last update; 25th of May 2018
It does not apply to the practices of the shop venues or third party services that I do not own or control (like Etsy, Creative Market, The Hungry JPEG, Design-/Fontbundles, Mailchimp and other venues where you may have used one of my services or purchased one of my items). You can always refer to the privacy policies of those specific marketplaces and services to learn about their practices.
1. Personal Information I collect from you and store
I only collect the information I receive from the online marketplaces where I sell my products or services (i.e. Etsy, Creative Market, The HungryJPEG, Design-/Fontbundles) and from my Mailchimp mailing list. It contains partly or in full the information you provided while signing up on those websites.
The information may include your name, email and postal address, payment information and the details of your order. If you contact me about a purchase or add a note to your purchase that is also considered information.
I don’t intend to collect any information of customers or website visitors below the age of 16 without the consent of their legal guardian. However, in most cases I can’t do an age check. If you believe I have inadvertently collected information on a person below the age of 16 you can contact me at email@example.com so I can delete that information.
I do not make use of automated decision-making including profiling.
I take every measure within my ability to safely store your information. Once downloaded I store my customer data in an encrypted format which is also password protected.
2. Why I collect and use your information
I rely on a number of legal bases to collect, use and share your information including:
- • to provide my services, such as when I use your information to fulfil and ship your order, to settle disputes, or to provide customer support;
- • to comply with a legal obligation or court order, or in connection with a legal claim, such as retaining information about your purchases as are required by tax law;
- • to improve my services;
- • to acquire your affirmative consent which is legally required, such as when you sign up for my email list.
It’s within your rights to object to providing your personal details. On most marketplace websites I sell at, this will mean that an order can’t be completed or fulfilled. If you believe the information that’s been asked for is unnecessary for completing the order, please don’t hesitate to reach out to me or to the website providing my services.
3. Other parties I work with that will share your personal information
I share your information for very limited reason in limited circumstances as follows and will never sell or share your information with third party advertisers:
- • Delivery companies – only if and to the extent necessary to ship a physical product. My main shipping companies are ‘MyParcel’, ‘PostNL’ and ‘Deutsche Post’.
- • My accountant/book-keeper for tax and administration purposes. Currently ‘Kubus Ederveen’.
- • As required for law compliance with the requesting authorities. In this case I may collect, use, retain, and share your information if I have a good faith belief that it is reasonably necessary to: (a) respond to legal process or to government requests; (b) enforce my agreements, terms and policies; (c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or (d) protect the rights, property, and safety of my customers, or others.
- • For transfer purposes; In case I need to send you digital goods, I will sometimes rely on cloud and/or transfer services online if the files are too big to send by email. In this case I may be required to share your email address to provide you with the necessary download link. Services I use on a regular basis for this are ‘WeTransfer’ and ‘Google Drive’.
I have checked these companies on their GDPR compliance and you can do the same by checking their privacy policies at any time. All of the companies I work with are either GDPR compliant or are openly in the process of updating towards compliance.
4. Time of retaining your information
The main factor for retaining your information will be my legal and regulatory obligations which will be a maximum of 10 years for electronic services/purchase of digital goods and 7 years for purchase of physical goods. This is the time period in which your relevant information will be in my administration.
For my marketing purposes I only use my current email lists and that information will be directly available to me only when you are subscribed by providing affirmative consent since May 2018. I don’t store your email address outside of the Mailchimp environment and when you unsubscribe to my mailing lists I will not retain your information.
5. Transfer of information to a country or service outside of Europe
I work with service providers located outside the EU who may store, host or process your information. The legal basis for using these services will be based on the ‘EU-US Privacy Shield’ and/or GDPR compliance.
The following companies are the ones I work with to store or process data:
- • Backblaze; my cloud backup provider.
- • Google; for email processing, cloud storage, sharing and web services
- • Apple iCloud; for incidental cloud storage, transfer between hardware and sharing services.
6. Your rights
If you reside in certain territories, including the EU, you have several rights regarding your personal information. Some of these apply only in certain limited cases.
Next to your right to be informed, which I try to achieve by this policy and referring to it on a regular basis, you have the following rights as well
- • Access: You have the right request and receive a copy of the personal information I store from you. You will find my contact information further below.
- • Rectification: If any of the personal data I collected from you has to be rectified you can request me to do so.
- • Erasure: You have the right to request erasure of your personal information.
- • Restrict Processing: This means that you can request me to limit the way I use your data
- • Data Portability: allows you to request, obtain and reuse the personal data you provided me with.
- • Object: You have the right to object to the processing of your personal information.
- • Complain: If you reside in the EU and wish to raise a concern about my use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.
Since I only collect the personal data needed for fulfilling your order and store said information to abide to the local administration laws, most requests can be fulfilled in limited cases only. I am required by law to respond to your request within one calendar month.
7. About me and contact options
For purposes of EU data protection law, my company is the data controller of your personal information. If you have any questions or concerns, you may contact me at firstname.lastname@example.org. Alternatively, you may mail me at: By Lef Design, Vossenweg 59, 6721 BM, Bennekom, The Netherlands