Subscribe to our emails
Be the first to know about new collections and special offers.
Article 1 — Introduction and Identity of the Controller
1.1 This Privacy Policy explains how Deem The Brand collects, uses, stores, and protects personal data in connection with the operation of its website and the sale of its products.
1.2 Deem The Brand acts as the data controller within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Dutch Implementation Act (Uitvoeringswet AVG).
Article 2 — Personal Data Collected
2.1 Deem collects and processes the following categories of personal data:
Transactional data: name, email address, delivery address, billing address, telephone number, and order history, collected when a Customer places an Order.
Payment data: payment method and transaction reference. Payment card details are processed exclusively by Shopify Payments and are not stored by Deem.
Communication data: content of emails, messages, or correspondence submitted to Deem via email or the Website contact form.
Technical data: IP address, browser type and version, device information, pages visited, and time spent on the Website, collected automatically via cookies and analytics tools.
Marketing data: email address and communication preferences, where a Customer has opted in to receive marketing communications.
2.2 Deem does not knowingly collect personal data from individuals under the age of 16. If Deem becomes aware that personal data of a minor has been collected without appropriate parental consent, such data will be deleted without undue delay.
Article 3 — Legal Basis for Processing
3.1 Deem processes personal data on the following legal bases under Article 6 GDPR:
Performance of a contract (Article 6(1)(b)): processing necessary to fulfil Orders, manage customer accounts, and provide after-sales support.
Legal obligation (Article 6(1)(c)): processing necessary to comply with Dutch tax law, accounting obligations, and other statutory requirements, including retention of financial records for a minimum of seven (7) years pursuant to Article 52 of the General Tax Act (Algemene wet inzake rijksbelastingen).
Legitimate interests (Article 6(1)(f)): processing for fraud prevention, website security, and improvement of our products and services, where such interests are not overridden by the data subject's rights and freedoms.
Consent (Article 6(1)(a)): processing for direct marketing communications and non-essential cookies, where the Customer has given explicit and freely withdrawable consent.
Article 4 — Purposes of Processing
4.1 Deem processes personal data for the following purposes:
Processing and fulfilling Orders, including communicating with third-party production and logistics partners as necessary
Sending transactional communications including order confirmations, shipping notifications, and customer service responses
Complying with Dutch and EU legal, tax, and accounting obligations
Fraud detection, prevention, and security monitoring
Analysing Website usage to improve user experience and commercial performance
Sending marketing communications to Customers who have opted in, subject to the right to withdraw consent at any time
4.2 Deem will not use personal data for purposes incompatible with those stated above without first obtaining the relevant data subject's consent.
Article 5 — Sharing of Personal Data
5.1 Deem does not sell, rent, or otherwise transfer personal data to third parties for their own commercial purposes.
5.2 Deem shares personal data with third parties only where necessary and on the following basis:
Production and fulfilment partner: Customer name and delivery address are shared with Deem's print-on-demand production partner, Gelato, solely for the purpose of manufacturing and dispatching Orders.
Payment processor: Payment data is processed by Shopify Payments (Shopify International Limited) in accordance with their privacy policy and PCI-DSS standards.
Email marketing platform: Customer email address, name, and purchase behaviour data are shared with Klaviyo Inc. for the purpose of sending marketing communications and managing our subscriber list, solely where the Customer has opted in to receive such communications.
Cookie consent management: Cookie consent preferences and associated technical identifiers are processed by Consentmo for the purpose of recording and managing visitor consent in accordance with applicable data protection law.
Analytics and advertising platforms: Anonymised or pseudonymised usage data may be shared with analytics providers. Where marketing cookies are accepted, data may be shared with platforms such as Meta and Google for advertising purposes, subject to the Customer's cookie consent preferences.
Tax and accounting advisor: Relevant transactional and financial data, including order values and customer billing information where necessary, may be shared with Deem's external tax and accounting advisor solely for the purpose of fulfilling our legal tax and accounting obligations under Dutch law.
Legal authorities: Deem may disclose personal data to competent authorities, courts, or regulators where required to do so by law or in connection with legal proceedings.
5.3 All third-party processors engaged by Deem are bound by data processing agreements ensuring compliance with GDPR.
Article 6 — International Data Transfers
6.1 Some of Deem's third-party service providers may process personal data outside the European Economic Area (EEA). Where such transfers occur, Deem takes reasonable steps to satisfy itself that appropriate safeguards are in place in accordance with Chapter V GDPR, including where applicable the use of Standard Contractual Clauses approved by the European Commission or reliance on an adequacy decision. Customers who wish to obtain further information about the safeguards relied upon in respect of any specific transfer may contact Deem at info@deemthebrand.com.
Article 7 — Data Retention
7.1 Deem retains personal data for no longer than is necessary for the purposes for which it was collected, subject to applicable legal retention obligations:
Order and transactional data: retained for a minimum of seven (7) years in accordance with Dutch tax law
Customer communications: retained for a maximum of two (2) years following resolution of the relevant matter
Marketing data: retained until consent is withdrawn or the Customer opts out
Technical and analytical data: retained for a maximum of twenty-six (26) months
Article 8 — Rights of Data Subjects
8.1 Data subjects whose personal data is processed by Deem have the following rights under GDPR:
Right of access (Article 15): the right to obtain confirmation of whether personal data is being processed and to receive a copy of such data.
Right to rectification (Article 16): the right to have inaccurate personal data corrected without undue delay.
Right to erasure (Article 17): the right to request deletion of personal data where the data is no longer necessary, consent has been withdrawn, or processing is unlawful, subject to legal retention obligations.
Right to restriction of processing (Article 18): the right to request that processing be restricted in certain circumstances.
Right to data portability (Article 20): the right to receive personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to object (Article 21): the right to object to processing based on legitimate interests or for direct marketing purposes.
Right to withdraw consent: where processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
8.2 To exercise any of the above rights, data subjects may submit a written request to info@deemthebrand.com. Deem will respond within thirty (30) calendar days. Where a request is complex or numerous, this period may be extended by a further two months, of which the data subject will be notified.
Article 9 — Security
9.1 Deem implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include SSL/TLS encryption of the Website, access controls, and secure data processing agreements with all third-party processors.
9.2 In the event of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, Deem will notify affected data subjects without undue delay and will report the breach to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, in accordance with Article 33 GDPR.