Last updated: 7 October 2026
This Privacy Policy explains how THE Golden Library (“we”, “us”) processes personal data when you visit thegoldenlibrary.com, create an account, use the forum, contact us, or buy a service. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Belgian data protection law.
1. Who is responsible for your data (controller)
THE Golden Library, operated by Daan De Graeve (private individual)
Vaartstraat 29 bus 18, 1000 Brussel, Belgium
Email: th*************@***il.com
Enterprise number (KBO/BCE): none at this time
We have not appointed a Data Protection Officer because we are not legally required to. For any privacy question, contact us at th*************@***il.com.
2. What data we collect, why, and on what legal basis
| Activity | Data | Purpose | Legal basis (GDPR art. 6) | Retention |
|---|---|---|---|---|
| Visiting the website | IP address, browser and device data, pages visited, date/time, referrer (server logs and our visitor-statistics plugin) | Operating and securing the site, basic visitor statistics | Legitimate interest (6.1.f): running a secure, working website | Server logs: 30 days; visitor statistics (stored on our own server by the statistics plugin): up to 13 months |
| User account (registration/login) | Username, email address, password (stored hashed), profile information you add | Providing your account and access to the forum and orders | Contract (6.1.b) | Until you delete your account or ask us to |
| Forum (wpForo) | Posts, topics, replies, profile, IP address of posts | Running the community forum | Contract (6.1.b) and legitimate interest (6.1.f) for moderation and abuse prevention | As long as the forum post exists; deleted with your account on request (posts may be anonymised instead of deleted where needed to keep threads readable) |
| Contact form (Contact Form 7) | Name, email address, message, any data you include | Answering your question | Legitimate interest (6.1.f), or pre-contractual steps (6.1.b) | Up to 12 months after the conversation ends |
| Orders (WooCommerce: THE List tasks) | Name, email, billing address, order details, order notes, payment status | Performing the contract, invoicing, customer service | Contract (6.1.b); legal obligation (6.1.c) for accounting records | Accounting records: 7 years (Belgian accounting/tax law); other order data: up to 2 years after the order (customer service and possible claims), unless it forms part of the accounting records |
| Payments (Stripe via WooPayments; PayPal) | Payment data is entered directly with the payment provider; we receive payment status and limited details (e.g. card brand, last 4 digits) | Processing your payment and preventing fraud | Contract (6.1.b); legitimate interest in fraud prevention (6.1.f) | As required for accounting (7 years) |
| Spam protection (CleanTalk) | IP address, email address and content of forms/comments/registrations, browser data used to detect bots | Protecting the site and forum against spam and abuse | Legitimate interest (6.1.f) | CleanTalk’s cloud log: 7 days by default (45 days if CleanTalk’s extended package is active), then deleted automatically |
| Google Fonts | Your IP address is sent to Google when your browser loads fonts from Google’s servers | Displaying the site’s typography | Legitimate interest (6.1.f) | Not stored by us |
| CanvasJS (cdn.canvasjs.com) | Your IP address is sent to the CDN when your browser loads the charting script | Displaying charts in our memory games/pages | Legitimate interest (6.1.f) | Not stored by us |
| Amazon affiliate links | We do not send personal data to Amazon. When you click an Amazon link, Amazon sets its own cookies and processes data under its own privacy notice | Earning a commission on qualifying purchases (see Affiliate Disclosure) | Not applicable on our side; Amazon is an independent controller for data it collects on its site | Determined by Amazon |
| bitcoin.de referral link | We do not send personal data to bitcoin.de. When you click the bitcoin.de referral link, you go to bitcoin.de, which may record that you came via our referral link and processes your data under its own privacy policy | Receiving a referral commission or bonus if you sign up (see Affiliate Disclosure) | Not applicable on our side; bitcoin.de (futurum bank AG) is an independent controller for data it collects on its site | Determined by bitcoin.de |
We do not sell personal data and we do not use your data for automated decision-making or profiling with legal effects.
3. Cookies
Our site uses cookies that are strictly necessary to run it (for example login, shopping cart and checkout cookies set by WordPress and WooCommerce, and security cookies set by CleanTalk and the payment providers). These do not require consent. We do not use analytics or marketing cookies. If we add them in the future, we will describe them here and ask for your consent via a cookie banner before they are set. You can delete or block cookies in your browser settings; blocking necessary cookies may stop login or checkout from working.
4. Who receives your data (processors and recipients)
We share personal data only where needed for the purposes above:
- Web hosting provider: Kyzoe Hosting & Design, Oostende, Belgium, which hosts the website and its database on servers in a data centre of Hetzner Online GmbH in Germany (EU).
- Stripe (via WooCommerce Payments / WooPayments, provided by Automattic): payment processing.
- PayPal (Europe) S.à r.l. et Cie, S.C.A.: payment processing.
- CleanTalk Inc.: spam protection.
- Automattic Inc. (WooPayments / WooCommerce services): payment and shop services.
- Google Ireland Ltd. / Google LLC: web fonts loaded from Google’s servers.
- CanvasJS (Fenopix Technologies): charting script delivered from its CDN.
- Email provider: Google (Gmail), Google Ireland Ltd., for sending and receiving email.
- Accountant / tax authorities, where required by law.
5. Transfers outside the European Economic Area
Some of these providers (for example Google, Automattic, Stripe, CleanTalk) may process data in the United States or other countries outside the EEA. Where they do, the transfer is based on the EU-U.S. Data Privacy Framework (for certified companies) or on the European Commission’s Standard Contractual Clauses, as provided in the providers’ data processing terms. You can ask us for more information on these safeguards.
6. Your rights
You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”), unless we must keep it by law;
- restrict processing;
- receive your data in a portable format (data portability);
- object to processing based on our legitimate interest;
- withdraw consent at any time, where processing is based on consent (this does not affect processing before withdrawal).
To exercise these rights, email th*************@***il.com. We will reply within one month. We may ask you to verify your identity. Registered users can also export or erase their data via the WordPress personal data tools on request.
7. Complaints
If you believe we process your data unlawfully, please contact us first. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels, co*****@*****ba.be, www.gegevensbeschermingsautoriteit.be.
8. Security
We use HTTPS, keep WordPress and plugins updated, use spam and abuse protection, and limit admin access. No method of transmission over the internet is completely secure, but we take reasonable measures to protect your data.
9. Children
The site is not directed at children under 13. Accounts and purchases are intended for adults or for minors with parental consent.
10. Changes
We may update this policy. The date at the top shows the latest version. Significant changes will be announced on the site.
