Free shipping within Germany on orders over €230

Skip to content
Obsidian Studio
← Obsidian Studio
Customer Archive — DOCUMENT 03

Privacy Policy

§1 Controller

The controller responsible for the processing of personal data through the Obsidian Studio online shop, available at the domain obsidianjewels.com, is:

Natalia Mikulska-Yildirim
Graf-Wilhelm-Straße 28
89613 Oberstadion
Baden-Württemberg
Germany

E-mail: info@obsidianjewels.com
WhatsApp: +49 151 68581336 (written contact only)

The controller is a natural person operating a business under the Obsidian Studio brand. There is no obligation to appoint a data protection officer and none has been appointed. On all data protection matters you may contact the controller directly at the e-mail address stated above.

§2 Scope of this Privacy Policy

This Privacy Policy sets out how personal data is processed for people using the Obsidian Studio online shop at the domain obsidianjewels.com, in particular people who

  • visit the website,

  • contact the Seller,

  • use the contact form,

  • use contact channels such as e-mail or WhatsApp,

  • visit the Seller's social media profiles,

  • place orders,

  • use other functions available on the website.

The shop does not operate a newsletter and does not offer customer accounts.

§3 Legal bases for processing

Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR) and with the relevant provisions of German law.

Depending on the purpose of processing, the legal basis may be:

  • Article 6(1)(b) GDPR – performance of a contract or steps taken prior to entering into a contract,

  • Article 6(1)(a) GDPR – consent of the data subject,

  • Article 6(1)(c) GDPR – compliance with a legal obligation of the controller, in particular tax and accounting obligations under German law,

  • Article 6(1)(f) GDPR – legitimate interests of the controller.

§4 Categories of data processed

Depending on how the website and services are used, the controller may process the following categories of data:

  • first and last name,

  • e-mail address,

  • telephone number,

  • billing and delivery address,

  • the content of messages sent through the contact form, by e-mail or via WhatsApp,

  • order-related data,

  • technical data such as IP address, information about the device, browser and activity on the website,

  • the shortened (hashed) IP address of the person using the contact form,

  • browser language and the address of the subpage from which the message was sent,

  • data arising from the use of social media profiles and from contact through those channels.

§5 Hosting, technical infrastructure and website security

The Obsidian Studio online shop is a bespoke web application built and maintained by the controller. The website was not created using a website builder.

The website is hosted on a server provided by Hostinger, located within the European Union, in Frankfurt am Main (Germany). The shop's domain is also registered with Hostinger, which additionally provides the shop's email mailboxes.

The shop's data — including order data, customer addresses, contact form messages and product photographs — is held in a database and file storage provided by Supabase. The servers on which this data is stored are located within the European Union, in the Frankfurt am Main region (Germany).

In connection with the use of hosting and technical infrastructure, the providers of these services may process technical data necessary to ensure the correct operation of the website, the security of the systems and the detection of abuse, in particular:

  • IP address,

  • date and time of access,

  • information about the web browser,

  • information about the operating system,

  • the URL of the referring page,

  • technical data relating to errors and security.

The legal basis for processing this data is Article 6(1)(f) GDPR, namely the controller's legitimate interest in the security, stability and correct functioning of the website.

The fonts used on the website are embedded directly on the controller's server. Your browser does not connect to third-party servers in order to retrieve them.

§6 Website analytics

The controller uses Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics is used to produce statistics on visits and on how the website is used, allowing the controller to develop the shop and improve its operation. This tool may process data such as the shortened IP address, information about the device and browser, the subpages visited, the duration of the visit and the source of the visit.

Google Analytics scripts are loaded only after prior consent has been given in the consent banner, in the "Analytics" category. Until consent is given, your browser establishes no connection whatsoever with Google servers.

The legal basis for processing is Article 6(1)(a) GDPR, namely consent. Consent may be withdrawn at any time in the consent settings available on the website, with effect for the future.

§7 Contact form

You may contact the controller using the contact form available on the website.

When the contact form is used, the following data is processed:

  • full name,

  • e-mail address,

  • subject of the message,

  • content of the message,

  • any other data you voluntarily provide in the body of the message.

Together with the message, the following technical data is also stored to protect the form against abuse and automated messages:

  • a cryptographic hash (SHA-256) of the sender's IP address — the IP address itself is not stored,

  • the browser language in which the message was sent,

  • the address of the subpage from which the message was sent.

Data from the form is processed in order to handle the enquiry, conduct correspondence and provide a reply. The technical data listed above is processed solely to detect and limit abuse.

The legal basis for processing is:

  • Article 6(1)(b) GDPR – where the contact concerns the conclusion or performance of a contract,

  • Article 6(1)(f) GDPR – where the contact is of a general nature and serves to handle correspondence, and in respect of protecting the form against abuse.

§8 Contact by e-mail and WhatsApp

The controller allows contact by e-mail and via WhatsApp.

Contact via WhatsApp is an additional and voluntary channel of communication. Using this channel may involve processing of data by the provider of the WhatsApp service in accordance with its own privacy rules. We recommend that you do not send particularly sensitive data, or information required to process an order, via WhatsApp where communication by e-mail or through the contact form is possible.

Where contact is made by e-mail or via WhatsApp, the following data may be processed:

  • first and last name,

  • telephone number,

  • e-mail address,

  • content of the message,

  • other data voluntarily provided.

The data is processed solely in order to conduct communication, handle the enquiry and, where applicable, take steps prior to entering into a contract.

The legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR, depending on the nature of the contact.

§9 Orders and performance of the contract

In connection with the placing and processing of orders, the controller processes the data necessary to conclude and perform the contract of sale.

The scope of data may include in particular:

  • first and last name,

  • delivery address,

  • billing address,

  • e-mail address,

  • telephone number, if provided,

  • data concerning the objects ordered,

  • payment data to the extent necessary to carry out the transaction.

Order-related messages — the order confirmation sent once payment has been received, dispatch notifications and sales documents — are sent by e-mail through the e-mail delivery provider named in §14.

Together with the order confirmation, the customer receives an individual link allowing them to view the order status. The link contains a unique identifier and requires neither a customer account nor a login.

Providing the data is voluntary but necessary in order to conclude and perform the contract of sale.

The legal basis is Article 6(1)(b) GDPR and, as regards tax and accounting records, Article 6(1)(c) GDPR.

§10 Payments

Payments in the shop are handled through the payment provider Stripe (Stripe Payments Europe, Limited, Ireland). To pay, the Customer is redirected to a payment page provided by Stripe.

In order to carry out the payment, the data necessary for the transaction is transmitted to Stripe, in particular e-mail address, order number, ordered objects, delivery costs and amount due. The Customer enters their name and payment details directly on Stripe's payment page. The payment methods available for a given order are shown during the ordering process; depending on the country, device and order value, these may include in particular credit and debit cards, Apple Pay, Google Pay, Link, Klarna and payment methods customary in the respective country, such as iDEAL, Bancontact, EPS, Satispay or MB WAY.

The scope of the data transmitted is limited to what is necessary to carry out the payment. Card details are entered directly in the payment provider's environment — the controller has no access to them and does not store them.

Apple Pay and Google Pay. If the Customer chooses Apple Pay or Google Pay, the payment details are provided through the respective provider (Apple Distribution International Limited, Ireland, or Google Ireland Limited, Ireland), which processes them under its own terms of use and privacy policy and under its own responsibility.

Link. Link is a Stripe service that allows the Customer to save payment details for future purchases. Its use is voluntary; Stripe processes the data saved for this purpose under its own responsibility.

Klarna. If the Customer chooses Klarna, the data necessary for the payment, in particular name, e-mail address, order details and amount due, is transmitted to Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Klarna may itself collect further details during the payment process, such as address or date of birth. Klarna processes this data under its own responsibility and may obtain information from credit agencies to verify identity and creditworthiness. Klarna decides whether payment with Klarna is possible. Further information can be found in Klarna's privacy notice.

Payment methods customary in individual countries. For payment methods such as iDEAL, Bancontact, EPS, Satispay or MB WAY, the Customer is redirected to their bank or to the respective payment provider to confirm the payment, which processes the resulting data under its own responsibility.

Detailed information on data processing by Stripe and the providers named above can be found in their own privacy policies.

The legal basis is Article 6(1)(b) GDPR. Any identity and credit check by Klarna is carried out on the basis of Article 6(1)(b) and (f) GDPR.

§11 Delivery of orders

In order to carry out delivery, the customer's personal data is transmitted to companies providing courier or postal services.

The current list of carriers used by the Seller is set out in the document "Shipping & Delivery Times".

The scope of the data transmitted covers only what is necessary to carry out the delivery, in particular:

  • first and last name,

  • delivery address,

  • e-mail address,

  • telephone number, where required by the carrier.

The legal basis is Article 6(1)(b) GDPR.

§12 Social media profiles

Obsidian Studio maintains a profile on Instagram.

The website contains text links to that profile. The links do not embed any external content in the page — simply viewing the page does not create a connection with the social network's servers. A connection is established only once the link is clicked and the external service is opened.

The controller may process personal data of people visiting the social media profile, in particular data made publicly available by users of that platform, the content of private messages and the content of comments.

The data is processed for the purposes of:

  • operating the social media profile,

  • communicating with users,

  • replying to messages and comments,

  • promoting the activity of Obsidian Studio.

The legal basis is Article 6(1)(f) GDPR, namely the controller's legitimate interest in communication and brand promotion.

Independently of the controller, users' data may also be processed by the operator of the social network in accordance with its own privacy policy.

§13 Cookies and browser local storage

The Obsidian Studio website uses cookies and browser local storage (localStorage). The consent banner used on the site is the controller's own solution and does not come from a third-party provider.

Strictly necessary technologies — always active, because the shop cannot function without them:

  • browser local storage: the contents of the Box (the cart), the details entered in the order form, and the record of your consent decision,

  • cookies: storage of the selected language and currency and, in the case of the administration area, sign-in and session handling.

The legal basis is Article 6(1)(f) GDPR and § 25(2) TDDDG, namely necessity for a service you have expressly requested.

Analytics and marketing technologies — loaded only after consent has been given:

  • the "Analytics" category — Google Analytics, as described in §6,

  • the "Marketing" category — currently inactive; no marketing tools are loaded.

The legal basis is Article 6(1)(a) GDPR and § 25(1) TDDDG, namely consent.

Until consent is given, your browser establishes no connection with third-party servers for analytics or marketing purposes.

You may change your consent settings or withdraw consent at any time using the "Cookie Settings" link in the site footer, with effect for the future. Cookie settings can also be changed in your web browser.

Restricting strictly necessary technologies may affect the correct operation of certain shop functions.

§14 Recipients of personal data

Personal data may be transmitted to entities cooperating with the controller, solely to the extent necessary to achieve the purposes set out in this Privacy Policy. Data processing agreements under Article 28 GDPR have been concluded with processors acting on the controller's behalf.

The recipients are in particular:

  • Hostinger – provider of website hosting (servers within the European Union, Frankfurt am Main), registrar of the domain and provider of the shop's email mailboxes,

  • Supabase – provider of the database and file storage in which the shop's data is held (servers within the European Union, Frankfurt am Main),

  • Resend – provider of the service for sending order-related and correspondence e-mails,

  • Stripe – payment provider,

  • Klarna Bank AB (publ) – provider of the Klarna payment method, where the Customer chooses it (under its own responsibility),

  • Apple and Google – providers of Apple Pay and Google Pay, where the Customer chooses that payment method (under their own responsibility),

  • Google Ireland Limited – provider of Google Analytics, only where consent has been given,

  • courier and postal companies – as described in §11,

  • providers of accounting, IT or legal services to the controller, where necessary for the operation of the business.

The controller transmits data solely to the extent necessary to achieve the specified purposes and in accordance with applicable law.

§15 Transfers to third countries

The shop's data, including order data and customers' contact details, is stored on servers located within the European Union.

Some of the service providers named in §14 are established outside the European Economic Area or belong to corporate groups based in third countries. In such cases, transfers take place solely on the basis of the mechanisms provided for in Chapter V GDPR, in particular an adequacy decision of the European Commission or standard contractual clauses, supplemented where necessary by additional safeguards.

At the request of the data subject, the controller will provide information about the transfer mechanism applied in relation to a specific provider.

§16 Retention periods

Personal data is stored for as long as is necessary to achieve the purpose for which it was collected, and thereafter for the period required by applicable law, in particular tax and accounting rules and the rules on pursuing and defending claims.

In particular:

  • order-related data and accounting records are retained for the period required by German law,

  • data relating to complaints and claims is retained until the limitation period expires,

  • data from the contact form and correspondence is retained for as long as is necessary to handle the matter,

  • technical data and server logs are retained for as long as is necessary to ensure the security and correct operation of the website.

§17 Data security

The controller applies appropriate technical and organisational measures to protect personal data against loss, destruction, unauthorised disclosure, alteration or access by unauthorised persons.

The connection to the website is encrypted. Access to the shop's administration area, where order data is processed, requires authentication and is available to the controller only.

The controller exercises due care to ensure the security of personal data processed through the online shop.

§18 Rights of data subjects

Data subjects have the rights provided for by applicable law, in particular:

  • the right of access,

  • the right to rectification,

  • the right to erasure,

  • the right to restriction of processing,

  • the right to data portability,

  • the right to object to processing,

  • the right to withdraw consent at any time where processing is based on consent, whereby withdrawal does not affect the lawfulness of processing carried out beforehand,

  • the right to lodge a complaint with the competent supervisory authority.

To exercise these rights, it is sufficient to contact the controller at the e-mail address given in §1.

§19 Supervisory authority

Data subjects have the right to lodge a complaint with the competent data protection supervisory authority if they consider that the processing of their personal data infringes applicable law.

The competent supervisory authority for the controller is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW)
Lautenschlagerstraße 20
70173 Stuttgart
Germany
Telephone: +49 711 615541-0
E-mail: poststelle@lfdi.bwl.de

Data subjects may also lodge a complaint with the supervisory authority of their place of habitual residence, place of work or the place of the alleged infringement.

§20 Whether providing data is voluntary

Providing personal data is in principle voluntary.

However, failure to provide data marked as necessary may prevent you from using certain shop functions, in particular contacting the Seller or having an order processed.

§21 Automated decision-making and profiling

The controller does not take decisions in relation to users based solely on automated processing, including profiling, which would produce legal effects concerning them or similarly significantly affect them.

§22 Changes to this Privacy Policy

The controller reserves the right to amend this Privacy Policy where:

  • applicable law changes,

  • the way the online shop operates changes,

  • new services, functions or tools are introduced,

  • adaptation to decisions of supervisory authorities or to case law becomes necessary.

Amendments will not affect rights already acquired by users.

The current version of this Privacy Policy is always available on the Obsidian Studio website.

§23 Effective date

This Privacy Policy applies from: 27 September 2026.


This English version is a translation provided for your convenience. The legally binding version is the German one. In the event of any discrepancy between the language versions, the German text prevails. This does not limit the protection afforded to consumers by the mandatory provisions of the law of their country of habitual residence.