Privacy policy
Privacy Policy
La Bella Rosa Studios – Etsy Shop
Last updated: May 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
La Bella Rosa Studios
Owner: Nadine Zech
c/o MDC#zech
Welserstraße 3
87463 Dietmannsried
Deutschland
Email: contact@labellarosa-studios.com
2. Principles of Data Processing
A. We process personal data solely to the extent permitted by law or where you have given your consent.
B. The main legal bases for our processing are in particular:
1. Article 6(1)(b) GDPR (performance of a contract and pre-contractual measures), e.g. for processing your orders.
2. Article 6(1)(c) GDPR (compliance with legal obligations), e.g. commercial and tax retention obligations (in particular under Sections 147 AO and 257 HGB).
3. Article 6(1)(f) GDPR (legitimate interests), e.g. for the efficient organisation of our business operations, IT security and the defence of legal claims.
C. We only collect the data that is actually necessary for the respective purpose (data minimisation).
3. Data Processing for Orders via Etsy
3.1 Data we process
When you place an order via our Etsy shop, we typically process the following personal data:
• First and last name
• Delivery address
• Billing address, if provided by Etsy
• Email address, if provided by Etsy for order processing
• Order details (product, quantity, price, order number)
• Payment information: This is processed by the payment service providers used by Etsy; we only receive payment confirmations, not full payment details (e.g. full credit card numbers).
Legal basis: Article 6(1)(b) GDPR (performance of the contract).
3.2 Purpose of processing
We use the data mentioned above exclusively for the following purposes:
• Processing and handling your order (production, shipping, customer service)
• Fulfilling legal obligations, in particular tax and commercial retention obligations under Sections 147 AO and 257 HGB.
4. Use of External Service Providers (Processors)
We use specialised service providers to perform our services. These providers process personal data exclusively on our behalf and on the basis of a data processing agreement (DPA) in accordance with Article 28 GDPR.
These processors are in particular:
• Prodigi (print-on-demand / fulfilment)
• Billbee (order processing / inventory management & automation)
5. Prodigi (Print-on-Demand and Fulfilment Provider)
5.1 Role of Prodigi and contractual basis
For the production and shipment of your order, we use the specialised print-on-demand service provider Prodigi. Prodigi processes your personal data (in particular name, delivery address, order details) exclusively in accordance with our instructions and for no other purpose.
Prodigi acts as our processor within the meaning of Article 28 GDPR.
For this purpose, a Data Processing Addendum / data processing agreement exists, which is part of Prodigi’s contractual framework and which sets out, among other things, the scope and purposes of processing, security measures and international data transfers.
The typical data processed by Prodigi include in particular: recipient name, delivery address, where applicable email/telephone number for shipping, order and product details, artwork/images for printing, and technical information necessary to provide the services.
Legal basis: Article 6(1)(b) GDPR (performance of the contract).
5.2 Purposes of processing by Prodigi
Prodigi processes personal data exclusively to the extent necessary to provide its services, in particular for:
• Receiving and validating orders
• Routing orders to production facilities
• Production (printing) of products
• Packaging, shipping, delivery and potential reprints
• Handling complaints, returns and support requests
• Quality assurance and optimisation of production processes
• Fraud prevention and platform security
• Compliance with legal obligations (e.g. tax documentation)
Prodigi processes your personal data only on our documented instructions and is bound by confidentiality.
5.3 Production sites and third countries
Depending on the destination country, your order may be produced and shipped by different Prodigi production sites:
1. Netherlands (EU)
– Processing takes place within the EU; no additional transfer mechanism is required as EU data protection law applies directly.
2. United Kingdom (UK)
– For the UK, there is an adequacy decision by the European Commission dated 28 June 2021. Data transfers are therefore permissible under Article 45 GDPR without additional safeguards.
3. United States (USA)
– There is no adequacy decision by the European Commission for the United States with regard to Prodigi’s locations; Prodigi is not certified under the EU–US Data Privacy Framework.
– Transfers (name, delivery address, order details) therefore take place on the basis of the EU Commission’s Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR, which form part of the Data Processing Addendum.
– Prodigi is contractually obliged to process your data exclusively in line with our instructions and in accordance with the requirements of the GDPR.
Risk notice: The Standard Contractual Clauses do not bind US authorities. Therefore, it cannot be completely ruled out that US authorities may access the transferred data under certain legal conditions. If we become aware that Prodigi can no longer comply with the SCCs, we will immediately suspend the data transfer.
4. Australia
– There is likewise no adequacy decision by the European Commission for Australia.
– Transfers (name, delivery address, order details) therefore also take place on the basis of the EU Standard Contractual Clauses under Article 46(2)(c) GDPR, which contractually oblige Prodigi to process data in accordance with the GDPR.
– Again, public authority access cannot be fully excluded; if we become aware of non-compliance with the SCCs, we will suspend transfer.
Prodigi operates a global fulfilment network and may share data with group companies, production partners, logistics providers, hosting and technology providers, insofar as this is necessary to perform the services. These recipients are protected by appropriate contractual and organisational measures.
5.4 Security measures at Prodigi
Prodigi has implemented extensive technical and organisational measures to ensure an appropriate level of security, in particular with regard to:
• Access and access control (role-based access control, least privilege, regular review of permissions)
• Authentication, including multi-factor authentication for administrative access
• Confidentiality obligations for employees and service providers
• Encryption of data in transit over public networks and minimised data transmission to production partners
• Data minimisation in the fulfilment process (only necessary data are transmitted to production and logistics partners)
• Logical separation of customer accounts and environments (production, staging, internal)
• Logging and monitoring of production systems and administrative access
• Vulnerability and patch management, regular security updates
• Backup and restore procedures
• Supplier controls for sub-processors and fulfilment partners
5.5 Retention periods at Prodigi
Prodigi differentiates between the following retention periods:
• Production images and artwork files: stored only as long as necessary for production, quality assurance, reprints and support, then deleted or rendered inaccessible.
• Order and shipping records: retained as required for customer service, disputes, chargebacks, warranty, legal retention and tax law.
• Invoices and payment records: retained for the period required under accounting and tax law.
• Support tickets and correspondence: retained to ensure customer service, dispute handling and quality assurance.
• Operational, security and platform logs: retained for a limited period for security, fraud prevention and audit purposes.
• Backups: retained in line with standard backup cycles and then overwritten.
As a rule, we delete or anonymise your data once it is no longer required for the purposes described and no legal retention obligations apply.
6. Billbee (Order Processing, Inventory Management & Automation)
6.1 Role of Billbee and contractual basis
For internal order processing, inventory management and automation (e.g. invoicing, shipping labels, status notifications), we use the service provider Billbee. Billbee processes personal data exclusively on our behalf and in accordance with our documented instructions.
We have concluded a data processing agreement with Billbee in accordance with Article 28 GDPR. This agreement regulates, in particular, the subject matter, duration, nature and purpose of the processing, categories of data and data subjects, technical and organisational measures, and the use of sub-processors.
Legal basis: Article 6(1)(b) GDPR (performance of the contract) for order processing; in addition Article 6(1)(c) GDPR (legal obligations, e.g. accounting) and Article 6(1)(f) GDPR (efficient organisation of our business operations).
6.2 Scope of data processing by Billbee
According to Billbee’s data processing description, the following data categories are processed in particular:
• Basic personal data (e.g. name)
• Contact data (e.g. email address, telephone number)
• Contract data (order and contractual relationship, product or contract interest)
• Customer history (e.g. previous orders)
• Contract billing and payment data (e.g. invoice amounts, payment status; no full payment instruments processed via payment service providers)
• Item and order data (products, quantities, prices, order status)
• Buyer data (customers of the shop owner)
Billbee provides interfaces to online shops, marketplaces, accounting tools and shipping providers and processes the data for order handling, inventory management and automation.
6.3 Technical and organisational measures at Billbee
The data processing agreement with Billbee describes extensive technical and organisational measures pursuant to Article 32 GDPR, including in particular:
• Ensuring confidentiality, integrity, availability and resilience of systems
• Physical and logical access controls, e.g. firewalls, anti-virus software, spam filters, patch and vulnerability management
• Input control and logging, especially where multiple employee accounts are used
• Pseudonymisation and encryption for storage and transmission; data are transmitted and stored using state-of-the-art encryption methods
• Ensuring availability (backups, disaster recovery)
• Support with compliance with obligations under Articles 32–36 GDPR (security, data protection impact assessments, consultation of supervisory authorities)
• Appointment of an external data protection officer who can be contacted by data subjects or the controller (e.g. privacy@billbee.io)
Billbee uses sub-processors for infrastructure (e.g. cloud providers such as AWS, monitoring services such as Datadog). Where data is transferred to third countries, such transfers rely – where necessary – on appropriate safeguards, in particular the EU Standard Contractual Clauses under Article 46(2)(c) GDPR.
6.4 Support regarding data subject rights and deletion
Billbee supports us in fulfilling data subjects’ rights (access, rectification, erasure, restriction, data portability) through appropriate technical and organisational measures and forwards requests from data subjects directly to us as the controller where they are addressed to Billbee.
After termination of the contract or upon our instructions, Billbee deletes or returns personal data in line with the contractually agreed periods and legal retention obligations; exceptions apply only where Billbee itself is subject to statutory retention requirements.
7. Payment Service Providers
For payment processing, we use external payment service providers (e.g. credit card, PayPal, instant bank transfer and any further methods indicated during checkout).
These providers receive the data required for payment processing (e.g. name, billing address, payment data) and process them as separate controllers in accordance with their own privacy policies.
We generally only receive information as to whether a payment was successful (payment confirmation) and do not receive full payment details (e.g. full credit card numbers).
Legal basis: Article 6(1)(b) GDPR (performance of the purchase contract).
8. Retention Periods (at Our Company)
We store personal data only for as long as necessary for the respective purposes or for as long as legal retention obligations apply:
• Order data: 10 years (tax and commercial retention obligations under Sections 147 AO and 257 HGB).
• Communication data (e.g. emails): up to 3 years after completion of the matter (regular limitation period for contractual claims).
After these periods have expired, the data are routinely deleted or anonymised.
Prodigi and Billbee each store data in accordance with their own GDPR-compliant retention and deletion concepts, which take into account, inter alia, legal requirements and operational necessities (complaints, tax law, security).
9. Recipients of Personal Data
We transfer your personal data only where necessary for the purposes mentioned above or where a legal obligation exists:
• Print-on-demand service provider Prodigi (processor)
• Production and fulfilment partners of Prodigi (only necessary fulfilment data)
• Logistics, postal and shipping service providers (to deliver your order)
• Payment service providers (for payment processing, as separate controllers)
• Billbee (order handling, inventory management, automation, as processor)
• Cloud and hosting providers, IT service providers and other sub-processors of Prodigi and Billbee (e.g. infrastructure, monitoring), in each case on the basis of Article 28 GDPR and, where applicable, Article 46 GDPR (Standard Contractual Clauses)
• Tax advisors, lawyers and public authorities, where necessary, e.g. to comply with legal obligations or to assert or defend legal claims.
We do not transfer your personal data to third parties for their own marketing purposes. Prodigi does not sell customer data and does not use it for direct marketing to our customers.
10. Your Rights as a Data Subject
You have the following rights under the GDPR with respect to your personal data:
1. Right of access (Article 15 GDPR): You may request information about the personal data we hold about you.
2. Right to rectification (Article 16 GDPR): You may request the rectification of inaccurate data and the completion of incomplete data.
3. Right to erasure (Article 17 GDPR): You may request the deletion of your personal data where no statutory retention obligations or overriding legitimate interests prevent this.
4. Right to restriction of processing (Article 18 GDPR): You may request restriction of processing under the conditions laid down by law.
5. Right to data portability (Article 20 GDPR): You may request to receive the data concerning you in a structured, commonly used and machine-readable format or to have it transmitted to another controller, where technically feasible.
6. Right to object (Article 21 GDPR): You may object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(f) GDPR.
7. Right to withdraw consent (Article 7(3) GDPR): Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
To exercise your rights, please contact us at:
Email: contact@labellarosa-studios.com
11. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Article 77 GDPR).
The authority responsible for us is in particular:
Bavarian Data Protection Authority (BayLDA)
Promenade 18
91522 Ansbach
Germany
12. No Automated Decision-Making
We do not carry out automated decision-making, including profiling, within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
13. Use of the Etsy Platform
Our products are offered and sold via the Etsy marketplace (Etsy, Inc., 117 Adams Street, Brooklyn, NY 11201, USA).
Etsy processes your personal data (e.g. name, delivery address, payment data, communication via the Etsy messaging system) as an independent controller within the meaning of Article 4(7) GDPR, separate from our processing.
We have no influence over Etsy’s data processing; Etsy’s own privacy policy is decisive, which you can find in Etsy’s privacy documentation.
As Etsy is a US-based company, your data will be transferred to the United States when you use the Etsy platform. Etsy relies on the EU Standard Contractual Clauses under Article 46(2)(c) GDPR and, where applicable, the EU–US Data Privacy Framework to legitimise such transfers. Details can be found in Etsy’s privacy policy.
We recommend that you read Etsy’s privacy policy carefully before placing an order.
14. Updates and Changes to this Privacy Policy
This privacy policy is currently valid and has the status May 2026. It is based in particular on the data processing agreements concluded with Prodigi and Billbee as well as the technical and organisational measures currently in use.
As our Etsy shop develops further, we introduce new service providers or legal/administrative requirements change, it may become necessary to amend this privacy policy. The current version will be made available on our website and/or in our Etsy shop.
15. Important Note on Practical Implementation
For this privacy policy to be effective in practice, it is necessary that:
1. a valid data processing agreement including the applicable Standard Contractual Clauses exists with Prodigi and that the security and transfer mechanisms described therein are actually implemented;
2. a valid data processing agreement exists with Billbee, including the technical and organisational measures and any third-country transfers (Standard Contractual Clauses) described in the DPA;
3. the internal processes described here (e.g. deletion periods, handling of data subject rights, information duties) are actually followed in your business.
If any of these contracts, the service providers used or the actual processing operations change, this privacy policy must be updated accordingly.