Last updated:
This policy explains what personal information luiza.art collects, why, how long it is kept and what you can ask us to do with it. The studio collects very little: what you type into a form, what is needed to ship a painting you bought, and — only if you agree — anonymous statistics about which pages are visited.
1.Who is responsible for your data
Luiza's Art, the studio of Luiza Gjuzi in Durrës, Albania, is the data controller for the information described here. There is no separate company, marketing department or data broker involved — the studio is one artist and this website.
For anything about your personal data, write to [email protected]. That address reaches Luiza directly.
2.What we collect
We only hold information you have given us or that your browser sends automatically as part of loading a page:
- Contact form — your name, email address, phone number if you enter one, and your message.
- Review form — your name, email address, star rating and the text of your review.
- Purchases — your name, email address and delivery address, together with the order reference, amount, currency, transaction reference and payment status reported by our payment provider. Card and bank details are handled by the payment provider and never reach this website.
- Technical information — the IP address your request came from, and the usual request details such as browser type and the page requested, which are written to short-lived server logs.
- Cookies — a small number of cookies, described in our Cookie Policy.
- Language choice — the language you pick from the switcher, stored in a cookie in your own browser.
3.Why we use it, and our legal basis
Under the GDPR we have to have a specific reason for each use of your data. Ours are:
- To answer your enquiry — because you asked us to get in touch, which is our legitimate interest in replying to people who contact the studio.
- To take payment, ship your painting and deal with returns — because this is necessary to perform the sales contract between us.
- To keep accounting and tax records of sales — because we are legally required to.
- To publish your review — on the basis of your consent, given when you submitted it, which you can withdraw at any time.
- To stop spam and abuse of our forms — our legitimate interest in keeping the site usable. We count submissions per IP address for one hour to do this.
- To measure how the site is used — only with your consent, through Google Analytics.
4.Cookies and analytics
Cookies that are not strictly necessary are set only after you accept them. Google Analytics does not load at all until you do, and if you decline, or later change your mind, its cookies are deleted from your browser.
Our Cookie Policy lists every cookie the site uses, what it is for and how long it lasts, and has a button that lets you change your choice at any time.
5.Who else sees your data
We do not sell your personal data, and we do not share it for anyone else's advertising. A small number of service providers process it on our behalf so the site can function:
- Paysera — processes card and bank payments and tells us the outcome. Paysera is a licensed payment institution and handles your payment details under its own privacy policy.
- Our email provider — carries the messages that form submissions and order confirmations are sent through.
- Our hosting and infrastructure — the servers, database, file storage and cache that run this site, all operated by the studio on infrastructure it controls rather than on a third-party content platform.
- Google Analytics — receives usage statistics, and only if you have accepted analytics cookies.
6.Where your data is stored
Your data is held in a database and file storage that the studio runs itself, rather than being spread across third-party marketing services.
Some of the providers above, including Google Analytics, may process data outside the European Economic Area. Where that happens, the transfer relies on the safeguards those providers put in place for international transfers, such as the European Commission's standard contractual clauses.
If you would like to know exactly where your data sits before you buy, email us and we will tell you.
7.How long we keep it
We keep personal data only as long as it is useful for the purpose it was collected for, or as long as the law requires:
- Contact enquiries — up to 24 months after our last exchange, so we can pick up an earlier conversation.
- Reviews — until you ask us to remove yours, or we take it down. Reviews that are never approved are deleted.
- Sales records — for as long as accounting and tax law requires us to keep them, which is normally several years after the sale.
- Rate-limiting counters — one hour, then they expire automatically.
- Server logs — a short rolling window, then overwritten.
- Analytics data — retained by Google Analytics according to its own retention setting, which we keep to the shortest practical period.
- Your cookie choice — 12 months, after which we ask again.
8.Your rights
Wherever you live, we will handle these requests to GDPR standards. You can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong or out of date.
- Delete your data, where we do not have to keep it for legal reasons such as sales records.
- Restrict or object to a particular use, including anything based on our legitimate interests.
- Provide your data in a portable, machine-readable form.
- Withdraw consent you have given, such as for a published review or for analytics cookies. Withdrawing consent does not affect what was lawful before you withdrew it.
9.How to exercise your rights
Email [email protected] and say what you would like us to do. We will reply within one month. There is no charge, and we do not need you to use any particular form of words.
We may ask you to confirm something only you would know about your order or your message, so we do not hand your data to somebody else.
10.Keeping your data safe
The site is served over HTTPS, so what you send is encrypted in transit. Access to the database and to the studio's admin area is limited to the artist, protected by a password stored only as a strong hash, and admin sessions are held in cookies that scripts in your browser cannot read.
No system is perfectly secure. If a breach ever affects your personal data and puts you at risk, we will tell you and the relevant supervisory authority as the law requires.
11.Children
This site is not aimed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us their details, email us and we will delete them.
12.No automated decision-making
We do not profile you and we do not make any decision about you by automated means. The only automated rule on the site counts form submissions per IP address to block spam, and it never affects an order.
13.Changes and how to complain
If this policy changes we will update the date at the top of this page, and for anything significant we will say so on the site.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to a data protection authority: in Albania the Information and Data Protection Commissioner, or, if you live in the European Union or the EEA, the supervisory authority for the country you live in.