1. Home
      2. G.D.P.R. Compliance

      GDPR Compliance &
      Data Privacy Notice

      Last revised: April 2025Effective: Upon publicationJurisdiction: European Union

      This notice describes how this website collects, processes, and retains data in connection with its operation. All processing activities are conducted in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation). Please review each section for details applicable to specific services and their respective legal bases.

      Contents

      1. 1Scope and Data Controller
      2. 2Analytics Google Analytics (gtag.js)
      3. 3Error Monitoring Sentry
      4. 4Payment Processing PayPal and Stripe
      5. 5Local Storage
      6. 6Session-Based Authentication (HTTP-Only Cookie)
      7. 7Data Retention
      8. 8Rights of Data Subjects
      9. 9Amendments to This Notice
      1Scope and Data Controller▾

      This Data Privacy Notice ("Notice") governs the collection, processing, and retention of personal and technical data by this website. It has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "General Data Protection Regulation" or "GDPR"), as well as any applicable national implementing legislation.

      The operator of this website acts as the data controller in respect of all personal data processed as described herein. For the purposes of this Notice, "data subject" refers to any natural person whose data is processed through the use of this website.

      Should you wish to exercise any of your rights under applicable data protection law, or require clarification as to the nature of any data processing activity described below, please contact us via the designated contact page.

      2Analytics Google Analytics (gtag.js)▾

      This website employs Google Analytics, a web analytics service operated by Google LLC ("Google"), implemented via the global site tag (gtag.js) library. Google Analytics enables the collection and analysis of aggregated behavioural and navigational data to assist in the evaluation and improvement of site performance.

      Consent mechanism. Analytics tracking is disabled by default. No data is transmitted to Google Analytics prior to the explicit grant of consent by the data subject. This is enforced via the Google Consent Mode v2 framework, whereby all consent parametersincluding: ad_user_data ad_personalizationanalytics_storage and ad_storageare initialised in a denied state and are only updated to granted upon a positive, freely given, and informed consent action.

      Data collected (upon consent): page URLs, referral sources, session duration, approximate geographic region (country/city level), browser type and version, device category, and aggregated interaction events. No personally identifiable information is collected or transmitted. IP addresses are anonymised at the point of collection.

      Legal basis: Consent (Article 6(1)(a) GDPR). Consent may be withdrawn at any time via the cookie preferences control accessible from any page of this website.

      Data processor: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Data transfers to the United States are governed by the EU–US Data Privacy Framework and applicable Standard Contractual Clauses. For further information, refer to Google's Privacy Policy and Google Analytics Terms of Service.

      3Error Monitoring Sentry▾

      To maintain technical stability and facilitate the timely diagnosis and remediation of software defects, this website integrates Sentry, an application performance monitoring and error tracking platform operated by Functional Software, Inc. ("Sentry").

      Data collected: In the event of a software exception or performance anomaly, Sentry may automatically capture technical diagnostic data, which may include: browser type, version, and rendering engine; operating system and device type; JavaScript stack traces and error messages; approximate geographic region; and application state context at the time of the error event.

      The foregoing data is collected solely for the purpose of identifying, reproducing, and resolving technical malfunctions. It is not used for user profiling, behavioural tracking, or any commercial purpose. No data collected via Sentry is shared with third parties other than Sentry acting as a data processor.

      Legal basis: Legitimate interests (Article 6(1)(f) GDPR) specifically, the legitimate interest of maintaining a functional, secure, and reliable service. This processing is proportionate and does not override the rights and freedoms of data subjects.

      Data processor: Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. International data transfers are subject to Standard Contractual Clauses. Further information is available via Sentry's Privacy Policy.

      4Payment Processing PayPal and Stripe▾

      This website facilitates payment transactions through two third-party payment service providers: PayPal (operated by PayPal Holdings, Inc.) and Stripe (operated by Stripe, Inc.). These providers process payment card data, billing information, and related transaction details directly on their respective secure platforms.

      Data collected by payment processors: When a user initiates a payment, the relevant payment processor may collect and process the following categories of data: cardholder name; payment card number, expiry date, and security code (processed exclusively by the payment processor and never transmitted to or stored by this website); billing address; transaction amount and currency; IP address and device fingerprint (for fraud detection purposes); and email address (where provided for receipt delivery).

      This website does not receive, store, or process raw payment card data at any point. All payment data is transmitted directly to the relevant payment processor via encrypted channels and is subject to that processor's independent data protection obligations, including compliance with the Payment Card Industry Data Security Standard (PCI-DSS).

      Legal basis: Performance of a contract (Article 6(1)(b) GDPR) processing is necessary to execute the payment transaction entered into at the data subject's request.

      Data processors:

      • PayPal Holdings, Inc., 2211 North First Street, San Jose, CA 95131, USA. Refer to PayPal's Privacy Statement for information on international data transfer mechanisms and data subject rights.
      • Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA. Refer to Stripe's Privacy Policy for information on data retention, international transfers, and applicable safeguards.

      Where required, Data Processing Agreements are in place with each of the above providers in accordance with Article 28 GDPR.

      5Local Storage▾

      Certain user interface preferences and session-state data are persisted locally within the user's browser via the Web Storage API (localStorage). This mechanism operates exclusively within the user's own device and browser environment; no data stored via local storage is transmitted to this website's servers or to any third party.

      Local storage is employed solely for the following functional purposes:

      • Retention of display preferences, such as the selected colour scheme (e.g., light or dark mode), to ensure a consistent visual experience across sessions.
      • Temporary maintenance of shopping cart contents during a browsing session, to preserve user selections in the absence of an authenticated session.

      The data retained in local storage cannot be used to identify, track, or profile individual users and does not constitute personal data for the purposes of the GDPR. Users may clear locally stored data at any time through their browser's built-in settings.

      Legal basis: Legitimate interests (Article 6(1)(f) GDPR) the provision of a functional and user-consistent browsing experience.

      6Session-Based Authentication (HTTP-Only Cookie)▾

      Upon the successful completion of a payment transaction, a strictly functional HTTP-only session cookie is issued to the user's browser. This cookie is technically necessary to authenticate the post-purchase session and to authorise the secure download or delivery of purchased digital products.

      This cookie does not serve any tracking, advertising, analytical, or behavioural profiling purpose. It is narrowly scoped to the immediate post-purchase session, expires upon session termination or within a defined maximum duration commensurate with the delivery workflow, and does not persist beyond what is strictly necessary for its functional purpose.

      The payload of this cookie is cryptographically signed and/or encrypted. It is not accessible via client-side JavaScript by virtue of the HttpOnly flag, and is transmitted exclusively over encrypted connections by virtue of the Secure flag.

      Legal basis: Performance of a contract (Article 6(1)(b) GDPR); or, alternatively, legitimate interests (Article 6(1)(f) GDPR) specifically, the delivery of purchased goods and services in a secure and technically reliable manner.

      7Data Retention▾

      Data is not retained for longer than is necessary for the purposes for which it was collected, in accordance with the principle of storage limitation (Article 5(1)(e) GDPR). Specific retention periods applicable to each category of processing are as follows:

      • Analytics data (Google Analytics): Retained in accordance with the retention period configured within the Google Analytics property, and subject to Google's own data lifecycle policies.
      • Error monitoring data (Sentry): Retained for the period necessary to investigate and resolve the reported issue, and subject to Sentry's configurable event retention settings.
      • Payment transaction data (PayPal / Stripe): Retained by the respective payment processors in accordance with their own retention policies and applicable financial regulatory requirements.
      • Session authentication cookie: Expires upon session termination or upon expiration of the maximum permitted session duration, whichever occurs first.
      • Local storage data: Persists until cleared by the user or until the browser's storage is purged; this data is not controlled by the website operator.
      8Rights of Data Subjects▾

      Subject to the conditions and limitations set out in applicable data protection legislation, data subjects whose personal data is processed by this website hold the following rights:

      • Right of access (Article 15 GDPR): the right to obtain confirmation as to whether personal data concerning the data subject is being processed, and, where that is the case, to access that data and related information.
      • Right to rectification (Article 16 GDPR): the right to obtain without undue delay the rectification of inaccurate personal data.
      • Right to erasure (Article 17 GDPR): the right to request deletion of personal data where the conditions specified under applicable law are met.
      • Right to restriction of processing (Article 18 GDPR): the right to request that processing be restricted in certain circumstances.
      • Right to data portability (Article 20 GDPR): the right to receive personal data in a structured, commonly used, and machine-readable format.
      • Right to object (Article 21 GDPR): the right to object to processing based on legitimate interests, including profiling.
      • Right to withdraw consent (Article 7(3) GDPR): where processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
      • Right to lodge a complaint (Article 77 GDPR): the right to lodge a complaint with a competent supervisory authority.

      To exercise any of the above rights, please contact us via the designated contact page. Requests will be acknowledged and processed without undue delay and, in any event, within one (1) calendar month of receipt, in accordance with Article 12 GDPR.

      9Amendments to This Notice▾

      This Notice may be revised from time to time to reflect changes in applicable law, regulatory guidance, or the data processing activities of this website. The date of the most recent revision is indicated at the foot of this page. Continued use of this website following the publication of a revised Notice constitutes acknowledgement of the updated terms, subject always to the requirement for a fresh, freely given consent where required by law.

      No data beyond the categories explicitly described in this Notice is collected, processed, or shared with third parties for commercial, unauthorised, or undisclosed purposes.

      This notice was last reviewed in April 2025.
      Contact us via the designated contact page for all data-related enquiries.
      Regulation (EU) 2016/679
      General Data Protection Regulation

      Handy Links

      • F.A.Q.
      • Contact
      • Session Work
      • About
      • GDPR Compliance
      • Cookies
      • Legal

      Payment Methods

      • Paypal
      • Stripe
      • Link
      • Klarna
      • Revolut
      • Google Pay
      • Apple Pay

      Keep In Touch

      • Youtube
      • Instagram
      • Facebook
      • Github

      Developed by Dimitris