Privacy Policy
Privacy Policy version 1.0
Effective Date: May 1, 2026
Your privacy is important to us. It is our policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, across our website, studioantiopa.com.
Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.
In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.
3. How Long We Retain Your Data
4. Cookie Consent and Tracking Technologies
6. Security of Your Personal Information
8. International Transfers of Personal Information
11. How to Exercise Your Rights
This policy applies to all users of our website studioantiopa.com, including customers, newsletter subscribers, and visitors.
1. Information We Collect
Information we collect falls into one of two categories: "Voluntarily provided" information and "Automatically collected" information.
"Voluntarily provided" information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions.
"Automatically collected" information refers to any information automatically sent by your devices in the course of accessing our products and services.
Studio Antiopa is a Data Controller with respect to the personal information you provide to us.
Legal Bases for Processing Your Personal Information:
· Consent From You
We process your personal data when you give us explicit permission, such as signing up for our newsletter or accepting cookies.
You may withdraw your consent at any time using the facilities we provide; however, this will not affect any use of your information that has already taken place. You may consent to providing your email address for the purpose of receiving marketing emails from us. While you may unsubscribe at any time, we cannot recall any email we have already sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy.
· Performance of a Contract: To Fulfill Your Requests or Orders
We process your personal data when you place an order, contact us, or take steps to use our services (e.g., filling out a contact form or creating an account). For example, if you reach out with a question, we may need your name and email to respond.
Legitimate Interest
We process your personal data when it is necessary for our legitimate interests, such as improving our services, preventing fraud, or ensuring the security of our website. We only do this when your rights do not override our interests.
· Legal Obligation
We process your personal data when we are required to do so by law, such as retaining financial records for tax purposes.
A. Data provided voluntarily
This includes information you actively submit to us, such as:
Service | Data Collected | Purpose | Legal Basis |
Making a purchase | Name, email, billing/shipping address, phone number, payment details (via Stripe/PayPal), order history Note: Full payment details (e.g., card numbers) are not stored on our servers but are processed securely by Stripe/PayPal. | Process orders, fulfill contracts, provide customer support, and prevent fraud. | Contract performance (GDPR Art. 6(1)(b)) |
Creating an account | Name, email, password (hashed), order history, shipping/billing addresses, phone number. | Enable faster checkout, order tracking, and account management. | Contract performance (GDPR Art. 6(1)(b)) |
Signing up to the newsletter | Name, email, IP address, browser info, newsletter preferences, and interaction data (e.g., opens/clicks) | Send newsletters, manage subscriptions, and improve our email campaigns. | Consent (GDPR Art. 6(1)(a)) |
Sending a message via the contact
form | Form submissions, including any personal data you choose to provide. | Respond to inquiries, provide support, and improve our services. | Consent (GDPR Art. 6(1)(a)) |
Filling out the return form | Form submissions, file uploads, and any personal data you submit. | Collect user feedback, manage requests, and improve our services. | Consent (GDPR Art. 6(1)(a)) |
These services act as Data Processors for this data, processing it on our behalf and in accordance with our instructions. MailerLite stores data on its own servers under the conditions detailed in the data processing agreement.
B. Data Collected Automatically
This includes information collected automatically when you visit our website:
Service | Data Collected | Purpose | Legal Basis |
Hosting provider | IP address, device info including operating system, browser info, pages visited, timestamps, session duration, and referrer url. | Security monitoring and ensuring technical site performance. | Legitimate interest (GDPR Art. 6(1)(f)) |
Google Analytics | IP address (anonymized for EU users), device info including operating system, browser info, pages visited, timestamps, session duration, geographical data, ad interactions, attribution data, referrer url, and behavior on our site including conversion behavior. | Analyze website traffic, improve user experience, and measure the effectiveness of our content and ads. | Consent (GDPR Art. 6(1)(a)) Activated only after explicit consent via our cookie banner or -button. |
Meta Pixel | IP address, browser info, device info including operating system, browser info, pages visited, timestamps, session duration, geographical data, ad interactions, attribution data, referrer url, and behavior on our site including conversion behavior. | Analyze website traffic, improve user experience, and measure the effectiveness of our content and ads. | Consent (GDPR Art. 6(1)(a)) Activated only after explicit consent via our cookie banner or -button. |
Pinterest Tag | Pinterest ID (if user is logged in), IP address, browser info, device info including operating system, browser info, pages visited, timestamps, session duration, geographical data, ad interactions, attribution data, referrer url, and behavior on our site including conversion behavior. | Track conversions and optimize Pinterest ad campaigns. | Consent (GDPR Art. 6(1)(a)) Activated only after explicit consent via our cookie banner or -button. |
Hostinger acts as a Data Processor (under a data processing agreement), while Google Analytics, Meta and Pinterest act as independent Data Controllers for this data. We only activate the last three services mentioned after you give your explicit consent, and you can withdraw your consent at any time.
C. Payment Data and Order Fulfillment (Processed by Third Parties)
We do not store your full payment details (e.g., credit card numbers) on our servers. Payment processing is handled by Stripe and PayPal.
Service | Data Collected | Purpose | Legal Basis |
Stripe | Payment details (last 4 digits of card, card brand, expiration date, billing info, tax status), order details, transaction history, customer names/emails, device ID, IP addresses, and unique identifiers. | Process payments, comply with legal requirements, fraud prevention, session management, analytics. | Contract performance (GDPR Art. 6(1)(b)) for payment processing. Legitimate interest (GDPR Art. 6(1)(f)) for fraud prevention. |
PayPal | Payment details (card numbers, billing info, tax status), order details, transaction history, customer names/emails, device ID, IP addresses, unique identifiers and location data. | Process payments, comply with legal requirements, fraud prevention, session management, analytics. | Contract performance (GDPR Art. 6(1)(b)) for payment processing. Legitimate interest (GDPR Art. 6(1)(f)) for fraud prevention. |
Order fulfillment | Order details (product type, size, quantity), shipping information (name, address, phone number, email), payment status. In some instances IP address, device info, browser type and technical logs for security and fraud prevention. | Fulfill orders (printing and shipping products), manage deliveries via sub-processors (delivery firms), fraud prevention. | Contract performance (GDPR Art. 6(1)(b)). Legitimate interest (GDPR Art. 6(1)(f)) for fraud prevention. |
Stripe and PayPal act as independent Data Controllers for the processing of customer data related to payment transactions.
We use Prodigi (a print-on-demand service) to fulfill orders for physical products (e.g., prints). When you place an order, we share the data mentioned in the table above with Prodigi to enable printing and delivery.
Prodigi acts as a Data Processor for order fulfillment under their Data Processing Agreement (DPA). They may use subcontractors (delivery firms) to ship your order. These delivery firms act as sub-processors under Prodigi’s DPA and are bound by the same data protection obligations.
Note: Prodigi may transfer data to delivery firms (e.g., DHL, Royal Mail, or local carriers) to fulfill your order. These firms are obligated to protect your data under Prodigi’s contracts and GDPR.
2. Where Your Data Is Stored
Your data is stored in the following locations, depending on the service:
Service | Storage Location |
Using the webshop WooCommerce | Hostinger’s servers in France. |
Account data WordPress/WooCommerce | Hostinger’s servers in France. |
Newsletter signup | Germany and Netherlands. |
Contact form | Sent to Hostinger’s servers in France. |
Return form | WordPress on Hostinger’s servers in
France. |
Cookie consent | Data from EU-based devices (based on IP-geo lookup) is collected through domains and on servers based in the EU before forwarding traffic to Analytics servers for processing. Data is processed and stored on Google’s servers, primarily located in the United States. Data transfers comply with SCCs (Standard Contractual Clauses), encryption and pseudonymisation to comply with GDPR for EU users and anonymizes IP addresses for EU users. |
Cookie consent | Meta Platforms Ireland Ltd. have data centres in the EU, but data may be transferred to servers in the United States. Data transfers comply with SCCs (Standard Contractual Clauses) and encryption to comply with GDPR for EU users. |
Cookie consent | Information controlled by Pinterest Europe Limited will be transferred or transmitted to, or stored and processed in, the United States or other countries outside of where you live. Data transfers comply with SCCs (Standard Contractual Clauses), encryption and pseudonymisation to comply with GDPR for EU users. |
Cookie consent preferences | Consent data is stored locally on
Hostinger’s servers in France. |
Payment processing | Data is collected and controlled by Stripe Payments Europe Ltd. (Ireland) for EU users and transferred, primarily to the United States, using SCCs (Standard Contractual Clauses), encryption and pseudonymisation to comply with GDPR for EU users. |
Payment processing | Data is processed by PayPal Europe Ltd. (Luxembourg) for EU users. PayPal has global servers and may transfer data to the United States. Data transfers comply with SCCs (Standard Contractual Clauses) and encryption to comply with GDPR for EU users. |
Fulfilling your order | Prodigi’s servers (primarily in the EU, UK and US). Delivery firms (sub-processors) may access data for shipping. |
3. How Long We Retain Your Data
We keep your personal information only for as long as necessary to fulfill the purposes for which it was collected. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information such as an email address when contacting us about a specific enquiry, we may retain this information for the duration of your enquiry remaining open. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you.
However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation.
Data Type | Retention Period |
WooCommerce Orders | Invoices, receipts, and financial records are retained for 5 years from the end of the financial year to which they relate, to comply with the Danish Bookkeeping Act (Bogføringsloven). |
Account Data | Account information (name, email, password, addresses) is retained for 2 years after your last activity (e.g., login or purchase) or until you request deletion. |
MailerLite Newsletter Subscribers | Until you unsubscribe or request deletion. |
WPForms | Contact form submissions (e.g., names, emails, and messages) are retained only for as long as necessary to resolve your request, up to a maximum of 12 months. After this period, the data will be permanently deleted. In exceptional cases, messages may be retained in anonymized form (with all personal identifiers removed) to improve our customer support services. |
Forminator | Return request data (including names, contact details, and any submitted pictures) will be retained only for as long as necessary to process your return, handle any disputes, or comply with legal obligations, up to a maximum of 2 years after resolution. After this period, all personal data will be permanently deleted. In exceptional cases, anonymized data (with all personal identifiers removed) may be retained to improve our services. |
Warranty Claims | If you submit a warranty claim (via the return form and therefore using Forminator, also described above), we will process your personal data (e.g., name, email, order details, and any provided evidence such as photos or descriptions) to assess and fulfill your claim. This data is retained for as long as necessary to resolve the claim and for 2 years afterward to comply with legal obligations. |
Hostinger | Technical server logs are stored for 30 days. |
Google Analytics | Event-level data is retained for 2 months and automatically deleted afterward. Aggregated reports are retained indefinitely but do not contain personal data. |
Meta Pixel | Meta retains this data according to its own Data Policy. For EU users, Meta acts as an independent Data Controller and retains data for as long as necessary to provide its services, comply with legal obligations, or as specified in its policies. We do not control Meta’s retention periods, but we ensure the Pixel is only activated after you give explicit consent via our cookie banner. |
Pinterest Tag | Pinterest retains this data according to its own Privacy Policy. For EU users, Pinterest acts as an independent Data Controller and retains data for as long as necessary to provide its services, comply with legal obligations, or as specified in its policies. We do not control Pinterest’s retention periods, but we ensure the tag is only activated after you give explicit consent via our cookie banner. |
WPConsent Logs | Consent logs are retained indefinitely to demonstrate compliance with GDPR consent requirements. |
Stripe | Stripe retains personal data in compliance with applicable data protection laws, and additional sector-specific rules that apply to Stripe. |
Paypal | Transaction data and customer data is retained as long as the the business account (Studio Antiopa) is active. Thereafter, it is retained for 10 years for legal compliance. |
Prodigi | Order data is retained for as long as necessary for fulfillment and legal compliance (e.g., tax or warranty purposes). |
4. Cookie Consent and Tracking Technologies
We use cookies and similar technologies (e.g., pixels, tags) to enhance your experience and analyze website traffic. Your consent is required for non-essential cookies under GDPR.
Please refer to our Cookie Policy for more information on cookies.
A. Cookie Consent Management
· We use WPConsent (powered by GetTerms) to manage cookie consent.
· All consent data is stored in Studio Antiopa’s WordPress database (hosted on Hostinger’s servers).
· Cookies are blocked by default until you provide explicit consent.
· You can withdraw consent at any time via the cookie preferences button on screen or your browser settings.
B. Google Consent Mode
· We use Google Consent Mode to dynamically adjust Google Analytics and Ads tags based on your consent choices.
· If you deny consent, no tracking tags (Google Analytics, Meta Pixel, Pinterest Tag) will load until you interact with the consent banner or cookie preferences button.
· If you grant consent, data is collected as usual.
· If you deny consent, Google may use anonymized modeling to estimate website traffic and behavior without storing personal data.
5. Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
A. Right to Access (GDPR Art. 15)
You can request a copy of the personal data we hold about you.
· How to Request: Send a message here with the subject line “Data Access Request.”
· Response Time: We will respond within 1 month, or 2 months for complex requests (we will notify you if an extension is needed).
B. Right to Rectification (GDPR Art. 16)
You can request corrections to inaccurate or incomplete data.
· How to Request: Send a message here with the subject line “Data Correction Request.”
C. Right to Erasure (“Right to Be Forgotten”) (GDPR Art. 17)
You can request the deletion of your personal data if:
· The data is no longer necessary for the purposes for which it was collected.
· You withdraw your consent (for consent-based processing).
· The data was processed unlawfully.
· Exceptions: We may retain data if required by law (e.g., Danish Bookkeeping Act requires retention of invoices for 5-6 years).
· How to Request: Send a message here with the subject line “Data Deletion Request.”
D. Right to Restrict Processing (GDPR Art. 18)
You can request that we limit the processing of your data in certain circumstances (e.g., while we verify a correction request).
E. Right to Data Portability (GDPR Art. 20)
You can request a machine-readable copy of your data to transfer to another service. Where possible, we will provide this information in CSV format or other easily readable machine format. You may also have the right to request that we transfer this personal information to a third party.
· How to Request: Send a message here with the subject line “Data Portability Request.”
F. Right to Object (GDPR Art. 21)
You can object to processing based on legitimate interests (e.g., direct marketing).
· How to Request: Send a message here with the subject line “Objection to Processing.”
G. Right to Withdraw Consent (GDPR Art. 7(3))
If we rely on consent as the legal basis for processing (e.g., newsletters, cookies), you can withdraw it at any time.
· How to Withdraw:
o For newsletters: Use the unsubscribe link in newsletter emails.
o For cookies: Use the cookie consent banner, the cookie preferences button on screen, or your browser settings.
H. Automated Decision-Making
We do not use automated decision-making (e.g., profiling) that produces legal effects or significantly affects you.
6. Security of Your Personal Information
When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification.
Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security.
You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services.
How We Protect Your Data
We implement the following technical and organizational measures to protect your data:
- Encryption: All data transmitted to our website is encrypted using HTTPS/TLS.
- Secure Hosting: Our website is hosted by Hostinger, which uses ISO 27001-certified data centers.
- Access Controls: Only authorized personnel can access your data.
- Regular Audits: We regularly review our data processing practices for compliance.
- Data Minimization: We collect only the data necessary for the stated purposes.
Notification of data breaches: We will comply with laws applicable to us in respect of any data breach.
7. Third-Party Data Sharing
We share your data with the following third-party processors to provide our services. For more information about the data shared with these third-parties, please refer to section “1. Information We Collect”.
Service | Purpose | Data Shared | Legal Basis | Privacy policy |
Hostinger | Website hosting and server management. | All website data (stored on their servers). | Contract performance (GDPR Art. 6(1)(b)) | |
Stripe | Payment processing. | Payment details, transaction data, and customer info (name, email). | Contract performance (GDPR Art. 6(1)(b)) | |
PayPal | Payment processing. | Payment details, transaction data, and customer info (name, email). | Contract performance (GDPR Art. 6(1)(b)) | |
MailerLite | Newsletter management. | Subscriber data (name, email, interaction data). | Consent (GDPR Art. 6(1)(a)) | |
Google Analytics | Website analytics. | Anonymized user behavior data (IP address, device, pages visited). | Consent (GDPR Art. 6(1)(a)) | |
Meta Pixel | Advertising and remarketing. | User behavior data (IP address, device, actions taken). | Consent (GDPR Art. 6(1)(a)) | |
Pinterest Tag | Conversion tracking and ad optimization. | User behavior data (IP address, device, actions taken). | Consent (GDPR Art. 6(1)(a)) | |
Prodigi | Order fulfillment and shipping. | Order details, shipping information, IP address, device info, browser type. | Contract performance (GDPR Art. 6(1)(b)) |
8. International Transfers of Personal Information
Some of our third-party processors (e.g., Stripe, PayPal, Meta, Google, Prodigi) may transfer data outside the European Economic Area (EEA). We ensure compliance with GDPR Chapter V by:
· Using Standard Contractual Clauses (SCCs) where required.
· Relying on adequacy decisions (e.g., for US companies under the EU-US Data Privacy Framework).
· Implementing additional safeguards (e.g., encryption, anonymization).
9. Children’s Privacy
Our services are not directed at children under 16. We do not knowingly collect personal data from children under 16.
If you are a parent or guardian and believe we have collected personal data from your child without consent, please contact us at antiopa@studioantiopa.com or via our contact form to request deletion of that data.
Note for Users Under 16: If you are under 16, you must have permission from a parent or guardian before providing any personal information to us.
10. Updates to This Policy
At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.
11. How to Exercise Your Rights
To exercise any of your rights under this policy or GDPR, send a message here or contact us at antiopa@studioantiopa.com.
We will respond to your request within 1 month (extendable to 2 months for complex requests). We may ask for proof of identity to verify your request.
12. Supervisory Authority
If you believe we have violated GDPR, you
have the right to lodge a complaint with your local data protection authority
(DPA). For Denmark, this is:
Datatilsynet (Danish Data
Protection Agency).
13. Contact Us
For any questions or concerns regarding your privacy, you may contact us using the following page: Contact Studio Antiopa
Studio Antiopa
Paradisæblevej 61, 1. Th.
2500 Valby
Denmark
antiopa@studioantiopa.com
+45 51 36 95 83
