PRIVACY POLICY

Last updated: 14 September 2026

Atelier Lemontrend (“Atelier Lemontrend”, “we”, “us” or “our”) respects your privacy
and is committed to protecting your personal data.

This Privacy Policy explains how we collect and process personal data when you visit
https://atelierlemontrend.com, contact us, subscribe to our newsletter,
book an appointment, create an account, place an order, or otherwise use our website
and services.

We process personal data in accordance with the General Data Protection Regulation
(“GDPR”) and other applicable Austrian and European data-protection laws.

Please read this Privacy Policy together with our Cookies Policy and Terms and Conditions.

1. CONTROLLER

The controller responsible for the processing of personal data through this website is:

Atelier Lemontrend
Vienna, Austria

The full legal and postal details of the controller are provided in our
Terms and Conditions available on this website.

For privacy-related questions or requests, you may contact us through our
Contact page.

2. WHAT PERSONAL DATA DO WE COLLECT?

The personal data we process depends on how you interact with our website and services.

Information you provide directly to us may include:

  • first and last name;
  • email address;
  • telephone number, where provided;
  • billing and shipping address;
  • company or business information;
  • account and login information;
  • order and transaction information;
  • information submitted through contact forms;
  • information provided when booking an appointment;
  • newsletter subscription information;
  • and any other information you voluntarily send to us.

Technical information may include:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • referring website;
  • pages visited;
  • date and time of requests;
  • server and security logs;
  • cookie and consent information;
  • and other technical information necessary for the operation and security of the website.

3. PURPOSES AND LEGAL BASES OF PROCESSING

Depending on the particular processing activity, we process personal data on one or
more of the following legal bases:

  • Article 6(1)(a) GDPR – Consent:
    where you have voluntarily consented to optional analytics, marketing,
    newsletter subscriptions, push notifications or third-party content.
  • Article 6(1)(b) GDPR – Contract:
    where processing is necessary to provide requested services, process an order,
    administer a customer account, arrange an appointment or otherwise perform a
    contract or take steps at your request before entering into a contract.
  • Article 6(1)(c) GDPR – Legal obligation:
    where processing is necessary to comply with accounting, tax, commercial,
    regulatory or other legal obligations.
  • Article 6(1)(f) GDPR – Legitimate interests:
    where processing is necessary for legitimate interests such as maintaining
    website security, preventing spam and fraud, protecting our systems,
    communicating with customers and operating our business, provided that such
    interests are not overridden by your rights and interests.

4. CONTACT FORMS AND COMMUNICATION

When you contact us through a contact form, by email or through another communication
channel, we process the information you provide in order to respond to your inquiry
and communicate with you.

Depending on the nature of your request, the legal basis is Article 6(1)(b) GDPR
where the communication relates to a contract or pre-contractual request, or
Article 6(1)(f) GDPR where we have a legitimate interest in responding to general
business inquiries.

We retain correspondence for as long as necessary to deal with the request and,
where applicable, for longer periods where required for contractual, evidentiary
or legal purposes.

5. WOOCOMMERCE, CUSTOMER ACCOUNTS AND ORDERS

Our online shop is operated using WooCommerce.

When you create an account or place an order, we may process information such as your
name, email address, billing and shipping address, telephone number where provided,
products or services ordered, order value, payment method, transaction information,
account information and technical information associated with the transaction.

This information is processed primarily for:

  • processing and fulfilling orders;
  • managing payments;
  • providing customer service;
  • administering customer accounts;
  • handling refunds, disputes and complaints;
  • preventing fraud and abuse;
  • and complying with accounting, tax and other statutory obligations.

The legal bases are primarily Article 6(1)(b) GDPR and Article 6(1)(c) GDPR.
Security and fraud-prevention measures may additionally be based on our legitimate
interests under Article 6(1)(f) GDPR.

6. PAYMENT PROCESSING

Stripe

We offer payment methods processed through Stripe.

When you select a payment method processed by Stripe, information required to process
the transaction may be transmitted to Stripe. This may include your name, email
address, billing information, transaction details, IP address and other information
necessary for payment processing, authentication, fraud prevention and regulatory
compliance.

For customers in the European Economic Area, Stripe services may be provided by
Stripe Payments Europe, Limited, Ireland.

The legal basis for transmitting information required to complete your payment is
Article 6(1)(b) GDPR. Processing required to comply with legal obligations is based
on Article 6(1)(c) GDPR. Fraud-prevention and security processing may additionally
be based on legitimate interests under Article 6(1)(f) GDPR.

PayPal

We also offer payments through PayPal.

If you select PayPal, the information required to process your payment may be
transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg.

Depending on the transaction, this may include your name, address, email address,
transaction details, payment information, IP address and other information required
for payment processing, fraud prevention and regulatory compliance.

The legal basis is primarily Article 6(1)(b) GDPR. Where processing is necessary to
meet statutory requirements, Article 6(1)(c) GDPR may also apply.

Stripe and PayPal process certain information under their own responsibility in
accordance with their respective privacy notices.

7. NEWSLETTER AND MAILERLITE

We use MailerLite to manage our newsletter, email marketing and
related communications.

If you voluntarily subscribe to our newsletter, we process the information provided
during registration, in particular your email address and, where provided, your name
and other subscription information.

MailerLite may also process technical and engagement information associated with
newsletter delivery, such as delivery status, newsletter interactions and unsubscribe
information.

For customers located in the European Economic Area, MailerLite services are provided
by MailerLite Limited, Ireland.

Newsletter processing is based on your consent under Article 6(1)(a) GDPR.

You may withdraw your consent at any time by using the unsubscribe link included in
our marketing emails or by contacting us. Withdrawal of consent does not affect the
lawfulness of processing carried out before withdrawal.

Where an email address must be retained on a suppression list in order to ensure that
no further marketing messages are sent following an unsubscribe request, we may retain
the minimum information required for that purpose.

8. CONSENT MANAGEMENT – SILKTIDE CONSENT MANAGER

We use a locally hosted implementation of Silktide Consent Manager
to manage your privacy choices on this website.

When you visit the website, you can choose which categories of optional technologies
you wish to allow. These may include functional, analytics and advertising
technologies.

Your consent preferences are stored locally in your browser and in a first-party
consent record so that the website can remember and respect your choices.

The consent-management mechanism itself is necessary to record and respect your
privacy preferences. Optional services are activated in accordance with the consent
choices you make.

You can change or withdraw your consent at any time using the privacy or cookie
settings available on the website.

Withdrawal of consent does not affect the lawfulness of processing carried out before
the withdrawal.

9. GOOGLE TAG MANAGER

We use Google Tag Manager (“GTM”) to technically manage website tags and consent
signals.

Google Tag Manager enables us to control the deployment of certain scripts and
services on the website. Services that require consent are configured to respond to
the consent choices made through our consent-management system.

The use of GTM does not change the legal basis applicable to the individual service
that is deployed through it. Where a service requires consent, the corresponding
processing is only permitted in accordance with your consent choice.

10. GOOGLE ANALYTICS 4

With your consent, we use Google Analytics 4 (“Google Analytics”)
to understand how visitors use our website and to improve our website, services and
user experience.

Google Analytics may process information including:

  • pages visited;
  • interactions with the website;
  • approximate location information;
  • device and browser information;
  • referrer information;
  • technical identifiers;
  • and IP-related technical information.

We use a consent-management mechanism and Google Consent Mode so that Google services
can respond to your consent choices.

Where storage or processing for analytics requires your consent, the legal basis is
Article 6(1)(a) GDPR.

You may withdraw your analytics consent at any time through the website's privacy
settings.

Google may process information on servers located outside the European Economic Area.
Where international transfers occur, appropriate safeguards under Chapter V of the
GDPR apply.

11. CLOUDFLARE

We use Cloudflare services to improve the security, reliability and performance of
our website.

In providing these services, Cloudflare may process technical information such as
IP addresses, request information, browser and device information, security-related
signals and server/network information.

The purpose of this processing includes protecting the website against malicious
traffic, attacks, abuse and other security threats and improving the reliable delivery
of website content.

The legal basis is our legitimate interest in operating a secure and reliable website
under Article 6(1)(f) GDPR.

12. CLOUDFLARE TURNSTILE

We use Cloudflare Turnstile to protect certain forms, login and
e-commerce functions against automated abuse, bots and spam.

Turnstile may process technical signals such as your IP address, user-agent information,
browser or device characteristics, TLS-related information, the website origin and
security signals necessary to distinguish legitimate users from automated traffic.

Turnstile is used for website and form security and not for advertising purposes.

The legal basis is our legitimate interest in protecting our website, customer accounts,
forms and transaction processes from abuse under Article 6(1)(f) GDPR.

13. CLEANTALK ANTI-SPAM AND SECURITY

We use services provided by CleanTalk to protect the website against
spam, automated submissions, abusive activity and security threats.

Depending on the interaction, CleanTalk may process technical and form-related
information required for spam or abuse detection, including IP addresses, email
addresses submitted through forms, URLs, technical metadata and information required
to assess whether a submission is legitimate.

The legal basis is our legitimate interest in preventing spam, fraud and abuse and in
protecting the integrity and security of our website under Article 6(1)(f) GDPR.

14. WEBPUSHR – PUSH NOTIFICATIONS

We use Webpushr to provide optional browser push notifications.

Webpushr is only activated in accordance with the applicable consent choice.
If you choose to enable push notifications, information associated with your browser
subscription may be processed. Depending on your configuration and use, this may
include browser and device information, push subscription identifiers, IP-related
technical information and information about interactions with push notifications.

The legal basis for optional push-notification processing is your consent under
Article 6(1)(a) GDPR.

You can withdraw your permission for push notifications through your browser settings
and, where applicable, through the privacy settings on our website.

15. CALENDLY

We use Calendly to allow visitors to schedule appointments or
consultations.

Calendly content is activated in accordance with the applicable consent choice.
If you choose to use the scheduling service, Calendly may process information necessary
to arrange the appointment, such as your name, email address, appointment details,
time zone and technical information associated with the booking.

Where you request an appointment in connection with our services, processing may be
necessary for pre-contractual steps under Article 6(1)(b) GDPR. Processing associated
with loading optional third-party content may additionally rely on your consent under
Article 6(1)(a) GDPR.

16. GOOGLE MAPS

We may embed Google Maps in order to display locations or geographic information.

Google Maps is treated as optional third-party content and is activated in accordance
with the applicable consent choice.

When Google Maps is activated, Google may receive technical information such as your
IP address, browser and device information and information about the page on which
the map is displayed.

The legal basis for loading optional Google Maps content is your consent under
Article 6(1)(a) GDPR.

17. SOCIAL MEDIA LINKS AND SHARING FUNCTIONS

Our website may contain links or sharing functions for social networks or other
third-party platforms.

A normal external link does not itself require us to transmit your personal data to
the destination platform. However, when you click a social-media or third-party link,
you leave our website and the relevant provider may process information in accordance
with its own privacy policy.

Where a third-party feature is embedded directly into the website and requires consent,
it will be handled in accordance with the consent settings applicable to that feature.

18. SERVER LOGS, HOSTING AND TECHNICAL SECURITY

When the website is accessed, our hosting and technical infrastructure may automatically
record information necessary to deliver and secure the website.

Server logs may contain information such as:

  • IP address;
  • date and time of access;
  • requested URL;
  • HTTP response status;
  • referring website;
  • browser and operating-system information;
  • and technical error or security information.

We process this information for the operation, troubleshooting, availability and
security of the website.

The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in providing
a functional, secure and reliable website.

19. COOKIES AND SIMILAR TECHNOLOGIES

Our website uses cookies, browser storage and similar technologies.

Some technologies are technically necessary for the operation, security, shopping
cart, payment, account functionality or storage of privacy preferences.

Other technologies, including optional analytics or third-party functionality, are
used only in accordance with the consent choices you make.

You can find further information about the categories and technologies we use in our
Cookies Policy

You may change your consent choices at any time through the privacy settings available
on the website.

20. RECIPIENTS OF PERSONAL DATA

Where necessary for the purposes described in this Privacy Policy, personal data may
be shared with service providers or other recipients including:

  • hosting and infrastructure providers;
  • website and security providers;
  • payment providers;
  • email and newsletter providers;
  • analytics providers where consent has been granted;
  • appointment-booking providers;
  • professional advisers such as accountants or legal advisers where necessary;
  • and public authorities where disclosure is required by law.

Where a service provider processes personal data on our behalf, we use appropriate
contractual and data-protection arrangements where required by law.

21. INTERNATIONAL DATA TRANSFERS

Some service providers used by our website are established outside Austria or may
process information outside the European Economic Area (“EEA”).

Where personal data is transferred to a country outside the EEA, such transfers are
made only where a lawful transfer mechanism under Chapter V of the GDPR is available.
Depending on the recipient, this may include:

  • an adequacy decision adopted by the European Commission;
  • participation in an applicable recognised data-transfer framework;
  • European Commission Standard Contractual Clauses;
  • or another legally recognised transfer mechanism.

Additional technical, contractual or organisational safeguards may be used where
appropriate.

22. HOW LONG DO WE KEEP PERSONAL DATA?

We keep personal data only for as long as necessary for the purpose for which it was
collected, unless a longer retention period is required by law or necessary for the
establishment, exercise or defence of legal claims.

For example:

  • order, invoice and transaction records may be retained for statutory accounting
    and tax retention periods;
  • customer correspondence may be retained for the duration necessary to handle
    the inquiry and any related contractual or legal matters;
  • newsletter data is retained until consent is withdrawn, subject to any
    necessary suppression record;
  • consent records may be retained for as long as necessary to demonstrate and
    respect your privacy choices;
  • security and technical logs are retained only for periods reasonably necessary
    for operational and security purposes.

When personal data is no longer required, it will be deleted or anonymised unless
further retention is legally permitted or required.

23. HOW DO WE PROTECT YOUR INFORMATION?

We use appropriate technical and organisational measures designed to protect personal
data against accidental or unlawful destruction, loss, alteration, unauthorised
disclosure or access.

These measures may include secure connections, access controls, website and server
security systems, anti-spam and bot-protection systems, backups, software updates,
monitoring and other security measures appropriate to the risks involved.

However, no internet transmission or electronic storage system can be guaranteed to
be completely secure.

24. YOUR RIGHTS UNDER THE GDPR

Subject to the conditions and limitations of applicable law, you have the following
rights regarding your personal data:

  • Right of access – to obtain information about whether and how
    we process your personal data and to receive a copy where applicable.
  • Right to rectification – to have inaccurate or incomplete
    personal data corrected.
  • Right to erasure – to request deletion of your personal data
    where the legal requirements are met.
  • Right to restriction of processing – to request that processing
    be restricted in certain circumstances.
  • Right to data portability – to receive certain personal data
    in a structured, commonly used and machine-readable format and, where technically
    feasible, have it transmitted to another controller.
  • Right to object – to object to processing based on
    Article 6(1)(e) or Article 6(1)(f) GDPR where the legal requirements are met.
  • Right to withdraw consent – where processing is based on consent,
    you may withdraw that consent at any time with effect for the future.
  • Right to lodge a complaint – you have the right to lodge a
    complaint with a competent data-protection supervisory authority.

To exercise your rights, please contact us through our
Contact page.

We may need to verify your identity before responding to a request where this is
necessary to protect your personal data.

25. AUSTRIAN DATA PROTECTION AUTHORITY

If you believe that the processing of your personal data infringes the GDPR or other
applicable data-protection law, you have the right to lodge a complaint with the
Austrian Data Protection Authority.

Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
Austria
Email: [email protected]

26. CHILDREN

Our website and services are not specifically directed at children.

We do not knowingly collect personal data from children in circumstances where
parental consent would be required under applicable law. If you believe that a child
has provided us with personal data unlawfully, please contact us so that we can review
the matter and take appropriate action.

27. THIRD-PARTY WEBSITES

Our website may contain links to websites or services operated by third parties.
We are not responsible for the privacy practices, security or content of third-party
websites.

We encourage you to review the privacy information provided by any third-party website
or service before submitting personal information to it.

28. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes to our website,
services, technologies, legal obligations or data-processing practices.

The current version will always be published on this page and identified by the
“Last updated” date at the top of the policy.

Where changes are material and applicable law requires additional notice or consent,
we will take appropriate steps to provide such notice or obtain consent.

29. HOW TO CONTACT US

If you have questions about this Privacy Policy, our processing of personal data or
wish to exercise your data-protection rights, please contact:

Atelier Lemontrend
Vienna, Austria
Contact Us

Our full legal and postal details are provided in our Terms and Conditions available
on this website.