PunkImagine / Legal information
Privacy
This notice explains which data are processed when you visit this website or contact PunkImagine.
1. Controller
Peter Punk / PunkImagineLiebknechtgasse 7/33/4
1160 Wien, Austria
For privacy questions and to exercise your rights: contact@punkimagine.com.
2. This website
This notice covers visits to punkimagine.com, contact by email and our own processing on the social media profiles listed below.
The website has no visitor registration, shop or contact form. We do not use marketing cookies, advertising pixels or embedded analytics tools here. Typography, images and decorative 3D scenes are supplied through files on our own web server. The scenes’ response to pointer movements is calculated locally in your browser; the website does not send this movement data to us.
You can switch between German and English and choose a light, dark or system appearance. The language is determined by the page address. An appearance you select is carried in the page address as the general parameter “theme=light” or “theme=dark”. We use no cookies, Local Storage or Session Storage for this. A new direct visit without this parameter follows your system setting. The requested address, including this parameter, may form part of the technical server logs described below; it contains no individual identifier.
3. Website delivery and hosting
To retrieve the website, your browser sends technical connection data to the web server. These include your IP address, the time, requested address and request method, and information about your device and browser. Hostinger’s server logs also include data volume, response time, error status and a country derived from the IP address. Depending on the browser, the previously visited page may also be transmitted.
We use this processing to deliver the website and protect its operation. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is in providing an available, secure and functional website.
Our service provider is Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, for web hosting and Hostinger Email. The web server selected in the hosting account is in the Netherlands; the stated backup location is Lithuania. Hostinger’s Data Processing Agreement covers hosting and email services.
Hostinger may use subprocessors. For transfers outside the European Economic Area to countries without a recognised adequate level of data protection, section 9 of the linked agreement provides, in particular, for EU standard contractual clauses. Information about safeguards is available in that agreement or from our privacy contact.
Logs and backups
Hostinger logs technical requests to deliver, troubleshoot and secure its services. We keep no additional personal visitor database and do not create visitor profiles from these data.
For hosting file backups, Hostinger states retention periods of seven days for daily backups and six weeks for weekly backups. These periods apply to those backups; they do not describe all security or email logs. The source is Hostinger’s backup information.
We have asked Hostinger for the binding deletion periods of internal server and security logs and the specific subprocessors and processing countries used for our services. These details are still outstanding. We will update this notice when they arrive. You can also contact us to request information and exercise your rights regarding these data.
4. Contact by email
If you write to us, we process your email address, the content of your message, and any information and attachments you send, to handle your enquiry. Providing these is voluntary; without a reachable address, we cannot reply.
For enquiries about a contract or a proposed collaboration, the legal basis is Article 6(1)(b) GDPR. For other enquiries, it is Article 6(1)(f) GDPR, based on our interest in responding to incoming requests.
We retain correspondence for as long as needed to handle the enquiry and directly related follow-up questions. If statutory retention duties apply, or documents are needed to establish, exercise or defend legal claims, further retention depends on those duties or the specific proceedings. The data are then deleted.
When sending email, Hostinger also processes technical delivery information, in particular the sender, recipient, time and delivery status. According to Hostinger, delivery logs are available in the administration area for 30 days. This is not a confirmed deletion date for all internal copies. We have also requested the further retention periods.
5. Links to other platforms
YouTube, GitHub, X, Instagram, TikTok, Threads, Bluesky and Ko-fi are accessible through ordinary links. We embed no video players, social feeds or social plugins from these providers on this website. You visit the provider’s service only when you follow a link; its privacy notices then apply.
6. Our social media profiles
We operate the PunkImagine profiles linked in the footer on YouTube, X, Instagram, TikTok, Threads, Bluesky and GitHub to present our content and communicate with interested people.
If you communicate with us there, we process visible profile information, your message or comment and associated timestamps as needed to respond and moderate. The legal basis is Article 6(1)(f) GDPR: our interest in accessible communication and constructive discussion. For specific pre-contractual or contractual matters, Article 6(1)(b) GDPR applies. You can contact us by email instead.
Public comments are visible to other users. Confidential information should not be posted there. Direct messages are technically accessible to the relevant platform provider; please do not send sensitive documents through them. We retain our own copies of correspondence according to the criteria in “Contact by email”. Platform storage and the distribution of public content also depend on the services involved; especially in decentralised networks, copies may remain beyond our control.
Providers also process data for their own purposes, such as security, personalisation, reach measurement and advertising. Data may be processed outside the EEA. Information about controllers, recipients, retention, transfer safeguards and platform settings is available here:
- YouTube / Google — privacy
- X — privacy
- Instagram / Meta — privacy
- Threads — supplemental privacy notice
- TikTok — EEA privacy policy
- Bluesky — privacy
- GitHub — privacy
Audience statistics
Platforms may provide aggregated information about views and interactions. Depending on the service, additional rules on responsibility apply to these statistics.
For TikTok, the TikTok Analytics Joint Controller Addendum describes joint responsibility for collecting and aggregating interaction data, where its conditions apply. TikTok is responsible in particular for technical processing, data security and handling data subject rights concerning these data. Our own information duties and a legal basis on our side remain necessary. You can also exercise your rights with us; we will coordinate the response with the provider.
Where we evaluate aggregated statistics to select and improve our content, this serves our legitimate interest in providing relevant information (Article 6(1)(f) GDPR). We do not use them to create cross-platform profiles of individuals. Collection by the platforms and their own purposes are separate from this. The scope and responsibility rules of automatically available account statistics are currently being checked against the respective product terms; we use no additional analytics services or advertising pixels.
7. Voluntary support through Ko-fi
You can support PunkImagine on Ko-fi through an ordinary link. Visiting our website loads no Ko-fi or Stripe content. We embed no payment widget and send no mouse movements or clicks to these providers. Following the link takes you to an external website.
The support page is operated by Ko-fi Labs Limited, United Kingdom; payments are processed through Stripe. Ko-fi and we are independently responsible for our respective processing. Depending on the function, Stripe acts as controller or processor; it identifies Stripe Technology Company, Limited, Ireland, as primarily responsible for its own processing outside the Americas. Details are available in the Ko-fi privacy notice and Stripe Privacy Center.
When you contribute, we receive information including your display name, email address, amount, currency, date, payment status and transaction reference, plus any optional message. Stripe may also provide your legal name, parts of your billing address and limited payment method information. Full card numbers and security codes are not collected on our website. Depending on your Ko-fi settings, your name and message may be public; check their visibility before submitting.
We use these data to identify and process your contribution and handle questions or refunds (Article 6(1)(b) GDPR), meet accounting and record-keeping obligations (Article 6(1)(c)), and, where necessary, prevent abuse and resolve payment disputes (Article 6(1)(f); our legitimate interest in secure payment handling). We do not use supporter email addresses for newsletters or advertising without separate consent. Support is voluntary; our website remains available without payment. Payment-related information is only required if you choose to contribute.
We generally retain accounting and payment records for seven years from the end of the relevant calendar year, and longer where needed for pending tax or court proceedings. We delete accompanying messages that are not required as records once the matter and directly related follow-up questions are resolved. Ko-fi and Stripe retain their own data under their linked privacy notices and legal obligations. Deleting our copies does not by itself remove records held independently by these providers.
Recipients include the platform and payment providers and financial institutions involved in the payment; legally required records may be disclosed to competent authorities. Ko-fi processes data in the UK, which is covered by an EU adequacy decision. Providers may also process data in other countries, including the US. Ko-fi identifies standard contractual clauses as a safeguard. Stripe describes adequacy decisions, the EU-US Data Privacy Framework for covered certified recipients, and standard contractual clauses in its data protection agreement. Details of applicable safeguards are available in these documents or through our privacy contact. Your rights below also apply to our processing of support-related data.
8. Your rights
Subject to the legal conditions, you have the right of access, rectification, erasure, restriction of processing and data portability.
Objection: Where processing is based on legitimate interests, you can object at any time on grounds relating to your particular situation. Where processing is based on your consent, you can withdraw it with effect for the future.
You can lodge a complaint with a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Wien, email: dsb@dsb.gv.at.
In connection with this website, we make no solely automated decisions with legal or similarly significant effects and carry out no profiling.
9. Last updated
12 September 2026. We update this information when the website or its services change.