Privacy Policy
Last updated: 10 August 2026
1. Controller
OÜ GurovDisUx (registry code 17552749), Pärnu mnt 12, Kesklinna linnaosa, Tallinn, Harju maakond, 10148, Estonia, is the controller of personal data collected through gux.design. Contact us about privacy at gurovdisux@inbox.eu.
We have not appointed a Data Protection Officer, because our processing does not meet the thresholds in Article 37 GDPR. We will revisit this if the scale of processing changes.
2. What we collect, why, and on what basis
2.1 Account data
Email address, name if you give it, and a password stored only as a hash. Used to give you an account, your download history and your order records. Legal basis: performance of a contract (Art. 6(1)(b)).
2.2 Order data
What you bought, when, the amount, currency, country, invoice details, and the record of your consent to immediate delivery. Used to fulfil the order, provide downloads, and meet accounting and tax obligations. Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
2.3 Payment data
Payments are handled by Stripe Payments Europe, Limited (Ireland), acting as an independent controller for fraud prevention and as our processor for the transaction. We receive confirmation of payment, the last four digits of the card and the payment status. We never receive or store full card numbers. Stripe’s own privacy policy is at stripe.com/privacy. Legal basis: contract (Art. 6(1)(b)).
2.4 Technical data
IP address, browser and device information, and pages requested, recorded in server logs. Used to keep the service secure, diagnose faults and prevent abuse. Legal basis: legitimate interests (Art. 6(1)(f)) in operating a secure service.
2.5 Marketing
We do not run a mailing list and send no marketing email. The only email you receive from us relates to an order you placed — confirmation, receipt and download links.
3. What we do not do
We do not sell or rent your personal data. We do not use it for automated decision-making or profiling that produces legal effects for you.
4. Who else processes your data
We share data only with providers who process it on our instructions under a data processing agreement:
- Hosting and infrastructure — Namecheap, Inc., on its Amsterdam (Netherlands) shared-hosting infrastructure, so the site and its database are held in the EU.
- Payment processing — Stripe Payments Europe, Limited (Ireland).
- Email — order email is generated by our own store software and sent from our hosting. There is no third-party email provider, and your address is not passed to a mailing service.
We may also disclose data where required by law or to establish or defend legal claims.
5. Transfers outside the EEA
Your data is stored in the EU. Site and database are hosted in Amsterdam, and payments are handled by Stripe’s Irish entity.
Two of our processors are US-incorporated even though the data itself sits in the EU. Namecheap, Inc. is established in the United States and its staff may access EU-hosted systems for support and maintenance; Stripe may transfer data to its US parent. Both transfers rely on Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. We use no other provider that moves your data outside the EEA.
6. How long we keep it
- Account data — while your account is open, then deleted or anonymised.
- Order and accounting records — 7 years from the end of the financial year, as required by the Estonian Accounting Act.
- Consent to immediate delivery — kept with the order record, as evidence that the waiver was validly obtained.
- Server logs — 30 days, then deleted.
7. Your rights
Under the GDPR you may ask us to: give you access to your data; correct it; erase it; restrict how we use it; provide it in a portable format; or object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what happened before.
Email gurovdisux@inbox.eu. We respond within one month, and will tell you if we need longer. Some data must be retained despite an erasure request where accounting law requires it.
8. Complaints
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, or to the supervisory authority where you live.
9. Cookies
A cookie is a small file stored by your browser. We group ours into three categories. Strictly necessary cookies are always active because the store cannot function without them, and the law does not require consent for them. Everything else is off until you switch it on, and you can change your mind at any time using the Cookie preferences link in the footer.
9.1 Strictly necessary — always active
| Cookie | Purpose | Retention |
|---|---|---|
wordpress_logged_in_*, wordpress_* |
Keeps you signed in and authenticates each request. | Session |
wp_woocommerce_session_* |
Links your browser to your cart on the server. | 7 days |
woocommerce_cart_hash, woocommerce_items_in_cart |
Tells the store when your cart has changed so totals stay correct. | Session |
wp-settings-* |
Remembers admin screen preferences. Only set for signed-in staff. | 1 year |
gux_consent |
Records the cookie choice you made here, so we do not ask again. | 180 days |
9.2 Analytics — off unless you allow it
| Cookie | Purpose | Retention |
|---|---|---|
sbjs_* (sourcebuster) |
WooCommerce order attribution. Records the site or campaign link you arrived from, the number of visits, and entry pages, so we can see which sources bring customers. Set only if you allow Analytics. | Session |
These are set by WooCommerce itself, not by a third party, and the data stays on our systems. If you decline, the script is never loaded and the cookies are never created — we do not merely ignore them.
9.3 Marketing — off, and nothing currently uses it
No advertising, remarketing or third-party tracking cookies are in use. The category exists so that none can be introduced without asking you first. If any such service is ever added, it will be listed here and everyone will be asked again.
9.4 Changing your choice
Select Cookie preferences in the footer of any page. Withdrawing is as easy as giving consent. You can also delete cookies in your browser settings, though removing the strictly necessary ones will sign you out and empty your cart.
10. Security
Traffic is served over HTTPS and passwords are stored hashed. No system is perfectly secure; if a breach occurs that is likely to be a high risk to your rights, we will notify you and the Data Protection Inspectorate as required by Articles 33 and 34.
11. Children
The Store is not directed at children under 16, and we do not knowingly collect their data.
12. Changes
We may update this policy. The date at the top shows when it last changed. Material changes affecting how we use your data will be notified to registered customers by email.