GDPR COMPLIANCE
LAST UPDATED: AUGUST 09, 2026 · VER. 1.0.0
This GDPR Compliance page outlines how Sakamototo AI ("we", "our", "the System") collects, stores, processes, and protects the personal data of individuals within the European Union and the European Economic Area (EEA), in accordance with the General Data Protection Regulation (EU) 2016/679.
Our storefront is powered by Fourthwall, Inc., which acts as our platform provider, payment processor, and data processor. Your data is handled under the terms described below.
WHO CONTROLS YOUR DATA
Sakamototo AI is the data controller for all personal information collected through sakamototo.pro. The controller determines how and why your data is processed.
Controller
Sakamototo AI
Operating Address
[Registered Business Address or PO Box]
Email
contact@sakamototo.pro
Website
sakamototo.pro
WHAT DATA WE COLLECT
We collect and process the following categories of personal data depending on your interaction with the System:
| Category | Data Points | Source |
|---|---|---|
| Identity | Full name, username | Order form, account creation |
| Contact | Email address, phone number, billing address, shipping address | Order form, checkout |
| Payment | Payment card token, PayPal account ID, transaction amount and currency | Fourthwall/Stripe/PayPal (we do not store raw card numbers) |
| Technical | IP address, browser type, device type, operating system, timezone, screen resolution | Automatic — server logs, cookies, analytics |
| Behavioural | Pages viewed, products clicked, time on site, referral source, navigation path | Automatic — cookies, analytics |
| Communications | Email correspondence, commission briefs, creative direction notes | Direct correspondence, commission form |
| Marketing | Email subscription status, opt-in timestamp, campaign interaction data | Mailchimp (if you opted in) |
WHY WE PROCESS YOUR DATA
We process your personal data only when we have a lawful basis to do so under Article 6 of the GDPR:
- Contract Performance (Art. 6(1)(b)) — Processing your orders, delivering digital products, shipping physical apparel and prints, executing commissioned work. This is the primary basis for all transaction-related processing.
- Consent (Art. 6(1)(a)) — Sending marketing emails, newsletter updates, and promotional communications. You can withdraw consent at any time via the unsubscribe link in any email or by contacting us.
- Legitimate Interest (Art. 6(1)(f)) — Analysing site traffic, improving store performance, fraud prevention, and maintaining the security of our systems. We balance these interests against your privacy rights and ensure minimal data is used.
- Legal Obligation (Art. 6(1)(c)) — Retaining transaction records for tax and accounting purposes as required by applicable law.
YOUR GDPR RIGHTS
As a data subject in the EU or EEA, you have the following rights under the GDPR. We will respond to any request within 30 days.
- Right of Access (Art. 15) — Request a copy of the personal data we hold about you, including how and why it is processed.
- Right to Rectification (Art. 16) — Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17) — Request deletion of your personal data ("right to be forgotten"). We will comply unless retention is legally required for tax or fraud prevention purposes.
- Right to Restrict Processing (Art. 18) — Request that we limit how your data is used while a complaint or correction is being verified.
- Right to Data Portability (Art. 20) — Request a machine-readable copy of your data (CSV/JSON) to transfer to another controller.
- Right to Object (Art. 21) — Object to processing based on legitimate interest, including direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to Withdraw Consent (Art. 7(3)) — Withdraw consent at any time where processing is based on consent. This does not affect the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint (Art. 77) — File a complaint with your local data protection supervisory authority if you believe your rights have been violated.
To exercise any of these rights, contact us at contact@sakamototo.pro with the subject line "GDPR REQUEST". We may ask you to verify your identity before processing your request.
HOW LONG WE KEEP YOUR DATA
We retain your personal data only as long as necessary to fulfil the purposes for which it was collected:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Order data | 5 years after last order | Tax and accounting legal obligations |
| Account data | Until account deletion requested | User control |
| Marketing data | Until unsubscribe or 2 years of inactivity | Consent-based |
| Communication data | 3 years after last correspondence | Legitimate interest (service continuity) |
| Analytics data | 26 months | Industry standard (Google Analytics) |
After the retention period expires, your data is securely deleted or anonymised so it can no longer be linked to you.
WHO WE SHARE YOUR DATA WITH
We engage the following third-party processors who handle your data on our behalf. Each processor has been vetted for GDPR compliance and operates under a Data Processing Agreement (DPA):
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Fourthwall, Inc. | Storefront hosting, payment processing, order fulfilment, customer support | Identity, contact, payment tokens, order history | United States |
| Stripe, Inc. | Payment card processing | Payment card token, transaction amount | United States |
| PayPal, Inc. | Payment processing | PayPal account ID, transaction amount | United States |
| Mailchimp (The Rocket Science Group) | Email marketing, newsletters, automations | Email address, name, purchase history, opt-in status | United States |
| Google LLC (Analytics) | Website traffic analysis, behaviour tracking | IP address (anonymised), browsing behaviour, device data | United States |
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
DATA TRANSFERS OUTSIDE THE EEA
Your personal data may be transferred to and processed in countries outside the European Economic Area, including the United States, where our core service providers (Fourthwall, Stripe, PayPal, Mailchimp, Google) are based.
When your data is transferred outside the EEA, we ensure an equivalent level of protection through one or more of the following safeguards:
- Standard Contractual Clauses (SCCs) — European Commission-approved contractual clauses that obligate the data importer to protect your data to GDPR standards. All our processors listed in Section 06 operate under SCCs.
- Data Protection Framework — Where applicable, transfers to US-based processors are covered by the EU-US Data Privacy Framework (if the processor is certified).
By using our services and submitting your data, you acknowledge these transfers. If you wish to obtain a copy of the applicable safeguards, contact us at contact@sakamototo.pro.
COOKIES & TRACKING
Our Site uses cookies and similar tracking technologies to ensure functionality, analyse traffic, and (with your consent) deliver personalised content.
| Type | Purpose | Duration | Opt-Out |
|---|---|---|---|
| Essential | Session management, cart functionality, CSRF protection, checkout flow | Session / persistent | Cannot opt out — required for site operation |
| Analytics | Page views, traffic sources, user behaviour (Google Analytics) | Up to 26 months | Browser settings or Google Analytics Opt-Out |
| Marketing | Email signup tracking, Mailchimp campaign attribution | Up to 2 years | Unsubscribe from emails or disable in browser settings |
Most web browsers allow you to control cookies through your browser settings. However, disabling essential cookies may prevent certain parts of the Site from functioning correctly.
HOW WE PROTECT YOUR DATA
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk:
- Encryption in Transit — All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS).
- Encryption at Rest — Data stored by our processors is encrypted using AES-256 or equivalent industry standards.
- Access Control — Access to personal data is restricted to authorised personnel only, on a need-to-know basis.
- Payment Security — All payment processing is handled by Stripe and PayPal, which are PCI DSS Level 1 compliant. We never store full credit card numbers.
- Regular Audits — We review our data processing practices and update our security measures periodically.
CONTACT THE DATA CONTROLLER
For all GDPR-related inquiries, data subject requests, or complaints, contact us through the following channels:
Email (preferred)
contact@sakamototo.pro
Subject Line
GDPR REQUEST — [your name]
Response Time
Within 30 calendar days
Data Controller
Sakamototo AI
Complaint to a Supervisory Authority
If you are not satisfied with our response to your request, you have the right to lodge a complaint with your local data protection authority. For users in the EU/EEA, a list of national data protection authorities is available at the European Data Protection Board: edpb.europa.eu.
CHANGES TO THIS POLICY
We may update this GDPR Compliance page from time to time to reflect changes in our data processing practices, legal requirements, or operational structure. When we make material changes:
- The "LAST UPDATED" date at the top of this page will be revised.
- A notification will be posted on our homepage for 30 days following the update.
- If the change materially affects your rights, we will notify registered users by email.
We encourage you to review this page periodically. Your continued use of the Site after any changes constitutes acceptance of the updated policy.