Privacy Policy
Last updated: 28 July 2026
1. Controller
The controller responsible for the processing of personal data on this website and in connection with our online store is:
Olivia Zoé Ziehme
Organized Muse
Lanser Straße 8
6080 Innsbruck
Austria
Email: hello@organized-muse.com
In this Privacy Policy, “we”, “us” and “our” refer to Organized Muse.
2. General information
We process personal data only to the extent necessary to operate our website and online store, communicate with customers and interested persons, process orders, provide customer services, send newsletters where consent has been given, fulfil legal obligations and protect our legitimate business interests.
Personal data means any information relating to an identified or identifiable natural person. Depending on how you use our website, this may include contact details, order details, payment information, shipping information, device and usage data, communication content and information you voluntarily provide to us.
The legal bases referred to in this Privacy Policy are those contained in Article 6(1) of the General Data Protection Regulation, or GDPR.
3. Hosting and operation of the online store
Our online store is operated using Shopify.
For customers and visitors located in the European Economic Area, the United Kingdom or Switzerland, personal data is initially received by:
Shopify International Limited
Victoria Buildings, 2nd Floor
1–2 Haddington Road
Dublin 4, D04 XN32
Ireland
Shopify provides the technical infrastructure required to display the website, operate the online store, manage products, process shopping carts and orders, provide customer accounts, manage checkout functions and support the security and stability of the store.
In this context, the following data may be processed:
- IP address
- browser and device information
- operating system
- date and time of access
- pages and products viewed
- referral URL
- cookie and consent information
- shopping-cart information
- customer-account information
- order, billing and shipping information
- communication and support data
- technical log and security data
The processing is carried out to provide the website and online-store functions, process orders, prevent misuse and fraud, maintain technical security and ensure the stability and performance of the store.
The legal bases are:
- Article 6(1)(b) GDPR for contractual and pre-contractual processing;
- Article 6(1)(f) GDPR for the secure, reliable and commercially reasonable operation of our website and online store;
- Article 6(1)(c) GDPR where processing is necessary to comply with legal obligations.
Where eligible, our Shopify store data is stored at rest in the European Union. However, Shopify may still use affiliated companies and subprocessors in other countries and may carry out international data transfers for certain processing activities. Shopify states that EEA customer data is initially processed by Shopify International Limited in Ireland and that international transfers may continue even where data is stored in Europe. Appropriate safeguards are used in accordance with applicable data-protection law.
4. Technical access data and server logs
When you visit our website, technical information is automatically processed in order to deliver the website to your device, identify and resolve technical problems and protect the website from misuse and attacks.
This information may include:
- IP address
- browser type and version
- device type
- operating system
- requested page or file
- date and time of access
- referring website
- error messages and technical event data
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure and stable operation of the website, error analysis, fraud prevention and protection of our systems and customers.
Technical log data is retained only for as long as necessary for these purposes, unless longer storage is required to investigate a security incident or comply with a legal obligation.
5. Orders and contract processing
When you place an order, we process the information necessary to conclude and perform the purchase contract.
This may include:
- full name
- email address
- billing address
- shipping address
- telephone number, where provided
- order number
- products and product variants ordered
- quantities and prices
- discount information
- payment method and payment status
- shipping and tracking information
- customer-account information
- correspondence relating to the order
- returns, refunds and complaints
- personalization information
The processing is necessary to:
- process and confirm your order;
- collect and allocate payments;
- prepare and ship the products;
- communicate with you regarding your order;
- handle returns, refunds and complaints;
- provide customer support;
- fulfil accounting, tax and record-keeping obligations.
The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for compliance with legal obligations.
If the required order information is not provided, we may be unable to conclude or perform the purchase contract.
6. Personalized products and initials
Where you request personalization of a planner, we process the initials entered by you and associate them with the relevant product and order.
The initials are processed for the sole purpose of producing and delivering the personalized product, documenting the requested personalization and handling any related customer-service enquiry or complaint.
The legal basis is Article 6(1)(b) GDPR.
Please do not enter sensitive personal information or any information other than the intended initials in the personalization field.
The personalization information is retained together with the relevant order data for as long as necessary to perform the contract and comply with legal documentation and retention obligations.
7. Customer accounts and order status
Shopify may provide passwordless customer-account and order-status functions. Customers can generally access their order information using the email address associated with the order and an authentication code.
The following data may be processed:
- email address
- authentication and login information
- customer profile
- previous and current orders
- shipping and tracking information
- return requests
- account preferences
The legal basis is Article 6(1)(b) GDPR where the account is used to manage an order or customer relationship. Article 6(1)(f) GDPR may also apply to the provision of convenient and secure account and support functions.
8. Payments
8.1 Shopify Payments
We intend to offer payments through Shopify Payments. Depending on the payment method selected and the availability in the customer’s country, this may include credit or debit card payments and accelerated payment functions offered within the Shopify Payments environment.
Payment data may include:
- name
- billing address
- payment method
- transaction amount
- currency
- transaction status
- payment identifiers
- fraud-prevention and authentication information
- limited card or account information
We do not receive full payment-card details where these are processed directly by the payment provider.
The processing is necessary to initiate, authenticate and complete the payment, prevent fraud, process refunds and comply with financial and legal obligations.
The legal bases are Article 6(1)(b), Article 6(1)(c) and, where applicable, Article 6(1)(f) GDPR.
Shopify’s privacy and data-processing terms apply to the processing carried out through Shopify Payments.
8.2 PayPal
Where you select PayPal, information required to process the payment is transferred to PayPal.
The payment service is generally provided in the European Economic Area by:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
PayPal processes data under its own responsibility for payment processing, account authentication, risk assessment, fraud prevention and compliance with financial and regulatory obligations.
Depending on the transaction, the following data may be transferred:
- name
- email address
- billing and delivery information
- order amount
- currency
- transaction and order identifiers
- payment status
- device, authentication and fraud-prevention information
The legal basis for the transfer is Article 6(1)(b) GDPR. Where required by law or necessary for fraud prevention, Article 6(1)(c) or Article 6(1)(f) GDPR may also apply.
PayPal’s own privacy statement applies to processing carried out independently by PayPal.
9. Shipping and delivery
We use SendDrop to organise and purchase shipping services and may select different parcel carriers depending on the destination, parcel characteristics, availability and shipping conditions.
The relevant recipients may include:
- SendDrop GmbH
- Österreichische Post AG
- General Logistics Systems Austria GmbH, or the relevant GLS company
- DPD Direct Parcel Distribution Austria GmbH, or the relevant DPD company
- DHL or the relevant DHL group company
The specific carrier used for an order may depend on the selected shipping service.
For shipping purposes, we may transfer:
- recipient name
- delivery address
- email address
- telephone number, where required or provided
- order or reference number
- parcel and shipment information
- tracking information
- delivery instructions
- customs information, where legally required
The data is processed to create shipping labels, hand over the parcel, provide tracking, complete delivery and manage delivery problems or claims.
The legal basis is Article 6(1)(b) GDPR. Article 6(1)(f) GDPR may apply to efficient logistics, shipment tracking and the prevention or resolution of delivery problems.
SendDrop provides privacy information and an agreement for commissioned data processing.
10. Contact enquiries and customer service
When you contact us by email, through our contact form or through another communication channel, we process the information you provide.
This may include:
- name
- email address
- order number
- subject of the enquiry
- message content
- attachments
- information relating to orders, returns, products or complaints
- date and time of the communication
The data is processed to respond to your enquiry, provide customer service, handle returns or complaints and document the communication where necessary.
The legal basis is Article 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual request. For general enquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the efficient and documented handling of communications and customer enquiries.
Messages are retained for as long as necessary to handle the enquiry and any resulting contractual or legal matters.
11. Google Workspace
We use Google Workspace for business email communication and file and document management.
The service is provided by the relevant Google contracting entity, generally Google Ireland Limited for customers in the European Economic Area.
Where you communicate with us or where documents relating to orders, customer support, accounting or business administration are stored in Google Workspace, the following data may be processed:
- name and contact details
- email content
- attachments
- order and customer-service information
- business documents and files
- metadata such as sender, recipient and time of communication
The legal basis is Article 6(1)(b) GDPR where the processing relates to a contract, Article 6(1)(c) GDPR where documents must be retained by law and Article 6(1)(f) GDPR for secure and efficient business communication and document management.
We limit storage in Google Workspace to information that is necessary for the relevant business purpose.
12. Accounting and sevdesk
We use or intend to use sevdesk for bookkeeping, invoicing and financial administration.
The service is provided by:
sevDesk GmbH
Hauptstraße 115
77652 Offenburg
Germany
Depending on the integration and accounting process, the following data may be transferred to sevdesk:
- customer name
- billing address
- email address
- customer and order numbers
- invoice data
- products, quantities, prices and taxes
- payment status
- refund and credit-note information
- accounting documents and supporting records
The processing is carried out to create and manage invoices, maintain accounting records, document business transactions and comply with tax and commercial record-keeping obligations.
The legal bases are Article 6(1)(b) GDPR where the processing is connected with the contract and Article 6(1)(c) GDPR for statutory accounting and tax obligations.
sevdesk acts as a processor for relevant customer data. We enter into the required data-processing agreement with sevdesk. sevdesk confirms that an agreement for commissioned processing forms the basis for processing customer information within the service.
13. Newsletter and email marketing with Klaviyo
We use Klaviyo to manage newsletter subscriptions and send marketing emails.
The service is provided by:
Klaviyo, Inc.
125 Summer Street
Boston, MA 02110
United States
When you subscribe to our newsletter, we may process:
- email address
- name, where provided
- date and time of registration
- consent status
- confirmation status
- IP address and technical registration information
- newsletter interactions
- email opens and link clicks, where permitted
- website and product interactions, where consented to and technically enabled
- purchase and customer information used for lawful newsletter personalisation or segmentation
We use a double opt-in process. After registration, you receive a confirmation email. Your subscription is completed only after you confirm the registration.
The legal basis for sending the newsletter and consent-based tracking is Article 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future by using the unsubscribe link contained in each marketing email or by contacting us. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
We retain your newsletter information until you unsubscribe or withdraw your consent, subject to limited retention of evidence necessary to document the consent and comply with legal obligations.
Klaviyo acts as a processor for relevant customer data and provides a data-processing agreement. Klaviyo’s agreement includes international-transfer safeguards and applies standard contractual clauses where the EU-U.S. Data Privacy Framework cannot be relied upon.
14. Klaviyo onsite functions
Klaviyo may also provide onsite functions such as newsletter forms and, where enabled and consented to, information about website or product interactions.
Depending on the configuration and consent status, Klaviyo may process:
- IP address
- device and browser information
- cookie or client identifiers
- pages and products viewed
- interaction with newsletter forms
- shopping and purchase events
- email address where the visitor has been identified
Technically necessary functions may be processed on the basis of Article 6(1)(f) GDPR where appropriate. Analytics, personalisation or marketing tracking that is not technically necessary is carried out only after consent under Article 6(1)(a) GDPR.
You can withdraw or change your consent through the cookie settings available on our website.
15. BundleSuite
We use BundleSuite to provide product-bundle and “Build Your Set” functions.
The app may be involved in:
- displaying bundle components;
- recording products and variants selected for a bundle;
- calculating bundle conditions or discounts;
- transferring bundle selections to the shopping cart;
- associating bundle components with a cart or order;
- technically analysing the use and correct functioning of the bundle interface.
Depending on the configuration, the following information may be processed:
- product and variant selections
- shopping-cart and order information
- bundle identifiers
- IP address
- browser and device information
- cookie or client identifiers
- website interactions
- customer and contact information where connected to an order
The legal basis is Article 6(1)(b) GDPR where processing is required to configure and purchase the selected bundle. Technically necessary processing may also be based on Article 6(1)(f) GDPR. Any non-essential analytics or tracking is carried out only after consent under Article 6(1)(a) GDPR.
The Shopify App Store states that BundleSuite may access customer contact information as well as device and activity data, including IP address, browser information, geolocation, browsing behaviour and a client-ID cookie. The app provider publishes a separate privacy policy.
16. Instagram feed
We use the GSC Instagram Feed, Instafeed app to display selected Instagram content on our website.
The integration may process technical data required to load and display the feed, such as:
- IP address
- browser and device information
- date and time of access
- page viewed
- interaction with the feed
- publicly available Instagram content and associated metadata
Depending on the app’s technical implementation, data may be processed by the app provider and, where content is loaded directly from Instagram, by Meta Platforms Ireland Limited or another relevant Meta company.
The purpose is to present our social-media content and visually enhance our website.
Where the app is technically configured without non-essential tracking, processing may be based on Article 6(1)(f) GDPR. Our legitimate interest is the presentation of our brand and content. Where the integration sets non-essential cookies, tracks visitor behaviour or establishes a connection to Meta for non-essential purposes, it is activated only after consent under Article 6(1)(a) GDPR.
The app is listed in the Shopify App Store as “GSC Instagram Feed, Instafeed”.
17. Cookies and similar technologies
Our website uses cookies and similar technologies.
Cookies are small text files or comparable identifiers that may be stored on or accessed from your device. They may be used to provide essential website functions, remember preferences, manage shopping carts, authenticate customers, secure the checkout and, where consent has been provided, measure or personalise website and marketing activity.
We distinguish between:
Strictly necessary technologies
These technologies are required for functions such as:
- website security
- shopping cart
- checkout
- customer authentication
- payment initiation
- fraud prevention
- cookie-consent storage
- basic website and bundle functionality
Where personal data is processed through strictly necessary technologies, the legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR.
Optional analytics, personalisation and marketing technologies
These technologies are used only where you have provided consent. The legal basis is Article 6(1)(a) GDPR.
Our Shopify cookie banner is configured for the EU countries to which we offer our services. You may accept, reject or select optional cookie categories. You may change your choice through the cookie settings available on our website.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
18. Shopify analytics
Shopify may provide store reports and analytics using information generated through the operation of the online store.
Depending on the settings and consent status, this may include:
- visits and sessions
- device and browser information
- referral information
- pages and products viewed
- shopping-cart and checkout activity
- purchases and order values
- regional or aggregated statistics
Basic operational statistics that are necessary for the administration and security of the store may be processed on the basis of Article 6(1)(f) GDPR. Analytics involving non-essential cookies or identifiers is carried out only after consent pursuant to Article 6(1)(a) GDPR.
19. No Google Analytics or Meta Pixel at present
At the date of this Privacy Policy, we do not use Google Analytics, Google Ads conversion tracking or the Meta Pixel.
This Privacy Policy will be updated before any such service is activated. Where legally required, these services will be blocked until consent has been provided through the cookie-consent mechanism.
20. Recipients of personal data
Depending on the processing activity, personal data may be disclosed to:
- Shopify and its authorised subprocessors;
- payment-service providers;
- SendDrop and the selected shipping carrier;
- Klaviyo;
- BundleSuite;
- the provider of the Instagram-feed app;
- Google Workspace;
- sevdesk;
- banks and financial institutions;
- tax advisers, accountants or professional advisers where required;
- public authorities, courts or supervisory authorities where legally required;
- IT, security or support providers acting on our behalf.
We disclose only the data required for the relevant purpose.
Processors are contractually required to process personal data only in accordance with our instructions and applicable data-protection law, unless they are legally required to act otherwise.
21. International data transfers
Some service providers, affiliated companies or subprocessors may be located outside the European Union or the European Economic Area.
Where personal data is transferred to a country for which the European Commission has adopted an adequacy decision, the transfer may be based on Article 45 GDPR.
Where no applicable adequacy decision exists, transfers may be based on appropriate safeguards under Article 46 GDPR, including the European Commission’s standard contractual clauses and, where applicable, supplementary technical and organisational measures.
For eligible U.S. recipients, a transfer may also be based on the EU-U.S. Data Privacy Framework where the recipient maintains a valid certification.
Shopify and Klaviyo describe the use of contractual and other recognised safeguards for international transfers.
You may contact us for further information about the applicable transfer safeguards.
22. Retention periods
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy or for as long as required by law.
In particular:
- order, invoice, payment and accounting documents are generally retained for seven years in accordance with Austrian tax and accounting requirements;
- data relevant to pending administrative, tax, court or contractual proceedings may be retained until the proceedings and applicable limitation periods have ended;
- customer-service and contact enquiries are retained for as long as necessary to answer the enquiry and handle resulting legal or contractual matters;
- newsletter data is retained until consent is withdrawn or the subscription is terminated, subject to limited retention necessary to document the consent;
- technical security and log data is retained for the period necessary to ensure security, investigate incidents and resolve technical problems;
- cookie and consent information is retained in accordance with the relevant cookie duration and the need to document consent;
- customer-account information is retained while the account or ongoing customer relationship exists, subject to mandatory legal retention periods.
Austrian business and accounting records and invoices are generally subject to a seven-year retention period. Longer periods can apply in special circumstances or while documents remain relevant to pending proceedings.
When the relevant purpose and retention period have ended, personal data is deleted or anonymised unless further processing is legally permitted or required.
23. Your rights
Subject to the conditions of the GDPR, you have the right to:
- obtain information about whether and how we process your personal data;
- request access to your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- receive data you have provided in a structured, commonly used and machine-readable format;
- request transmission of the data to another controller where technically feasible;
- object to processing based on legitimate interests;
- withdraw consent at any time with effect for the future;
- lodge a complaint with a data-protection supervisory authority.
Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is required for the establishment, exercise or defence of legal claims.
Where personal data is processed for direct marketing, you may object at any time without stating reasons.
To exercise your rights, contact:
We may request appropriate information to verify your identity before responding to a request.
24. Right to lodge a complaint
You have the right to lodge a complaint with a competent data-protection supervisory authority.
The supervisory authority responsible in Austria is:
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
Austria
Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
The Austrian Data Protection Authority confirms these current contact details and accepts complaints by email, post or through its online process.
You may also contact the supervisory authority at your habitual place of residence, place of work or the place of the alleged infringement.
25. Automated decision-making
We do not currently use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
Automated technical checks used for payment authentication, fraud prevention or website security may be carried out by payment or service providers under their own responsibility. These do not mean that Organized Muse makes a solely automated decision about you within the meaning described above.
26. Data security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.
These measures may include encrypted transmission, access controls, account security measures, limited access to business systems, software updates and the use of professional service providers.
However, no method of transmission or storage can guarantee absolute security.
27. Obligation to provide data
You are not generally required to provide personal data merely to browse our website.
Certain information is required where you wish to:
- place an order;
- receive delivery;
- make a payment;
- request personalization;
- create or access a customer account;
- submit a return or customer-service request;
- subscribe to the newsletter.
Without the information required for the relevant purpose, we may be unable to provide the requested service or conclude and perform the contract.
28. Links to third-party websites and social media
Our website may contain links to external websites or social-media profiles.
When you click an external link, the relevant third-party provider processes data under its own responsibility. This Privacy Policy does not govern the processing carried out on third-party websites.
Please review the privacy information of the relevant provider before using the external service.
29. Changes to this Privacy Policy
We may update this Privacy Policy where our services, technical systems, legal requirements or processing activities change.
The version available on this website at the time of your visit applies. The date of the most recent update is stated at the beginning of the Privacy Policy.