oops, take me back!

Privacy Policy (Datenschutzerklärung)

honey & havens

Legal entity: Jessica Franov (sole proprietorship / Einzelunternehmerin)

Website: https://honeyhavens.eu

Email: hello@honeyhavens.eu

Address: 4/2 Rögergasse, 1090 Vienna, Austria

VAT/UID: not applicable

Last updated: 28.06.2026

1. Data Controller

The controller responsible for the processing of personal data within the meaning of Art. 4(7) GDPR is:

Jessica Franov

trading as honey & havens

Email: hello@honeyhavens.eu

Address: 4/2 Rögergasse, 1090 Vienna, Austria

This contact point serves as the primary channel for all data protection inquiries.

2. Scope and Purpose of This Website

This Privacy Policy applies to all processing of personal data when you:

  • Visit this website

  • Submit contact forms or enquiries

  • Book or receive photography services

  • Communicate via email or other channels

  • Access client galleries or deliverables (e.g. Pic-Time)

  • Interact with cookies, analytics, or embedded services

The website is used to provide information about photography services, facilitate enquiries and bookings, manage client relationships, and deliver digital photographic content.

3. Applicable Legal Framework

We process personal data in accordance with:

  • Regulation (EU) 2016/679 (GDPR)

  • Austrian Data Protection Act (DSG)

  • Austrian Telecommunications Act (TKG 2021) implementing the ePrivacy Directive (2002/58/EC)

4. Definitions

“Personal data” means any information relating to an identified or identifiable natural person (Art. 4 GDPR).

“Processing” means any operation performed on personal data.

5. Categories of Personal Data Processed

We process only data necessary for the purposes described below:

5.1 Identity and Contact Data

  • Name

  • Email address

  • Telephone number (if provided)

5.2 Contract and Service Data

  • Booking details

  • Session planning information and questionnaires

  • Communications relating to services

5.3 Payment and Accounting Data

  • Invoice data (name, billing address, services rendered)

  • Payment metadata via payment providers (we do not store full card details)

  • Accounting records required under Austrian tax law (BAO, UStG)

5.4 Photographic Data

  • Images produced during photography sessions

  • Associated metadata where technically embedded

5.5 Technical Data

  • IP address (temporarily for security and logs)

  • Browser type and version

  • Device and operating system

  • Access timestamps

  • Cookie identifiers

5.6 Usage Data

  • Page interactions

  • Navigation behaviour

  • Aggregated analytics events (where consented)

6. Methods of Data Collection

Personal data is collected when you:

  • Submit enquiries or forms

  • Communicate via email

  • Enter into a service agreement

  • Provide session information or questionnaires

  • Access client galleries

  • Browse the website (cookies and analytics tools)

No personal data is obtained from data brokers.

7. Purposes of Processing

We process personal data exclusively for:

  • Responding to enquiries and pre-contractual communication

  • Performance of photography services (Art. 6(1)(b) GDPR)

  • Booking, scheduling, and client management

  • Production, editing, and delivery of photographic works

  • Accounting, invoicing, and tax compliance

  • Website hosting, security, and technical operation

  • Analytics (only where consented)

  • Compliance with legal obligations

We process only data that is necessary for each purpose in accordance with the principle of data minimisation (Art. 5 GDPR).

8. Legal Bases for Processing

Processing is carried out under:

  • Art. 6(1)(b) GDPR – Contract performance (services, communication, delivery)

  • Art. 6(1)(c) GDPR – Legal obligations (tax, accounting retention)

  • Art. 6(1)(f) GDPR – Legitimate interests (secure website operation, abuse prevention, limited analytics)

  • Art. 6(1)(a) GDPR – Consent (optional cookies, analytics, promotional image use)

Where processing is based on legitimate interest, we ensure a balancing of interests in accordance with GDPR requirements.

Where processing is based on consent, you may withdraw consent at any time with future effect.

9. Photography and Image Processing

Photographs may constitute personal data where individuals are identifiable.

Images are:

  • Collected solely for contract fulfilment (Art. 6(1)(b))

  • Edited and delivered via secure client gallery systems

  • Stored only as long as necessary for service delivery and agreed retention periods

  • Accessible only to you and authorised service providers

9.1 Marketing and Portfolio Use

Photographs are only used for marketing, portfolio, website, or social media purposes where you have given explicit, informed, and separate consent via a dedicated opt-in at the time of enquiry or booking (Art. 6(1)(a) GDPR).


Consent is optional and not required to receive photography services. Consent may be withdrawn at any time with effect for future use.

10. Data Processors and Recipients

We use GDPR-compliant processors under Art. 28 GDPR, including:

  • Squarespace, Inc. (website hosting, infrastructure, security)

  • Pic-Time Ltd. (client galleries and image delivery)

  • Microsoft Corporation (Microsoft 365 email services)

  • Payment service providers (e.g. Stripe, PayPal)

  • Analytics/cookie providers (only where consented)

All processors are bound by Data Processing Agreements (DPAs) in accordance with Art. 28 GDPR.

No data is sold to third parties.

11. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), including the United States, such transfers are safeguarded by:

  • European Commission Standard Contractual Clauses (SCCs, 2021 version)

  • Additional technical and organisational measures in line with Schrems II requirements where applicable

12. Cookies and Similar Technologies

This website uses cookies in accordance with §165 TKG 2021 and the ePrivacy Directive.

12.1 Cookie Categories

  • Strictly necessary cookies (required for website operation)

  • Functional cookies (enhanced features)

  • Analytics cookies (only with explicit consent)

12.2 Consent Mechanism

Non-essential cookies are only activated after explicit opt-in consent via a cookie banner that is:

  • Freely given

  • Specific

  • Informed

  • Unambiguous

Consent can be modified or withdrawn at any time with equal ease to granting it.

13. Data Retention

We retain personal data only as long as necessary:

  • Enquiry data: up to 24 months unless a contract is concluded

  • Contract and client data: 7 years (Austrian tax law obligations under BAO/UStG)

  • Invoice and accounting data: 7 years (§132 BAO)

  • Photographic deliverables: duration of contract + agreed gallery availability period

  • Technical logs: up to 30 days unless required for security incidents

  • Analytics data: according to provider settings (often anonymised and time-limited)

After expiry, data is securely deleted or anonymised.

14. Data Security

We implement appropriate technical and organisational measures under Art. 32 GDPR, including:

  • TLS/HTTPS encryption

  • Access controls and authentication

  • Principle of least privilege

  • Secure backups

  • Processor security assessments where applicable.

No system is completely secure, but measures are designed to reduce risk to an appropriate level.

15. Data Subject Rights

You have the following rights under GDPR:

  • Access (Art. 15)

  • Rectification (Art. 16)

  • Erasure (Art. 17)

  • Restriction (Art. 18)

  • Data portability (Art. 20)

  • Objection (Art. 21)

  • Withdrawal of consent (Art. 7(3))

Requests may be sent to:

hello@honeyhavens.eu

We respond within 30 days unless legally extended.

You also have the right to lodge a complaint with:

Austrian Data Protection Authority (Datenschutzbehörde)

Barichgasse 40–42, 1030 Vienna, Austria

https://www.dsb.gv.at

16. External Services and Embedded Content

Where external services are embedded (e.g. client galleries, payment systems), those providers may independently process personal data as separate controllers or processors under their own privacy policies.

17. Children’s Data

Services are not directed at individuals under 16 years of age. We do not knowingly collect data from minors.

18. Changes to This Policy

This Privacy Policy may be updated to reflect legal, technical, or operational changes. The latest version will always be available on this page.

19. Contact

honey & havens

Jessica Franov

Email: hello@honeyhavens.eu

Address: 4/2 Rögergasse, 1090 Vienna, Austria