Privacy Policy
Last updated: 30 September 2026
1. Controller and overview
The controller responsible for data processing on this website is:
Nadja König – Illustration
Schwanseestr. 69
81549 München, Germany
Email: office@nadjakoenig.com
The controller is the natural person who, alone or jointly with others, decides on the purposes and means of processing personal data.
Personal data is any data that can be used to identify you personally. We process data that you give us yourself, for example when you place an order, send an email or sign up for the newsletter. Other data is collected automatically by our IT systems when you visit the website, mainly technical data such as browser, operating system and time of access. Some data is processed so that the website works correctly and orders can be handled. Other data is only processed with your consent, for example for statistics, advertising or embedded content from third parties.
2. Hosting and server log files
Our website is hosted by RAIDBOXES GmbH, Hafenstr. 32, 48151 Münster, Germany. When you visit the website, RAIDBOXES automatically records server log files, including your IP address, date and time, the page requested, the referrer, browser type and operating system. This data is not combined with other data sources.
The legal basis is Art. 6 (1) (f) GDPR. We have a legitimate interest in providing the website in a technically flawless, secure and fast way. We have a data processing agreement with RAIDBOXES under Art. 28 GDPR. Details: RAIDBOXES privacy policy.
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” and the lock symbol in the address bar.
3. Legal bases, storage period and your rights
Legal bases. We process data on the following legal bases of the GDPR: consent (Art. 6 (1) (a)), contract and pre-contractual measures (point b), legal obligations such as retention for tax and commercial law (point c) and legitimate interest (point f). Where we store information on your device or access it for services that are not strictly necessary, your consent under Section 25 (1) of the German TDDDG is also required. The legal basis for each case is given with the individual service.
Storage period. We store data for as long as the purpose exists, for example until an order has been fully completed. After that we delete it, unless statutory retention periods apply. We keep invoices and accounting records for eight years, business letters for six years and books and annual accounts for ten years.
Third countries. Some services are based in the USA or belong to US companies. Where the provider is certified under the EU-US Data Privacy Framework, we base the transfer on the European Commission’s adequacy decision; otherwise on standard contractual clauses. This is stated with each service.
Your rights. You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw consent at any time with effect for the future; for cookies via the cookie settings (link “Cookie settings” at the bottom of every page). An email to office@nadjakoenig.com is enough.
Right to object under Art. 21 GDPR. Where we process data on the basis of a legitimate interest, you can object at any time on grounds relating to your particular situation. You can object to direct marketing at any time without giving reasons.
Right to lodge a complaint. You can lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
4. Cookies and consent management
We use cookies and similar technologies. We set technically necessary cookies on the basis of Section 25 (2) TDDDG and Art. 6 (1) (f) GDPR, for example for the shopping cart, the language selection and saving your cookie choice. All other cookies and services only load once you have given your consent (Section 25 (1) TDDDG, Art. 6 (1) (a) GDPR).
Borlabs Cookie. To manage consent we use Borlabs Cookie by Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany. The plugin stores your choice in a cookie called “borlabs-cookie” with a random ID so that we can prove your consent. The data stays on our server. The legal basis is Art. 6 (1) (c) GDPR (obligation to provide proof).
Language selection. The website is bilingual. The Polylang plugin stores your language in a technically necessary cookie (“pll_language”).
Shop. WooCommerce sets technically necessary cookies for the shopping cart and session (e.g. “woocommerce_cart_hash”, “wp_woocommerce_session_”).
5. Contacting us and sending emails
If you contact us by email or via the contact form, we store and process your enquiry with all the data you provide in order to handle it. The legal basis is Art. 6 (1) (b) GDPR if the enquiry relates to a contract or its preparation, for example a booking request, otherwise Art. 6 (1) (f) GDPR. We delete the data once the enquiry has been dealt with and no retention obligations apply.
Contact form. On the “Contact & Imprint” page you can write to us using a form. We process your name, email address and message. The details are forwarded to us by email and may also be stored in the website database. We delete them once the enquiry has been dealt with. To protect against spam we use an invisible field; no third-party services are involved. The legal basis is the same as for emails.
Emails from the website, for example order confirmations, are sent via the mail server of STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO processes the sender, recipient and content of the email. We have a data processing agreement with STRATO. The legal basis is Art. 6 (1) (b) and (f) GDPR.
6. Online shop
Orders and customer account. The shop runs on WooCommerce and Germanized on our own server. For an order we process your name, billing and delivery address, email address, phone number (if provided), products ordered, payment method and order history. If you create a customer account, we also store this data for future orders until you delete the account. The legal basis is Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR for keeping invoices.
Payment with PayPal. We offer payment via PayPal, including the payment methods available there. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. When you pay, we pass your order and payment data to PayPal. PayPal may carry out a credit check. On shop and checkout pages a PayPal script loads so that the payment method can be displayed. The legal basis is Art. 6 (1) (b) GDPR. Details: PayPal privacy statement.
Shipping. For shipping we pass your name and delivery address to the shipping company we use, for example Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, or DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany. We do not pass on your email address or phone number. The legal basis is Art. 6 (1) (b) GDPR.
Withdrawal via the website. If you use the “Withdraw from contract” function, we process your name, email address, order number and your declaration in order to handle the withdrawal and confirm receipt. The legal basis is Art. 6 (1) (b) and (c) GDPR.
Order attribution. WooCommerce can store how you found the shop (order attribution, e.g. search engine or social media). This only happens with your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG); the data stays on our server.
7. Newsletter and Mailchimp
Newsletter. For the newsletter we need your email address. We use the double opt-in procedure: after signing up you receive an email in which you confirm your subscription. We store the time of sign-up, the time of confirmation and your IP address so that we can prove the subscription. The legal basis is your consent under Art. 6 (1) (a) GDPR. You can unsubscribe at any time via the link in every issue.
Mailchimp. The newsletter is sent via Mailchimp, a service of Intuit Inc., 2700 Coast Avenue, Mountain View, CA 94043, USA. Your sign-up data is stored on Mailchimp servers in the USA. Mailchimp analyses whether a newsletter was opened and which links were clicked. The sign-up form and its scripts only load after you have given consent in the cookie banner. Intuit is certified under the EU-US Data Privacy Framework. The data processing agreement with standard contractual clauses is part of Mailchimp’s terms of use.
Mailchimp for WooCommerce. The shop is connected to Mailchimp. If you have subscribed to the newsletter, your order data such as the products you bought is also transferred to Mailchimp so that we can send you relevant content. Without newsletter consent, no customer data is passed on to Mailchimp. The legal basis is your consent (Art. 6 (1) (a) GDPR).
8. Statistics and marketing
The following services only load if you have agreed to the “Marketing” group in the cookie banner. The legal basis is Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. You can withdraw your consent at any time in the cookie settings.
Jetpack Stats. We use the statistics function of Jetpack, a service of Aut O’Mattic A8C Ireland Ltd., Business Centre, No. 1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland, and its parent company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. Jetpack records which pages are visited, as well as browser, device, referrer and a shortened IP address, in order to evaluate visitor numbers. Automattic is certified under the EU-US Data Privacy Framework.
Meta Pixel. In the shop we use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The pixel records which pages and products you view and whether you buy something, so that we can show ads on Facebook and Instagram to interested people and measure their success. Meta may link this data to your Facebook or Instagram account. We and Meta are joint controllers for collecting and transferring the data (Art. 26 GDPR); the agreement can be found at facebook.com/legal/controller_addendum. Data may be transferred to Meta Platforms Inc. in the USA, which is certified under the EU-US Data Privacy Framework.
9. Embedded content and fonts
Instagram feed. In the footer we show posts from our Instagram profile (Smash Balloon plugin). Images and videos are loaded from servers of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. Meta receives your IP address and technical data. The feed only loads once you have given consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). Until then you see a placeholder.
YouTube and Vimeo. Some pages contain videos from YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) or Vimeo (Vimeo.com Inc., 330 West 34th Street, 5th Floor, New York, NY 10001, USA). The videos only load after your consent via a placeholder. When a video plays, the providers receive your IP address and usage data and may set cookies. The legal basis is Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. Google and Vimeo are certified under the EU-US Data Privacy Framework.
Adobe Fonts. For our fonts we use Adobe Fonts by Adobe Systems Software Ireland Limited, 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. When you open a page, your browser loads the fonts from Adobe servers, and your IP address is transmitted to Adobe. According to Adobe, no cookies are set for the fonts. The legal basis is Art. 6 (1) (f) GDPR. We have a legitimate interest in a consistent and appealing presentation of our website. Details: Adobe Fonts and privacy.
Services not used. Our pages contain no Google Maps, OpenStreetMap maps, X or Facebook embeds and no Google reCAPTCHA.