Privacy Policy
Preamble
This Privacy Policy explains what types of personal data we process, for what purposes, and to what extent. It applies to all processing of personal data carried out in connection with the provision of our services and, in particular, on our website and social media profiles (collectively referred to as the "online offering").
Last updated: 9 July 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Legal Bases
- Security Measures
- Data Retention and Deletion
- Rights of Data Subjects
- Business Services
- Payment Processing
- Hosting
- Contact and Enquiry Management
- Marketing Communication
- Social Media
- Changes to this Policy
- Definitions
Controller
Simon Duhatschek
Mansio Studio
Römerweg 38
71083 Herrenberg
Germany
Email: contact@mansiostudio.com
Legal Notice: https://mansiostudio.com/impressum
Overview of Processing Activities
Types of Data Processed
- Master data
- Payment data
- Contact data
- Content data
- Contract data
- Usage data
- Meta, communication and process data
- Log data
Categories of Data Subjects
- Service recipients and clients
- Prospective customers
- Communication partners
- Users
- Business and contractual partners
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations
- Communication
- Security measures
- Direct marketing
- Provision of our online offering and user experience
- IT infrastructure
- Public relations
- Sales promotion
- Business processes and operations
Legal Bases
Legal bases under the GDPR: The following is an overview of the legal bases under the GDPR on which we process personal data.
- Consent (Art. 6(1)(a) GDPR) — The data subject has given consent to the processing of their personal data.
- Performance of a contract (Art. 6(1)(b) GDPR) — Processing is necessary for the performance of a contract or to take pre-contractual steps.
- Legal obligation (Art. 6(1)(c) GDPR) — Processing is necessary for compliance with a legal obligation.
- Legitimate interests (Art. 6(1)(f) GDPR) — Processing is necessary for the purposes of legitimate interests pursued by the controller.
German data protection law: In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (BDSG).
Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
TLS/SSL encryption (HTTPS): Our website is secured with an SSL/TLS certificate. Data transmitted between your browser and our server is always encrypted.
Data Retention and Deletion
We delete personal data in accordance with legal requirements once the underlying consent is withdrawn or no further legal basis for processing exists.
Statutory retention periods under German law:
- 10 years — books, records, annual financial statements (§ 147 AO, § 257 HGB)
- 8 years — accounting vouchers, invoices (§ 147 AO, § 257 HGB)
- 6 years — other business documents and correspondence (§ 147 AO, § 257 HGB)
- 3 years — contract-related data (§§ 195, 199 BGB)
Rights of Data Subjects
As a data subject under the GDPR, you have the following rights:
- Right to object
- Right to withdraw consent
- Right of access
- Right to rectification
- Right to erasure and restriction of processing
- Right to data portability
- Right to lodge a complaint with a supervisory authority: The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Business Services
We process personal data of our contractual and business partners in order to initiate, perform, and conclude contractual relationships.
- Types of data processed: Master data; payment data; contact data; contract data; usage data; meta, communication and process data.
- Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
- Purposes: Provision of contractual services; communication; business processes and operations.
- Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Payment Processing
We offer efficient and secure payment options as part of our contractual relationships. All payment transactions are carried out exclusively via encrypted connections.
Data processed by payment service providers includes master data, banking data, and contract and transaction details. We do not receive account or credit card information — only payment confirmation.
- Types of data processed: Master data; payment data; contract data; meta, communication and process data.
- Data subjects: Service recipients and clients; business and contractual partners.
- Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Services used:
- Paddle (Merchant of Record): We use Paddle as our Merchant of Record for payment processing. Paddle acts as the legal seller to our customers and handles all international tax compliance. Payment data is transmitted directly to Paddle and is not stored by us. Provider: Paddle.com Market Limited, 15 Ingestre Place, Soho, London W1F 0JH, United Kingdom; Website: https://www.paddle.com; Privacy Policy: https://www.paddle.com/legal/privacy.
Hosting
We process user data in order to provide our online services. For this purpose, we process the user's IP address.
- Types of data processed: Usage data; meta, communication and process data; log data.
- Data subjects: Users.
- Purposes: Provision of our online offering; IT infrastructure; security measures.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Services used:
- Vercel (Web Hosting and CDN): Our online offering is hosted on Vercel's servers and delivered via Vercel's integrated content delivery network. Connection data such as IP addresses and server log files may be processed by Vercel. Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA; Website: https://vercel.com; Privacy Policy: https://vercel.com/legal/privacy-policy. Basis for third-country transfer: Standard Contractual Clauses (SCCs).
- Server log files: Access to our online offering is logged in the form of server log files. Log file information is stored for a maximum of 30 days and then deleted or anonymised. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
Contact and Enquiry Management
When you contact us (e.g. by email or via social media), the information provided by the enquiring party is processed to the extent necessary to respond to the enquiry.
- Types of data processed: Contact data; content data.
- Data subjects: Communication partners.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Marketing Communication
We process personal data for the purposes of marketing communication, which may take place via various channels such as email, in accordance with legal requirements.
Recipients have the right to object to marketing communication at any time, free of charge.
- Types of data processed: Master data; contact data.
- Data subjects: Communication partners.
- Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Social Media
We maintain online presences on social networks and process user data in this context in order to communicate with users or provide information about us.
- Instagram: Social network. Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfer: Data Privacy Framework (DPF).
Changes to this Policy
We encourage you to review this Privacy Policy regularly. We update it whenever changes to our data processing activities make this necessary.
Definitions
- Personal data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on personal data, such as collection, storage, transmission, or deletion.
- Controller: The natural or legal person who determines the purposes and means of the processing of personal data.
- Processor: A natural or legal person who processes personal data on behalf of the controller.