Privacy Policy

1. Controller

The controller for data processing on this website within the meaning of the GDPR is:

2. Hosting

This website is hosted by Render Services, Inc. (525 Brannan Street, Suite 300, San Francisco, CA 94107, USA) in a data centre in Frankfurt am Main, Germany. Render processes the technical data arising when the site is accessed (see section 3) on our behalf, on servers within the European Union. The legal basis is our legitimate interest in the secure and reliable operation of the website (Art. 6 (1)(f) GDPR).

The provider is established in the United States. Even though processing takes place on servers in the EU, access from a third country cannot be entirely excluded. For such cases the transfer is based on the European Commission's Standard Contractual Clauses (Art. 46 (2)(c) GDPR).

3. Server log files

When you access this website, information transmitted by your browser is recorded automatically:

This data is processed solely to ensure trouble-free operation and to defend against attacks. The legal basis is Art. 6 (1)(f) GDPR. It is not combined with other data sources and is not evaluated for advertising.

4. Images and video on portfolio pages

The images and videos shown on portfolio pages are loaded directly from the Personal Data Server (PDS) of the artist concerned. Your IP address is therefore transmitted to the operator of that PDS, because this is technically necessary in order to deliver the media. Which provider hosts a given PDS is decided by the artist, not by us. The legal basis is Art. 6 (1)(f) GDPR.

5. Cookies

This website sets one cookie, and only after you sign in: ax_session. It contains a random token that names a session held on our server — never a credential, and nothing that can be decoded. It is set with the HttpOnly, Secure and SameSite=Lax attributes, so no script can read it and it is not sent with cross-site subrequests. Signing out deletes it.

This cookie is strictly necessary in order to provide a service you have expressly requested, so it requires no consent under § 25 (2) TDDDG. There is no consent banner because there is nothing to consent to: we set no other cookies and use no analytics, tracking or advertising services.

6. Signing in with your ATProto identity

Signing in uses the AT Protocol's OAuth flow against your own PDS. When a session is created we store, on our server: your decentralised identifier (DID), your handle for display, timestamps, and the credentials that keep the session alive (a refresh token and a private key), held under a hash of your session token. The legal basis is performance of our contract with you (Art. 6 (1)(b) GDPR). Signing out deletes the session record.

Your artwork and portfolio records are not copied to our servers. They are stored in your own PDS, and this site reads and writes them there on your instruction.

7. Payments

Subscriptions are handled by Paddle.com Market Ltd (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom) as Merchant of Record. Paddle is the seller of record and an independent controller for the payment data it collects: name, billing address, email address and payment details are entered on Paddle's checkout and are processed under Paddle's privacy policy. We never see or store your card details.

On the /checkout page — and on no other page — your browser loads Paddle.js from cdn.paddle.com, which transmits your IP address to Paddle. This is technically necessary to display the checkout you asked for (Art. 6 (1)(b) GDPR).

So that we know whether your studio is open, we keep a subscription record on our own server containing your DID, the subscription status, and the relevant dates. It contains no payment details. The legal basis is Art. 6 (1)(b) GDPR.

8. Storage periods

Server log files are kept only as long as our host retains them for operational security. Session records are deleted when you sign out or the session expires. Subscription records are kept for the duration of the subscription and thereafter for as long as statutory retention obligations require. Paddle keeps transaction records under its own policy, including the retention periods tax law imposes on it as seller.

9. Encryption

This website uses TLS encryption for security. You can recognise an encrypted connection by the “https://” in your browser's address bar.

10. Your rights

Under the GDPR you have the right to:

An informal message to the email address above is enough to exercise any of them.

11. Right to lodge a complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Art. 77 GDPR).