Privacy policy
⚠ This page is not complete: the company details are missing. It must not be publicly reachable in this state.
LEGAL_ENTITY_VAT
Who is responsible for your data
Amberro — Damian Hooft, Melkeppe 36, 2498 CW Den Haag, Nederland. Email: kontakt@amberro.de.
We have not appointed a data protection officer; at this size that is not required under Art. 37 GDPR.
What we process, why, and on what basis
The child's photograph. You upload a photo so that the pictures in the book can be drawn from it. The legal basis is Art. 6(1)(b) GDPR — the processing is necessary to perform the contract, because the photo is the input to the product. We do not rely on consent for this, because a consent withdrawn mid-production would make the book impossible.
The photo first becomes one drawn character. Every other page is drawn from that character, not from the photo again.
The child's name, age and pronoun. For the text of the book. Art. 6(1)(b) GDPR.
Your email address. So we can send you the book and the order confirmation. Art. 6(1)(b) GDPR.
Payment data. We never see or store card details. Payment runs through our payment provider; we receive only the fact that payment was made, and a reference.
Server logs. Technical log data arises when the site is called up. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in secure operation.
Who else sees the data
We use service providers who process on our behalf (Art. 28 GDPR):
- the provider that draws the pictures and the provider that writes the text
- the storage service that holds the photo and the finished book
- the service that sends our email
- the payment provider, which acts as its own controller
Transfers outside the EU. Some of these providers process outside the European Economic Area. This takes place on the basis of the European Commission's standard contractual clauses or an adequacy decision.
We do not sell data and we pass nothing on for third-party advertising.
No facial recognition
We do not compare the photo against other photos or against any database, and we do not create biometric templates for the unique identification of a person. No automated decision within the meaning of Art. 22 GDPR takes place.
How long we keep things
The uploaded photo is removed from the upload area when the order is created and belongs from then on only to that one order. We keep the order, the photo and the book for as long as is necessary to perform the contract and to answer questions about it. Statutory retention periods apply to invoicing records.
You can ask us to delete it at any time — an email to kontakt@amberro.de is enough. We then delete the photo and the book. Invoicing data has to be kept until the statutory periods expire.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Write to kontakt@amberro.de.
You may also complain to a data protection supervisory authority.
Cookies
We set only technically necessary cookies. There are no advertising cookies and no third-party tracking.
Reviewed by a lawyer: not yet. This page is confirmed by a lawyer before anything goes on sale.