Privacy Policy
Last Updated 29.07.2026
Last updated: 29 July 2026
1. Controller
The controller responsible for processing personal data through this website is:
Handmade by Fátima Ferreira
Owner: Maria de Fátima de Sousa Ferreira
Rembrandtstraße 13/3c
1210 Vienna
Austria
Email: fatima@handmadebyfatimaferreira.at
Website: https://www.handmadebyfatimaferreira.at
2. General information
We process personal data only where this is necessary to operate our website, respond to enquiries, process orders, deliver products, meet legal obligations or send communications for which consent has been given.
The applicable legal bases include:
- Article 6(1)(a) GDPR — consent
- Article 6(1)(b) GDPR — steps taken before entering into a contract and performance of a contract
- Article 6(1)(c) GDPR — compliance with legal obligations
- Article 6(1)(f) GDPR — our legitimate interests, particularly the secure and efficient operation of the website, customer communication and the establishment, exercise or defence of legal claims
Where consent is the legal basis, it may be withdrawn at any time with effect for the future.
3. Website hosting and Webflow
This website and its online shop are hosted and operated using Webflow.
When you visit the website, technical data may be processed automatically. This can include:
- IP address
- Date and time of access
- Requested page or file
- Referring page
- Browser and operating-system information
- Device and technical connection information
- Security and server-log information
This processing is necessary to display the website, maintain its security, prevent misuse and ensure technical stability.
Webflow also processes data submitted through contact forms, newsletter forms and the online-shop checkout on our behalf.
Provider:
Webflow, Inc., United States
Privacy information: https://webflow.com/legal/eu-privacy-policy
Data Processing Addendum: https://webflow.com/legal/dpa
The legal basis is Article 6(1)(b) GDPR where processing is necessary to provide requested shop functions and Article 6(1)(f) GDPR for secure and reliable website operation.
Webflow may process information in the United States or through subprocessors in other countries. Webflow states that it uses recognised transfer mechanisms, including the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses, where applicable.
4. Contact enquiries
When you contact us through the website or by email, we process the information you provide, particularly:
- Name
- Email address
- Message content
- Information voluntarily included in the enquiry
We use this information to respond to your enquiry and, where applicable, prepare or perform a contract.
The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a prospective or existing contract. For other enquiries, the legal basis is Article 6(1)(f) GDPR and our legitimate interest in responding to communications addressed to us.
Enquiry data is retained until the enquiry has been resolved and then only for as long as necessary for follow-up communication, legal obligations or the establishment, exercise or defence of legal claims. If the enquiry results in an order or contract, the corresponding contractual retention periods apply.
5. Newsletter
When you subscribe to our newsletter, we process your email address to send information about new products, offers and news concerning Handmade by Fátima Ferreira.
Newsletter subscriptions are collected and stored through Webflow.
The legal basis is your consent under Article 6(1)(a) GDPR and, for electronic marketing communications, Section 174 of the Austrian Telecommunications Act 2021.
Subscription is voluntary. You may withdraw your consent at any time by using the unsubscribe option included in a newsletter or by writing to:
fatima@handmadebyfatimaferreira.at
Withdrawal does not affect the lawfulness of processing performed before withdrawal.
Your email address is retained until you unsubscribe or withdraw your consent. Information necessary to demonstrate that valid consent was obtained may be retained for as long as required to establish, exercise or defend legal claims.
If an external newsletter-delivery provider is introduced, this Privacy Policy will be updated before that provider is used.
6. Orders and online-shop processing
When you place an order through the website, we process the information required to conclude and fulfil the purchase contract. Depending on the information provided and the selected services, this may include:
- Name
- Billing address
- Delivery address
- Email address
- Telephone number, if provided
- Ordered products and quantities
- Order number
- Purchase price and payment status
- Shipping and delivery information
- Communications concerning the order
- Information necessary for returns, refunds, guarantees or complaints
The legal basis is Article 6(1)(b) GDPR. Information required for accounting, taxation and other mandatory records is processed under Article 6(1)(c) GDPR.
Contractual and accounting records are generally retained for seven years in accordance with Austrian statutory retention obligations. Certain information may be retained for longer where necessary for product-liability periods, pending proceedings or the establishment, exercise or defence of legal claims.
7. Payments
We offer payment methods processed through Stripe and PayPal. When you select one of these payment methods, the information required to process and secure the transaction is transmitted to the selected payment provider.
This may include:
- Name and contact information
- Billing information
- Order amount and currency
- Transaction identifiers
- Payment-method information
- IP address and device information
- Information used for fraud prevention, security and regulatory compliance
We do not receive complete card or PayPal login credentials.
Payment processing is necessary to perform the purchase contract under Article 6(1)(b) GDPR. Additional processing by payment providers for fraud prevention, legal compliance and security may be based on their legal obligations and legitimate interests.
Stripe:
Privacy information: https://stripe.com/privacy
PayPal (Europe) S.à r.l. et Cie, S.C.A.:
Privacy information: https://www.paypal.com/de/legalhub/paypal/privacy-full
Stripe and PayPal may act partly as processors and partly as independent controllers for activities such as payment security, fraud prevention, regulatory compliance and dispute handling. Their own privacy notices apply to processing performed under their independent responsibility.
8. Shipping and fulfilment
To prepare and deliver orders, order information is processed through the following workflow:
Webflow → Make → Sendcloud → DPD or Österreichische Post
Make automates the transmission of order information from Webflow to Sendcloud. Sendcloud uses the information to prepare shipping labels, organise delivery and, where enabled, provide shipment tracking.
Depending on what is required for the selected delivery service, the transferred information may include:
- Recipient’s name
- Delivery address
- City, postal code and country
- Email address or telephone number, where required for delivery notifications
- Order or shipment reference
- Parcel information
- Order value where necessary for shipping, insurance or customs processing
Only information required to prepare, perform or document the delivery is transmitted.
The legal basis is Article 6(1)(b) GDPR. Where shipping records must be retained to comply with legal obligations, Article 6(1)(c) GDPR applies.
Service providers:
Make, an automation service provided by the Celonis group
Privacy and GDPR information: https://www.make.com/en/privacy-and-gdpr
Sendcloud B.V., Eindhoven, Netherlands
Privacy information: https://www.sendcloud.com/privacy-policy/
DPD Austria
Österreichische Post AG
The selected carrier receives the information required to deliver the parcel and may process delivery information under its own legal obligations and privacy terms.
9. Cookies and consent management
This website uses cookies and comparable browser technologies.
Technically necessary technologies may be used without consent where they are indispensable for functions expressly requested by the visitor. These functions include website security, shopping-cart operation, checkout, payment processing, fraud prevention and storing privacy preferences.
Non-essential Functional, Analytics or Marketing technologies are activated only after the visitor gives the corresponding consent.
The legal basis for non-essential technologies is Article 6(1)(a) GDPR together with Section 165(3) of the Austrian Telecommunications Act 2021.
We use Concord Technologies, Inc. to manage cookie and privacy choices. Concord stores information concerning the visitor’s consent selection so that the website can respect and document that choice.
Concord privacy and data-protection information:
https://www.concord.tech/legal/data-protection-agreement
Visitors can reject non-essential technologies and can change or withdraw their selection at any time using the permanently accessible “Open Privacy Settings” control.
A current list of detected technologies, providers, purposes and categories is available through the privacy-settings panel.
10. External links and social-media profiles
The website contains links to third-party websites and social-media profiles, including Instagram, Facebook, TikTok and Etsy.
A simple external link does not itself give us access to information about your activities on the destination service. When you click such a link, the destination provider processes your information under its own privacy policy. This may include your IP address, account information and information about your interaction with that service.
We are not responsible for processing performed independently by external websites.
11. Recipients of personal data
Personal data is disclosed only where necessary and may be received by:
- Website and hosting providers
- Technical service providers
- Consent-management providers
- Payment providers
- Automation and shipping-platform providers
- Parcel carriers
- Accounting and tax advisers
- Public authorities where disclosure is legally required
- Legal advisers, courts or insurers where necessary for legal claims
Service providers acting as processors may process personal data only according to our documented instructions and applicable data-protection agreements.
12. International data transfers
Some service providers or their subprocessors may process personal data outside the European Economic Area.
Where a recipient is located in a country for which the European Commission has issued an adequacy decision, the transfer may rely on that decision. In other cases, appropriate safeguards are used where required, such as the European Commission’s Standard Contractual Clauses and supplementary contractual or technical measures.
Further information about the applicable safeguards may be requested using the contact information in Section 1.
13. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected and as required by applicable legal obligations.
In particular:
- Contact enquiries are retained until resolved and, where necessary, for applicable claim periods.
- Newsletter data is retained until consent is withdrawn or the subscription ends.
- Order, invoice and accounting records are generally retained for seven years.
- Information necessary for product-liability documentation may be retained for up to ten years.
- Consent records may be retained for as long as necessary to demonstrate compliance.
- Data may be retained for longer when required for ongoing legal, administrative or judicial proceedings.
After the applicable purpose and retention period end, the information is deleted or anonymised unless further retention is legally required.
14. Your rights
Subject to the conditions of the GDPR, you have the right to:
- Obtain information about whether and how your personal data is processed
- Receive a copy of your personal data
- Request correction of inaccurate or incomplete information
- Request deletion of personal data
- Request restriction of processing
- Receive data you provided in a portable format
- Object to processing based on legitimate interests
- Withdraw consent at any time with effect for the future
- Lodge a complaint with a data-protection supervisory authority
Requests can be sent to:
fatima@handmadebyfatimaferreira.at
We may request appropriate information to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at
15. Automated decisions
We do not independently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects.
Payment providers may use automated systems for fraud prevention, payment-risk assessment and compliance purposes under their own responsibility. Further information is available in the respective provider’s privacy notice.
16. Security
We take appropriate organisational and technical measures to protect personal data against accidental or unlawful loss, alteration, disclosure, access or destruction.
No internet transmission or electronic-storage system can be guaranteed to be completely secure.
17. Changes to this Privacy Policy
We may update this Privacy Policy when legal requirements, website functions or service providers change.
The current version and its update date will always be published on this page.
