Privacy
Updated 6 September 2026.
Who is responsible for your data
The controller of purchase data in the photography.antisoosaar.ee preset shop is Blacksunset OÜ, registry code 16513658, address Hariduse põik 1, Kõrveküla alevik, Tartu vald, Tartu maakond, 60512, Estonia. For questions about your data, email anti@nulleuri.ee or call +372 5820 0900.
This notice covers preset purchases, order emails, downloads and use of a shop account.
What we record when you buy
Your order includes the name, email address, billing details and other contact fields you complete at checkout, the products purchased, price, order time, payment method and payment status. If you contact us about your purchase, we also use your message and the information needed to help you. The main order details are stored in our shop’s database.
When you choose immediate digital delivery, we record the exact wording, version, language and time of your acknowledgement, together with a copy of the terms that applied to your order. This lets us show what you agreed to when buying. The acknowledgement is included in your order email. It concerns delivery of the files and is not consent to receive advertising.
You do not need an account to buy. When you use an existing account, the order is associated with it and you can view the related purchase details there. You must still provide the information needed for the purchase: without it, we cannot fulfil the order or arrange access to the files.
Using the site also involves processing connection and device information, such as your IP address, browser information, request time and session identifier. File download permissions and the information needed to use them are associated with the order. Web server and security logs help investigate faults and prevent unauthorised access.
Why we use the data
We use data to enter into or perform the contract when taking your order, matching payment to it, providing file access and helping with your purchase. Keeping invoices and other required accounting records is a legal obligation.
For security and resolving legal claims, we use the necessary information based on our legitimate interests: protecting purchases and customer data, and being able to resolve questions about an order. Optional visitor analytics is based on your consent.
Who receives the data
When you pay through Montonio, the order, amount and payer details needed for payment are sent to the payment service, and we receive the payment result. Montonio Finance UAB acts as a separate controller when providing the payment initiation service. Its privacy notice explains its processing.
We use Hostinger for website hosting and for receiving messages sent to our contact address. Technical service providers have access to the information needed to provide their services. The seller’s authorised people handle orders and messages. We may also disclose necessary data to a competent authority where required by law.
If you allow analytics cookies, Google Analytics is used to understand visits to the site. Google receives the technical and usage information needed for this purpose; analytics helps us understand how the site is used and improve its content and operation.
Service providers’ infrastructure and support services may also be located outside the European Economic Area. Such transfers use an applicable adequacy decision or other safeguards provided by law, including the European Commission’s standard contractual clauses. Further information is available in Hostinger’s data processing terms and Google’s data processing terms. You can also ask us for information about particular recipients and safeguards.
How long we keep the data
Accounting source documents must be kept for seven years from the end of the financial year in which the transaction was entered in the accounting records using those documents. This does not mean that all account, cookie and technical data must be retained for the same period.
We keep order and immediate-delivery records for as long as they are needed to provide purchased access, fulfil contractual obligations or resolve a legal claim. Correspondence about a purchase is kept for the time needed to resolve and follow up on that matter. Account and order data is not automatically deleted on a fixed date. When you request erasure, we assess which information is still needed and which must be removed or anonymised.
WooCommerce’s technical file logs have a 30-day retention period. Other server and security logs, and backups, are kept according to the time needed to investigate a fault or security incident and restore the service. They are not intended as a permanent archive of purchase data. You can ask us to explain the retention of particular information.
Cookies and your choices
The shop uses technical cookies to keep your cart and let you sign in. WooCommerce’s core cookies associate your browser with the cart and help detect changes to it. Your selected shop language is associated with the shopping session. Blocking cookies may prevent the cart or account from working properly.
CookieYes remembers your consent choice for up to 365 days. Analytics and other optional cookies only start after the relevant consent. Google Analytics uses cookie identifiers, device information and site activity to produce visitor statistics. Read Google Analytics’ explanation of its data use.
You can change your choice at any time through “Cookie settings” in the footer. Withdrawing consent does not make processing carried out before withdrawal unlawful. Refusing necessary purchase information or cookies needed to operate the site may prevent a purchase; refusing analytics does not.
Your rights
You can ask for a copy of your data and for inaccuracies to be corrected. Where the law provides, you can request erasure, restriction or data portability, and object to processing based on legitimate interests. An erasure request does not remove the duty to retain legally required records.
Email anti@nulleuri.ee. We may need information to verify your identity. We normally respond within one month; if a lawful extension is needed, we explain the reason within that period.
If you believe your data protection rights have been infringed, you can complain to the Estonian Data Protection Inspectorate or contact the data protection authority in your country of residence.