Privacy Policy

Privacy Policy version 1.0

Effective Date: May 1, 2026

Your privacy is important to us. It is our policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, across our website, studioantiopa.com.

Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.

In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.

1. Information We Collect

2. Where Your Data Is Stored

3. How Long We Retain Your Data

4. Cookie Consent and Tracking Technologies

5. Your Rights Under GDPR

6. Security of Your Personal Information

7. Third-Party Data Sharing

8. International Transfers of Personal Information

9. Children’s Privacy

10. Updates to This Policy

11. How to Exercise Your Rights

12. Supervisory Authority

13. Contact Us

This policy applies to all users of our website studioantiopa.com, including customers, newsletter subscribers, and visitors.

1. Information We Collect

Information we collect falls into one of two categories: "Voluntarily provided" information and "Automatically collected" information.

"Voluntarily provided" information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions.

"Automatically collected" information refers to any information automatically sent by your devices in the course of accessing our products and services.

Studio Antiopa is a Data Controller with respect to the personal information you provide to us.

Legal Bases for Processing Your Personal Information:

·         Consent From You

We process your personal data when you give us explicit permission, such as signing up for our newsletter or accepting cookies.

You may withdraw your consent at any time using the facilities we provide; however, this will not affect any use of your information that has already taken place. You may consent to providing your email address for the purpose of receiving marketing emails from us. While you may unsubscribe at any time, we cannot recall any email we have already sent. If you have any further enquiries about how to withdraw your consent, please feel free to enquire using the details provided in the Contact Us section of this privacy policy.

·         Performance of a Contract: To Fulfill Your Requests or Orders

We process your personal data when you place an order, contact us, or take steps to use our services (e.g., filling out a contact form or creating an account). For example, if you reach out with a question, we may need your name and email to respond.

Legitimate Interest

We process your personal data when it is necessary for our legitimate interests, such as improving our services, preventing fraud, or ensuring the security of our website. We only do this when your rights do not override our interests.

·         Legal Obligation

We process your personal data when we are required to do so by law, such as retaining financial records for tax purposes.

A. Data provided voluntarily

This includes information you actively submit to us, such as:

Service

Data Collected

Purpose

Legal Basis

Making a purchase
WooCommerce

Name, email, billing/shipping address, phone number, payment details (via Stripe/PayPal), order history

Note: Full payment details (e.g., card numbers) are not stored on our servers but are processed securely by Stripe/PayPal.

Process orders, fulfill contracts, provide customer support, and prevent fraud.

Contract performance (GDPR Art. 6(1)(b))

Creating an account
WordPress/WooCommerce

Name, email, password (hashed), order history, shipping/billing addresses, phone number.

Enable faster checkout, order tracking, and account management.

Contract performance (GDPR Art. 6(1)(b))

Signing up to the newsletter
MailerLite

Name, email, IP address, browser info, newsletter preferences, and interaction data (e.g., opens/clicks)

Send newsletters, manage subscriptions, and improve our email campaigns.

Consent (GDPR Art. 6(1)(a))

Sending a message via the contact form
WPForms

Form submissions, including any personal data you choose to provide.

Respond to inquiries, provide support, and improve our services.

Consent (GDPR Art. 6(1)(a))

Filling out the return form
Forminator

Form submissions, file uploads, and any personal data you submit.

Collect user feedback, manage requests, and improve our services.

Consent (GDPR Art. 6(1)(a))

 

These services act as Data Processors for this data, processing it on our behalf and in accordance with our instructions. MailerLite stores data on its own servers under the conditions detailed in the data processing agreement.

B. Data Collected Automatically

This includes information collected automatically when you visit our website:

Service

Data Collected

Purpose

Legal Basis

Hosting provider
Hostinger

IP address, device info including operating system, browser info, pages visited, timestamps, session duration, and referrer url.

Security monitoring and ensuring technical site performance.

Legitimate interest (GDPR Art. 6(1)(f))

Google Analytics

IP address (anonymized for EU users), device info including operating system, browser info, pages visited, timestamps, session duration, geographical data, ad interactions, attribution data, referrer url, and behavior on our site including conversion behavior.

Analyze website traffic, improve user experience, and measure the effectiveness of our content and ads.

Consent (GDPR Art. 6(1)(a))

Activated only after explicit consent via our cookie banner or -button.

Meta Pixel

IP address, browser info, device info including operating system, browser info, pages visited, timestamps, session duration, geographical data, ad interactions, attribution data, referrer url, and behavior on our site including conversion behavior.

Analyze website traffic, improve user experience, and measure the effectiveness of our content and ads.

Consent (GDPR Art. 6(1)(a))

Activated only after explicit consent via our cookie banner or -button.

Pinterest Tag

Pinterest ID (if user is logged in), IP address, browser info, device info including operating system, browser info, pages visited, timestamps, session duration, geographical data, ad interactions, attribution data, referrer url, and behavior on our site including conversion behavior.

Track conversions and optimize Pinterest ad campaigns.

Consent (GDPR Art. 6(1)(a))

Activated only after explicit consent via our cookie banner or -button.

 

Hostinger acts as a Data Processor (under a data processing agreement), while Google Analytics, Meta and Pinterest act as independent Data Controllers for this data. We only activate the last three services mentioned after you give your explicit consent, and you can withdraw your consent at any time.

C. Payment Data and Order Fulfillment (Processed by Third Parties)

We do not store your full payment details (e.g., credit card numbers) on our servers. Payment processing is handled by Stripe and PayPal.

Service

Data Collected

Purpose

Legal Basis

Stripe

Payment details (last 4 digits of card, card brand, expiration date, billing info, tax status), order details, transaction history, customer names/emails, device ID, IP addresses, and unique identifiers.

Process payments, comply with legal requirements, fraud prevention, session management, analytics.

Contract performance (GDPR Art. 6(1)(b)) for payment processing. Legitimate interest (GDPR Art. 6(1)(f)) for fraud prevention.

PayPal

Payment details (card numbers, billing info, tax status), order details, transaction history, customer names/emails, device ID, IP addresses, unique identifiers and location data.

Process payments, comply with legal requirements, fraud prevention, session management, analytics.

Contract performance (GDPR Art. 6(1)(b)) for payment processing. Legitimate interest (GDPR Art. 6(1)(f)) for fraud prevention.

Order fulfillment
Prodigi

Order details (product type, size, quantity), shipping information (name, address, phone number, email), payment status. In some instances IP address, device info, browser type and technical logs for security and fraud prevention.

Fulfill orders (printing and shipping products), manage deliveries via sub-processors (delivery firms), fraud prevention.

Contract performance (GDPR Art. 6(1)(b)). Legitimate interest (GDPR Art. 6(1)(f)) for fraud prevention.

 

Stripe and PayPal act as independent Data Controllers for the processing of customer data related to payment transactions.

We use Prodigi (a print-on-demand service) to fulfill orders for physical products (e.g., prints). When you place an order, we share the data mentioned in the table above with Prodigi to enable printing and delivery.

Prodigi acts as a Data Processor for order fulfillment under their Data Processing Agreement (DPA). They may use subcontractors (delivery firms) to ship your order. These delivery firms act as sub-processors under Prodigi’s DPA and are bound by the same data protection obligations.

Note: Prodigi may transfer data to delivery firms (e.g., DHL, Royal Mail, or local carriers) to fulfill your order. These firms are obligated to protect your data under Prodigi’s contracts and GDPR.

2. Where Your Data Is Stored

Your data is stored in the following locations, depending on the service:

Service

Storage Location

Using the webshop WooCommerce

Hostinger’s servers in France.
Backup: Lithuania.

Account data WordPress/WooCommerce

Hostinger’s servers in France.
Backup: Lithuania.

Newsletter signup
MailerLite

Germany and Netherlands.

Contact form
WPForms

Sent to Hostinger’s servers in France.
Backup: Lithuania.

Return form
Forminator

WordPress on Hostinger’s servers in France.
Backup: Lithuania.

Cookie consent
Google Analytics

Data from EU-based devices (based on IP-geo lookup) is collected through domains and on servers based in the EU before forwarding traffic to Analytics servers for processing. Data is processed and stored on Google’s servers, primarily located in the United States. Data transfers comply with SCCs (Standard Contractual Clauses), encryption and pseudonymisation to comply with GDPR for EU users and anonymizes IP addresses for EU users.

Cookie consent
Meta Pixel

Meta Platforms Ireland Ltd. have data centres in the EU, but data may be transferred to servers in the United States. Data transfers comply with SCCs (Standard Contractual Clauses) and encryption to comply with GDPR for EU users.

Cookie consent
Pinterest Tag

Information controlled by Pinterest Europe Limited will be transferred or transmitted to, or stored and processed in, the United States or other countries outside of where you live. Data transfers comply with SCCs (Standard Contractual Clauses), encryption and pseudonymisation to comply with GDPR for EU users.

Cookie consent preferences
WPConsent

Consent data is stored locally on Hostinger’s servers in France.
Backup: Lithuania.

Payment processing
Stripe

Data is collected and controlled by Stripe Payments Europe Ltd. (Ireland) for EU users and transferred, primarily to the United States, using SCCs (Standard Contractual Clauses), encryption and pseudonymisation to comply with GDPR for EU users.

Payment processing
PayPal

Data is processed by PayPal Europe Ltd. (Luxembourg) for EU users. PayPal has global servers and may transfer data to the United States. Data transfers comply with SCCs (Standard Contractual Clauses) and encryption to comply with GDPR for EU users.

Fulfilling your order
Prodigi

Prodigi’s servers (primarily in the EU, UK and US). Delivery firms (sub-processors) may access data for shipping.

 

3. How Long We Retain Your Data

We keep your personal information only for as long as necessary to fulfill the purposes for which it was collected. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information such as an email address when contacting us about a specific enquiry, we may retain this information for the duration of your enquiry remaining open. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you.

However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation.

Data Type

Retention Period

WooCommerce Orders

Invoices, receipts, and financial records are retained for 5 years from the end of the financial year to which they relate, to comply with the Danish Bookkeeping Act (Bogføringsloven).

Account Data

Account information (name, email, password, addresses) is retained for 2 years after your last activity (e.g., login or purchase) or until you request deletion.

MailerLite Newsletter Subscribers

Until you unsubscribe or request deletion.

WPForms

Contact form submissions (e.g., names, emails, and messages) are retained only for as long as necessary to resolve your request, up to a maximum of 12 months. After this period, the data will be permanently deleted. In exceptional cases, messages may be retained in anonymized form (with all personal identifiers removed) to improve our customer support services.

Forminator

Return request data (including names, contact details, and any submitted pictures) will be retained only for as long as necessary to process your return, handle any disputes, or comply with legal obligations, up to a maximum of 2 years after resolution. After this period, all personal data will be permanently deleted. In exceptional cases, anonymized data (with all personal identifiers removed) may be retained to improve our services.

Warranty Claims

If you submit a warranty claim (via the return form and therefore using Forminator, also described above), we will process your personal data (e.g., name, email, order details, and any provided evidence such as photos or descriptions) to assess and fulfill your claim. This data is retained for as long as necessary to resolve the claim and for 2 years afterward to comply with legal obligations.

Hostinger

Technical server logs are stored for 30 days.

Google Analytics

Event-level data is retained for 2 months and automatically deleted afterward. Aggregated reports are retained indefinitely but do not contain personal data.

Meta Pixel

Meta retains this data according to its own Data Policy. For EU users, Meta acts as an independent Data Controller and retains data for as long as necessary to provide its services, comply with legal obligations, or as specified in its policies. We do not control Meta’s retention periods, but we ensure the Pixel is only activated after you give explicit consent via our cookie banner.

Pinterest Tag

Pinterest retains this data according to its own Privacy Policy. For EU users, Pinterest acts as an independent Data Controller and retains data for as long as necessary to provide its services, comply with legal obligations, or as specified in its policies. We do not control Pinterest’s retention periods, but we ensure the tag is only activated after you give explicit consent via our cookie banner.

WPConsent Logs

Consent logs are retained indefinitely to demonstrate compliance with GDPR consent requirements.

Stripe

Stripe retains personal data in compliance with applicable data protection laws, and additional sector-specific rules that apply to Stripe.

Paypal

Transaction data and customer data is retained as long as the the business account (Studio Antiopa) is active. Thereafter, it is retained for 10 years for legal compliance.

Prodigi

Order data is retained for as long as necessary for fulfillment and legal compliance (e.g., tax or warranty purposes).

 

4. Cookie Consent and Tracking Technologies

We use cookies and similar technologies (e.g., pixels, tags) to enhance your experience and analyze website traffic. Your consent is required for non-essential cookies under GDPR.

Please refer to our Cookie Policy for more information on cookies.

A. Cookie Consent Management

·         We use WPConsent (powered by GetTerms) to manage cookie consent.

·         All consent data is stored in Studio Antiopa’s WordPress database (hosted on Hostinger’s servers).

·         Cookies are blocked by default until you provide explicit consent.

·         You can withdraw consent at any time via the cookie preferences button on screen or your browser settings.

B. Google Consent Mode

·         We use Google Consent Mode to dynamically adjust Google Analytics and Ads tags based on your consent choices.

·         If you deny consent, no tracking tags (Google Analytics, Meta Pixel, Pinterest Tag) will load until you interact with the consent banner or cookie preferences button.

·         If you grant consent, data is collected as usual.

·         If you deny consent, Google may use anonymized modeling to estimate website traffic and behavior without storing personal data.

5. Your Rights Under GDPR

Under GDPR, you have the following rights regarding your personal data:

A. Right to Access (GDPR Art. 15)

You can request a copy of the personal data we hold about you.

·         How to Request: Send a message here with the subject line “Data Access Request.”

·         Response Time: We will respond within 1 month, or 2 months for complex requests (we will notify you if an extension is needed).

B. Right to Rectification (GDPR Art. 16)

You can request corrections to inaccurate or incomplete data.

·         How to Request: Send a message here with the subject line “Data Correction Request.”

C. Right to Erasure (“Right to Be Forgotten”) (GDPR Art. 17)

You can request the deletion of your personal data if:

·         The data is no longer necessary for the purposes for which it was collected.

·         You withdraw your consent (for consent-based processing).

·         The data was processed unlawfully.

·         Exceptions: We may retain data if required by law (e.g., Danish Bookkeeping Act requires retention of invoices for 5-6 years).

·         How to Request: Send a message here with the subject line “Data Deletion Request.”

D. Right to Restrict Processing (GDPR Art. 18)

You can request that we limit the processing of your data in certain circumstances (e.g., while we verify a correction request).

E. Right to Data Portability (GDPR Art. 20)

You can request a machine-readable copy of your data to transfer to another service. Where possible, we will provide this information in CSV format or other easily readable machine format. You may also have the right to request that we transfer this personal information to a third party.

·         How to Request: Send a message here with the subject line “Data Portability Request.”

F. Right to Object (GDPR Art. 21)

You can object to processing based on legitimate interests (e.g., direct marketing).

·         How to Request: Send a message here with the subject line “Objection to Processing.”

G. Right to Withdraw Consent (GDPR Art. 7(3))

If we rely on consent as the legal basis for processing (e.g., newsletters, cookies), you can withdraw it at any time.

·         How to Withdraw:

o   For newsletters: Use the unsubscribe link in newsletter emails.

o   For cookies: Use the cookie consent banner, the cookie preferences button on screen, or your browser settings.

H. Automated Decision-Making

We do not use automated decision-making (e.g., profiling) that produces legal effects or significantly affects you.

6. Security of Your Personal Information

When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification.

Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure and no one can guarantee absolute data security.

You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services.

How We Protect Your Data

We implement the following technical and organizational measures to protect your data:

  • Encryption: All data transmitted to our website is encrypted using HTTPS/TLS.
  • Secure Hosting: Our website is hosted by Hostinger, which uses ISO 27001-certified data centers.
  • Access Controls: Only authorized personnel can access your data.
  • Regular Audits: We regularly review our data processing practices for compliance.
  • Data Minimization: We collect only the data necessary for the stated purposes.

 

Notification of data breaches: We will comply with laws applicable to us in respect of any data breach.

7. Third-Party Data Sharing

We share your data with the following third-party processors to provide our services. For more information about the data shared with these third-parties, please refer to section “1. Information We Collect”.

Service

Purpose

Data Shared

Legal Basis

Privacy policy

Hostinger

Website hosting and server management.

All website data (stored on their servers).

Contract performance (GDPR Art. 6(1)(b))

Hostinger Privacy Policy

Stripe

Payment processing.

Payment details, transaction data, and customer info (name, email).

Contract performance (GDPR Art. 6(1)(b))

Stripe Privacy Policy

PayPal

Payment processing.

Payment details, transaction data, and customer info (name, email).

Contract performance (GDPR Art. 6(1)(b))

PayPal Privacy Statement

MailerLite

Newsletter management.

Subscriber data (name, email, interaction data).

Consent (GDPR Art. 6(1)(a))

MailerLite Privacy Policy

Google Analytics

Website analytics.

Anonymized user behavior data (IP address, device, pages visited).

Consent (GDPR Art. 6(1)(a))

Google Privacy Policy

Meta Pixel

Advertising and remarketing.

User behavior data (IP address, device, actions taken).

Consent (GDPR Art. 6(1)(a))

Meta Privacy Policy

Pinterest Tag

Conversion tracking and ad optimization.

User behavior data (IP address, device, actions taken).

Consent (GDPR Art. 6(1)(a))

Pinterest Privacy Policy

Prodigi

Order fulfillment and shipping.

Order details, shipping information, IP address, device info, browser type.

Contract performance (GDPR Art. 6(1)(b))

Prodigi Privacy Policy

 

8. International Transfers of Personal Information

Some of our third-party processors (e.g., Stripe, PayPal, Meta, Google, Prodigi) may transfer data outside the European Economic Area (EEA). We ensure compliance with GDPR Chapter V by:

·         Using Standard Contractual Clauses (SCCs) where required.

·         Relying on adequacy decisions (e.g., for US companies under the EU-US Data Privacy Framework).

·         Implementing additional safeguards (e.g., encryption, anonymization).

9. Children’s Privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from children under 16.

If you are a parent or guardian and believe we have collected personal data from your child without consent, please contact us at antiopa@studioantiopa.com or via our contact form to request deletion of that data.

Note for Users Under 16: If you are under 16, you must have permission from a parent or guardian before providing any personal information to us.

10. Updates to This Policy

At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.

11. How to Exercise Your Rights

To exercise any of your rights under this policy or GDPR, send a message here or contact us at antiopa@studioantiopa.com.

We will respond to your request within 1 month (extendable to 2 months for complex requests). We may ask for proof of identity to verify your request.

12. Supervisory Authority

If you believe we have violated GDPR, you have the right to lodge a complaint with your local data protection authority (DPA). For Denmark, this is:
Datatilsynet (Danish Data Protection Agency).

13. Contact Us

For any questions or concerns regarding your privacy, you may contact us using the following page: Contact Studio Antiopa

Studio Antiopa
Paradisæblevej 61, 1. Th.
2500 Valby
Denmark
antiopa@studioantiopa.com
+45 51 36 95 83