Privacy Policy
Information on the processing of personal data pursuant to Art. 13 of the General Data Protection Regulation (GDPR).
1. Controller
The controller for data processing on this website within the meaning of the GDPR is:
Sylvan James Smit
Sonnenallee 162
12059 Berlin
Germany
Email: [email protected]
2. Hosting
This website is hosted by Render Services, Inc. (525 Brannan Street, Suite 300, San Francisco, CA 94107, USA) in a data centre in Frankfurt am Main, Germany. Render processes the technical data arising when the site is accessed (see section 3) on our behalf, on servers within the European Union. The legal basis is our legitimate interest in the secure and reliable operation of the website (Art. 6 (1)(f) GDPR).
The provider is established in the United States. Even though processing takes place on servers in the EU, access from a third country cannot be entirely excluded. For such cases the transfer is based on the European Commission's Standard Contractual Clauses (Art. 46 (2)(c) GDPR).
3. Server log files
When you access this website, information transmitted by your browser is recorded automatically:
- the IP address of the requesting device
- the date and time of the request
- the address (URL) requested and the HTTP status code
- the volume of data transferred
- the referrer URL and the browser and operating system identifier (user agent)
This data is processed solely to ensure trouble-free operation and to defend against attacks. The legal basis is Art. 6 (1)(f) GDPR. It is not combined with other data sources and is not evaluated for advertising.
4. Images and video on portfolio pages
The images and videos shown on portfolio pages are loaded directly from the Personal Data Server (PDS) of the artist concerned. Your IP address is therefore transmitted to the operator of that PDS, because this is technically necessary in order to deliver the media. Which provider hosts a given PDS is decided by the artist, not by us. The legal basis is Art. 6 (1)(f) GDPR.
5. Cookies
This website sets one cookie, and only after you sign in: ax_session. It contains a random token that names a session held on our server — never a credential, and nothing that can be decoded. It is set with the HttpOnly, Secure and SameSite=Lax attributes, so no script can read it and it is not sent with cross-site subrequests. Signing out deletes it.
This cookie is strictly necessary in order to provide a service you have expressly requested, so it requires no consent under § 25 (2) TDDDG. There is no consent banner because there is nothing to consent to: we set no other cookies and use no analytics, tracking or advertising services.
6. Signing in with your ATProto identity
Signing in uses the AT Protocol's OAuth flow against your own PDS. When a session is created we store, on our server: your decentralised identifier (DID), your handle for display, timestamps, and the credentials that keep the session alive (a refresh token and a private key), held under a hash of your session token. The legal basis is performance of our contract with you (Art. 6 (1)(b) GDPR). Signing out deletes the session record.
Your artwork and portfolio records are not copied to our servers. They are stored in your own PDS, and this site reads and writes them there on your instruction.
7. Payments
Subscriptions are handled by Paddle.com Market Ltd (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom) as Merchant of Record. Paddle is the seller of record and an independent controller for the payment data it collects: name, billing address, email address and payment details are entered on Paddle's checkout and are processed under Paddle's privacy policy. We never see or store your card details.
On the /checkout page — and on no other page — your browser loads Paddle.js from cdn.paddle.com, which transmits your IP address to Paddle. This is technically necessary to display the checkout you asked for (Art. 6 (1)(b) GDPR).
So that we know whether your studio is open, we keep a subscription record on our own server containing your DID, the subscription status, and the relevant dates. It contains no payment details. The legal basis is Art. 6 (1)(b) GDPR.
8. Storage periods
Server log files are kept only as long as our host retains them for operational security. Session records are deleted when you sign out or the session expires. Subscription records are kept for the duration of the subscription and thereafter for as long as statutory retention obligations require. Paddle keeps transaction records under its own policy, including the retention periods tax law imposes on it as seller.
9. Encryption
This website uses TLS encryption for security. You can recognise an encrypted connection by the “https://” in your browser's address bar.
10. Your rights
Under the GDPR you have the right to:
- access the data held about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing (Art. 21 GDPR)
An informal message to the email address above is enough to exercise any of them.
11. Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Art. 77 GDPR).