Version: 15 September 2026
1. Who is responsible?
Ninetta9, trading as Ninetta9 Customs, is responsible for processing personal data as described in this notice.
Address: Cornelis van der Lijnstraat 1, 2593 NG Den Haag
Dutch Chamber of Commerce number: 98726315
Email: ninetta9customs@hotmail.com
Website: [TO BE COMPLETED: final domain name of this online shop]
2. What data do we use and why?
Enquiries and quotations
We use your name, email address, size or dimensions, description, attachments and correspondence to answer your enquiry and prepare an offer. The legal basis is taking steps at your request before entering into a contract.
Orders and fulfilment
We use your contact details, delivery address, order details, design agreements and necessary payment information to fulfil your order and provide service. The legal basis is performance of the contract.
Administration
We retain necessary invoice and transaction details to meet tax and administrative requirements. The legal basis is compliance with a legal obligation.
Website security and general questions
We may use technical data, including IP address, time, session data and error messages, to prevent misuse and secure the website. We use general correspondence to answer questions. The legal basis is our legitimate interest in secure business operations and being accessible. We limit this processing to what is necessary and consider your privacy interests.
Publishing personal images
If we wish to use identifiable photos, your name or other personal information in our portfolio or on social media, we ask for separate consent in advance. We explain what we will publish and where. You may withdraw that consent.
You must provide the data necessary to process your enquiry or order if you wish to use these services. Without that data, we may be unable to make an offer or deliver. Attachments are optional unless a specific image is necessary for the design you request.
3. Photos and attachments
Only send files that are necessary for your enquiry and that you may share with us. Do not send identity documents, medical data or other sensitive information.
Attachments are temporarily processed on the server during submission and sent to our mailbox with your enquiry. They may therefore remain in email and backups even after temporary server files have been deleted.
If a file contains someone else's data, inform that person that you are sharing it with us. We remain responsible for our own legal obligations towards that person.
4. Who receives data?
We only share necessary data with service providers involved in:
- Hosting and technical management: [TO BE COMPLETED: confirmed STRATO contracting entity and any administrator].
- Email: [TO BE COMPLETED: applicable Microsoft/Outlook service and contracting entity for the Hotmail address].
- Shipping: [TO BE COMPLETED: carrier(s)].
- Bookkeeping: [TO BE COMPLETED: provider, if used].
- Payment: [TO BE COMPLETED: bank or payment service actually used].
Where a party processes data on our behalf, we make the legally required arrangements. Some recipients, such as banks, also process data under their own responsibility.
We provide data to public authorities when legally required. We do not sell your personal data.
5. Processing outside the EEA
[TO BE COMPLETED BEFORE PUBLICATION: check whether hosting, email, support and other providers process data outside the European Economic Area.]
If data is transferred outside the EEA, we identify here the recipients or recipient categories, countries and applicable safeguard, such as an adequacy decision or European standard contractual clauses with any necessary supplementary measures.
You can request information on the applicable safeguards and a copy of them by email.
6. How long do we retain data?
This section will be completed before live use. The suggestions below are not yet an established or technically implemented retention policy:
- Non-binding enquiries that do not lead to an order: up to [TO BE COMPLETED; suggestion: 6 months] after the last contact.
- Design files and personal reference photos: up to [TO BE COMPLETED; suggestion: 3 months] after completion, unless still necessary for an ongoing complaint or separately agreed follow-up work.
- Necessary order and service data: [TO BE COMPLETED: justified period taking account of guarantees, complaints and potential legal claims].
- Basic tax records: generally 7 years; where a specific tax scheme requires a longer period, that period applies.
- Security logs and misuse prevention data: up to [TO BE COMPLETED: actual configured period], unless longer retention is necessary to investigate a specific incident.
- Publications based on consent: for the agreed publication period or until you withdraw consent.
- Backups: deleted data is removed from regular backups within [TO BE COMPLETED: backup cycle] at the latest.
In a dispute, we retain only the necessary data for as long as required to handle or substantiate legal claims.
7. Cookies and external links
The enquiry form uses a first-party PHP session cookie (PHPSESSID by default) for a security token to prevent forged requests. It is a session cookie with HttpOnly and SameSite=Strict; Secure is also set on HTTPS. We will check the final cookie name and server settings on the live hosting. The bag is currently stored only in the open page's memory and disappears on reload. The current website code contains no advertising trackers or embedded Instagram or Spotify players. Hosting logs and other live technologies still need to be checked.
Strictly necessary technologies do not require consent. For tracking cookies and other technologies that require consent, we ask before activating them. Refusing and later withdrawing consent must be easy.
Links to Instagram, Spotify and other websites take you to services with their own privacy policies. If we embed external content directly, we explain what data is shared before activation and request consent where necessary.
8. Security and automated decisions
We take appropriate technical and organisational measures, proportionate to the data and risks, to prevent unauthorised access, loss and misuse.
[TO BE CHECKED BEFORE PUBLICATION: we do not make solely automated decisions that produce legal effects concerning you or otherwise significantly affect you.]
9. Your rights
You may ask us to access, correct or erase your personal data. Subject to statutory conditions, you may also request restriction of processing or data portability.
Where processing is based on legitimate interests, you may object on grounds relating to your particular situation. You may always object to direct marketing.
You may withdraw consent at any time. This does not affect the lawfulness of previous processing.
Send your request to ninetta9customs@hotmail.com. We generally respond within one month. For a complex request or multiple requests, the period may be extended by up to two months; we will inform you within the first month and explain why.
If we have reasonable doubts about your identity, we only request the additional information necessary to verify it.
You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via www.autoriteitpersoonsgegevens.nl, or with the competent data protection authority in the EU country where you live or work.
10. Changes
We update this notice when our data processing changes. The current version is available on our website. Where necessary, we inform you separately about material changes.
← Back to the website