Privacy policy
GDPR-compliant, no tracking, no third-party cookies
1. Controller
Antiquitäten-Haus Heymann GmbH
Elisabethenstraße 58, 64283 Darmstadt, Germany
E-mail: info@antik-heymann.de · Phone: +49 6151 997032
2. Hosting and server log files
This website is hosted by webgo GmbH, Heidenkampsweg 81, 20097 Hamburg, Germany.
The hosting provider processes personal data (e.g. IP address, date and time of access, pages accessed, referrer URL, browser type and operating system) in server log files in order to ensure secure and stable operation of the website.
Legal basis: Art. 6(1)(f) GDPR. A data processing agreement (DPA) under Art. 28 GDPR is in place.
3. Contact and enquiries
If you contact us (e.g. by e-mail, phone, WhatsApp or via a form), we process the information you provide in order to handle your request.
Data we may collect: name, e-mail address, phone number, message content and optionally uploaded photos.
Legal basis:
- Art. 6(1)(b) GDPR (pre-contractual / contractual communication)
- Art. 6(1)(a) GDPR (consent for online forms)
Retention:
- deletion after the request is closed,
- at the latest after 90 days (general enquiries, purchase enquiries, product enquiries),
- at the latest after 6 months (restoration enquiries, since these projects are often confirmed only months later).
For abuse protection we additionally store the IP address and a timestamp on form submissions (Art. 6(1)(f) GDPR). This metadata is deleted no later than 30 days.
WhatsApp: we additionally offer WhatsApp (WhatsApp Ireland Limited) as a contact channel. When used, personal data (in particular phone number and message content) may be transmitted to WhatsApp. Transfer to third countries (e.g. USA) cannot be ruled out. Use is voluntary and based on your consent (Art. 6(1)(a) GDPR).
4. Use of AI services (visualisation and processing)
For room visualisations and to support the processing of enquiries we use AI services (in particular OpenAI and Anthropic, USA).
Texts and images may be transmitted in the process. To minimise personal data, texts are automatically pseudonymised before transmission (e.g. names, e-mail addresses and contact details are replaced by placeholders).
Images cannot be anonymised technically. We therefore ask you not to include people or identifiable personal items in uploaded photos.
Legal basis: Art. 6(1)(a) or (b) GDPR. OpenAI is certified under the EU-US Data Privacy Framework (DPF). For Anthropic, we rely on EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Both providers process data solely to deliver the respective service and do not use it to train their models (API use).
Retention: AI-related content (e.g. uploaded photos for room visualisations) is deleted no later than 90 days.
5. Payment processing (Stripe)
For certain paid services we use Stripe (Stripe Payments Europe Ltd., Ireland).
When you make a payment, the payment data required is transmitted directly to Stripe. Legal basis: Art. 6(1)(b) GDPR.
Stripe may transfer data to the USA. Stripe is certified under the EU-US Data Privacy Framework.
Retention: invoice and payment data is stored for 10 years in line with statutory requirements (HGB / AO). Personal content from the service itself (descriptions, photos) is deleted after 6 months.
6. Cookies and technical functions
We use exclusively one strictly necessary session cookie to ensure the functionality of the website (e.g. CSRF protection and technical processes). Legal basis: § 25 (2) no. 2 TDDDG.
No tracking or analytics tools are used. There is no analysis of your user behaviour for marketing purposes.
7. Retention (general)
Personal data is deleted as soon as the purpose for processing no longer applies, unless statutory retention obligations require further storage.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection.
You may withdraw any consent given at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority.
9. Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
10. Data security
This website uses SSL/TLS encryption (HTTPS).
11. Updates
We reserve the right to update this privacy policy if technical or legal conditions change.