GDPR PRIVACY NOTICE

Introduction

This GDPR Privacy Notice applies to users of Tales Recipes (www.talesrecipes.com) who are located in the European Economic Area (EEA). This notice supplements our general Privacy Policy and provides additional information required by the EU General Data Protection Regulation (GDPR).

Data Controller

For the purpose of the GDPR, the data controller is: Tales Recipes Email: [email protected] Website: www.talesrecipes.com

Legal Basis for Processing

We process your personal data on the following legal bases:

Consent (Article 6(1)(a) GDPR):

  • Newsletter subscriptions
  • Cookie usage (except essential cookies)
  • Comment submissions
  • Recipe ratings and reviews

Legitimate Interests (Article 6(1)(f) GDPR):

  • Website analytics
  • Security measures
  • Service improvement
  • Content optimization

Contract Performance (Article 6(1)(b) GDPR):

  • User account management (if applicable)
  • Responding to your inquiries
  • Processing your requests

Legal Obligation (Article 6(1)(c) GDPR):

  • Compliance with EU law
  • Tax regulations (if applicable)
  • Response to legal requests

Data We Collect

Personal Data:

  • Email address (for newsletter subscribers)
  • Name (if provided in comments)
  • IP address
  • Cookie identifiers
  • Browser type and version
  • Operating system
  • Referral source
  • Length of visit
  • Page views
  • Website navigation
  • Time zone setting

Special Categories of Data:

We do not intentionally collect or process any special categories of personal data (as defined in Article 9 GDPR).

How We Use Your Data

We use your personal data for:

  1. Providing our services
  2. Improving website functionality
  3. Analyzing user behavior
  4. Sending newsletters (with consent)
  5. Managing comments and interactions
  6. Ensuring website security
  7. Complying with legal obligations

Data Retention

We retain personal data only for as long as necessary to:

  • Provide requested services
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements

Specific retention periods:

  • Newsletter subscription data: Until unsubscription
  • Comment data: As long as the content remains published
  • Analytics data: 26 months
  • Cookie data: Varies by cookie type (see Cookie Policy)

Your Rights Under GDPR

You have the following rights:

Right to Access (Article 15 GDPR)

  • Request confirmation of data processing
  • Access your personal data
  • Receive copy of data held

Right to Rectification (Article 16 GDPR)

  • Correct inaccurate personal data
  • Complete incomplete personal data

Right to Erasure (Article 17 GDPR)

  • Request deletion of personal data
  • Remove consent for processing

Right to Restriction (Article 18 GDPR)

  • Limit processing of personal data
  • Maintain but not process data

Right to Portability (Article 20 GDPR)

  • Receive data in structured format
  • Transmit data to another controller

Right to Object (Article 21 GDPR)

  • Object to processing based on legitimate interests
  • Object to direct marketing

Rights Related to Automated Decision Making (Article 22 GDPR)

  • Not be subject to automated decisions
  • Obtain human intervention
  • Express your point of view
  • Contest automated decisions

International Data Transfers

If we transfer your data outside the EEA, we ensure adequate protection through:

  • EU Standard Contractual Clauses
  • Adequacy decisions by the European Commission
  • Other appropriate safeguards

Cookies and Tracking

We use cookies and similar technologies. For detailed information, see our Cookie Policy. Essential cookies cannot be disabled as they are required for website functionality.

Third-Party Services

We use the following third-party services:

  1. Google Analytics
    • Purpose: Website analytics
    • Data collected: Usage data, IP address
    • Location: United States
  2. Google AdSense
    • Purpose: Advertisement display
    • Data collected: Cookie data, IP address
    • Location: United States

Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • SSL encryption
  • Secure data storage
  • Access controls
  • Regular security assessments

Making a Request

To exercise your rights or make inquiries about your personal data:

  1. Email us at [email protected]
  2. Provide sufficient information to identify you
  3. Specify which right you wish to exercise
  4. Indicate the data to which your request relates

We will respond to requests within one month, with possible extension of two months for complex requests.

Complaints

You have the right to lodge a complaint with your local data protection authority if you are unhappy with how we handle your personal data.

Changes to This Notice

We may update this GDPR Privacy Notice periodically. Changes will be posted on this page with an updated revision date. Significant changes will be notified directly to affected users.

Last Updated: February 19, 2024