Privacy Policy

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection regulations, is:

Artisans Effort
2/5 Tarapada Chatterjee Lane,
Howrah, West Bengal
India

Represented by: Arbaaz Jan
Email: artisans.effort@gmail.com
Phone: +91 9432580922

GSTIN: 19ADTPJ8722A1ZD

The management also acts as the contact point for data protection matters. Under Art. 37 GDPR and Section 38 of the German Federal Data Protection Act (BDSG), the company is currently not legally required to appoint a Data Protection Officer; this policy will be updated should that change.

2. General Information on Data Processing

2.1 Scope of processing

We only process personal data of our users and customers to the extent necessary to provide a functioning website and our content and services, or where a legal permission or your consent applies.

2.2 Legal bases

Where we obtain consent for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis. For processing necessary for the performance of a contract, Art. 6(1)(b) GDPR applies, including processing required for pre-contractual measures. Where processing is necessary to comply with a legal obligation, Art. 6(1)(c) GDPR applies. Where processing is necessary to protect our legitimate interests or those of a third party, and the interests, fundamental rights and freedoms of the data subject do not override those interests, Art. 6(1)(f) GDPR applies.

2.3 Erasure and storage period

Personal data is erased or restricted as soon as the purpose of storage no longer applies, unless statutory retention obligations require otherwise (in particular German commercial and tax law retention periods under Sections 257 HGB and 147 AO, generally six or ten years).

3. Provision of the Website and Creation of Log Files

Each time our website is accessed, our system automatically collects data and information from the accessing computer system (server log files), including: browser type and version, operating system used, referrer URL, host name of the accessing device, time of the server request, and the (where applicable, anonymised) IP address.

This data is stored to ensure the functionality of the website, to guarantee system security, and to optimise our offering. The legal basis is Art. 6(1)(f) GDPR. This data is deleted after no more than 6 months, unless retention is required for security purposes.

4. Contacting Us

When you contact us via our contact form or by email, the data you provide (name, email address, message text, and where applicable phone number and company details) is stored by us for the purpose of processing your enquiry and in case of follow-up questions.

The legal basis is Art. 6(1)(b) GDPR for enquiries related to entering into a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in efficiently handling enquiries) or Art. 6(1)(a) GDPR where consent was obtained. Data is deleted once it is no longer required to achieve the purpose for which it was collected, generally once the relevant matter has been conclusively resolved, and at the latest after 6 months.

6. Business Customer and B2B Enquiries

As part of our business activities (including import/export, wholesale, and supplier relationships), we process contact and business data of the contact persons of our business partners (name, company affiliation, business email address, phone number, address). The legal basis is Art. 6(1)(b) GDPR (establishing/conducting the business relationship) and Art. 6(1)(f) GDPR (legitimate interest in maintaining business relationships).

7. Newsletter

If you subscribe to our newsletter, we use the data required for this, or data you separately provide, to regularly send you our email newsletter based on your consent. Subscription follows a double opt-in process: after signing up, you will receive a confirmation email which you must confirm to complete your subscription. We log the subscription and confirmation to be able to demonstrate the subscription process.

We use the service Mailchimp (The Rocket Science Group, LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA) to send our newsletter. Your data may be transferred to the USA in this context; the provider has committed to appropriate safeguards (e.g. EU Standard Contractual Clauses and/or certification under the EU-U.S. Data Privacy Framework, where applicable). Further information can be found in Mailchimp's privacy notice.

The legal basis is your consent, Art. 6(1)(a) GDPR. You may withdraw your consent at any time, e.g. via the unsubscribe link in the newsletter or by emailing artisans.effort@gmail.com. The lawfulness of processing carried out prior to withdrawal remains unaffected.

8. Cookies and Website Analytics

8.1 Cookies

Our website uses cookies — small text files stored on your device. Technically necessary cookies (e.g. for the shopping cart or login) are used on the basis of Art. 6(1)(f) GDPR and Section 25(2) of the German Telecommunications-Telemedia Data Protection Act (TTDSG), as they are strictly necessary to provide the website. Non-essential cookies (e.g. for analytics and marketing) are only used with your consent under Section 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR, which you may grant or refuse via our consent banner.

8.2 Google Analytics

Subject to your consent, this website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses cookies that enable an analysis of your use of the website. The information generated by the cookie is generally transmitted to and stored on a Google server; IP anonymisation is enabled, so your IP address is shortened by Google within the EU/EEA beforehand.

The legal basis is your consent, Art. 6(1)(a) GDPR in conjunction with Section 25(1) TTDSG. You may withdraw your consent at any time via our website's cookie settings. A transfer to the USA cannot be entirely excluded; Google has committed to compliance with the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses. Further information: Google's privacy policy at policies.google.com/privacy.

9. Recipients and Categories of Recipients

Your personal data is only transferred to third parties where necessary for contract performance (e.g. payment service providers, shipping providers), where we are legally obliged to do so (e.g. tax authorities), or where you have given your consent. We also engage processors (e.g. hosting providers, email/newsletter service providers) under data processing agreements pursuant to Art. 28 GDPR.

10. International Data Transfers

Where we transfer data to service providers outside the EU/EEA (in particular the USA), this only occurs where an adequate level of data protection is ensured, whether through an adequacy decision of the EU Commission, appropriate safeguards such as the EU Standard Contractual Clauses (Art. 46 GDPR), or certification under the EU-U.S. Data Privacy Framework.

11. Your Rights as a Data Subject

Subject to the applicable statutory requirements, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on Art. 6(1)(f) GDPR, in particular the right to object to direct marketing (Art. 21 GDPR)
  • Right to withdraw any consent given, with effect for the future (Art. 7(3) GDPR)
  • Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)

To exercise your rights, please use the contact details given in Section 1. The supervisory authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian Commissioner for Data Protection and Freedom of Information), Postfach 3163, 65021 Wiesbaden, India, www.datenschutz.hessen.de.

12. Data Security

We use the widely accepted SSL/TLS encryption protocol combined with the highest level of encryption supported by your browser while you visit our website, and otherwise take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorised access.

13. Currency and Amendment of this Privacy Policy

This privacy policy is currently valid (as of: July 2026). As we develop our website and offerings further, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current version is always available on our website.

Last updated: July 2026

Need Help? Contact Us!