Privacy Policy

Robert Bodnar – Filmmaking
April 2026

1. Responsibility

I, Robert Bodnar, am the controller of the personal data processed through this website and my creative services.
Contact Details:
Wiener Straße 53, 8020 Graz, Austria
Email: bdnr2024@gmail.com
Phone: 0660 12 12 900

2. Data Scope and Acquisition

I process information only to the extent necessary to provide high-quality visual content and professional communication.

  • Engagement Data: Name, email, and phone number provided via contact forms or direct messages (WhatsApp, Instagram, TikTok).

  • Financial Records: Billing addresses, VAT IDs, and payment history.

  • Creative Assets: Raw footage, photographs, and briefing documents containing personal likenesses or project-specific details.

  • Technical Metrics: Anonymized IP addresses and browsing behavior collected via Google Analytics.

3. Legal Framework for Processing

All data processing is grounded in the EU General Data Protection Regulation (GDPR):

  • Contractual Necessity (Art. 6.1.b): To manage inquiries, execute photo/video shoots, and deliver final assets.

  • Statutory Requirements (Art. 6.1.c): Adhering to Austrian tax law (§ 132 BAO), which mandates a 7-year retention of financial records.

  • Legitimate Interest (Art. 6.1.f): Promoting my creative work via my portfolio and social media, and maintaining website security.

  • Consent (Art. 6.1.a): For optional tracking or marketing activities you explicitly agree to.

4. External Services & Global Transfers

To host this website, manage large-scale video files, and handle global communication, I utilize specialized third-party providers. Where data is transferred to the USA or other third countries, it is protected by the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs):

  • Hosting & Platform: This website is hosted by Squarespace (Squarespace Ireland Ltd. / Squarespace Inc.). Squarespace processes data to ensure the site’s functionality and security.

  • Project Delivery & Storage: I use Google Drive (Google Cloud) and WeTransfer for the secure storage and transfer of high-resolution visual assets.

  • E-mail Communication: I use Google Gmail (Google LLC, USA) for professional correspondence. Google processes data on servers worldwide. The transfer is safeguarded by SCCs. More information: https://policies.google.com/privacy.

  • Web Analysis: Google Analytics is used to evaluate site performance and user behavior. I have enabled IP anonymization (see Section 10 for details).

  • Social Interaction: Direct interactions on Instagram, TikTok, WhatsApp, X (Twitter), or Telegram are subject to the privacy terms of the respective providers. I have no influence over the data processing carried out by these platforms.

5. Other Recipients of Your Data

I do not sell your personal data to any third parties. To run my business and execute projects, I only share your information with the following recipients when necessary:

  • Tax Advisor & Accountant: I share financial and billing information as required by law to fulfill my tax obligations in Austria.

  • Creative Partners & Contractors: On larger productions, I may share relevant project details with assistants, stylists, or drone operators. This is strictly limited to the extent necessary for the successful execution of your project.

  • Legal Authorities: If required by a court order or legal obligation, I will disclose data to the competent authorities.

6. Data Retention (Storage Durations)

I retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law:

  • Contract & Billing Data: Retained for 7 years after the end of the relevant fiscal year to comply with Austrian tax law (§ 132 BAO).

  • Project Files (Visual Assets): Final photos and films are generally archived for 3 years after delivery as a courtesy. After this period, files may be deleted without notice (unless otherwise agreed in our contract).

  • Communication Data: Emails and messages are stored for the duration of our business relationship plus a 3-year buffer thereafter for the purpose of defending potential legal claims.

  • Website Analytics: Data collected via Google Analytics is automatically deleted after 14 months (standard retention setting).

  • Marketing Data: If you have subscribed to my updates, your data is kept until you withdraw your consent (unsubscribe).

After these periods, data is either securely deleted or fully anonymized.

7. Data Security

Your creative content and personal details are protected by SSL/TLS encryption on my website and rigorous access controls for all cloud-based storage solutions used in my production pipeline.

8. Your Legal Entitlements & Right to Complain Under the GDPR, you have the following specific rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): You may request confirmation of whether I process your data and receive a copy of that data.

  • Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate data or the completion of incomplete data.

  • Right to Erasure (Art. 17 GDPR): You may request the deletion of your data (e.g., if the data is no longer needed), provided this does not conflict with statutory retention periods like Austrian tax law.

  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to request that the processing of your data be limited under certain legal conditions.

  • Right to Data Portability (Art. 20 GDPR): You may request to receive your data in a structured, commonly used, and machine-readable format.

  • Right to Object (Art. 21 GDPR): You may object to processing based on "legitimate interests" at any time.

  • Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw it at any time with effect for the future.

How to exercise your rights: To exercise any of the above rights, please send an email to bdnr2024@gmail.com. I will respond to your request within one month.

Right to Lodge a Complaint: If you believe that the processing of your data violates data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Austria:

  • Österreichische Datenschutzbehörde (DSB)

  • Barichgasse 40–42, 1030 Vienna, Austria

  • Website: www.dsb.gv.at

9. Email Marketing & Newsletters (Squarespace) If you subscribe to my newsletter or receive updates as a client, your data is processed through Squarespace Email Campaigns.

  • Purpose: To provide you with information regarding my photography and filmmaking projects, specialized offers, and creative updates.

  • Data Collection & Analysis: When you receive a newsletter, Squarespace uses technologies (such as web beacons) to track whether you opened the email or clicked specific links. This performance measurement helps me improve the quality and relevance of the content.

  • Legal Basis: This processing is based on your consent (Art. 6.1.a GDPR) or, in the case of existing customers, on my legitimate interest (Art. 6.1.f GDPR) in direct marketing.

  • Service Provider: Squarespace Ireland Ltd., Le Ship, 70 Sir John Rogerson's Quay, Dublin 2, Ireland ("Squarespace").

  • Global Transfers: Data may be transferred to and stored by Squarespace Inc. in the United States. This transfer is secured by the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs).

  • Your Rights: You may withdraw your consent or object to the processing at any time by using the "unsubscribe" link at the bottom of any email or by contacting bdnr2024@gmail.com.

10. Cookies

My website uses cookies to ensure functionality and analyze traffic. Cookies are small text files stored on your device by your browser.

  • Strictly Necessary Cookies: These are required for the website to function properly (e.g., security, navigation). Legal basis: Art. 6.1.f GDPR (Legitimate Interest).

  • Analytics Cookies (Google Analytics): These help me understand how visitors interact with the site so I can improve my portfolio's performance. Legal basis: Consent (Art. 6.1.a GDPR).

  • Managing Cookies: You can manage or delete cookies through your browser settings at any time. Please note that blocking certain cookies may affect the functionality of the website.

11. Google Analytics

This website uses Google Analytics, a web analysis service provided by Google LLC. Google Analytics uses cookies to help analyze how visitors use the site.

  • IP Anonymization: I have enabled IP anonymization (anonymizeIp) on this website. This means Google truncates your IP address within Member States of the European Union or in other states party to the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases is the full IP address sent to a Google server in the USA and truncated there.

  • Legal Basis: Art. 6.1.f GDPR (Legitimate interest in analyzing website usage to improve my services). Where required by law, I obtain your consent before setting analytics cookies (Art. 6.1.a GDPR).

  • Opt-Out: You can prevent Google Analytics from collecting your data by downloading and installing the browser plug-in available here: https://tools.google.com/dlpage/gaoptout.

12. Google Fonts

This website uses Google Fonts to ensure a visually consistent and professional presentation. When you visit this site, your browser loads the required fonts (Manrope and Poppins) directly from Google’s servers.

  • Legal Basis: Art. 6.1.f GDPR (Legitimate interest in a professional design).

  • Safeguard: Data transfer is protected by the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs).

13. Policy Updates

I may refine this policy to reflect changes in technology or law. The most current version is always available at robert-bodnar.com.