Privacy Policy

This Privacy Policy explains how PrintCraft Studio processes personal data in connection with its photo and art printing services, website use, consultations, file review, production, and collection arrangements. It applies to visitors, customers, and other individuals who interact with the studio through the website or related service channels.

Use of information
Handled under this policy framework
User rights
Requests and access options are described below
Support channel

Contact Information

Email contact
Telephone
+351 912 915 137
Postal address
Rua 26 de Dezembro 26, 2550 Cadaval
Privacy contact

Use the contact details below for privacy questions, requests, or complaints about this policy.

01

Data We Collect

We may process identification and contact details, order and file information, consultation notes, payment and billing records, delivery or collection details, and technical data such as device, browser, and usage information. Where a customer submits artwork or image files, we also process the content needed to review, prepare, and produce the requested print service.

The categories collected depend on the inquiry, order, or appointment requested.
02

Sources of Data

We collect personal data when a user submits an image print inquiry, uploads files, requests a consultation, asks for a test print quote, approves production, makes payment, or contacts us by email or other available channels. We may also receive limited technical data automatically when the website is used.

Most data comes directly from the customer or from the files and messages they send.
03

Types of Cookies

The website may use essential cookies to support core functions, preference cookies to remember selected settings, and analytics or performance cookies to understand how the site is used. Cookies may be session-based or persistent, depending on their purpose and duration.

We use only the cookie categories needed for operation, measurement, and preference handling.
04

Cookie Controls

Users may block or delete cookies through their browser settings. If the browser is configured to reject certain cookies, some site functions may not work as intended. Where a cookie banner or preference tool is available, users can use it to manage non-essential cookies.

Cookie choices can be adjusted through browser settings and, where available, site controls.
User Rights

Your Rights

Depending on the circumstances, individuals may have rights to access their data, correct inaccurate information, request deletion, object to certain processing, or ask for restriction of processing. Where processing is based on consent, that consent may be withdrawn for future processing without affecting prior lawful processing.

The availability of each right depends on the legal basis and the nature of the processing.
Requests

How to Make a Request

To exercise a privacy right, a person should provide enough information to identify the relevant record and the nature of the request. We may ask for additional details to confirm identity or to locate the correct file, especially where the request concerns order records, artwork files, or consultation history.

Requests are handled through the contact details listed in this policy.
Data Retention

Retention of Data

We keep personal data only for as long as needed for the relevant inquiry, order, accounting, dispute handling, or legal compliance purpose. After that period, data is deleted, anonymized, or archived with restricted access where retention is still required by law or for legitimate business records.

Retention depends on the purpose of the record and any legal obligation to keep it.
Policy Updates

Policy Updates

When we make material changes, we will update the policy text on the website and may provide additional notice where appropriate. The version in force is the one published at the time of use, unless a later effective date is stated.

We may revise this policy to reflect legal, operational, or technical changes.
GDPR

GDPR Overview

For GDPR purposes, PrintCraft Studio acts as the controller for personal data processed in connection with website inquiries, consultations, orders, production, collection, and related administration. Processing is based on the legal grounds described in this policy, including performance of a contract, compliance with legal obligations, legitimate interests, and consent where required.

Where GDPR applies, this policy explains how personal data is processed for users in the European Economic Area and, where relevant, other individuals protected by EU data protection rules.

This section is intended for GDPR-covered processing activities.
GDPR-aware data handling

GDPR Rights

Where GDPR applies, individuals may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent where processing relies on consent. A request may require verification of identity and may be limited where retention or disclosure is required by law or necessary for the establishment, exercise, or defense of legal claims.

GDPR rights are available subject to the conditions and limits set by law.
Processing category

Purposes of Processing

We use personal data to respond to inquiries, review files for basic technical suitability, prepare quotations, manage consultations, process orders and payments, coordinate production and collection, maintain business records, protect the website and our systems, and comply with legal obligations. Where a test print or proof is requested, we use the submitted files and related instructions to carry out that specific service.

Processing is limited to the operational needs of the studio and the website.
Third-party sharing

Service Providers

We may share personal data with payment processors, technical service providers, communication tools, and other operational partners that help us run the website, manage orders, process payments, or support file handling and record keeping. These parties are expected to use the data only for the services they provide to us and to apply appropriate confidentiality and security measures.

Service providers receive only the data needed to perform their assigned function.