Privacy Policy
1. Identity of the Data Controller
At Finditstudis, safeguarding our horticulture community's digital transparency and data security is a core pillar. This statement documents the nature of personal processing, telemetry collection, and your individual rights when utilizing our directory platform at www.finditstudis.garden.
The responsible Data Controller for processing activities under European Union General Data Protection Regulation (GDPR) mandates is:
Finditstudis Digital Services GmbH
Botanical Lane 42, 10115 Berlin, Germany
E-Mail: [email protected]
Data Protection Officer: [email protected]
2. Server Log Files & Technical Processing
When you access our platform, our hosting infrastructure automatically gathers technical indicators transmitted by your browser. We process this basic network telemetry to detect hacking attempts, mitigate distributed denial of service (DDoS) vectors, analyze performance errors, and verify layout responsiveness.
This technical log array processes the following variables:
- IP Address of the requesting hardware device
- Date and precise timestamp of access
- Referrer URL (the previous page from which you navigated to us)
- Requested directory pages, images, or document URIs
- Operating system, user-agent details, browser brand, and software version
Legal Basis: Art. 6(1)(f) GDPR (Our legitimate interest in maintaining a stable, virus-free, secure web directory).
3. Interactive Inquiries & Booking Forms
When utilizing our platform's contact form, listing portals, or workshop reservation simulators, we process personal contact elements. We store this input directly in safe database environments to successfully transmit your reservations, establish customer files, or reply to administrative issues.
The processing scope contains: full name, corporate botanical credentials (for studio owners), email address, telephone numbers, and selected session parameters. These are preserved for the lifespan of your account, or until deletion is formally requested.
Legal Basis: Art. 6(1)(b) GDPR (Processing is necessary for the performance of a contract or preliminary pre-contractual requests).
4. Newsletter & Email Marketing Sequences
If you subscribe to "The Sprout" newsletter list, we log your email address, submission origin, and consent confirmation. We implement a rigorous Double Opt-In (DOI) verification protocol to protect users from fraudulent registrations. You have the total legal right to unsubscribe or update your contact options at any moment by utilizing the unsubscribe button integrated in the footers of all directory communications.
To optimize our publication structures, our templates contain a tiny tracking pixel. This records whether newsletters are opened, and which internal horticulturist links are clicked. This diagnostic is anonymized and never combined with specific profile indicators.
Legal Basis: Art. 6(1)(a) GDPR (Your explicit, voluntary consent).
5. External Services, Hosting, & Third-Party Processors
To run our operations, we rely on third-party service providers (Data Processors) under strict data protection agreements. Data is hosted within highly secure European data centers compliant with ISO 27001 data safety practices.
These third parties include:
- Cloud hosting providers and content delivery networks (CDNs)
- Email dispatch systems and customer relationship managers
- Anonymized analytical telemetry tools (Google Analytics, Plausible)
We do not transfer data to third parties outside of the European Economic Area (EEA) unless a valid adequacy decision by the European Commission is in place, or the processor guarantees compliance via Standard Contractual Clauses (SCCs).
6. Security and SSL/TLS Encryption
To prevent intercepted transmission or access, finditstudis.garden enforces SSL (Secure Sockets Layer) and TLS (Transport Layer Security) data protection algorithms across all site processes. You can identify active security protocols by the padlock symbol and the prefix "https://" displayed in your browser’s URL bar. Data sent through our contact portals cannot be read by third parties while in transit.
7. Your Universal Legal Rights (GDPR)
If you reside within the European Economic Area, you hold extensive rights regarding your data variables. You can easily invoke these options by sending an explicit request to our Data Protection Officer:
- Right to Access (Art. 15 GDPR): You have the absolute right to request confirmation of whether we process your data and receive a complete inventory file detailing all records.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete credentials stored in our database.
- Right to Erasure / Right to be Forgotten (Art. 17 GDPR): Request complete, structural deletion of your account records.
- Right to Restriction of Processing (Art. 18 GDPR): Request that we suspend processing your variables while maintaining storage during ongoing legal or identity disputes.
- Right to Data Portability (Art. 20 GDPR): Request transfer of your data files in a modern, machine-readable format.
- Right to Object (Art. 21 GDPR): Object to processing activities based on legitimate interests or direct marketing pipelines.
- Right to Lodge a Complaint: You have the legal right to report our platform’s processing habits to a local regulatory supervisory authority within your country or state.
8. California Consumer Privacy Rights (CCPA / CPRA)
If you are a resident of California, the CCPA and CPRA grant you additional protective rights. Finditstudis does not sell your personal data, nor share it with third parties for cross-context behavioral advertising purposes. You have the right to request disclosure of the specific categories of personal information collected, the right to delete that information, the right to opt-out of sharing (if ever initiated), and the right to non-discrimination for exercising these privacy choices.