⚠ SITE UNDER CONSTRUCTION — information may not be accurate        ⚠ SITE UNDER CONSTRUCTION — information may not be accurate        ⚠ SITE UNDER CONSTRUCTION — information may not be accurate       

GDPR — Instructions for Use

Last updated: February 2025

Document type: Information Notice under Articles 12–14 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR").
This Notice explains how personal data are processed when you browse, contact, or purchase from Canvartin, including posters, canvases, and papercraft products (including personalized orders).
Website: https://canvartin.com/

Table of Contents

2) Controller identification

The data controller within the meaning of GDPR Article 4(7) is Nadezhda Khusainova (trading name: Canvartin; Tax ID/NIF: ESZ0887444V), established in Spain.

The controller's postal address, email, and phone/WhatsApp are provided in the Contact and complaints section to avoid repetition while keeping this Notice readable.

3) Scope and roles

3.1 Who this Notice applies to

3.2 Controller vs. other controllers

3.3 No unrelated processing

Personal data are processed only for defined purposes described in this Notice, aligned with GDPR Article 5(1)(b) (purpose limitation) and Article 5(1)(c) (data minimisation).

4) GDPR principles applied

Processing is organised to comply with GDPR Article 5(1) principles:

5) Personal data categories

5.1 Identification and contact data

5.2 Order and transaction data

5.3 Communications and support data

5.4 Personalisation content (custom data)

5.5 Data not intentionally collected

The controller does not request or require special categories of personal data under GDPR Article 9. If you voluntarily include such data in personalisation content or messages, it will be processed only to the extent strictly necessary to fulfil your request and respond to you.

6) Processing by product line: Posters / Canvases / Papercraft

6.1 Posters (non-personalised)

For standard posters, processing is limited to what is needed to accept the order, produce/pack the poster, and ship it.

6.2 Canvases (non-personalised)

For standard canvases, processing is limited to what is needed to fulfil the purchase contract, ship the product, and manage after-sales requests.

6.3 Papercraft products (kits and printed parts)

For papercraft products, processing is limited to accepting and fulfilling the order, shipping, and support. Papercraft kits may include components such as printed paper parts and, depending on the kit, accessories (e.g., craft knife, white glue, plastic ruler, plastic packaging, ballpoint pen). The presence of accessories does not change the categories of personal data processed; it may increase the need for accurate delivery details and careful after-sales handling.

7) Personalisation (custom orders)

7.1 What "personalisation" means

Personalisation refers to processing that uses information you provide to create a product specifically for you. Examples include adding names, dates, short messages, custom colour requests, or printing your image on a poster/canvas (where offered).

7.2 Personalisation data and responsibilities

7.3 Legal bases for personalisation

7.4 Minimisation for custom content

Personalisation is designed around GDPR Article 5(1)(c): only the content strictly required to produce the personalised item is processed. Excess content included in messages (unrelated personal details) is not required and should not be shared.

7.5 Personalisation proof and dispute handling

To resolve "not as ordered" disputes, the controller may retain:

This supports contract performance (Article 6(1)(b)) and legitimate interests in dispute prevention and resolution (Article 6(1)(f)).

8) Purposes and legal bases (GDPR Article 6)

PurposeWhat this includesPrimary legal basis (GDPR)Key GDPR references
Order creation and management Accepting orders, confirming details, preparing production/packing instructions, status updates. Art. 6(1)(b) Contract performance GDPR (Art. 6; Art. 13(1)(c))
Delivery and logistics Address validation (where needed), shipping labels, carrier handover, delivery notifications, handling failed deliveries. Art. 6(1)(b) Contract performance GDPR Art. 6; Art. 5(1)(c)
Customer support and communications Answering questions, providing instructions and clarifications, handling complaints, replacements, missing items. Art. 6(1)(b) Contract performance
Art. 6(1)(f) Legitimate interests
GDPR Art. 6; Art. 13; Art. 21
Personalisation production Processing custom text/images to create the personalised poster/canvas/papercraft element you ordered. Art. 6(1)(b) Contract performance GDPR Art. 6; Art. 5(1)(b)-(c)
Accounting, invoicing, and compliance Invoices/receipts, bookkeeping, mandatory record retention, responding to lawful authority requests. Art. 6(1)(c) Legal obligation GDPR Art. 6(1)(c); Art. 13(1)(c)
Returns, refunds, and disputes Return authorisation, refund processing, fraud prevention in returns, evidence preservation. Art. 6(1)(b) Contract performance
Art. 6(1)(c) Legal obligation (where applicable)
Art. 6(1)(f) Legitimate interests
GDPR Art. 6; Art. 5(1)(e); Art. 21
Security, fraud prevention, and misuse prevention Protecting communications and order integrity, detecting suspicious activity, preventing identity misuse and chargeback abuse. Art. 6(1)(f) Legitimate interests GDPR Art. 6(1)(f); Art. 32; Art. 5(1)(f)

8.1 Legitimate interests balancing (GDPR Article 6(1)(f), Article 21)

Where processing relies on legitimate interests, the controller assesses:

You may object to processing based on legitimate interests at any time (GDPR Article 21). Where the objection is valid, processing will be stopped unless compelling legitimate grounds override your interests, rights, and freedoms, or the processing is needed for legal claims.

9) Recipients, processors, and disclosures

9.1 Recipient categories (GDPR Article 13(1)(e))

Personal data may be shared only to the extent necessary with:

9.2 Processors (GDPR Article 28)

Where an external provider processes personal data on the controller's behalf, the controller ensures that:

9.3 No sale of personal data

The controller does not sell personal data to third parties.

10) International transfers (GDPR Chapter V)

10.1 When transfers may occur

Transfers outside the European Economic Area (EEA) may occur if a recipient/service provider processes or stores data in a third country or allows remote access from a third country. Transfers may also occur when communicating with you if you are located outside the EEA.

10.2 Transfer mechanisms (Articles 44–49)

International transfers are carried out only in accordance with GDPR Chapter V (GDPR Articles 44–49). Where applicable, the controller relies on:

10.3 Additional safeguards

Where SCCs are used, the controller applies additional safeguards when needed, consistent with GDPR Article 32 and relevant EDPB guidance: https://edpb.europa.eu/

11) Retention (GDPR Article 5(1)(e))

11.1 Core rule

Personal data are retained only as long as needed for the stated purposes and for compliance with legal obligations. Retention decisions consider:

11.2 Retention by category (practical overview)

CategoryRetention approachPurpose alignment
Orders, delivery, and support historyKept for the time necessary to perform the contract and manage reasonable after-sales support, then deleted or anonymised unless required for compliance or claims.Art. 6(1)(b), Art. 6(1)(f), Art. 5(1)(e)
Invoices and accounting recordsKept for the period required by applicable accounting/tax law; access limited to authorised persons.Art. 6(1)(c), Art. 5(1)(e)
Personalisation files and approvalsKept as needed to produce the personalised product and to handle disputes/returns; then deleted unless continued retention is required for legal claims or mandatory bookkeeping.Art. 6(1)(b), Art. 6(1)(f), Art. 5(1)(e)
Returns/refunds documentationKept as needed to complete the return/refund and to manage fraud risks and disputes; longer if required by law or to defend legal claims.Art. 6(1)(b), Art. 6(1)(c), Art. 6(1)(f)
Suppression (do-not-contact) recordsKept to ensure marketing opt-outs are respected.Art. 6(1)(f), Art. 21

12) Data subject rights (GDPR Articles 12–23)

12.1 Your rights

12.2 How requests are handled (Articles 12–14)

12.3 Limits and exceptions

Rights are not absolute. The controller may refuse or limit a request where allowed by GDPR (e.g., where retention is required by law or needed for legal claims), and will explain the reasons as required by GDPR Article 12(4).

13) Objections, withdrawals, and suppression lists

13.1 Objection to processing (Article 21)

Where processing relies on legitimate interests (GDPR Article 6(1)(f)), you may object at any time on grounds relating to your particular situation (GDPR Article 21(1)). The controller will stop processing unless compelling legitimate grounds override your interests, rights, and freedoms, or processing is required for legal claims.

13.2 Direct marketing (Article 21(2)–(3))

If personal data are processed for direct marketing, you may object at any time. After an objection, the data will no longer be processed for direct marketing (GDPR Article 21(2)–(3)).

13.3 Withdrawal of consent (Article 7(3))

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal (GDPR Article 7(3)).

13.4 Suppression lists

To respect objections/opt-outs, the controller may keep a minimal record (e.g., email address) on a suppression list. This ensures that you are not contacted again for marketing, aligning with legitimate interests and compliance duties (GDPR Article 6(1)(f); Article 21).

14) Returns, refunds, and disputes

14.1 Return requests and required data

When you request a return or refund, the controller processes the information needed to:

14.2 Legal bases for returns-related processing

14.3 Evidence and documentation

For disputes and quality issues, the controller may ask for and process:

Any documentation is limited to what is necessary (GDPR Article 5(1)(c)) and retained only as long as needed for the return/dispute process and related legal obligations (GDPR Article 5(1)(e)).

14.4 Personalised products and returns

Personalised products may require additional verification of the agreed custom specification. The controller may retain a record of the personalisation input and approval steps to assess whether the delivered item matches the confirmed order. This supports contract performance and legitimate interests in fair dispute handling (GDPR Article 6(1)(b) and Article 6(1)(f)).

15) Security and confidentiality (GDPR Article 32)

15.1 Security objective

The controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (GDPR Article 32(1)), taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as risks of varying likelihood and severity to individuals.

15.2 Risk-based approach (what risks are considered)

Security measures are selected to reduce risks such as:

15.3 Organisational measures

15.4 Technical measures (security controls described at a functional level)

Security controls are implemented to support confidentiality, integrity, and availability (GDPR Article 32(1)). Controls are described at a functional level to remain accurate as systems evolve and to avoid misleading statements.

15.5 Protection of personalisation content

Because personalisation content may include names, messages, and images, additional care is applied:

15.6 Payment security boundary

Payment processing is typically performed by payment service providers. The controller processes only what is necessary to confirm payment status, match transactions to orders, and manage refunds and disputes. This supports data minimisation (GDPR Article 5(1)(c)) and reduces exposure of sensitive payment details.

15.7 Security testing and review (ongoing appropriateness)

In line with GDPR Article 32(1)(d), the controller applies processes for:

15.8 Confidentiality in customer support channels

Support communications may contain order details and addresses. To reduce risks:

16) Personal data breaches (GDPR Articles 33–34)

If a personal data breach occurs, the controller evaluates the likelihood and severity of risks to individuals. Where required:

17) Children's data

The controller does not knowingly collect personal data from children. If you believe that a child has provided personal data, you may contact the controller to request deletion where applicable, subject to legal retention obligations.

18) Changes to this Notice

This Notice may be updated to reflect changes in processing or legal requirements. The latest version will be published on the website with an updated "Last updated" date. Processing remains governed by GDPR transparency and fairness requirements (GDPR Articles 12–14).

19) Contact and complaints

Controller: Nadezhda Khusainova
Address: Calle Lince, 10. Coín, Málaga, 29100, Spain
Email: admin@canvartin.com
Phone / WhatsApp: +34 624 640 928
Website: https://canvartin.com/

Right to lodge a complaint (GDPR Article 77): You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
Spain (AEPD): https://www.aepd.es/

Annex: GDPR Articles referenced (official links)

25) Cookies and similar technologies (online identifiers) – transparency and choices

25.1 When this section applies

This section applies when you interact with the website and any embedded services that store or access information on your device (for example through cookies, local storage, pixels, or similar technologies). Where such technologies involve personal data, the processing is also subject to GDPR (Regulation (EU) 2016/679).

25.2 Legal rules referenced

25.3 Categories of cookie-related data that may be processed

25.4 Purposes and legal bases

Cookie/technology categoryPurposeLegal basis (GDPR Article 6)Consent expectation
Strictly necessaryEnable core site functions you explicitly request (navigation, checkout continuity, security functions).Art. 6(1)(b) Contract (where needed to provide requested service) and/or Art. 6(1)(f) Legitimate interests (secure and stable website operation).Typically not subject to opt-in under ePrivacy where strictly necessary, but still disclosed transparently.
PreferencesRemember choices (e.g., language) to improve usability.Art. 6(1)(f) Legitimate interests and/or Art. 6(1)(a) Consent where required by applicable national rules.May require consent depending on implementation and national rules.
AnalyticsUnderstand aggregated website usage to improve content and navigation.Art. 6(1)(a) Consent where analytics are not strictly necessary.Opt-in where required; configurable to reduce identifiability where applicable.
MarketingMeasure advertising effectiveness and show relevant ads across websites/apps.Art. 6(1)(a) Consent.Opt-in.

25.5 Cookie preference controls and withdrawal

25.6 Cookie recordkeeping

Where required to demonstrate compliance, the controller may store a record of your cookie consent choice (time, scope, and preference signal) to meet accountability requirements (GDPR Article 5(2)) and consent conditions (GDPR Article 7(1)).


26) Marketing, service messages, and contact preference management

26.1 Transactional / service communications

The controller sends messages that are necessary to perform the contract or to manage your request (for example: order confirmation, delivery updates, clarification of personalisation details, return instructions). These communications are not sent for advertising purposes.

26.2 Direct marketing (where offered)

Where marketing is offered (for example newsletters, promotions, new product announcements), the controller processes your contact details and preferences to deliver those communications.

26.3 Preference management, unsubscribe, and proof of compliance


27) Reviews, testimonials, and user-submitted content (where applicable)

27.1 What data may be processed

27.2 Purposes and legal bases

27.3 Minimisation for images

If you upload images that contain personal data (faces, names, addresses visible in the background), the controller processes only what is necessary for the review purpose and may request replacement or redaction where appropriate, consistent with data minimisation (GDPR Article 5(1)(c)).


28) Social media pages and messaging (independent controllers)

28.1 Controller's processing

If you contact the controller through social media messages or comments, the controller processes the content you provide to respond to your enquiry and manage customer service.

28.2 Platform processing

Social media platforms typically process personal data for their own purposes as independent controllers. Their processing is governed by their own privacy notices. The controller does not control the platform's processing activities.


29) Shipping labels, misdelivery risk, and address verification

29.1 Shipping label data

To deliver physical products (posters, canvases, papercraft), the controller processes and shares with carriers the minimum information required for delivery, such as the recipient name, delivery address, and contact details where needed.

29.2 Address accuracy and delivery exceptions

When a delivery fails (incorrect address, incomplete details, undeliverable location), the controller may:

29.3 Wrong recipient / misdelivery reports

If you report a misdelivery, the controller processes the information needed to investigate (order reference, carrier tracking, proof of delivery). Processing remains limited to what is necessary to resolve the delivery incident (GDPR Article 5(1)(c)) and is retained only as long as needed (GDPR Article 5(1)(e)).


30) Physical records and packaging-related visibility

30.1 Paper documents used for fulfilment

If paper-based order documents are used during packing (for example a picking/packing note), they contain only the information required to fulfil the order. Such documents are handled to reduce visibility of personal data to unauthorised persons.

30.2 Disposal

When paper documents are no longer needed, they are disposed of in a manner intended to prevent unauthorised access to personal data, consistent with GDPR Article 32 and storage limitation (GDPR Article 5(1)(e)).


31) Records of processing activities and accountability documentation (Article 30; Article 5(2))

31.1 Accountability

The controller applies the accountability principle (GDPR Article 5(2)) and maintains compliance documentation where required.

31.2 Records of processing activities (GDPR Article 30)

Where applicable, the controller maintains records of processing activities, which may include:

GDPR reference: GDPR Art. 30


32) Data Protection Impact Assessments and prior consultation (Articles 35–36)

32.1 DPIA (GDPR Article 35)

If the controller introduces processing that is likely to result in a high risk to the rights and freedoms of natural persons, the controller will carry out a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35.

32.2 Prior consultation (GDPR Article 36)

Where a DPIA indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, the controller will consult the competent supervisory authority before processing, as required by GDPR Article 36. GDPR Art. 36


33) Special operational cases: replacements, missing items, and partial shipments

33.1 Replacements and missing items

If you report missing or incorrect items (including papercraft kit components), the controller processes the minimum information required to:

33.2 Partial shipments

Where an order is fulfilled in more than one shipment (for example due to availability), the controller processes shipment identifiers and carrier references to manage delivery and customer communications. Processing remains limited to what is needed to complete fulfilment.


34) Legal basis precision, compatibility, and secondary uses

34.1 No incompatible secondary use

If the controller considers processing personal data for a purpose other than the one for which the data were collected, the controller will assess compatibility in line with GDPR Article 6(4) and provide information as required by GDPR Articles 13–14.

34.2 Legal obligation vs. contract vs. legitimate interests

Where multiple legal bases could appear relevant, the controller selects the most appropriate basis for the specific processing purpose and applies safeguards to ensure fairness and proportionality (GDPR Article 5(1)(a)).


35) Data about third parties provided by customers (recipient addresses, gift orders, shared images)

35.1 When you provide another person's details

If you provide another person's name/address for delivery (for example a gift order) or submit an image containing third-party personal data, you are responsible for ensuring you have a lawful basis to share that information with the controller for the stated purpose.

35.2 How the controller processes such data


36) Operational rules for rights requests (clarifications, partial fulfilment, and secure delivery)

36.1 Scope of disclosure for access requests

In response to an access request (GDPR Article 15), the controller provides:

GDPR reference: GDPR Art. 15

36.2 Rights of others

Where fulfilling a request would adversely affect the rights and freedoms of others, the controller may redact or limit disclosure as permitted by GDPR while still providing a meaningful response (GDPR Article 15(4)).

36.3 Secure delivery of responses

The controller may select a response channel that reduces the risk of unauthorised disclosure (GDPR Article 5(1)(f); Article 32), and may request identity verification where reasonable doubts exist (GDPR Article 12(6)).


37) Business continuity and organisational changes

37.1 Reorganisation, transfer, or restructuring

If the controller's business structure changes (for example a reorganisation affecting fulfilment operations), personal data may be transferred only to the extent necessary and in accordance with GDPR principles.

37.2 Legal bases and safeguards


38) EU representative (Article 27)

GDPR Article 27 applies to certain controllers not established in the Union. The controller is established in Spain. GDPR reference: GDPR Art. 27