Privacy Policy

Last updated: 10 May 2026

1. Controller

The data controller for this website under the GDPR is:

Barbara Pos
Linzer Straße 17
4100 Ottensheim
Austria

Contact: klamsines.hoeschen@gmail.com

2. Scope

This privacy policy applies to klamsine.at and all related order, enquiry and account functions. It explains what personal data is processed, to what extent and for what purpose.

3. 18+ notice and adult-content confidentiality

This website is intended exclusively for users aged 18 or older. An age confirmation is shown on first visit.

Orders and enquiries relating to adult content are treated confidentially. Such data is accessible only to persons and service providers to the extent necessary for contract performance, payment, delivery, support or legal obligations.

4. Data processed by activity

4.1 Digital content order (videos, photo sets)

Email address, order content, payment confirmation, download access tokens.

4.2 Physical goods order (worn textiles, sets)

First and last name, delivery address, email address, order content, payment confirmation, optional tracking information.

4.3 Custom video request

Provided name or alias, email address, description of the requested service, technical connection data for spam protection (IP address, user agent).

4.4 Customer account and magic-link login

Email address, short-lived login tokens, access history of purchased content. Login sessions are handled server-side and via short-lived technical tokens in the browser (sessionStorage / secure cookies); these tokens are used solely to authenticate the current session and are deleted on session close or expiry.

4.5 Newsletter

A newsletter is currently not offered. Should this change, this policy will be updated accordingly.

5. Purposes and legal bases

  • Contract performance (Art. 6(1)(b) GDPR): processing of orders, custom requests, delivery, payment, account functions.
  • Legal obligations (Art. 6(1)(c) GDPR): tax retention duties, accounting law.
  • Legitimate interests (Art. 6(1)(f) GDPR): IT security, spam protection, abuse prevention.

6. Payment processing via CCBill

Payment is processed by CCBill as an external payment service provider. CCBill processes payment and contact data on its own responsibility on its own infrastructure and may transfer data to third countries. For such transfers, appropriate safeguards such as standard contractual clauses are used. CCBill's privacy information is available directly from CCBill.

7. Hosting, database, email and technical providers

  • Hosting (Vercel Inc.): website delivery, region Frankfurt (fra1) within the EU. Data processing agreement under GDPR. As part of edge delivery, Vercel processes technical server log files (IP address, timestamp, user agent, requested URL) for IT security, abuse prevention and delivery stability. These records are processed automatically for a short retention period and are not used for profiling.
  • Database and authentication (Supabase): storage of orders, enquiries and account data, region eu-central-1 (Frankfurt) within the EU. Data processing agreement under GDPR.
  • Transactional email (Resend): sending of confirmations, login links and delivery information. Where data is transferred outside the EU/EEA, appropriate safeguards such as standard contractual clauses are used.
  • DNS (Simply.com): domain-name resolution for klamsine.at. DNS queries do not process customer-related personal data in identifiable form beyond ordinary internet name resolution.
  • Payment processing (CCBill): see section 6.

8. Cookies, tracking and external content

This website does not use any analytics or tracking services (such as Google Analytics, Plausible or Meta Pixel). No external Google Fonts are loaded, no social-media embeds (YouTube, Instagram, X) are used, and no marketing cookies are set.

Only strictly technically necessary cookies and session data are used. Specifically: a language cookie (NEXT_LOCALE), a sessionStorage marker for the one-time 18+ confirmation, and server-side and browser-side tokens for signed-in sessions. These items are processed without consent because they are strictly necessary for the operation of the website (Art. 6(1)(f) GDPR and § 165(3) Austrian Telecommunications Act 2021).

9. Retention period

Personal data is stored for as long as necessary to perform the contract and to comply with statutory retention periods (in particular § 132 BAO Austrian Federal Fiscal Code). Enquiries without a contract are deleted or anonymised once they are no longer needed for their original purpose.

10. Recipients and transfers to third countries

Recipients are exclusively the processors and payment service providers listed in sections 6 and 7. Transfers to third countries take place only within the services described there; in such cases appropriate safeguards under Art. 46 GDPR are used.

11. Your rights

You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Requests can be sent informally to the contact address listed in section 1.

12. Right to lodge a complaint

You have the right to lodge a complaint with the Austrian Data Protection Authority:
Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria, www.dsb.gv.at.

13. Contact

For all data-protection enquiries please contact: klamsines.hoeschen@gmail.com.