Privacy Policy
Last updated: November 17, 2025
1. Data Controller
The data controller responsible for processing your personal data is:
Simon Plieseis
Eva-Maria-Mazzucco-Platz 2
1220 Wien, Austria
Phone: +43 660 9518389
Email: [email protected]
VAT ID: ATU80348205
2. Overview
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website and services. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and Austrian data protection laws.
3. Types of Personal Data We Collect
We may collect the following types of personal data:
3.1 Data You Provide to Us
- Contact Information: Name, email address, phone number (if provided)
- Order Information: Child's name, song preferences, theme selections, custom lyrics or instructions
- Payment Information: Processed securely through Stripe (we do not store full payment card details)
- Communication Data: Messages, feedback, or correspondence you send to us
3.2 Automatically Collected Data
- Technical Data: IP address, browser type and version, device information, operating system
- Usage Data: Pages visited, time spent on pages, click patterns, referring website
- Cookies and Similar Technologies: See section 8 for details
4. Purpose and Legal Basis for Processing
We process your personal data for the following purposes and legal bases:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Processing and fulfilling your orders | Article 6(1)(b) - Contract performance |
| Processing payments | Article 6(1)(b) - Contract performance |
| Communicating with you about your order | Article 6(1)(b) - Contract performance |
| Responding to inquiries and support requests | Article 6(1)(f) - Legitimate interests |
| Improving our website and services | Article 6(1)(f) - Legitimate interests |
| Compliance with legal obligations | Article 6(1)(c) - Legal obligation |
| Marketing communications (with consent) | Article 6(1)(a) - Consent |
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Order Data: Retained for 7 years from the date of purchase (as required by Austrian tax and commercial law)
- Customer Communications: Retained for 3 years after the last communication
- Marketing Data: Retained until you withdraw consent or opt-out
- Technical/Log Data: Retained for 12 months
6. Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of Access (Article 15): You can request a copy of the personal data we hold about you.
- Right to Rectification (Article 16): You can request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17): You can request deletion of your personal data under certain circumstances.
- Right to Restrict Processing (Article 18): You can request limitation of how we process your data.
- Right to Data Portability (Article 20): You can request transfer of your data to another service provider.
- Right to Object (Article 21): You can object to processing based on legitimate interests.
- Right to Withdraw Consent (Article 7): Where processing is based on consent, you can withdraw it at any time.
- Right to Lodge a Complaint (Article 77): You have the right to file a complaint with the Austrian Data Protection Authority.
To exercise any of these rights, please contact us at:
Email: [email protected]
We will respond to your request within one month.
7. Data Sharing and Third-Party Services
We may share your personal data with the following third parties:
7.1 Payment Processing
We use Stripe to process payments. Stripe collects and processes payment information in accordance with their privacy policy. We do not store your full payment card details.
Stripe's Privacy Policy: https://stripe.com/privacy
7.2 Hosting and Infrastructure
Our website is hosted on third-party servers. These service providers act as data processors and are bound by contractual obligations to protect your data.
7.3 Legal Requirements
We may disclose your personal data if required by law, court order, or governmental authority, or to protect our rights, property, or safety.
8. Cookies and Tracking Technologies
Our website may use cookies and similar tracking technologies to enhance your experience. Cookies are small text files stored on your device.
We use cookies for:
- Essential website functionality
- Analytics and website performance monitoring
- Remembering your preferences
You can control cookies through your browser settings. However, disabling certain cookies may affect website functionality.
9. International Data Transfers
Some of our service providers may be located outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Other appropriate safeguards as required by GDPR
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (HTTPS/TLS)
- Secure payment processing through Stripe
- Regular security assessments
- Access controls and authentication
11. Children's Data
Our services involve creating personalized songs for children. We collect minimal information about children (such as names) only as provided by parents or guardians. We do not knowingly collect personal data directly from children under 16 without parental consent.
If you are a parent or guardian and believe we have collected information about your child without consent, please contact us immediately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
13. Contact Information and Complaints
If you have questions, concerns, or wish to exercise your rights regarding this Privacy Policy or our data practices, please contact us:
Simon Plieseis
Eva-Maria-Mazzucco-Platz 2
1220 Wien, Austria
Phone: +43 660 9518389
Email: [email protected]
VAT ID: ATU80348205
Right to Lodge a Complaint: If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde):
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Wien, Austria
Website: www.dsb.gv.at
Email: [email protected]