Privacy Policy
Valid for www.beatrizherrera.de — Göttingen, Germany
I’m glad you are here. Your privacy matters deeply to me. This policy explains what data is collected, why it is collected, how it is used, and what your rights are under the EU General Data Protection Regulation (GDPR).
1. Controller
Beatriz Herrera Campo / Mini Atelier by Beatriz Herrera Eisenacher Str. 13 37085 Göttingen, Germany Email: contact@beatrizherrera.de Umsatzsteuer-ID: DE353975381
This website is operated by a self‑employed individual offering:
Custom illustration services
Original artworks
Mini Atelier handcrafted items
Digital illustration products
Producers Galerie offerings
2. Hosting (DM Solutions)
When you visit this website, the hosting provider automatically processes technical data in server log files:
IP address
Date and time of access
Browser type and version
Operating system
Referrer URL
Accessed pages
Amount of data transferred
Hostname of the accessing device
Purpose: secure and stable website operation Legal basis: Art. 6(1)(f) GDPR Retention: approx. 30 days
3. WordPress & Kadence Theme
This website runs on WordPress using the Kadence theme. WordPress processes technical data (e.g., IP address) to deliver the website. Kadence does not collect personal data.
4. Contact Form (Kadence Forms)
If you contact me through the contact form, I process:
Name
Email address
Message
Spam protection: honeypot (no Google reCAPTCHA). Purpose: responding to your inquiry Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR Retention: deleted after your request is fully processed
Messages are delivered via Solid Mail, which processes email metadata and content (Art. 6(1)(f) GDPR).
5. Newsletter (MailPoet)
If you subscribe to the newsletter, MailPoet processes:
Name
Email address
Subscription preferences
Double opt‑in is used. You may unsubscribe at any time. Legal basis: Art. 6(1)(a) GDPR
After unsubscribing, your email is removed from the mailing list and temporarily stored on a blacklist to prevent accidental re‑subscription.
6. WooCommerce (Shop Functionality)
If you purchase products or services, WooCommerce processes:
Name
Address
Email
Phone number
Payment information
IP address
Session data
Cart contents
WooCommerce uses functional cookies to enable cart and checkout functionality. Legal basis: Art. 6(1)(b) GDPR.
6.1 Payment Providers
Depending on your chosen payment method, data may be transferred to:
WooCommerce Payments (transaction data, billing details)
PayPal (payment details, billing information)
Google Pay (Google Ireland Ltd.)
Legal basis: Art. 6(1)(b) GDPR.
7. Jetpack (Stats & Security)
Jetpack modules are used for:
anonymized visitor statistics
brute force protection
IP checks
Jetpack may set functional cookies and process IP addresses. Legal basis: Art. 6(1)(f) GDPR.
8. GTranslate (Multilingual Functionality)
GTranslate processes:
IP addresses
Browser language
Translation requests
A language preference cookie may be set. Legal basis: Art. 6(1)(f) GDPR.
The free version loads a small Google Translate icon from fonts.gstatic.com, which may transmit your IP address to Google. If you prefer not to send this request, avoid using the language switcher.
9. Google Fonts (Local Hosting via OMGF)
Fonts (“Lora” and “Work Sans”) are hosted locally. No connection is made to Google Fonts. No personal data is transmitted to Google.
OMGF ensures fonts are stored and delivered locally. No personal data is transmitted to OMGF or third parties.
10. Twenty20 Before/After Plugin
Used to display comparison images. Processes image files and loads necessary scripts. Legal basis: Art. 6(1)(f) GDPR.
11. Kadence Security
11.1 Cookies
Kadence creates a functional cookie (itsec_interstitial_browser) to track login processes.
11.2 Security Logs
Logged conditionally:
IP address
User ID (logged‑in users)
Username (login attempts)
Logged during:
login attempts
logout requests
suspicious URL requests
content changes
password updates
Retention: 60 days
11.3 Data Sharing
For two‑factor authentication, a QR code is generated via a Kadence‑hosted API. Your username is sent to the API but not logged.
Kadence Site Scanner may detect publicly posted personal data (e.g., comments).
11.4 Distributed Brute Force Protection
Visitor IP addresses attempting login may be shared with solidwp.com. Legal basis: Art. 6(1)(f) GDPR.
12. Cookies (General Statement)
This website uses functional cookies required for:
WooCommerce
Jetpack
GTranslate
WordPress session handling
No marketing or tracking cookies are used unless explicitly activated. You may disable cookies in your browser, but some functions may not work correctly.
13. External Links
This website contains links to external platforms:
Adobe Portfolio
Facebook
Instagram
YouTube
Pinterest
LinkedIn
These providers process personal data independently. I am not responsible for their data processing practices.
14. Your Rights (GDPR)
You have the right to:
Access your data
Rectify incorrect data
Request deletion
Restrict processing
Object to processing
Data portability
Lodge a complaint
Contact: contact@beatrizherrera.de
15. Data Deletion
Personal data is deleted when no longer required, unless legal retention obligations apply.
16. Changes to This Privacy Policy
This privacy policy may be updated to reflect changes in legal requirements or website functionality. Please check this page regularly.
Last updated: 02.09.2026
