried out exclusively on the basis of your explicit consent via our consent banner pursuant to Art. 6 (1) (a) GDPR.
Recipients / Data Transfer
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As a subsidiary of Google LLC (USA), it cannot be excluded that data will be transferred to the servers of the parent company in the USA and stored there. Detailed information on this third-country transfer and the technical and contractual security guarantees taken by us can be found centrally in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
Retention Period
The data transmitted by us to Google at user level and event level (e.g., clicks) is set to be deleted automatically and permanently on Google's servers after 14 months.
Provision Required/Voluntary
Provision is voluntary. You can withdraw your consent at any time with effect for the future via the 'Cookie Settings' in the footer of our website.
International Data Transfers (Third-Country Transfers)
As part of the provision of our website and our services, we work with external partners and service providers who have their registered office or their servers in a third country outside the European Union (EU) or the European Economic Area (EEA) – in particular in the USA. This currently concerns the Google services we use (Google Analytics, Google Tag Manager).
When we transmit personal data to these service providers, we ensure that an adequate level of data protection is maintained. For this purpose, we have taken the following legal and technical protective measures:
- Data Processing Agreements (DPAs): We have concluded legally compliant data processing agreements with our partners in the USA pursuant to Art. 28 GDPR. In these agreements, the providers commit to processing your data only in accordance with our strict instructions.
- Data Privacy Framework (DPF): The USA has been recognized by the EU Commission as a country with an adequate level of data protection, provided that the respective US company has certified itself. Our partners (Google) are certified under the 'EU-U.S. Data Privacy Framework'. This guarantees that European data protection standards are complied with when processing data in the USA.
- Standard Contractual Clauses (SCCs): In addition and as an extra safeguard, the data transfer is based on the Standard Contractual Clauses provided by the EU Commission pursuant to Art. 46 GDPR.
Validity and Amendments to this Privacy Policy
This privacy policy is currently valid and has the status of June 2026. Due to the further development of our website or due to changed statutory requirements, it may become necessary to adapt this policy. We reserve the right to change this privacy policy at any time and without notice. The current version published on our website always applies to your visit. Insofar as future changes affect consent-based data use, we will – as far as legally required – obtain new consent from you.