
Privacy Policy
Last updated: 14.11.2025
1. Data Controller
The controller responsible for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:
Bow Studio Books
[Insert full business address]
Email: hello@bowstudiobooks.com
Website: www.bowstudiobooks.com
2. General Information on Data Processing
(1) We process personal data only to the extent necessary to provide a functional website, process orders, and deliver our products and services.
(2) “Personal data” means any information relating to an identified or identifiable natural person (Art. 4 (1) GDPR).
(3) The processing of personal data takes place on the basis of the GDPR, the BDSG, and other applicable legal provisions.
3. Categories of Data Processed
We may process the following categories of data:
-
Identification data (first and last name, address, email address, phone number)
-
Contract data (purchased products, order number, invoice details)
-
Payment data (payment method, transaction ID, billing information)
-
Communication data (messages, correspondence)
-
Technical data (IP address, device type, browser information, access times, cookies, analytics data)
4. Purpose and Legal Basis of Processing
(a) Contract Performance (Art. 6 (1)(b) GDPR)
Data is processed to conclude and perform purchase contracts, including order management, delivery, invoicing, and customer service.
(b) Legal Obligations (Art. 6 (1)(c) GDPR)
We may process data to comply with tax, accounting, and commercial-law requirements.
(c) Legitimate Interests (Art. 6 (1)(f) GDPR)
We process limited technical data (e.g., analytics, IP logs) to maintain the security, functionality, and optimization of our website.
(d) Consent (Art. 6 (1)(a) GDPR)
If you subscribe to our newsletter or allow cookies and analytics, processing is based on your explicit consent, which can be withdrawn at any time.
5. Data Collection on Our Website
(a) Server Log Files
When you visit our website, our hosting provider automatically collects information such as IP address, browser type, referrer URL, and time of access.
This data is required for technical delivery and system security. It is not merged with other data sources.
(b) Contact Form and Email
If you contact us by form or email, your inquiry and related data are processed for the purpose of responding to your request.
Legal basis: Art. 6 (1)(b) GDPR (contract initiation) or Art. 6 (1)(f) GDPR (legitimate interest).
(c) Newsletter
You can voluntarily subscribe to our newsletter. We use a double-opt-in process to verify your consent.
Your data (email address, name if provided) is used solely for sending newsletters and can be deleted upon withdrawal of consent.
(d) Orders and Account Registration
When placing an order or creating an account, we collect necessary information (name, address, email, payment data) to process your purchase and deliver products.
6. Payment Processing
Payments are handled via third-party providers such as Stripe, PayPal, or Wix Payments.
These providers process payment data under their own responsibility and in compliance with the GDPR.
Legal basis: Art. 6 (1)(b) GDPR (contract performance).
We do not store complete payment card details on our servers.
7. Cookies and Tracking Technologies
(1) We use cookies to ensure technical functionality and analyze usage patterns. Cookies are small text files stored on your device.
(2) Necessary cookies are required for the website to function (Art. 6 (1)(f) GDPR).
Analytics and marketing cookies are used only with your consent (Art. 6 (1)(a) GDPR).
(3) You can withdraw consent or disable cookies in your browser settings at any time.
8. Analytics and Third-Party Tools
We may use services such as Google Analytics, Wix Analytics, or equivalent tools to evaluate website usage.
These tools use cookies and transmit pseudonymized data to servers, possibly outside the EU.
Google LLC and other providers are certified under the EU–U.S. Data Privacy Framework, ensuring an adequate level of protection.
Legal basis: Art. 6 (1)(a) GDPR (consent).
You may withdraw consent at any time with future effect.
9. Data Sharing and Recipients
We share personal data only as necessary for the purposes described above:
-
Payment processors (Stripe, PayPal)
-
Email and newsletter providers (e.g., Mailchimp, Wix Email Marketing)
-
Cloud storage and IT service providers (Wix.com Ltd., Google Workspace)
-
Shipping carriers for physical goods (DHL, Deutsche Post, etc.)
All processors are bound by data-processing agreements under Art. 28 GDPR and act solely on our instructions.
10. Data Retention
(1) We store personal data only as long as required for contractual performance, legal retention periods, or legitimate business purposes.
(2) Data related to tax or commercial obligations is retained for up to 10 years in accordance with Sections 147 AO and 257 HGB.
(3) After expiration of the relevant periods, the data is deleted or anonymized.
11. Data Transfers Outside the EU / EEA
If we transfer data to processors located outside the European Economic Area, such transfer takes place only under the conditions of Art. 44 ff. GDPR (adequacy decision, standard contractual clauses, or other safeguards).
12. Data Subject Rights
Under the GDPR, you have the following rights:
-
Right of access (Art. 15 GDPR)
-
Right to rectification (Art. 16 GDPR)
-
Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
-
Right to restriction of processing (Art. 18 GDPR)
-
Right to data portability (Art. 20 GDPR)
-
Right to object (Art. 21 GDPR)
-
Right to withdraw consent (Art. 7 (3) GDPR)
To exercise these rights, contact us at hello@bowstudiobooks.com.
We may require verification of your identity before fulfilling a request.
13. Security of Your Data
We use technical and organizational measures to protect data against unauthorized access, loss, alteration, or destruction.
All data transmission between your browser and our website is secured via SSL/TLS encryption.
14. Automated Decision-Making / Profiling
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
15. Links to Other Websites
Our website may contain links to third-party websites.
We are not responsible for the content or data-protection practices of such websites.
Please review their privacy policies separately.
16. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal or technical changes.
The latest version is always available at www.bowstudiobooks.com/privacy-policy.
17. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular the State Data Protection Authority of Berlin or the authority of your habitual residence (Art. 77 GDPR), if you believe that your personal data is being processed unlawfully.
18. Contact
If you have any questions or requests regarding this Privacy Policy or the processing of your personal data, please contact:
Bow Studio Books
Email: hello@bowstudiobooks.com
Website: www.bowstudiobooks.com
© Bow Studio Books – All rights reserved.
