Privacy Policy
Your privacy matters to us. This policy explains what data we collect, why we collect it, and the rights you have over it.
VT Photo Workplace Inc. (“VT Photo,” “we,” “us,” or “our”) operates the website vtphotoworkplace.com and related services. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our website, book studio workplaces, subscribe to our newsletter, or otherwise interact with our platform.
By using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
1.Information We Collect
1.1 Information You Provide Directly
- Account information: Name, email address, and password when you create an account.
- Contact forms: Name, email, and message content when you contact us.
- Studio bookings: Booking details, preferred dates, location preferences, and payment information.
- Newsletter subscriptions: Email address and communication preferences.
- Community participation: Profile information, photos, comments, and forum posts you choose to share.
1.2 Information Collected Automatically
- Device data: Browser type, operating system, device identifiers, and screen resolution.
- Usage data: Pages visited, time spent on pages, click paths, referring URLs, and search queries.
- Location data: Approximate geographic location derived from your IP address.
- Cookies and similar technologies: See Section 5 for details.
1.3 Information From Third Parties
We may receive information from payment processors (e.g., Stripe) to confirm transactions, from analytics providers (e.g., Google Analytics) to understand site usage, and from social media platforms if you choose to link your accounts.
2.How We Use Your Information
We use the information we collect for the following purposes:
- Provide services: Process studio bookings, deliver tutorials, and manage your account.
- Communications: Send booking confirmations, newsletters, and respond to inquiries.
- Improvement: Analyze usage patterns to improve content, features, and user experience.
- Security: Detect and prevent fraud, abuse, and unauthorized access.
- Legal compliance: Fulfill legal obligations and enforce our Terms of Service.
- Marketing: With your consent, send promotional emails about new tutorials, gear reviews, and studio offers. You can unsubscribe at any time.
3.Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
| Legal Basis | Examples |
|---|---|
| Contractual necessity | Processing bookings, managing your account |
| Consent | Newsletter subscriptions, marketing emails, non-essential cookies |
| Legitimate interests | Site analytics, fraud prevention, improving our services |
| Legal obligation | Tax records, responding to lawful government requests |
6.Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
- Account data: Retained while your account is active and for 30 days after deletion request.
- Booking records: Retained for 7 years for tax and legal compliance.
- Newsletter subscriptions: Retained until you unsubscribe.
- Analytics data: Aggregated and anonymized after 26 months.
- Contact form submissions: Retained for 12 months, then deleted.
7.Data Security
We implement industry-standard technical and organizational measures to protect your data:
- All data transmitted between your browser and our servers is encrypted via TLS 1.3.
- Passwords are hashed using bcrypt with per-user salts — we never store plaintext passwords.
- Payment information is processed by PCI DSS-compliant payment processors and never touches our servers.
- Access to personal data is restricted to authorized personnel on a need-to-know basis.
- We conduct regular security audits and vulnerability assessments.
While no system is 100% secure, we are committed to protecting your data and will notify affected users within 72 hours in the event of a data breach, as required by GDPR.
8.Your Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data (“right to be forgotten”).
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: Withdraw consent at any time without affecting prior processing.
To exercise any of these rights, contact us at our contact page or email privacy@vtphotoworkplace.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9.Your Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:
- Right to know: Request details about the categories and specific pieces of personal information we have collected.
- Right to delete: Request deletion of personal information we have collected from you.
- Right to opt-out: Opt out of the “sale” of personal information. Note: we do not sell personal data.
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, email us at privacy@vtphotoworkplace.comwith the subject line “CCPA Request.” We will verify your identity and respond within 45 days.
10.International Data Transfers
VT Photo Workplace is headquartered in Germany. If you access our services from outside the European Economic Area, your data may be transferred to and processed in countries with different data protection laws. We ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) and adequacy decisions, to protect your data during international transfers. Our primary hosting provider (Vercel) maintains SOC 2 Type II certification and adheres to EU-U.S. data transfer frameworks.
11.Children’s Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child under 16 has provided us with personal information, please contact us immediately at privacy@vtphotoworkplace.com and we will take steps to delete the data promptly.
12.Third-Party Links
Our website may contain links to third-party websites, including gear affiliate links, social media platforms, and partner services. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any personal information. Links to third-party sites do not constitute an endorsement of their privacy practices.
13.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the “Last updated” date at the top of this page and, where appropriate, by sending an email notification. We encourage you to review this page periodically for the latest information. Your continued use of our services after changes are posted constitutes your acceptance of the updated policy.
14.Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you can reach us through:
VT Photo Workplace Inc.
📧 privacy@vtphotoworkplace.com
📍 Kreuzbergstraße 36, 10965 Berlin, Germany
📞 +1 (555) 012-3456