Who We Are
Devil Wears Occult is operated by Created At OÜ, a company registered in Estonia. Our website address is: https://occult.ee. For privacy-related inquiries, please contact us at: info@occult.ee.
Data Controller
Created At OÜ (operating as Devil Wears Occult) is the data controller for the information collected through our website. This means we determine the purposes and means of processing your personal data.
What Personal Data We Collect and Why
Orders and Accounts
When you place an order through our site, we collect necessary information to fulfill your order including:
- Name
- Billing address
- Shipping address
- Email address
- Phone number
- Payment information (payment card details are processed by our secure payment providers and not stored on our servers)
This data is used to:
- Process and fulfill your orders
- Communicate with you about your order
- Comply with legal obligations (such as tax requirements)
- Process returns and refunds when applicable
Comments
When visitors leave comments on the site, we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
Our site uses cookies for various purposes. When you visit our site, we’ll inform you about the cookies we use and ask for your consent where required by law.
If you leave a comment on our site, you may opt-in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Marketing Communications
If you opt-in to our marketing communications, we will use your email address to send you newsletters and promotional messages. You can unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting us directly.
Embedded Content from Other Websites
Articles on this site may include embedded content (e.g., videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Legal Basis for Processing
We process your personal data on the following legal grounds:
- Contract performance: Processing necessary for the performance of a contract with you (e.g., to fulfill your order)
- Legal obligation: Processing necessary for compliance with our legal obligations
- Legitimate interests: Processing necessary for our legitimate interests, provided those interests do not override your rights and freedoms
- Consent: Processing based on your specific consent (e.g., for marketing communications)
Who We Share Your Data With
We only share your personal data when necessary for providing our services:
- Shipping companies and logistics providers to deliver your orders
- Payment processors to handle transactions
- Service providers that help us operate our business (e.g., web hosting, analytics)
- Legal authorities when required by law
If you request a password reset, your IP address will be included in the reset email.
Visitor comments may be checked through an automated spam detection service.
Data Transfers Outside the EEA
When we transfer your data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Transferring to countries that have been deemed to provide adequate protection by the European Commission
- Using specific contracts approved by the European Commission (Standard Contractual Clauses)
- Transferring to organizations that are part of approved certification mechanisms like the EU-US Privacy Shield
How Long We Retain Your Data
We keep your personal data only for as long as necessary:
- Order information: We keep order data for [X] years for tax and legal compliance purposes
- Account information: Stored until you delete your account or request erasure
- Marketing preferences: Stored until you unsubscribe or request erasure
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
Your Data Protection Rights
Under the GDPR, you have the following rights:
- Right to access: You can request copies of your personal data
- Right to rectification: You can request that we correct inaccurate information
- Right to erasure: You can request that we delete your personal data in certain circumstances
- Right to restrict processing: You can request that we restrict processing of your data
- Right to data portability: You can request the transfer of your data to another organization
- Right to object: You can object to our processing of your personal data
- Rights related to automated decision making and profiling: You can request human intervention where automated decisions are made about you
To exercise any of these rights, please contact us at info@occult.ee. We will respond to all legitimate requests within one month.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal reasons. We will post the updated policy on our website and, where appropriate, notify you by email.
Contact Information
If you have any questions about this privacy policy or our data practices, please contact us at:
Email: info@occult.ee Company: Created At OÜ (Devil Wears Occult)
If you are located in the EU and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority.