Privacy Policy

1. Data Controller

Starup Photography – Charlotte Starup
Petersbrunner Str. 17a
82319 Starnberg, Germany
Phone: +49 173 346 7454
Email: info@starupphoto.com
Website: www.starupphoto.com

2. Purposes & Legal Bases of Data Processing (Art. 6 GDPR)

Website operation & security
(Server logs, technical functions) – Legitimate interest (Art. 6(1)(f) GDPR)

Appointment scheduling & contact requests
– Contract / pre-contractual measures (Art. 6(1)(b) GDPR)

Newsletter dispatch
– Consent (Art. 6(1)(a) GDPR)

Statistics & marketing
– Consent (Art. 6(1)(a) GDPR)

3. Server Log Files

When you visit our website, data is automatically collected:

IP address (shortened/anonymised)

Date/time of access

Browser type/version

Operating system

Referrer URL

Legal basis: Art. 6(1)(f) GDPR (secure website operation).
Storage duration: typically 7–30 days.

4. Services Used

Hosting
Our website is hosted by a German provider (e.g., IONOS). A data processing agreement (Art. 28 GDPR) is in place.

Google Analytics 4
We use Google Analytics 4 for reach measurement with IP anonymisation.
Provider: Google Ireland Ltd.
Data transfers to the USA are based on Standard Contractual Clauses (SCCs).
Processing begins only after consent (cookie banner).
???? Opt-out: Google Browser Add-on

Google Ads / Remarketing
Cookies for personalised advertising are set only with consent.
Provider: Google Ireland Ltd.

Meta / Facebook Pixel
Used to measure the performance of advertisements.
Provider: Meta Platforms Ireland Ltd.
Data transfer to the USA based on SCCs.
Only active with consent.

Mailchimp (Newsletter)
For newsletters we use Mailchimp (The Rocket Science Group LLC, USA).

Double opt-in procedure

Data transfer to the USA based on SCCs
Legal basis: Consent

Instagram & YouTube Embeds
Embedded content from Instagram or YouTube may appear on our site.
Data is transferred to the providers only if you have agreed to this beforehand.

5. Cookies & Consent Management

We use cookies and similar technologies.

Types of cookies:

Essential – required for website functionality

Statistics – Google Analytics 4 (only with consent)

Marketing – e.g., Google Ads, Meta Pixel (only with consent)

External media – Instagram/YouTube (only with consent)

You can change or withdraw your consent at any time via the cookie banner.

6. Contacting Us

When you contact us by email or form, your data is used solely to process your request.

Legal basis: Art. 6(1)(b) GDPR (contract/pre-contract measures) or
Art. 6(1)(f) GDPR (general enquiries).

7. Storage Periods

Server logs: 7–30 days

Contract/payment data: legal retention periods (6–10 years)

Newsletter data: until consent is withdrawn

Cookies: as listed in the cookie banner

8. Your Rights

You have the right to:

Access (Art. 15 GDPR)

Rectification (Art. 16 GDPR)

Erasure (Art. 17 GDPR)

Restriction of processing (Art. 18 GDPR)

Data portability (Art. 20 GDPR)

Object (Art. 21 GDPR)

Withdraw consent (Art. 7(3) GDPR)

Right to lodge a complaint:
Bavarian Data Protection Authority (BayLDA)
Promenade 18, 91522 Ansbach, Germany

9. Data Security

Our website is secured with TLS/SSL encryption.
We implement technical and organisational measures in accordance with Art. 32 GDPR to protect your data from loss, manipulation, or unauthorised access.

10. Version

This Privacy Policy is effective as of 11 September 2025.
Updates due to new services or legal requirements will be published here.