Privacy Policy
Effective: 1 May 2025 · Version 2025-01
1. Who we are
GERDA Gallery ("we", "us", "our") operates the website gerdapaint.com. We sell original artwork by contemporary artist Gerda. Contact: [email protected].
2. Data we collect
Purchase data: name, email, phone, shipping address, order details.
Technical data: IP address, browser, device, cookies (see Cookie Policy).
Communications: enquiries and newsletter subscriptions.
We do not collect payment card data — this is handled exclusively by Stripe.
3. Legal basis (GDPR Art. 6)
- Contract — to fulfil your purchase order.
- Legitimate interests — fraud prevention, security.
- Consent — analytics and marketing cookies (opt-in only).
- Legal obligation — tax records, GDPR compliance.
4. How we use your data
- Process and ship your order.
- Send order confirmation and shipping updates.
- Respond to your enquiries.
- Send marketing emails (only with consent; unsubscribe any time).
- Comply with legal and tax obligations.
5. Data sharing
We share data only where necessary:
- Stripe — payment processing (SCC, EU data protection).
- DHL — delivery of your order.
- Resend — transactional email (SCC).
- Cloudinary — image hosting (EU region, SCC).
- Anthropic — AI-assisted SEO for artworks only. We never send customer personal data to Anthropic.
We do not sell your personal data to third parties.
6. Your rights (GDPR Art. 15–21)
- Access — request a copy of your data.
- Erasure — request deletion of your data.
- Rectification — correct inaccurate data.
- Portability — receive your data in machine-readable format.
- Objection — opt out of marketing at any time.
Submit a request at gerdapaint.com/privacy/request or email [email protected].
7. Retention
- Order records — 7 years (tax law requirement), then anonymised.
- Consent records — 3 years, then deleted.
- Newsletter subscriptions — until you unsubscribe, then 90 days.
8. International transfers
Where data is transferred outside the EEA, we use Standard Contractual Clauses (SCC) approved by the European Commission.
9. Cookies
See our Cookie Policy.
10. Updates
We may update this policy. The effective date above reflects the latest version. We will notify registered users of material changes.