Privacy policy
Privacy Policy
Last updated: 29 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
Christian Kernchen e.K.
Joergstr. 31
80689 Munich
Germany
Phone: +49 89 289 747 35
Email: kontakt@kernchen.com
2. Subject matter of this Privacy Policy
This Privacy Policy explains how we process personal data when you visit our KERNCHEN® online store, use a customer account, place an order, contact us or offer us an artwork for sale or brokerage.
Personal data means any information relating to an identified or identifiable natural person. This may include, in particular, names, addresses, contact details, order and payment information, communication content, technical device and access data, and information concerning artworks and their provenance.
We process personal data only where there is a legal basis for doing so. The relevant legal bases are explained below.
3. Accessing and technically providing the online store
When you access our online store, technically necessary information is processed. This may include, in particular, your IP address, date and time of access, pages accessed, referrer URL, browser type, operating system, device information, language settings and information about errors and security-related events.
The processing is carried out to provide the online store technically, deliver content correctly, ensure the stability and security of the service, detect misuse and attacks, and analyse technical errors.
The legal bases are Article 6(1)(b) GDPR insofar as the processing is necessary to take steps at your request prior to entering into a contract or to perform a contract, and Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and economically efficient operation of our online store, the prevention of misuse and the protection of our systems and business processes.
4. Shopify as the shop platform
Our online store is operated using the Shopify e-commerce platform. The provider for merchants established in the European Economic Area is generally Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Shopify processes personal data in particular to provide the online store, checkout, customer accounts, order management, payment functions, security functions and other Shopify services used by us.
Where Shopify processes personal data on our behalf, this is carried out on the basis of a data processing agreement. Depending on the Shopify function used, Shopify may also process personal data as an independent controller.
Shopify Network Intelligence is enabled in our shop. In this context, Shopify may process information about your interactions with our shop together with information from your interactions with Shopify and other Shopify merchants in order to provide so-called enhanced services. These include, in particular, functions for security and fraud prevention, improving and personalising Shopify services, shop performance and—where permitted by you—personalising advertising. Other merchants do not thereby receive direct access to the personal data of our shop.
For these purposes, data is transmitted to Shopify and, where applicable, to service providers used by Shopify. These recipients may also be located outside Germany or the European Economic Area. Where consent is required for non-essential processing, personalised advertising or comparable purposes, the corresponding processing takes place only after you have given your consent.
Further information about Shopify's independent processing of data, your rights in relation to Shopify and the privacy options offered by Shopify can be found in Shopify's Consumer Privacy Policy and the Shopify Privacy Portal.
5. Cookies and similar technologies
Our online store uses cookies and comparable technologies through which information may be stored on or accessed from your terminal device. These may include, in particular, session cookies, local storage technologies, pixels, device identifiers and similar technologies.
Technologies that are strictly necessary are used to provide functions of the online store expressly requested by you. These include, in particular, the shopping cart, checkout, login, customer account, security, fraud prevention, language settings and storage of your privacy choices. Their use is based on Section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). The associated processing of personal data is based, depending on the purpose, on Article 6(1)(b) or Article 6(1)(f) GDPR.
We use technologies that are not strictly necessary, in particular for additional analytics, personalisation or marketing purposes, only where you have previously given consent through the cookie banner. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.
You can withdraw or change consent you have given at any time with effect for the future via the cookie settings provided in the shop. The lawfulness of processing carried out before withdrawal remains unaffected. Details of the technologies used, providers, purposes and storage periods are displayed in the cookie settings.
6. Orders and contract processing
When you place an order, we process the data required to conclude and perform the contract. This includes, in particular:
- name and contact details,
- billing and delivery address,
- artworks or other goods ordered,
- order value, prices, taxes and shipping information,
- selected payment method and payment status,
- communications concerning the order, and
- information concerning returns, withdrawal, complaints and refunds.
The processing is carried out to process and accept your order, process payment, deliver the goods, communicate about order status, handle statutory rights in respect of defects and process returns or refunds. The legal basis is Article 6(1)(b) GDPR.
Where we must process order and business data to comply with obligations under commercial, tax, anti-money-laundering, cultural-property or sanctions law, Article 6(1)(c) GDPR is the legal basis.
To prevent fraud, payment defaults and other misuse, order, payment and technical data may also be checked for irregularities. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are protecting our assets, our customers and our business processes, and preventing unlawful transactions.
7. Payment processing
Depending on the device, availability and technical requirements, checkout may offer Shopify Payments, credit and debit cards, Shop Pay, Apple Pay, Google Pay and bank transfer as advance payment.
For electronic payments, the data required for payment processing is transmitted directly to Shopify and the respective participating payment service providers, banks, card organisations or wallet providers. This may include, in particular, name, billing address, order amount, currency, transaction identifier, device and security data and payment information. Complete card details are generally processed by the participating payment service providers and are normally not fully accessible to us.
The processing is carried out to perform the payment method selected by you and therefore to perform the contract pursuant to Article 6(1)(b) GDPR. Statutory verification, documentation and retention obligations are based on Article 6(1)(c) GDPR. Security and fraud checks may also be based on Article 6(1)(f) GDPR.
If you use Apple Pay or Google Pay, the privacy policies of the respective wallet provider additionally apply. These providers may process personal data under their own data protection responsibility.
For payment by bank transfer, we process, in particular, the name of the account holder, the bank details used, the payment reference, the amount transferred and receipt of payment. The legal basis is Article 6(1)(b) GDPR.
8. Shipping and delivery
To deliver your order, we transmit the necessary data to the parcel service, art transporter, freight forwarder or other shipping provider used for the respective delivery. As a rule, only the information required for delivery is transmitted, in particular name, delivery address, contact details, shipment information and, where applicable, information required to arrange a delivery date.
The processing and transmission are carried out to perform the contract pursuant to Article 6(1)(b) GDPR. Where a telephone number or email address is used solely for additional delivery notifications and this is not already necessary to carry out the delivery, it is used on the basis of your consent pursuant to Article 6(1)(a) GDPR.
9. Customer account
You may use a customer account to view and manage your orders, order status, addresses, return and cancellation requests and, where applicable, available store credit.
For the customer account, we process, in particular, your email address, authentication information used for login, your stored contact details, order history, return and cancellation requests and account settings. With the new Shopify customer accounts used by us, login is generally passwordless using a verification code sent to your email address.
The processing is carried out to provide the account functions requested by you pursuant to Article 6(1)(b) GDPR and to securely manage the account pursuant to Article 6(1)(f) GDPR.
You may request deletion of your customer account. Data subject to statutory retention obligations or required for the establishment, exercise or defence of legal claims may remain stored in restricted form for the period required after the account has been deleted.
10. Contact, advice and Private Sales
If you contact us by email, telephone, contact form or another method, we process the data you provide. This includes, in particular, your name, contact details, the content and time of your enquiry and subsequent correspondence.
If the contact concerns an order, an intended contract, personal advice or an enquiry about an artwork, Article 6(1)(b) GDPR is the legal basis. For general business enquiries or communication with contact persons at a company, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the proper handling and documentation of business communications.
Enquiries relating to Private Sales are treated confidentially in accordance with the nature of the enquiry. Information is disclosed only insofar as this is necessary to process the enquiry, carry out a requested transaction, examine an artwork or comply with legal obligations.
11. Offering artworks and provenance information
If you offer us an artwork for purchase or brokerage, we may process, in particular, information about you, your contact details, the artwork, ownership, provenance, acquisition history, condition, authenticity, signature, invoices, expert reports, certificates and other documentation.
The processing is carried out to assess your enquiry, prepare a possible purchase or brokerage agreement and communicate with you pursuant to Article 6(1)(b) GDPR. Checks to protect against fraud, establish authority to dispose of the work and safeguard legitimate interests of artists, rights holders, owners and purchasers are carried out on the basis of Article 6(1)(f) GDPR.
Where legally required identity, origin, sanctions, anti-money-laundering or documentation checks are necessary, processing is carried out on the basis of Article 6(1)(c) GDPR.
If you provide us with personal data of third parties, such as information about previous owners, experts or other persons involved, please ensure that you are entitled to provide that information.
12. Security, misuse and fraud prevention
We and our technical and payment-related service providers may process personal data to detect, prevent and investigate unauthorised access, fraudulent orders, identity misuse, payment defaults, manipulation and other unlawful or security-threatening activities.
For this purpose, order, payment, account, device, network and usage data as well as risk indicators provided by Shopify or payment service providers may be processed. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the security of the online store, the protection of our customers and the prevention of financial loss and infringements of rights.
13. Recipients and service providers
Where necessary for the purposes described above, personal data may in particular be transmitted to the following categories of recipients:
- Shopify and subprocessors used by Shopify,
- payment service providers, banks, card organisations and wallet providers,
- parcel services, art transporters, freight forwarders and other logistics providers,
- IT, hosting, email, telecommunications, security and support service providers,
- tax advisers, lawyers, auditors and other professional advisers,
- artists, rights holders, experts or other parties insofar as this is necessary for a specific art transaction or examination, and
- authorities, courts and other public bodies where a statutory obligation or a valid administrative or court order exists.
Service providers commissioned by us are contractually bound where legally required and may process personal data only on our instructions and for the agreed purposes. Disclosure for their own purposes takes place only where there is an independent legal basis for doing so.
We do not sell your personal data.
14. Processing outside the European Economic Area
When using Shopify and other service providers, personal data may be processed outside Germany and the European Economic Area. This applies in particular to affiliated companies, data centres and subprocessors of internationally operating providers.
A transfer to a third country takes place only where the requirements of Articles 44 et seq. GDPR are met. This may be based, in particular, on an adequacy decision of the European Commission, appropriate safeguards such as the European Commission's Standard Contractual Clauses, or an exception permitted by law. Where required, supplementary protective measures are taken into account.
Further information on international transfers by Shopify can be found in Shopify's privacy information and Data Processing Addendum.
15. Storage periods
We store personal data only for as long as necessary for the respective processing purpose or for as long as statutory retention obligations apply.
Order, contract, invoice, payment and accounting data is generally retained for six, eight or ten years in accordance with commercial and tax law requirements. The respective period generally begins at the end of the calendar year in which the relevant document, business transaction or record arose.
We generally retain data relating to warranty cases, returns, withdrawals and other contractual claims until the applicable statutory limitation periods have expired. The regular limitation period under German civil law is generally three years and usually begins at the end of the year in which the claim arose.
We generally store general contact and advisory enquiries until they have been finally dealt with and thereafter for an appropriate period, normally no longer than until expiry of the general limitation period, unless longer retention is required.
Customer account data is generally stored until the account is deleted. Order and business data subject to statutory retention requirements remains stored for the duration of the statutory retention period irrespective of deletion of the account.
Consents and the associated evidence are stored for as long as necessary to demonstrate lawful processing and defend against possible claims. Information on the storage duration of cookies and comparable technologies can be found in the cookie settings.
Longer storage may take place where this is necessary for the establishment, exercise or defence of legal claims, compliance with statutory obligations, or because of an administrative or court order. Once the purpose of processing ceases to apply, the data is deleted or, where statutory retention obligations exist, restricted from further processing.
16. Obligation to provide data
Providing the information marked as required in checkout is necessary in order to complete an order and perform the contract. Without this information, we cannot process or fulfil the order.
For payment, identity, sanctions or other legally required checks, it may be necessary to provide additional information. Without the required information, a transaction may not be possible.
For general contact enquiries and when offering an artwork, you need provide only the information necessary to properly process your specific enquiry. Additional information is voluntary.
17. Automated decisions
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Shopify, payment service providers and other security service providers may use automated procedures for fraud, risk or payment checks. Such checks may lead to rejection of a payment method, a request for additional information or manual review of an order. Where a service provider independently determines the purposes and means of processing, its privacy information additionally applies.
18. Your data protection rights
Subject to the statutory requirements, you have in particular the following rights:
- the right of access to personal data processed about you pursuant to Article 15 GDPR,
- the right to rectification of inaccurate data or completion of incomplete data pursuant to Article 16 GDPR,
- the right to erasure pursuant to Article 17 GDPR,
- the right to restriction of processing pursuant to Article 18 GDPR,
- the right to data portability pursuant to Article 20 GDPR,
- the right to object to processing pursuant to Article 21 GDPR, and
- the right to withdraw consent you have given at any time with effect for the future pursuant to Article 7(3) GDPR.
If we process personal data on the basis of Article 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
You may object to the processing of personal data for direct marketing purposes at any time without stating reasons.
To exercise your rights, you can contact kontakt@kernchen.com. To prevent unauthorised access to data, we may request reasonable proof of your identity.
Where Shopify processes personal data under its own responsibility, you may additionally exercise your rights in relation to Shopify via the Shopify Privacy Portal.
19. Right to lodge a complaint
Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. In particular, you may contact the supervisory authority responsible for us:
Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht – BayLDA)
Promenade 18
91522 Ansbach
Germany
Website: www.lda.bayern.de/de/beschwerde.html
20. Updates to this Privacy Policy
We update this Privacy Policy when our online store, the service providers used, the functions offered, our data processing activities or legal requirements change. The version published in the online store at the relevant time applies.