
AUREIR processes personal data to the smallest extent possible. This notice describes which data is processed when visiting the website, for what purpose, and on what legal basis.
Controller.
Website Operation and Logfiles.
When the website is accessed, technically necessary access data is processed in order to deliver the website, ensure stability, and detect attacks or malfunctions.
- IP address
- date and time of the request
- requested URL and volume of data transmitted
- referrer, browser, operating system, and device data
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable, and technically error-free operation of the website. Technical runtime logs are stored for no more than 30 days, depending on the active hosting plan, and are then deleted. They are retained for longer only where required to investigate a specific security incident or malfunction or to pursue legal claims.
Web Analytics and Performance Measurement.
Vercel Web Analytics and Speed Insights process usage and performance data to evaluate page views and measure technical loading and response times. This may include the time and path of the request, referrer, approximate location, browser, operating system, and device type. URL parameters and fragments are removed before transmission. The data is evaluated as aggregated statistics on website usage and technical performance.
Vercel Web Analytics does not set third-party cookies. Page views are not linked to a person or IP address; an identifier generated from the request is discarded after 24 hours. Measurement is not used for advertising, profiling, or cross-site marketing tracking. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in measuring reach and improving the website's technical operation.
Browser Storage.
The shopping cart may be stored in the browser on the device used.
The data remains stored in the browser of the device used until it is removed by the browser, by the user, or by cart logic. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in providing functional cart and reservation behavior.
Contact.
When contact is made by email or telephone, the information provided is processed insofar as this is necessary to respond to the request. This may include name, contact details, the content of the message, and technical communication data.
The legal basis is Art. 6(1)(b) GDPR if the request is related to a contract or pre-contractual measures. In all other cases, the legal basis is Art. 6(1)(f) GDPR. Requests are deleted once they have been fully handled unless contractual, statutory, or evidentiary reasons require further retention.
AUREIR Journal.
For AUREIR Journal signups, AUREIR processes data required to register, confirm, and manage the subscription. The Journal is sent irregularly and provides information about new editions, availability, exhibitions, and events.
Processed data includes email address, selected language, signup source, an optional reference to an object of interest, and information required to confirm the signup and manage unsubscribe requests.
Signup uses a double opt-in process. After entry, a confirmation email is sent. The subscription is marked as confirmed only after confirmation.
Unsubscription is possible through the unsubscribe link. The unsubscription is stored so that no further Journal emails are sent.
Unconfirmed signups are deleted after seven days. Confirmed and unsubscribed records are retained for subscription management and suppression until deletion is requested or a legal reason for further storage exists.
The legal basis for Journal signup is Art. 6(1)(a) GDPR. Technical administration and proof of signup are additionally based on Art. 6(1)(f) GDPR.
Contract, Checkout, and Payment.
To prepare and process orders, AUREIR processes the personal data required for the order, delivery, payment, and contract administration.
Stripe Checkout may be used for payment processing. Payment takes place on a payment page provided by Stripe.
In particular, the following data may be processed:
- name, email address, billing address, and shipping address
- cart, products, variants, exemplars, and order amount
- payment data at Stripe
- order and payment status as well as payment and invoice references
Stripe processes payment data according to its own privacy and processing terms. The legal basis for processing and transmitting the data required for the order and payment is Art. 6(1)(b) GDPR. Information marked as required during checkout is necessary to conclude the contract; the order cannot be completed without it.
Inventory and Reservations.
For limited AUREIR objects, availability may be checked and a temporary reservation may be used.
Processing serves availability management during the purchase process. The legal basis is Art. 6(1)(b) GDPR where processing is required for pre-contractual steps or contract performance, and otherwise Art. 6(1)(f) GDPR.
Withdrawal Form.
When the electronic withdrawal form is used, AUREIR processes the data entered there to receive, document, and handle the withdrawal and to send the statutory electronic confirmation of receipt.
Processing is carried out for the performance of the contract and compliance with legal obligations on the basis of Art. 6(1)(b) and (c) GDPR. Where further retention is necessary for the establishment, exercise, or defence of legal claims, it is based on Art. 6(1)(f) GDPR. The service providers named in the “Third-party Providers and Processors” section are used for storage and email delivery.
Third-party Providers and Processors.
The following service providers are used to provide the website and process individual functions.
Where data is transferred to the United States, transfers to appropriately certified recipients are based on the adequacy decision for the EU-US Data Privacy Framework pursuant to Art. 45 GDPR. Where that framework does not apply, the European Commission's Standard Contractual Clauses are agreed pursuant to Art. 46 GDPR. Information about these safeguards or a copy may be requested using the contact details above.
| Provider | Processing |
|---|---|
| Vercel |
|
| Strato |
|
| Supabase |
|
| Upstash |
|
| Resend |
|
| Stripe |
|
Fonts.
The website uses fonts that are delivered locally via the same domain. When the website is accessed, no connection is made to external font providers.
Storage Periods.
- Cart data in the browser remains stored until it is removed by the browser, by the user, or by cart logic.
- Technical runtime logs are stored for no more than 30 days, depending on the active hosting plan. Data relating to a specific security incident or malfunction may be retained until the matter has been fully handled and, where necessary, for longer to pursue legal claims.
- IP addresses used to limit request frequency are deleted automatically after the applicable technical window expires; the longest current period is approximately 21 minutes.
- Contact requests are deleted once they have been fully handled unless contractual, statutory, or evidentiary reasons require further retention.
- Unconfirmed Journal signups are deleted after seven days.
- Confirmed and unsubscribed Journal records are retained for subscription management and suppression until deletion is requested or a legal reason for further storage exists.
- Records from the withdrawal form and copies of the confirmations of receipt sent are generally retained for six years from the end of the calendar year in which they were received. They are retained for longer only where required by legal obligations or to handle an ongoing legal matter.
- Order and contract data is stored for contract performance and subsequently for statutory retention periods. Commercial and business correspondence is generally retained for six years, and invoices and accounting records for eight years, in each case from the end of the relevant calendar year.
- Reservation data is processed for the duration of the temporary reservation; expired or cancelled reservations may be released.
Rights of data subjects.
Under the GDPR, data subjects have the following rights in particular:
- right of access under Art. 15 GDPR
- right to rectification under Art. 16 GDPR
- right to erasure under Art. 17 GDPR
- right to restriction of processing under Art. 18 GDPR
- right to data portability under Art. 20 GDPR
- right to object under Art. 21 GDPR
- right to withdraw consent granted under Art. 7(3) GDPR
To exercise these rights, an informal notice to contact@aureir.com is sufficient.
Right to lodge a complaint.
Data subjects have the right to lodge a complaint with a data protection supervisory authority regarding the processing of personal data. In particular, the Saxon Commissioner for Data Protection and Transparency, Maternistraße 17, 01067 Dresden, Germany, is competent.