At DEREED Apparel Inc. ("DEREED", "we", "us", or "our"), respecting your privacy and safeguarding your personal information is fundamental to our craft. This Privacy Policy details our transparent policies regarding the collection, processing, transfer, storage, and erasure of personal data obtained via dereed.fashion, our client portal, mobile interfaces, and global flagship ateliers.
We never sell, monetize, or broker your personal data to external advertisers. Data collected is used solely to engineer, verify, fulfill, and support your archival garment purchases.
1. Information We Collect
We collect personal data that you provide directly to us, as well as telemetry generated automatically during your interaction with our storefront:
- Customer Identity & Contact Details: Name, billing address, physical shipping destination, email address, contact telephone number, and VIP client identification tags.
- Transaction & Payment Records: Order item handles, sizes, custom tailoring measurements, timestamp of transaction, and tokenized payment authorization tokens (e.g. Razorpay/Stripe token references). We never store raw credit card numbers or CVV codes on our servers.
- Authentication & Account Credentials: Cryptographically hashed passwords (via bcrypt/Argon2), OAuth identification hashes (Google sign-in), and session verification tokens.
- Storefront Interaction & Telemetry: Device operating system, browser user agent, masked IP address, referring URL, drop page latency, and localized timezone.
- Concierge Inquiries: Transmitted inquiry forms, support tickets, sizing recommendations, and warranty service requests.
2. How We Use Your Information
We process your data for the following operational, commercial, and legal purposes:
Fulfillment & Logistics
Generating customs declarations (DDP), dispatching insured packages via DHL/FedEx, and sending real-time tracking updates.
Serialized Drop Allocation
Enforcing fair purchase limits (e.g., maximum 2 pieces per household) and defending against malicious automated checkout bots.
Lifetime Warranty Validation
Verifying serial authenticity tags when past-season garments are submitted for atelier seam repair or hardware refurbishment.
Direct Communications
Responding to concierge tickets, transmitting invoices, and notifying subscribers of new Chapter releases.
3. Legal Grounds for Processing (GDPR Article 6)
Under the EU General Data Protection Regulation (GDPR) and UK Data Protection Act 2018, we process your personal data under the following lawful bases:
- Contract Performance: Processing necessary to execute order fulfillment, shipping, and return transactions.
- Legitimate Interests: Protecting our digital platform against credit fraud, bot attacks, and infrastructure abuse.
- Consent: Explicit opt-in for drop newsletters and non-essential analytical cookies (which you may revoke at any time).
- Legal Obligation: Maintaining accounting, tax, and customs transaction records required by statutory law.
5. Cross-Border Data Transfers
Because DEREED operates ateliers across the United Kingdom, Japan, India, and the European Union, your data may be transferred and processed in jurisdictions outside your country of residence. When transferring data out of the European Economic Area (EEA) or UK, we implement standard contractual clauses (SCCs) approved by the European Commission to guarantee equivalent levels of data protection.
6. Cryptographic Security Standards
We maintain defense-in-depth technical safeguards to protect your personal data against unauthorized access, loss, or alteration:
- End-to-end TLS 1.3 encryption across all public and authenticated endpoints.
- AES-256 encryption at rest for customer databases and storage volumes.
- Zero-trust database architecture with strictly isolated tenant parameters and parameterized SQL queries.
- Mandatory multi-factor authentication (MFA) on all internal atelier administrative systems.
7. Data Retention & Archival Policies
We retain personal data only for as long as necessary to fulfill the purposes for which it was gathered, or as mandated by statutory financial recordkeeping laws (typically 7 years for invoice and customs declarations). Upon expiration of the retention window or upon receiving a verified erasure request, your records are permanently purged or irrevocably anonymized.
8. Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on your geographic jurisdiction, you hold enforceable rights regarding your personal information:
To exercise any of these rights, email Sales@Dereed.com. We respond to all verified requests within 30 calendar days without charging processing fees.
9. Children's Privacy
DEREED does not knowingly collect, solicit, or market to individuals under the age of 16. If we learn that we have inadvertently collected personal data from a child under 16 without verified parental consent, we will promptly delete that information from our servers.
10. Data Protection Officer (DPO) & Regulatory Inquiries
If you have questions, complaints, or feedback regarding our privacy stewardship, please contact our dedicated Data Protection Officer:
Questions Regarding This Document?
For privacy, compliance, or regulatory queries, contact our legal counsel directly at Sales@Dereed.com or submit an inquiry via our Client Concierge.