Privacy policy
DJ Orphix Merchandise Store – Privacy & Data Protection Policy
Disclaimer: This document is created for informational purposes to outline how you're data is processed.
The e-shop hosted on this website is operated by DJ Orphix.
General Provisions
- Personal Data Controller: In compliance with the General Data Protection Regulation (GDPR), the Personal Data Controller is DJ Orphix, located in Fife Scotland,
- Contact Details: The contact details of the Controller are:
- Email: buisness@djorphix.com
- Definition: "Personal data" refers to any information that relates to an identified or identifiable natural person who visits or purchases from this store.
2. The Source of Personal Data
- Consent and Contracts: The Controller processes personal data obtained with explicit consent from the Customer, collected through the contract to purchase and the fulfillment of the electronic order created in the e-shop.
- Data Minimisation: The Controller processes only the identifying and contact details of the Customer which are strictly necessary for the fulfillment of the purchase contract.
- Usage Restrictions: The Controller processes personal data solely for shipping, billing, accounting purposes, and necessary communication between the contracting parties for the duration required by law. Personal data will not be made public and will not be transferred to third countries outside standard GDPR-compliant processing networks.
3. Purpose of Data ProcessingThe Controller processes personal data of the Customer for the following targeted purposes:
- Order Fulfillment: Processing electronic orders created by the Customer (requiring name, shipping/billing address, email, and telephone number).
- Legal Compliance: Observing laws and regulations arising from the contractual relationship between the Customer and the Controller (such as tax and financial reporting requirements).
- Contractual Necessity: Personal data is strictly necessary for the fulfillment of the purchase contract. An order cannot be successfully concluded or shipped without this data.
4. Duration of Personal Data Storage
- Retention Period: The Controller stores personal data for the period necessary to fulfill the rights and obligations arising from the contractual relationship between the Controller and the Customer, and for a duration of 3 years following the conclusion of the contractual relationship.
- Data Erasure: The Controller must safely delete all personal data after the expiration of the period required for the storage of personal data.
5. Recipients and Processors of Personal Data
Third parties processing personal data of the Customer are subcontractors of the Controller. The services of these subcontractors are indispensable for the successful fulfillment of the purchase contract and the processing of the electronic order. The operational subcontractors of the Controller are:
- djorphix.com
- Royal Mail / DHL / EVRI
- PayPal / Visa / MasterCard
6. Rights of the CustomerIn compliance with the Regulation, the Customer is entitled to the following rights regarding their data:
- The right of access to their personal data.
- The right to rectification of inaccurate or incomplete personal data.
- The right to erasure of personal data if it is no longer required.
- The right to object to the processing of personal data.
- The right to data portability to receive their data in a structured format.
- The right to withdraw consent to the processing of personal data at any time, in writing or by email sent to: buisness@djorphix.com
- The right to lodge a complaint with the relevant national supervisory authority if a breach of the Regulation is suspected.
7. Security of Personal Data
- Precautionary Measures: The Controller declares that they take all technical and organizational precautions necessary for the robust protection of customer personal data.
- Data Storage Protection: Technical precautions have been taken to secure data storage spaces. This includes securing computer access with unique passwords, utilizing updated antivirus software, and performing regular security maintenance on all connected systems.
8. Final Provisions
- Customer Confirmation: By placing an electronic order on the website, the Customer confirms they have been fully informed about all the conditions of personal data protection and accept them to the full extent.
- Explicit Acceptance: The Customer explicitly accepts these rules by ticking the designated mandatory checkbox within the order purchase form before checkout.
- Policy Updates: The Controller can update these Rules at any time. The newest, updated version will instantly become active upon being published on the website.
These Rules come into effect on 5 September 2026
