Privacy Policy
This explains what personal data DEUSPIXEL collects, why, how long it is kept, and what you can do about it. It is written to meet the General Data Protection Regulation and Croatian data protection law.
The short version
- We collect the minimum needed to sell you a file and answer your messages.
- We never sell or rent your data to anyone, for any reason.
- There are no advertising trackers on this site. No Google Analytics, no Meta pixel.
- We do not send marketing email unless you specifically ask for it.
- Order records are kept eleven years, because Croatian tax law requires it.
- You can ask for a copy of your data, or ask us to delete it, at any time.
1. Who is responsible for your data
The data controller is the business that decides why and how your data is used. For everything on deuspixel.com, that is us.
| Controller | DEUSPIXEL, obrt za usluge i trgovinu, vl. Nenad Dukić |
| Owner | Nenad Dukić |
| Address | Ulica Tome Masaryka 7B, 40000 Čakovec, Croatia |
| OIB | 03827516949 |
| Contact | deuspixel.com/contact |
DEUSPIXEL is a one person business. There is no separate Data Protection Officer, and under Article 37 of the GDPR one is not required for an operation of this size and type. Data questions go directly to Nenad.
2. What we collect and why
We collect only what is needed. There is no profiling, no automated decision making, and no data collected out of curiosity.
2.1 When you place an order
| Data | Why we need it |
|---|---|
| Name | To identify the order and address you properly |
| Email address | To send your files, your receipt and your order updates |
| Billing country | Required by the payment provider, and it tells us which consumer law applies to you |
| Order contents and value | To deliver the right files and to keep the invoice record the law requires |
| The name you supply for personalised art | To make the product you ordered |
| Withdrawal consent, with a timestamp and your IP address | Proof that you agreed to immediate download and understood the consequence. See section 2.4 |
We do not receive or store your full card number. Payment details go directly to the payment provider and never reach our server.
2.2 When you use the contact form
| Data | Why we need it |
|---|---|
| Name | To reply to you properly |
| Email address | To send the reply |
| Subject of your message | To route and prioritise it |
| Order number, if you give one | To find your order faster |
| The message itself | To understand what you need |
| Your IP address and the time sent | Recorded automatically by the form plugin, used to identify spam |
2.3 When you simply visit the site
Our hosting provider keeps standard server logs, which include IP addresses, the pages requested, timestamps and browser information. These are generated automatically by the web server, are used only to keep the site running and secure, and are not used to build any profile of you.
2.4 The withdrawal consent record, explained plainly
At checkout you tick a box confirming you want immediate access to your download and understand that this ends your fourteen day right to cancel. We record that you ticked it, when, the exact wording shown to you, and the IP address it came from.
2.5 What we never collect
- Your full card or bank details, those go straight to the payment provider
- Any special category data, such as health, religion, politics or ethnicity
- Location beyond the country on your billing address
- Anything from social media profiles
- Behavioural or advertising profiles of any kind
3. Our lawful basis for each purpose
The GDPR requires a lawful basis for every use of your data. Ours are set out below, so you can see exactly which applies where.
| What we do | Lawful basis |
|---|---|
| Process your order and deliver your files | Contract, Article 6(1)(b). We cannot sell you a file without this. |
| Reply to your message | Legitimate interests, Article 6(1)(f). You wrote to us and expect an answer. |
| Keep invoice and accounting records | Legal obligation, Article 6(1)(c). Croatian tax law requires it. |
| Record your withdrawal consent | Legal obligation, Article 6(1)(c), under EU consumer law. |
| Keep the site secure and stop spam | Legitimate interests, Article 6(1)(f). |
| Send you a newsletter, if you sign up | Consent, Article 6(1)(a). You may withdraw it at any time. |
4. How long we keep it
Data is deleted when it is no longer needed, except where the law requires us to keep it longer.
| Record | Kept for |
|---|---|
| Completed orders and invoices | 11 years from the end of the accounting year, required by Croatian law |
| Withdrawal consent records | Same as the order they belong to |
| Pending or failed orders | 1 month |
| Cancelled orders | 3 months |
| Customer accounts left unused | 24 months, then deleted |
| Contact form messages | 24 months after the conversation ends |
| Server logs | As set by our host, typically a few weeks |
5. Who else sees your data
We never sell, rent or trade your data. It is shared only with the suppliers we need to run the shop, and only to the extent they need it. Each is bound by a data processing agreement.
| Who | What they handle | Where |
|---|---|---|
| Our web host | Stores the website and its database, so all order data sits there | EU |
| Namecheap PrivateEmail | Sends and receives our email, including your order emails | See section 6 |
| Payment provider | Takes the payment. They receive your card details directly, we never do | See section 6 |
| OpenStreetMap | Serves the map on our contact page. Sets no cookies | EU |
| Accountant | Sees invoice records for bookkeeping and tax filing | Croatia |
We may also disclose data if we are legally required to, for example to a tax authority or a court. We would tell you unless the law prevents us.
If DEUSPIXEL is ever sold or transferred, customer data may transfer with it. You would be told before that happened and your rights would carry across unchanged.
6. Transfers outside the EU
We are based in Croatia and prefer EU suppliers. Some processing may still happen outside the European Economic Area, mainly because payment providers and email services operate globally.
Where data goes outside the EEA, it is protected by one of the safeguards the GDPR allows, normally the European Commission’s Standard Contractual Clauses, or an adequacy decision covering the destination country.
You can ask us which safeguard applies to a specific supplier and we will tell you.
7. Cookies and tracking
This site uses very few cookies, and none of them track you.
| Cookie | Purpose | Consent needed |
|---|---|---|
| WooCommerce cart and session | Remembers what is in your basket and keeps you logged in through checkout | No, strictly necessary |
| WordPress login | Only set if you create an account and log in | No, strictly necessary |
Strictly necessary cookies do not require consent under the ePrivacy Directive, because the site cannot function without them.
7.1 What this site does not use
- Google Analytics or any other analytics platform
- Meta, TikTok, Pinterest or any advertising pixel
- Google Maps, which would send your IP to Google before you agreed
- Google Fonts loaded from Google servers
- Any cross site tracking or retargeting of any kind
7.2 The map on our contact page
Our contact page shows a map served by OpenStreetMap. We chose it specifically because it sets no cookies and does not send your data to an advertising company. Loading the page does make a request to openstreetmap.org, which necessarily reveals your IP address to them, in the same way any image loaded from another site would.
8. Your rights
Under the GDPR you have the following rights. They are free to use and we will not make it difficult.
- AccessAsk for a copy of the personal data we hold about you.
- RectificationHave anything inaccurate corrected.
- ErasureAsk us to delete your data, subject to the retention rules in section 4.
- RestrictionAsk us to pause processing while a dispute is sorted out.
- PortabilityReceive your data in a machine readable format, or have it sent to another provider.
- ObjectionObject to processing based on legitimate interests.
- Withdraw consentWhere we rely on consent, withdraw it at any time. This does not affect anything done before.
- ComplainLodge a complaint with a supervisory authority. See section 12.
There is no automated decision making or profiling on this site, so the rights in Article 22 of the GDPR do not arise.
9. How to exercise your rights
Use the contact form and say what you want. There is no special form to fill in and no fee.
To protect you, we may ask a question that confirms you are who you say you are, usually an order number or the email address used on the order. We will not demand identity documents for a routine request.
We respond within one month, as the GDPR requires. If a request is unusually complex we may extend that by up to two further months, and we will tell you and explain why within the first month.
10. How we keep data secure
- The whole site runs over HTTPS, so traffic between you and us is encrypted
- Card details never touch our server, they go directly to the payment provider
- Access to the shop administration is limited to the owner, with a strong unique password
- Software and plugins are kept up to date
- Only data that is genuinely needed is collected in the first place, which is the most effective security measure of all
No system is perfectly secure. If a breach ever occurred that was likely to put your rights at risk, we would notify the Croatian supervisory authority within 72 hours and tell you directly without undue delay, as Articles 33 and 34 require.
11. Children
This shop is intended for adults. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it promptly.
12. Complaints
If you are unhappy with how we have handled your data, tell us first. We would rather fix it than have you go elsewhere frustrated.
You also have the right to complain to a data protection authority. Ours is the Croatian one:
| Authority | Agencija za zaštitu osobnih podataka, AZOP |
| Address | Selska cesta 136, 10000 Zagreb, Croatia |
| Telephone | +385 1 4609 000 |
| azop@azop.hr | |
| Website | azop.hr |
If you live in another EU country, you may complain to your own national data protection authority instead. You do not have to come to the Croatian one.
13. Changes to this policy
We update this policy when what we do with data changes. The date at the top always shows the current version.
If a change materially affects your rights, for example adding a new category of data or a new supplier, we will make that clear rather than quietly editing the page.
14. How to contact us
Any question about your data, or any request under section 8, goes to the same place and reaches Nenad directly.
| Contact form | deuspixel.com/contact |
| info@deuspixel.com | |
| Post | DEUSPIXEL, Ulica Tome Masaryka 7B, 40000 Čakovec, Croatia |
| Response time | Within one working day, usually sooner |
This policy was last updated on 30 July 2026. If anything here is unclear, ask. A privacy policy nobody understands protects nobody.