Legal

Privacy Policy

Your privacy matters to us. This policy explains how DEO collects, uses, and protects your personal information.

Last updated:December 15, 2024
Effective:January 1, 2026
GDPR CompliantCCPA Compliant

We never sell your data

Your personal information is never monetised or traded.

Enterprise-grade encryption

TLS 1.3 in transit, AES-256 at rest, bcrypt for passwords.

Delete anytime

Request full deletion of your data within 30 days.

GDPR & CCPA compliant

We meet the highest global privacy standards.

Contents

Have a concern?

Our Data Protection team is here to help with any privacy-related questions.

privacy@deo.com
1

Personal Information

When you create an account, make a purchase, or contact us, we may collect your full name, email address, phone number, shipping and billing addresses, and payment information. Payment data is processed by our PCI-compliant payment partners and is never stored on our servers.

2

Account Data

If you create a DEO account, we store your login credentials (password is encrypted), order history, wishlist items, and communication preferences to provide a personalised experience.

3

Automatically Collected Data

When you visit our site, we automatically collect your IP address, browser type and version, operating system, device identifiers, referring URLs, pages viewed, time spent on pages, and click patterns. This data helps us improve performance and user experience.

1

Order Fulfilment

We use your personal and shipping information to process orders, send confirmations, provide tracking updates, and handle returns or exchanges.

2

Communication

We may send transactional emails (order confirmations, shipping notifications), respond to your enquiries, and — with your consent — send marketing communications about new products, promotions, and events. You can unsubscribe at any time.

3

Personalisation

We use browsing behaviour, purchase history, and preferences to recommend products, customise your homepage experience, and tailor marketing communications to your interests.

4

Analytics & Improvement

Aggregated and anonymised usage data helps us understand traffic patterns, identify popular products, diagnose technical issues, and improve site performance and design.

1

Essential Cookies

Required for the website to function properly. These handle session management, shopping cart persistence, security tokens, and authentication. They cannot be disabled.

2

Analytics Cookies

We use tools like Google Analytics to understand how visitors interact with our site. These cookies collect anonymised data about page views, session duration, and navigation paths.

3

Marketing Cookies

With your consent, we may use cookies from advertising partners to deliver relevant ads across other platforms. These cookies track visits across websites to build interest profiles.

4

Managing Cookies

You can manage your cookie preferences through our cookie banner or your browser settings. Note that disabling certain cookies may affect site functionality.

1

Service Providers

We share necessary data with trusted service providers who assist us with payment processing (Stripe), shipping and logistics (DHL, FedEx), email delivery (SendGrid), cloud hosting (AWS), and customer support tools. These partners are contractually bound to protect your data.

2

Legal Requirements

We may disclose your information if required by law, court order, or governmental request, or if we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our users.

3

Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change and any choices you may have regarding your information.

4

No Selling of Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. Your data is never monetised.

1

Encryption

All data transmitted between your browser and our servers is encrypted using TLS 1.3. Sensitive information such as passwords are hashed using bcrypt, and payment data is handled exclusively by PCI DSS Level 1 certified processors.

2

Access Controls

Internal access to customer data is restricted on a need-to-know basis. All access is logged, monitored, and subject to regular audits. Employees undergo mandatory security training.

3

Incident Response

We maintain a formal incident response plan. In the unlikely event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by applicable law.

1

Active Accounts

We retain your personal data for as long as your account is active or as needed to provide you with services, comply with legal obligations, resolve disputes, and enforce agreements.

2

Inactive Accounts

Accounts inactive for more than 36 months may be flagged for deletion. We will attempt to notify you before removing your data. Transaction records may be retained for up to 7 years for tax and legal compliance.

3

Deletion Requests

You may request deletion of your personal data at any time by contacting us. We will process your request within 30 days, subject to any legal retention requirements.

1

Access & Portability

You have the right to request a copy of all personal data we hold about you in a structured, commonly used, machine-readable format.

2

Correction

You can update or correct your personal information at any time through your account settings, or by contacting our support team.

3

Deletion

You have the right to request the deletion of your personal data, subject to certain legal exceptions such as tax record-keeping requirements.

4

Objection & Restriction

You may object to or restrict certain processing activities, including direct marketing. You can opt out of marketing emails at any time via the unsubscribe link in any email.

5

Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

1

Transfer Mechanisms

If you are located outside the United States, your data may be transferred to and processed in the US where our servers are located. We ensure adequate protection through Standard Contractual Clauses (SCCs) or equivalent legal mechanisms approved by relevant authorities.

2

EU / UK Users

For users in the European Economic Area and United Kingdom, we comply with GDPR requirements. Your data is protected by appropriate safeguards regardless of where it is processed.

1

Age Restriction

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal data, we will take steps to delete such information promptly.

1

Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised 'Last Updated' date. Material changes will be communicated via email or a prominent notice on our website.

1

Privacy Enquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection team.

Mail

123 Watch Street
New York, NY 10001

Response Time

Within 30 days

Terms of Service

Read our terms and conditions

Our Terms of Service outline the rules and guidelines for using the DEO platform, including purchasing, returns, and account management.

Read Terms

Cookie Policy

Manage your preferences

Learn more about the cookies and tracking technologies we use and how you can control them through your browser or our preference centre.

Cookie Settings

This privacy policy is provided for informational purposes and does not constitute legal advice. If you have specific legal questions, please consult a qualified attorney. © 2026 DEO. All rights reserved.