Privacy policy
Last updated: September 2026. This is a translation for convenience; the German version is legally binding.
1. Controller
The controller responsible for data processing on this website under the General Data Protection Regulation (GDPR) is:
Ashok GunasekaranWunder Frame StudiosZeuschelstraße 57b13127 BerlinGermanyEmail: hello@wunderframestudios.com
We have not appointed a data protection officer because we are not legally required to.
2. Summary
We use no analytics or tracking, no marketing cookies and no embedded social media. We process personal data only to deliver and secure this website and to answer your enquiries.
3. Hosting, delivery and server logs (Cloudflare)
This website runs on Cloudflare Workers; Cloudflare also provides DNS and network protection. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.
When you visit the site, technically necessary connection data is processed: IP address, date and time, requested URL, referrer URL, browser type and version, operating system, HTTP status code and amount of data transferred.
The purpose is to deliver the website and keep it stable and secure (for example, fending off attacks and abuse). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure, working website. We do not analyse this data or keep our own access logs. Cloudflare keeps log data according to its own policies. For transfers to the USA, see section 11.
4. Images via the Sanity CDN
Your browser loads this website's images directly from the content delivery network cdn.sanity.io operated by Sanity AS (Norway). This sends your IP address, browser information and the requested image address to Sanity. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is fast, reliable image delivery.
5. Cookies and access to your device
We set one cookie, and it is technically necessary: NEXT_LOCALE. It stores your language ("de" or "en") and is set only when you switch language or open a language version that differs from your browser's language setting. It is a session cookie and is deleted when you close your browser. The legal basis is § 25(2) no. 2 TDDDG (strictly necessary for the service you requested) together with Art. 6(1)(f) GDPR.
For security reasons, Cloudflare may in individual cases set further technically necessary cookies, for example when a security check is shown. For Cloudflare Turnstile, see section 7. None of this requires your consent, so we do not use a cookie banner.
6. Enquiry form
When you contact us through the enquiry form, we process:
- Required: type of shoot, name, email address, message
- Optional: preferred date or birth/event date, location, phone/WhatsApp, how you heard about us
- Added automatically: the language version you used and the time of your enquiry
- Added by us: processing status, a reserved date if any, and internal notes
Your IP address is used briefly when you submit the form, to prevent abuse (section 7). It is not stored with your enquiry.
What happens: your enquiry is stored in our content system, Sanity (section 8). Through the email service Brevo (section 9) we receive a notification with your details in our mailbox (section 10), and you receive an automatic confirmation.
Purpose and legal basis: we process your details to answer your enquiry and to prepare a quote or contract (Art. 6(1)(b) GDPR – steps taken before entering into a contract). For general enquiries not aimed at a contract, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is answering your request. Telling us how you heard about us is optional; we use it on the basis of Art. 6(1)(f) GDPR to understand how clients find us.
Please share only what we need for your enquiry. We use a due date or birth date only to plan the shoot; we do not need health or other sensitive details.
How long we keep your data: if no booking follows, we delete your enquiry, including the related emails, 6 months after our last contact. If you book with us, we keep the data for as long as we need it to carry out the contract, and after that until the statutory limitation period ends (usually three years from the end of the year in which the job was completed). Documents subject to statutory retention duties (in particular § 147 AO) are kept for the period those rules set. After deletion, versions and backups held by our service providers may remain for a limited time for technical reasons.
We need the required fields to handle your enquiry; the form cannot be sent without them. You can always email us instead.
7. Protection against spam and abuse (including Cloudflare Turnstile)
The form contains a field that is invisible to people and a timing check, both to detect automated submissions. We also limit how many enquiries can be sent from one IP address within a short time; for this, Cloudflare briefly uses your IP address as the counter key, and we do not store it.
On the enquiry page we use Cloudflare Turnstile (provider: Cloudflare, Inc., see section 3). Turnstile loads a script from challenges.cloudflare.com and processes your IP address, browser and device characteristics (such as the user agent) and technical interaction and timing signals to detect automated access. When you submit the form, we send the check token that Turnstile created, together with your IP address, to Cloudflare for verification. The legal basis for accessing information on your device is § 25(2) no. 2 TDDDG; for further processing it is Art. 6(1)(f) GDPR, our legitimate interest being protecting our form against spam and abuse. More information: https://www.cloudflare.com/turnstile-privacy-policy/
8. Content system and storage of enquiries (Sanity)
We store this website's content and incoming enquiries with Sanity AS (Norway). Enquiries are not publicly accessible; only we can access them, through password-protected accounts. Sanity uses sub-processors, including some outside the EEA (see section 11). Legal basis: as in section 6.
9. Sending emails (Brevo)
We send the notification to ourselves and your confirmation through Brevo. The provider is Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France. Brevo processes your name, email address, the content of your message and sending metadata (time, delivery status). The legal basis is Art. 6(1)(b) or (f) GDPR. We have a data processing agreement with Brevo (Art. 28 GDPR).
10. Contact by email and our mailbox (Zoho)
When you email us, or we reply to you, we process your email address, your name and the content of the correspondence. Our mailbox is provided by Zoho Corporation B.V. (Netherlands) in the EU. The legal basis is Art. 6(1)(b) or (f) GDPR; retention follows section 6.
11. Transfers to third countries
Cloudflare, Inc. is based in the USA and certified under the EU-US Data Privacy Framework. Transfers are therefore based on the European Commission's adequacy decision (Art. 45 GDPR), with Standard Contractual Clauses (Art. 46(2)(c) GDPR) as an additional safeguard. Where Sanity, Brevo or Zoho use sub-processors outside the EEA, this is based on an adequacy decision or Standard Contractual Clauses. Norway is part of the EEA, so the GDPR applies there.
12. Fonts
Our fonts are served from our own server. Visiting the site does not connect you to Google or any other font provider.
13. Link to Instagram
We link to our Instagram profile with a plain link only. Only when you click it are you taken to Instagram (Meta Platforms Ireland Ltd.), where Meta's privacy policy applies.
14. Photos of our clients
We only publish photos of clients with their express written consent, and for children with the consent of those with parental responsibility. Consent can be withdrawn at any time for the future by writing to hello@wunderframestudios.com; we will then remove the images from our website.
15. Recipients
Apart from us, your data is received only by the service providers named above, acting as our processors. We do not pass your data to anyone else or sell it, unless the law requires us to.
16. Your rights
You have the right to access your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21, see below). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). Just write to hello@wunderframestudios.com.
You also have the right to complain to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Berliner Beauftragte für Datenschutz und InformationsfreiheitAlt-Moabit 59–61, 10555 Berlinmailbox@datenschutz-berlin.de · www.datenschutz-berlin.de17. Right to object under Art. 21 GDPR
Where we process your data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing it unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
18. No automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The automatic spam check (section 7) only decides whether the form can be sent; if it blocks you by mistake, you can always reach us by email.
19. Encryption
For security, this website uses TLS encryption (you can see this from "https://").
20. Changes
We update this policy when the website or the law changes. The version published here applies.
