Back to the site

PERSONAL DATA PROCESSING POLICY FOR DATA COLLECTED THROUGH DEKAART.RU

Basis for inclusion in the register: Order No. 89 dated February 15, 2012
Notification registration date: February 3, 2012
Registration No.: 12-0236060

1. General Provisions

1.1

This Personal Data Processing Policy has been prepared in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006, “On Personal Data, ” and establishes the procedures for processing personal data and the measures taken by [Operator Name] to ensure the security of personal data, hereinafter referred to as the “Operator.”

1.2

The Operator considers respect for human and civil rights and freedoms in the processing of personal data, including the protection of privacy and personal and family confidentiality, to be one of the primary objectives and essential conditions of its activities.

1.3

This Personal Data Processing Policy, hereinafter referred to as the “Policy, ” applies to all information that the Operator may obtain about visitors to dekaart.ru.

2. Key Terms Used in This Policy

2.1 Automated Processing of Personal Data

Processing of personal data using computer technology.

2.2 Restriction of Personal Data Processing

The temporary suspension of personal data processing, except where processing is required to verify or update personal data.

2.3 Website

A collection of graphic and informational materials, computer programs, and databases made available online at dekaart.ru.

2.4 Personal Data Information System

A combination of personal data contained in databases and the information technologies and technical tools used to process such data.

2.5 Anonymization of Personal Data

Actions that make it impossible to determine, without the use of additional information, whether personal data belongs to a specific User or other data subject.

2.6 Processing of Personal Data

Any action or set of actions performed with personal data, whether by automated means or without such means.

2.7 Operator

[Operator Name], which independently organizes and carries out the processing of personal data.

2.8 Personal Data

Any information relating directly or indirectly to an identified or identifiable User of https://dekaart.ru.

2.9 Personal Data Authorized by the Data Subject for Public Distribution

Personal data to which an unlimited number of persons have been granted access by the data subject through consent to the processing of personal data authorized for public distribution.

2.10 User

Any visitor to dekaart.ru.

2.11 Disclosure of Personal Data

Actions intended to disclose personal data to a specific person or a defined group of persons.

2.12 Public Distribution of Personal Data

Actions intended to disclose personal data to an indefinite group of persons.

2.13 Cross-Border Transfer of Personal Data

The transfer of personal data to the territory of a foreign state.

2.14 Destruction of Personal Data

Actions resulting in the irreversible destruction of personal data.

3. Principal Rights and Obligations of the Operator

3.1 The Operator Has the Right To:

  • obtain accurate information and documents containing personal data from the data subject;
  • continue processing personal data without the data subject’s consent after consent has been withdrawn, where legal grounds for such processing exist under applicable personal data legislation;
  • independently determine the measures necessary and sufficient to comply with the obligations imposed by personal data legislation.

3.2 The Operator Is Required To:

  • provide the data subject, upon request, with information concerning the processing of their personal data;
  • organize personal data processing in accordance with the applicable laws of the Russian Federation;
  • respond to inquiries and requests from data subjects;
  • provide the competent personal data protection authority with the required information within 30 days of receiving a request;
  • publish this Policy or otherwise ensure access to it;
  • take measures to protect personal data;
  • cease processing and destroy personal data where required by law.

4. Principal Rights and Obligations of Data Subjects

4.1 Data Subjects Have the Right To:

  • obtain information concerning the processing of their personal data;
  • request the correction, restriction, or destruction of their personal data;
  • withdraw consent to the processing of their personal data;
  • challenge the actions or inaction of the Operator before the competent authority or a court.

4.2 Data Subjects Are Required To:

  • provide the Operator with accurate information about themselves;
  • notify the Operator of changes to their personal data.

4.3

Persons who provide the Operator with inaccurate information may be held liable in accordance with the laws of the Russian Federation.

5. Categories of Personal Data Processed

5.1

The Operator processes the following personal data of Users:

  • surname, first name, and patronymic;
  • email address;
  • telephone numbers;
  • anonymized visitor data, including cookies, collected through website analytics services.

5.2

Special categories of personal data, including race, nationality, political opinions, and similar information, are not processed.

6. Principles of Personal Data Processing

6.1

Personal data is processed lawfully and fairly.

6.2

Processing is limited to specific, predetermined, and legitimate purposes.

6.3

The combination of databases containing personal data processed for incompatible purposes is not permitted.

6.4

Only personal data necessary for the stated purposes is processed.

6.5

The accuracy, sufficiency, and relevance of personal data are maintained.

6.6

Personal data is stored no longer than necessary for the purposes for which it is processed, unless a longer retention period is required by law.

7. Purposes of Personal Data Processing

7.1

The principal purposes of processing are:

  • communicating with the User by email;
  • providing information and consultations regarding services and products;
  • analyzing User behavior on the Website in order to improve its quality.

7.2

The User may unsubscribe from notifications by sending an email to deka.art.rostov@gmail.com with the subject line “Unsubscribe from Notifications.”

8. Legal Grounds for Processing

8.1

Personal data is processed on the basis of:

  • Federal Law No. 149-FZ of July 27, 2006, “On Information, Information Technologies, and Information Protection”;
  • the consent of Users to the processing of their personal data.

8.2

Personal data is processed when Users complete forms on the Website or submit information by email.

9. Conditions for Personal Data Processing

9.1

Personal data is processed with the consent of the data subject.

9.2

In cases provided for by law, personal data may be processed without consent.

9.3

The Operator does not disclose personal data to third parties or distribute it publicly without the data subject’s consent, except where required or permitted by law.

10. Procedures for Collection, Storage, Transfer, and Other Processing Activities

10.1

The Operator ensures the security of personal data and takes measures to prevent unauthorized access.

10.2

Personal data is not transferred to third parties except where required or permitted by law.

10.3

A User may request that their personal data be updated by sending an email to deka.art.rostov@gmail.com with the subject line “Personal Data Update.”

10.4

The processing period is determined by the purposes for which the data was collected or by applicable legal requirements.

10.5

A User may withdraw consent to the processing of personal data by sending an email to deka.art.rostov@gmail.com with the subject line “Withdrawal of Consent to Personal Data Processing.”

11. Actions Performed with Personal Data

11.1

The Operator may perform the following actions with personal data:

  • collection, recording, and organization;
  • storage and accumulation;
  • use and transfer where legally permitted;
  • deletion and destruction.

11.2

Personal data may be processed using both automated and non-automated methods.

12. Cross-Border Transfer of Personal Data

12.1

Before carrying out a cross-border transfer, the Operator must ensure that the foreign state provides adequate protection for the rights of personal data subjects.

12.2

Transfers to countries that do not provide an adequate level of protection may take place only with the written consent of the data subject or where necessary for the performance of a contract.

13. Confidentiality

13.1

The Operator and other persons granted access to personal data must not disclose such data to third parties or distribute it publicly without the data subject’s consent, unless otherwise provided by federal law.

13.2

The confidentiality of personal data must be maintained even after processing has ended.

14. Personal Data Security

14.1

We protect personal data through the following measures:

14.1.1

Encryption of data during transmission using HTTPS.

14.1.2

Protection against distributed denial-of-service attacks.

14.1.3

Restriction of internal access to personal data.

15. Final Provisions

15.1

Users may obtain clarification regarding the processing of their personal data by contacting the Operator at:

deka.art.rostov@gmail.com

15.2

The Operator may amend this Policy unilaterally.

A revised version becomes effective upon publication on the Website.

15.3

The current version of this Policy is always available at:

dekaart.ru/legal-privacy

General Director: Oleg Anatolyevich Yurchenko
[Position and Full Name of the Responsible Person]

DEKA-ART LLC
Taxpayer Identification Number: 6165171915
Registered address: 139A Tekucheva Street, Rostov-on-Don, Rostov Region, 344018, Russian Federation
________________

DEKA-ART

International Privacy & Cookie Policy

EU/EEA • United Kingdom • United States

Effective date: [INSERT DATE]   |   Last updated: [INSERT DATE]

IMPORTANT — COMPLETE BEFORE PUBLICATION

This document is a practical working template, not legal advice. Replace every bracketed field, verify every vendor and cookie, and have qualified privacy counsel review the final version for the company’s actual activities, target markets, contracts, analytics, advertising, hosting, and international data transfers.

Publication Checklist

· Insert the legal name, registered address, email address, and telephone number of the data controller.

· Confirm whether DEKA-ART LLC, another entity, or more than one entity controls the English-language website.

· List every website form, analytics service, advertising pixel, CRM, email provider, hosting provider, embedded video, map, chat, and payment tool.

· Complete the cookie table using a live cookie scan of dekaart.ru and the English-language pages.

· Set actual retention periods and document the legal basis for each processing purpose.

· Confirm whether the website sells or shares personal information, uses targeted advertising, or honors Global Privacy Control signals.

· Confirm the safeguards used for transfers from the EEA/UK to Russia, the United States, or other countries.

· Add an EU/EEA representative and/or UK representative if legally required.

· Publish a cookie banner that blocks non-essential cookies until consent in the EEA/UK and provides an equally prominent “Reject” option.

· Ensure that privacy requests can be submitted, verified, logged, and answered within applicable deadlines.

1. Scope of This Policy

This Privacy & Cookie Policy explains how [FULL LEGAL ENTITY NAME] (“Deka-Art,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information when you:

· visit or interact with dekaart.ru and any English-language pages, subdomains, or forms that link to this Policy;

· contact us by website form, email, telephone, messenger, social media, or video call;

· request information, a consultation, an estimate, or a proposal;

· become a prospective, current, or former client, supplier, contractor, or business contact; or

· interact with our online portfolio, journal, embedded media, analytics, or advertising technologies.

This Policy is intended to provide information relevant to individuals in the European Economic Area (EEA), the United Kingdom, and the United States. Some rights apply only where a particular law covers Deka-Art or the relevant processing activity.

2. Who Is Responsible for Your Personal Information

Data controller

[FULL LEGAL ENTITY NAME]

Registered address

[FULL REGISTERED ADDRESS]

Business / tax ID

[INSERT]

Privacy email

deka.art.rostov@gmail.com or [DEDICATED PRIVACY EMAIL]

Telephone

[INSERT]

EU/UK representative

[INSERT IF REQUIRED, OTHERWISE STATE “Not appointed”]

3. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of information:

Identity and contact information: name, telephone number, email address, postal address, preferred language, and other contact details.

Project and property information: property type, location, plans, measurements, photographs, videos, budgets, design preferences, household requirements, project timelines, and communications about a potential or active project.

Commercial and contract information: proposals, contracts, invoices, payment status, purchase and supplier information, and records of services requested or provided.

Communications: messages, correspondence, consultation notes, call details, and information you voluntarily provide.

Technical and usage information: IP address, device type, browser, operating system, language, approximate location derived from IP, referring pages, pages viewed, timestamps, session identifiers, cookie identifiers, and interaction data.

Marketing preferences: newsletter choices, communication preferences, and consent records.

Professional and business information: company, job title, business contact details, and information relevant to suppliers, contractors, investors, or commercial clients.

Sensitive information: we do not intentionally request special-category or sensitive personal information through the public website. Please do not submit such information unless it is necessary and we have specifically requested it.

4. How We Collect Information

· Directly from you when you complete a form, contact us, request a consultation, enter into a contract, or communicate with our team.

· Automatically through cookies, server logs, analytics tools, embedded content, and similar technologies.

· From service providers and business partners, such as website hosting, CRM, analytics, communications, payment, professional, and project-management providers.

· From publicly available sources or referrals, where permitted by law.

5. Why We Use Personal Information and Our Legal Bases

For individuals in the EEA and UK, we identify a lawful basis under the GDPR or UK GDPR before processing personal data. The table below should be completed and aligned with Deka-Art’s actual operations.

Purpose

Typical data

EEA/UK lawful basis

Typical retention

Respond to inquiries and arrange consultations

Contact, project, communication data

Steps at your request before a contract; legitimate interests

24 months after last meaningful contact

Prepare proposals and perform design or renovation contracts

Identity, contact, project, commercial data

Contract; legal obligations

Contract term + [6/7/10] years

Manage suppliers, contractors, and professional contacts

Business contact and commercial data

Contract; legitimate interests; legal obligations

Relationship + [6/7/10] years

Operate, secure, and troubleshoot the website

Technical and usage data

Legitimate interests; legal obligations

Server/security logs: [30–180] days unless needed for an incident

Analytics and website improvement

Cookie identifiers and usage data

Consent in EEA/UK where required; consent or legitimate interests elsewhere as permitted

Analytics data: [14/26] months

Marketing communications

Contact details and preferences

Consent, or legitimate interests where permitted

Until opt-out or [24] months of inactivity

Comply with law and establish or defend legal claims

Relevant records

Legal obligation; legitimate interests

As required by law or until claims expire

6. Cookies and Similar Technologies

Cookies are small files or identifiers stored on or accessed from your device. We may also use pixels, local storage, tags, SDKs, and similar technologies.

6.1 Cookie Categories

Category

Purpose

Consent status

Examples / vendors

Strictly necessary

Security, page delivery, load balancing, consent storage, and core functionality.

Always active where technically necessary.

[HOSTING / CMS / COOKIE CONSENT TOOL]

Preferences

Remember language, region, interface, or accessibility choices.

Consent where required.

[LIST]

Analytics

Measure visits, page performance, traffic sources, and interactions.

Prior consent in EEA/UK unless a narrow exemption clearly applies.

[GA4 / YANDEX METRICA / OTHER — VERIFY]

Advertising / targeting

Measure campaigns, build audiences, or personalize advertising.

Prior consent in EEA/UK; opt-out rights may apply in the US.

[META PIXEL / GOOGLE ADS / OTHER — VERIFY]

Embedded content

Enable videos, maps, social media, chat, or other third-party content.

Consent where the provider places non-essential cookies.

[YOUTUBE / VIMEO / MAPS / MESSENGERS — VERIFY]

6.2 Your Cookie Choices

Where required, non-essential cookies and tracking technologies will not be activated until you make a choice. The cookie interface should provide equally accessible options to accept or reject non-essential cookies and allow category-level choices.

· You can change or withdraw your choice at any time through the “Cookie Settings” link in the website footer.

· Rejecting non-essential cookies should not prevent access to the core website.

· Withdrawing consent does not affect processing that occurred before withdrawal.

· Browser controls may also block or delete cookies, but some site functions may be affected.

6.3 Cookie Inventory — Complete After Technical Scan

Cookie / technology

Provider

Purpose

Category

Duration

First/third party

Legal basis

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

7. Analytics, Advertising, and Embedded Services

The website may use third-party services. Replace this section with the actual tools in use. Examples may include website analytics, advertising pixels, embedded videos, maps, messenger links, CRM tools, email delivery, anti-spam, and hosting services.

· Analytics providers may receive online identifiers, device information, approximate location, and interaction data.

· Embedded content providers may collect data when content loads or when you interact with it.

· Advertising providers may use identifiers to measure campaigns or deliver targeted advertising, subject to consent and opt-out requirements.

· Links to Telegram, social networks, or third-party websites are governed by those providers’ own privacy practices once you leave our website.

8. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients where necessary and lawful:

· website hosting, content-management, security, and IT providers;

· CRM, email, telephone, messenger, scheduling, and collaboration providers;

· analytics, advertising, and cookie-consent providers;

· architects, designers, engineers, contractors, suppliers, installers, and project partners involved in a requested service;

· accountants, auditors, insurers, banks, lawyers, and other professional advisers;

· government agencies, courts, regulators, or law-enforcement bodies where required by law;

· a buyer, investor, or successor in connection with a business transaction, subject to appropriate safeguards.

We do not state that we “never share” personal information, because routine website and business operations often require limited disclosure to service providers. The final policy must accurately describe the actual recipients and contracts.

9. International Data Transfers

Deka-Art may operate from Russia and may use providers located in Russia, the United States, the EEA, the UK, or other countries. As a result, personal information may be processed outside the country where you live.

For transfers of EEA or UK personal data to a country that is not recognized as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:

· European Commission Standard Contractual Clauses (SCCs);

· the UK International Data Transfer Agreement or UK Addendum to the EU SCCs;

· an applicable adequacy decision;

· an approved certification or other lawful safeguard; or

· a specific statutory derogation used only where legally appropriate.

Where required, we will assess the legal and practical risks of the transfer and implement supplementary technical, contractual, or organizational safeguards. Contact us to request information about the relevant transfer mechanism, subject to lawful redactions.

10. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide services, maintain business and tax records, resolve disputes, enforce agreements, and comply with legal obligations.

· Inquiries that do not become projects: [24 months] after the last meaningful contact.

· Client project and contract records: contract term plus [6/7/10] years, depending on applicable limitation, accounting, tax, and construction-record requirements.

· Supplier and contractor records: relationship plus [6/7/10] years.

· Marketing records: until you opt out, plus a limited suppression record to honor the opt-out.

· Cookie consent records: [6–24 months] or as required to demonstrate consent.

· Analytics data: [14/26] months or the configured provider period.

· Security logs: generally [30–180] days, unless retained longer to investigate an incident or legal claim.

These periods are placeholders. The company must adopt and follow an internal retention schedule that matches its systems and legal obligations.

11. Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include HTTPS encryption in transit, access controls, role-based permissions, backups, provider due diligence, staff confidentiality obligations, anti-malware protections, monitoring, and incident-response procedures.

No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.

12. Your Rights in the EEA and United Kingdom

Subject to applicable conditions and exceptions, you may have the right to:

· be informed about how your personal data is used;

· request access to your personal data;

· request correction of inaccurate or incomplete data;

· request deletion of personal data;

· request restriction of processing;

· object to processing based on legitimate interests or to direct marketing;

· receive certain data in a portable format;

· withdraw consent at any time where processing is based on consent;

· not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to applicable law;

· complain to a competent data-protection authority.

We may ask for information necessary to verify your identity. We generally respond within one month, subject to lawful extensions for complex or multiple requests.

13. United States Privacy Rights

Depending on your state of residence, the law applicable to Deka-Art, and the nature and scale of our processing, you may have rights to:

· confirm whether we process your personal information and access that information;

· correct inaccuracies;

· delete personal information;

· obtain a portable copy of certain information;

· opt out of the sale of personal information;

· opt out of the sharing or use of personal information for cross-context behavioral or targeted advertising;

· opt out of certain profiling that produces legal or similarly significant effects;

· limit certain uses or disclosures of sensitive personal information, where applicable;

· appeal a decision concerning a privacy request in states that provide an appeal right;

· receive non-discriminatory treatment for exercising privacy rights.

13.1 California Notice

If the California Consumer Privacy Act (CCPA), as amended, applies to Deka-Art, California residents may have the rights described above. The final policy must disclose, for the preceding 12 months, the categories of personal information collected, sources, business or commercial purposes, categories of recipients, and whether information is sold or shared.

Current status — select and verify one before publication:

· [OPTION A] We do not sell personal information and do not share personal information for cross-context behavioral advertising as those terms are defined by the CCPA.

· [OPTION B] We may share online identifiers and internet activity with advertising partners. California residents may opt out through “Your Privacy Choices” and recognized opt-out preference signals.

13.2 Global Privacy Control and Universal Opt-Out Signals

Where required by applicable US law, we will process legally recognized browser-based opt-out preference signals, such as Global Privacy Control, as a request to opt out of sale, sharing, or targeted advertising for the browser or device that sends the signal.

14. How to Exercise Privacy Rights

Submit a privacy request using one of the following methods:

· Email: deka.art.rostov@gmail.com or [DEDICATED PRIVACY EMAIL]

· Web form: [INSERT PRIVACY REQUEST FORM URL]

· Telephone: [INSERT NUMBER]

· Postal address: [INSERT ADDRESS]

Please describe your request and the jurisdiction in which you live. We may need to verify your identity and authority before completing the request. An authorized agent may submit a request where permitted by law, subject to verification requirements.

15. Marketing Communications

You may opt out of marketing emails at any time by using the unsubscribe link in the message or contacting us. We may retain a minimal suppression record so that we do not send further marketing communications to an address that has opted out. Service-related or contractual communications are not marketing and may continue where necessary.

16. Children’s Privacy

The website and our services are intended for adults seeking architecture, interior design, renovation, or related professional services. They are not directed to children under 13, and we do not knowingly collect personal information online from children under 13. If you believe a child has provided personal information, contact us so that we can review and, where appropriate, delete it.

17. Third-Party Websites and Services

The website may contain links to third-party websites or services. We are not responsible for the privacy or security practices of third parties. Review their privacy notices before providing information or enabling their content.

18. Changes to This Policy

We may update this Policy to reflect changes in our services, technologies, vendors, or legal obligations. The revised version will be posted on this page with a new “Last updated” date. Where required, we will provide additional notice or request renewed consent.

19. Complaints and Regulatory Authorities

Please contact us first so that we can try to address your concern. You may also have the right to complain to a competent privacy or data-protection authority.

· EEA: the supervisory authority in the country of your habitual residence, workplace, or the place of the alleged infringement.

· United Kingdom: Information Commissioner’s Office (ICO).

· United States: the relevant state attorney general or privacy regulator, where applicable.

20. Contact Us

[FULL LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Email: deka.art.rostov@gmail.com or [PRIVACY EMAIL]
Telephone: [INSERT]
EU/UK representative: [INSERT IF APPLICABLE]


Appendix A — Recommended Cookie Banner Copy

First Layer

We value your privacy

We use necessary cookies to operate this website. With your permission, we also use analytics, preference, and advertising technologies to understand website use and improve our services. You can accept all, reject non-essential cookies, or manage individual categories. You can change your choice at any time through Cookie Settings.

· Accept All

· Reject Non-Essential

· Cookie Settings

Cookie Settings Panel

Strictly Necessary — Always Active
Required for security, page delivery, core website functions, and remembering your privacy choices.

Preferences
Remember choices such as language or interface settings.

Analytics
Help us understand how visitors use the website and improve performance.

Advertising
Support campaign measurement and, where enabled, targeted advertising.

Embedded Content
Enable third-party videos, maps, chat, or social features that may collect information about your device and activity.

· Save Choices

· Accept All

· Reject Non-Essential

Appendix B — Recommended Privacy Checkbox Copy

Use an unchecked checkbox for optional consent. Do not bundle marketing consent with a request-for-consultation form.

Required form acknowledgement: I have read the Privacy Policy and understand how Deka-Art will use my information to respond to my inquiry.

Optional marketing consent: I would like to receive occasional news, project updates, and service information from Deka-Art. I can unsubscribe at any time.

Appendix C — Internal Data and Vendor Inventory

System/vendor

Data collected

Purpose

Individuals

Location

Retention

Transfer mechanism

Contract / DPA

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

[INSERT]

Appendix D — Official Reference Sources

The template was prepared with reference to official public guidance and legal materials current as of July 11, 2026. These sources do not replace legal advice or a review of the company’s actual data flows.

· European Commission — information that must be provided when personal data is collected

· European Commission — GDPR territorial scope

· European Commission — rules on international data transfers

· European Commission — Standard Contractual Clauses

· European Data Protection Board — cookie banner taskforce report

· UK Information Commissioner’s Office — privacy information requirements

· California Attorney General — CCPA rights

· California Privacy Protection Agency — CCPA resources

· Colorado Attorney General — Colorado Privacy Act

· Federal Trade Commission — Children’s Online Privacy Protection Rule

Appendix E — High-Priority Legal Review Questions

1. Does Deka-Art intentionally offer services to, or monitor the behavior of, individuals in the EEA or UK? If yes, confirm GDPR territorial scope and representative obligations.

2. Which entity is the controller for leads, contracts, website analytics, and marketing?

3. Which cookies and trackers actually load before and after consent?

4. Does the website use Yandex Metrica, Google Analytics, Meta Pixel, Google Ads, embedded YouTube/Vimeo, maps, chat, Telegram widgets, reCAPTCHA, or another provider?

5. Where are website, CRM, email, and project records hosted, and which countries can access them?

6. What transfer mechanism and supplementary safeguards support EEA/UK transfers to Russia or the United States?

7. Does Deka-Art meet statutory thresholds under California or other US state privacy laws?

8. Does any advertising or analytics activity constitute “sale, ” “sharing, ” or targeted advertising under applicable US law?

9. Can the website detect and honor Global Privacy Control or other legally recognized universal opt-out signals?

10. Are the listed retention periods technically implemented and documented?

11. Does the company have a process for access, deletion, correction, portability, objection, opt-out, appeal, identity verification, and breach response?

12. Do all service providers have appropriate confidentiality, data-processing, and security terms?

This site uses cookies for site functionality and traffic analysis. Privacy policy