Privacy Policy
1. General information
This Privacy Policy explains how we process personal data when you use the website https://surreal.art (the “Website”) and our services under the brand Surreal.
We process personal data in accordance with the General Data Protection Regulation (GDPR / DSGVO) and applicable Austrian data protection law.
2. Data controller
The data controller responsible for processing your personal data is:
black.com GmbH
FN 448732 a
Am Belvedere 8
1100 Vienna
Austria
ATU70639927
Email: office@surreal.art
We have not appointed a data protection officer, as this is not legally required.
3. Scope of personal data processing
We process personal data only to the extent necessary to operate the Website, provide our services, and fulfil contractual and legal obligations.
We do not use tracking, profiling, advertising cookies, or analytics tools.
4. User accounts
To place orders on Surreal, customers must create a user account.
During account creation and use, we process the following data:
- Name
- Email address
- Billing and delivery address
- Order and account history
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
5. Orders and commissioned artworks
When you place an order, we process personal data necessary to handle the commissioning, payment, delivery, and, where applicable, mounting of the artwork.
This may include:
- Order details and specifications (e.g. size, delivery options)
- Communication related to your order
- Delivery and installation information
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and legal obligations (Art. 6(1)(c) GDPR).
6. Payments
Payments on the Website are processed by Stripe.
Depending on the payment method you choose, Stripe may process payment data using the following methods:
- Credit and debit cards
- PayPal
- Apple Pay
- Google Pay
- Bank transfers
- Klarna
Payment data is processed directly by Stripe. We do not store full payment or credit card details.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
7. Marketplace model and data sharing with artists
Surreal operates as an online marketplace and facilitator. The purchase contract for the artwork is concluded between you and the respective artist.
To enable fulfilment of the order, we share only the personal data necessary (such as name, delivery address, and order details) with the respective artist.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
8. Delivery, logistics, and mounting services
For delivery and optional mounting services, we may share personal data with logistics providers or installation partners.
Data shared is limited to what is necessary to perform the service (e.g. name, address, contact details, delivery instructions).
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
9. Cookies and local storage
The Website uses only technically necessary cookies and similar technologies required for core functionality, such as login sessions, shopping cart functionality, and security.
These cookies do not track users and do not require consent under applicable law.
10. Marketing communications
We do not send marketing or promotional communications without your explicit consent.
If you have given consent, you may withdraw it at any time with effect for the future.
Legal basis: consent (Art. 6(1)(a) GDPR).
11. Hosting and data transfers
The Website is hosted in Switzerland.
Switzerland is recognised by the European Commission as providing an adequate level of data protection.
Personal data may also be processed by service providers outside the EU only where legally permitted and subject to appropriate safeguards.
12. Data retention
We retain personal data only for as long as necessary to fulfil contractual obligations and comply with legal retention requirements.
Account and order data may be retained for statutory retention periods under Austrian law.
13. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse.
14. Your rights
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure where legally applicable
- Restrict processing
- Data portability
- Object to processing where legally permitted
- Withdraw consent at any time
To exercise your rights, please contact us using the details above.
15. Right to lodge a complaint
You have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) or another competent supervisory authority.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The version applicable at the time of use shall apply.