oops, take me back!
Privacy Policy (Datenschutzerklärung)
honey & havens
Legal entity: Jessica Franov (sole proprietorship / Einzelunternehmerin)
Website: https://honeyhavens.eu
Email: hello@honeyhavens.eu
Address: 4/2 Rögergasse, 1090 Vienna, Austria
VAT/UID: not applicable
Last updated: 28.06.2026
1. Data Controller
The controller responsible for the processing of personal data within the meaning of Art. 4(7) GDPR is:
Jessica Franov
trading as honey & havens
Email: hello@honeyhavens.eu
Address: 4/2 Rögergasse, 1090 Vienna, Austria
This contact point serves as the primary channel for all data protection inquiries.
2. Scope and Purpose of This Website
This Privacy Policy applies to all processing of personal data when you:
Visit this website
Submit contact forms or enquiries
Book or receive photography services
Communicate via email or other channels
Access client galleries or deliverables (e.g. Pic-Time)
Interact with cookies, analytics, or embedded services
The website is used to provide information about photography services, facilitate enquiries and bookings, manage client relationships, and deliver digital photographic content.
3. Applicable Legal Framework
We process personal data in accordance with:
Regulation (EU) 2016/679 (GDPR)
Austrian Data Protection Act (DSG)
Austrian Telecommunications Act (TKG 2021) implementing the ePrivacy Directive (2002/58/EC)
4. Definitions
“Personal data” means any information relating to an identified or identifiable natural person (Art. 4 GDPR).
“Processing” means any operation performed on personal data.
5. Categories of Personal Data Processed
We process only data necessary for the purposes described below:
5.1 Identity and Contact Data
Name
Email address
Telephone number (if provided)
5.2 Contract and Service Data
Booking details
Session planning information and questionnaires
Communications relating to services
5.3 Payment and Accounting Data
Invoice data (name, billing address, services rendered)
Payment metadata via payment providers (we do not store full card details)
Accounting records required under Austrian tax law (BAO, UStG)
5.4 Photographic Data
Images produced during photography sessions
Associated metadata where technically embedded
5.5 Technical Data
IP address (temporarily for security and logs)
Browser type and version
Device and operating system
Access timestamps
Cookie identifiers
5.6 Usage Data
Page interactions
Navigation behaviour
Aggregated analytics events (where consented)
6. Methods of Data Collection
Personal data is collected when you:
Submit enquiries or forms
Communicate via email
Enter into a service agreement
Provide session information or questionnaires
Access client galleries
Browse the website (cookies and analytics tools)
No personal data is obtained from data brokers.
7. Purposes of Processing
We process personal data exclusively for:
Responding to enquiries and pre-contractual communication
Performance of photography services (Art. 6(1)(b) GDPR)
Booking, scheduling, and client management
Production, editing, and delivery of photographic works
Accounting, invoicing, and tax compliance
Website hosting, security, and technical operation
Analytics (only where consented)
Compliance with legal obligations
We process only data that is necessary for each purpose in accordance with the principle of data minimisation (Art. 5 GDPR).
8. Legal Bases for Processing
Processing is carried out under:
Art. 6(1)(b) GDPR – Contract performance (services, communication, delivery)
Art. 6(1)(c) GDPR – Legal obligations (tax, accounting retention)
Art. 6(1)(f) GDPR – Legitimate interests (secure website operation, abuse prevention, limited analytics)
Art. 6(1)(a) GDPR – Consent (optional cookies, analytics, promotional image use)
Where processing is based on legitimate interest, we ensure a balancing of interests in accordance with GDPR requirements.
Where processing is based on consent, you may withdraw consent at any time with future effect.
9. Photography and Image Processing
Photographs may constitute personal data where individuals are identifiable.
Images are:
Collected solely for contract fulfilment (Art. 6(1)(b))
Edited and delivered via secure client gallery systems
Stored only as long as necessary for service delivery and agreed retention periods
Accessible only to you and authorised service providers
9.1 Marketing and Portfolio Use
Photographs are only used for marketing, portfolio, website, or social media purposes where you have given explicit, informed, and separate consent via a dedicated opt-in at the time of enquiry or booking (Art. 6(1)(a) GDPR).
Consent is optional and not required to receive photography services. Consent may be withdrawn at any time with effect for future use.
10. Data Processors and Recipients
We use GDPR-compliant processors under Art. 28 GDPR, including:
Squarespace, Inc. (website hosting, infrastructure, security)
Pic-Time Ltd. (client galleries and image delivery)
Microsoft Corporation (Microsoft 365 email services)
Payment service providers (e.g. Stripe, PayPal)
Analytics/cookie providers (only where consented)
All processors are bound by Data Processing Agreements (DPAs) in accordance with Art. 28 GDPR.
No data is sold to third parties.
11. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), including the United States, such transfers are safeguarded by:
European Commission Standard Contractual Clauses (SCCs, 2021 version)
Additional technical and organisational measures in line with Schrems II requirements where applicable
12. Cookies and Similar Technologies
This website uses cookies in accordance with §165 TKG 2021 and the ePrivacy Directive.
12.1 Cookie Categories
Strictly necessary cookies (required for website operation)
Functional cookies (enhanced features)
Analytics cookies (only with explicit consent)
12.2 Consent Mechanism
Non-essential cookies are only activated after explicit opt-in consent via a cookie banner that is:
Freely given
Specific
Informed
Unambiguous
Consent can be modified or withdrawn at any time with equal ease to granting it.
13. Data Retention
We retain personal data only as long as necessary:
Enquiry data: up to 24 months unless a contract is concluded
Contract and client data: 7 years (Austrian tax law obligations under BAO/UStG)
Invoice and accounting data: 7 years (§132 BAO)
Photographic deliverables: duration of contract + agreed gallery availability period
Technical logs: up to 30 days unless required for security incidents
Analytics data: according to provider settings (often anonymised and time-limited)
After expiry, data is securely deleted or anonymised.
14. Data Security
We implement appropriate technical and organisational measures under Art. 32 GDPR, including:
TLS/HTTPS encryption
Access controls and authentication
Principle of least privilege
Secure backups
Processor security assessments where applicable.
No system is completely secure, but measures are designed to reduce risk to an appropriate level.
15. Data Subject Rights
You have the following rights under GDPR:
Access (Art. 15)
Rectification (Art. 16)
Erasure (Art. 17)
Restriction (Art. 18)
Data portability (Art. 20)
Objection (Art. 21)
Withdrawal of consent (Art. 7(3))
Requests may be sent to:
We respond within 30 days unless legally extended.
You also have the right to lodge a complaint with:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna, Austria
16. External Services and Embedded Content
Where external services are embedded (e.g. client galleries, payment systems), those providers may independently process personal data as separate controllers or processors under their own privacy policies.
17. Children’s Data
Services are not directed at individuals under 16 years of age. We do not knowingly collect data from minors.
18. Changes to This Policy
This Privacy Policy may be updated to reflect legal, technical, or operational changes. The latest version will always be available on this page.
19. Contact
honey & havens
Jessica Franov
Email: hello@honeyhavens.eu
Address: 4/2 Rögergasse, 1090 Vienna, Austria