← Back

Privacy Policy

Preamble

This Privacy Policy explains what types of personal data we process, for what purposes, and to what extent. It applies to all processing of personal data carried out in connection with the provision of our services and, in particular, on our website and social media profiles (collectively referred to as the "online offering").

Last updated: 9 July 2026

Table of Contents

Controller

Simon Duhatschek
Mansio Studio
Römerweg 38
71083 Herrenberg
Germany

Email: contact@mansiostudio.com

Legal Notice: https://mansiostudio.com/impressum

Overview of Processing Activities

Types of Data Processed

  • Master data
  • Payment data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication and process data
  • Log data

Categories of Data Subjects

  • Service recipients and clients
  • Prospective customers
  • Communication partners
  • Users
  • Business and contractual partners

Purposes of Processing

  • Provision of contractual services and fulfilment of contractual obligations
  • Communication
  • Security measures
  • Direct marketing
  • Provision of our online offering and user experience
  • IT infrastructure
  • Public relations
  • Sales promotion
  • Business processes and operations

Legal Bases

Legal bases under the GDPR: The following is an overview of the legal bases under the GDPR on which we process personal data.

  • Consent (Art. 6(1)(a) GDPR) — The data subject has given consent to the processing of their personal data.
  • Performance of a contract (Art. 6(1)(b) GDPR) — Processing is necessary for the performance of a contract or to take pre-contractual steps.
  • Legal obligation (Art. 6(1)(c) GDPR) — Processing is necessary for compliance with a legal obligation.
  • Legitimate interests (Art. 6(1)(f) GDPR) — Processing is necessary for the purposes of legitimate interests pursued by the controller.

German data protection law: In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (BDSG).

Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

TLS/SSL encryption (HTTPS): Our website is secured with an SSL/TLS certificate. Data transmitted between your browser and our server is always encrypted.

Data Retention and Deletion

We delete personal data in accordance with legal requirements once the underlying consent is withdrawn or no further legal basis for processing exists.

Statutory retention periods under German law:

  • 10 years — books, records, annual financial statements (§ 147 AO, § 257 HGB)
  • 8 years — accounting vouchers, invoices (§ 147 AO, § 257 HGB)
  • 6 years — other business documents and correspondence (§ 147 AO, § 257 HGB)
  • 3 years — contract-related data (§§ 195, 199 BGB)

Rights of Data Subjects

As a data subject under the GDPR, you have the following rights:

  • Right to object
  • Right to withdraw consent
  • Right of access
  • Right to rectification
  • Right to erasure and restriction of processing
  • Right to data portability
  • Right to lodge a complaint with a supervisory authority: The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany

Business Services

We process personal data of our contractual and business partners in order to initiate, perform, and conclude contractual relationships.

  • Types of data processed: Master data; payment data; contact data; contract data; usage data; meta, communication and process data.
  • Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
  • Purposes: Provision of contractual services; communication; business processes and operations.
  • Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Payment Processing

We offer efficient and secure payment options as part of our contractual relationships. All payment transactions are carried out exclusively via encrypted connections.

Data processed by payment service providers includes master data, banking data, and contract and transaction details. We do not receive account or credit card information — only payment confirmation.

  • Types of data processed: Master data; payment data; contract data; meta, communication and process data.
  • Data subjects: Service recipients and clients; business and contractual partners.
  • Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Services used:

  • Paddle (Merchant of Record): We use Paddle as our Merchant of Record for payment processing. Paddle acts as the legal seller to our customers and handles all international tax compliance. Payment data is transmitted directly to Paddle and is not stored by us. Provider: Paddle.com Market Limited, 15 Ingestre Place, Soho, London W1F 0JH, United Kingdom; Website: https://www.paddle.com; Privacy Policy: https://www.paddle.com/legal/privacy.

Hosting

We process user data in order to provide our online services. For this purpose, we process the user's IP address.

  • Types of data processed: Usage data; meta, communication and process data; log data.
  • Data subjects: Users.
  • Purposes: Provision of our online offering; IT infrastructure; security measures.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Services used:

  • Vercel (Web Hosting and CDN): Our online offering is hosted on Vercel's servers and delivered via Vercel's integrated content delivery network. Connection data such as IP addresses and server log files may be processed by Vercel. Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA; Website: https://vercel.com; Privacy Policy: https://vercel.com/legal/privacy-policy. Basis for third-country transfer: Standard Contractual Clauses (SCCs).
  • Server log files: Access to our online offering is logged in the form of server log files. Log file information is stored for a maximum of 30 days and then deleted or anonymised. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).

Contact and Enquiry Management

When you contact us (e.g. by email or via social media), the information provided by the enquiring party is processed to the extent necessary to respond to the enquiry.

  • Types of data processed: Contact data; content data.
  • Data subjects: Communication partners.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Marketing Communication

We process personal data for the purposes of marketing communication, which may take place via various channels such as email, in accordance with legal requirements.

Recipients have the right to object to marketing communication at any time, free of charge.

  • Types of data processed: Master data; contact data.
  • Data subjects: Communication partners.
  • Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Social Media

We maintain online presences on social networks and process user data in this context in order to communicate with users or provide information about us.

Changes to this Policy

We encourage you to review this Privacy Policy regularly. We update it whenever changes to our data processing activities make this necessary.

Definitions

  • Personal data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data, such as collection, storage, transmission, or deletion.
  • Controller: The natural or legal person who determines the purposes and means of the processing of personal data.
  • Processor: A natural or legal person who processes personal data on behalf of the controller.