Privacy policy

 
Privacy Notice pursuant to Articles 13, 14 and 21 GDPR
Preamble
With the following information, we inform you about the processing of your personal data and about your rights under the General Data Protection Regulation (GDPR). The specific data processed and the manner in which it is used depend largely on the services agreed upon in each individual case.

 
1. Data Controller
The data controller responsible for data processing is:

Thilo Endres
Merzigweg 6
89077 Ulm
Germany
Email: t.endres@t-online.de

 
2. Which data do we process?
We process personal data that we receive from you in the course of our business relationship. In addition, we process – where necessary – personal data that we lawfully receive from institutions (e.g. kindergartens or schools) on the basis of a corresponding assignment or consent.

The processed data includes in particular:

Name, address, email address, telephone number
Image data (photographs)
Order, payment and invoicing data
Communication data (e.g. emails, contact forms)
 
3. Purposes and legal bases of processing
3.1 Performance of a contract (Art. 6 para. 1 lit. b GDPR)
Personal data is processed for the purpose of providing photographic services, offering online galleries, selling image files and photo products, and handling orders and payments.

 
3.2 Legitimate interests (Art. 6 para. 1 lit. f GDPR)
Where necessary, we process personal data to:

Ensure IT security
Optimize internal workflows
Assert or defend legal claims
In the context of photographic assignments in kindergartens, schools or at events, processing is also carried out on the basis of our legitimate interest in fulfilling the commissioned assignment. Information about photography and existing rights to object is provided on site.

 
3.3 Consent (Art. 6 para. 1 lit. a GDPR)
If you have given us your consent to process personal data for specific purposes (e.g. publication of images), the processing is carried out on this basis. Consent may be withdrawn at any time with effect for the future.

 
3.4 Legal obligations (Art. 6 para. 1 lit. c GDPR)
We process personal data to comply with legal obligations, in particular statutory retention requirements under commercial and tax law.

 
4. Recipients of data / data processors
To provide our services, we use carefully selected service providers. These providers receive personal data exclusively within the framework of data processing agreements pursuant to Art. 28 GDPR.

4.1 Online galleries and order processing
Fotografen Online Service GmbH (fotograf.de)

 
4.2 Payment service providers
PayPal (Europe) S.à r.l. et Cie, S.C.A.
Stripe Payments Europe Ltd. (credit and debit cards, Apple Pay, Google Pay)

 
4.3 AI-assisted support for image selection (Neurapix)
To support photographic post-processing and image selection, the service Neurapix may be used. The provider is Neurapix GmbH, Germany.

The service is not used in all cases, but only when required to efficiently preselect and evaluate photographs. The final image selection and final editing are always carried out by the photographer.

Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR (performance of a contract) and Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient and consistent image processing).

A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider. The provider does not use the image data for its own purposes.

 
5. Data retention period
Personal data is stored only for as long as necessary to achieve the stated purposes or as required by statutory retention obligations.
Accounting and invoicing data is retained for up to 10 years in accordance with legal requirements.

 
6. Transfer of data to third countries
Personal data is transferred to countries outside the European Economic Area (EEA) only if this is necessary for contract performance or if a valid legal basis exists.

 
7. Your rights
You have the right at any time to:

Access (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Lodge a complaint with a supervisory authority (Art. 77 GDPR)
 
8. Obligation to provide data
Without the provision of certain personal data, it is not possible to provide photographic services or process orders.

 
9. Email notifications
If you subscribe to email notifications, your data will be used exclusively for this purpose. You may withdraw your consent at any time.

 
10. Cookies and website functions
Our website uses technically necessary cookies.
Analytics or marketing cookies are used only if you have expressly consented to their use.

 
11. Right to object pursuant to Art. 21 GDPR
You have the right to object at any time to the processing of your personal data if such processing is based on Art. 6 para. 1 lit. f GDPR.

The objection may be submitted informally by email to:
t.endres@t-online.de

 
Status: January 2026