Privacy Policy

PRIVACY POLICY & TERMS OF USE

Effective Date: 25/11/2025
Website: decostalabs.com
Company: DECOSTA LABS LIMITED
Contact Email: info@decostalabs.com
Developer: LOOP Digital Marketing LTD (loopdigitalmarketing.com)
Developer Email: contact@loopdigitalmarketing.com


1. INTRODUCTION

This combined Privacy Policy and Terms of Use (“Agreement”) governs your access and use of the website decostalabs.com (“Website”), owned and operated by DECOSTA LABS LIMITED, a private limited company registered in the Republic of Cyprus (“Company”, “we”, “our”, “us”). This Agreement describes how we collect, use, store, disclose, and safeguard your personal data when you interact with our Website, purchase products, create an account, or use any related services. It also outlines your rights and responsibilities and sets forth the rules and conditions under which you may use the Website.

DECOSTA LABS LIMITED is committed to maintaining the highest standards of privacy, data protection, transparency, and lawful processing in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Cyprus Data Protection Law, and all applicable EU consumer and e-commerce laws.

The Website is developed on the WordPress platform and utilizes multiple third-party plugins, security modules, payment gateways, analytic tools, and extensions. The development and technical implementation were carried out by LOOP Digital Marketing LTD, an independent service provider. LOOP Digital Marketing LTD is not the controller of personal data collected on the Website and bears no liability for any content, operations, data collection activities, or commercial transactions undertaken by DECOSTA LABS LIMITED. All obligations, disclosures, liabilities, legal responsibilities, and data-protection commitments related to the operation of the Website belong exclusively to DECOSTA LABS LIMITED.

By using the Website, purchasing products, or creating an account, you agree to the terms of this Agreement. If you do not agree, you should immediately discontinue your use of the Website.


2. DEFINITIONS

For clarity, the following definitions apply:

  • “Personal Data” means any information relating to an identifiable natural person as defined under GDPR.

  • “Processing” means any operation performed on personal data such as collection, storage, modification, transmission, or deletion.

  • “User”, “you”, “your” refers to any visitor, account holder, or purchaser using the Website.

  • “Controller” refers to DECOSTA LABS LIMITED, which determines the purposes and means of processing personal data.

  • “Processor” may refer to trusted third-party service providers engaged in hosting, analytics, payment processing, or marketing services.

  • “Website” refers to decostalabs.com, including all pages, e-shop functions, downloadable materials, and related digital assets.


3. PERSONAL DATA WE COLLECT

We may collect and process the following categories of personal data:

3.1 Information Provided Directly by You

  • Full name

  • Billing and shipping address

  • Email address

  • Phone number

  • Payment information (processed securely via third-party payment gateways; we do not store full card details)

  • Account login details (username, hashed password)

  • Order history and transaction details

  • Contact form submissions

  • Newsletter subscription preferences

3.2 Information Collected Automatically

Through cookies, analytics scripts, and WordPress plug-ins, we may collect:

  • IP address

  • Browser type and version

  • Device information

  • Operating system

  • Referring URL

  • Pages visited

  • Time spent on pages

  • Access times

  • User behavior and interaction metrics

3.3 Data from Third-Party Integrations

Depending on your usage, we may receive limited personal data from:

  • Payment gateways (e.g., credit card status, transaction confirmation)

  • Email marketing providers

  • Anti-fraud and security services

  • Shipping carriers for order verification

All such data is used strictly for the purpose of fulfilling orders, improving service quality, and ensuring secure Website operation.


4. LEGAL BASIS FOR PROCESSING

We process personal data under the following lawful bases:

  1. Contractual necessity — To process purchases, deliver products, manage your account, and provide customer support.

  2. Legal obligation — To comply with tax, accounting, anti-fraud, and consumer protection laws.

  3. Legitimate interest — To improve our Website, prevent fraud, secure our systems, and enhance your user experience.

  4. Consent — For marketing communications, newsletter subscriptions, cookies that are not strictly necessary, and personalised advertising where applicable.

You may withdraw consent at any time without affecting the lawfulness of prior processing.


5. HOW WE USE YOUR DATA

Your personal data may be used for the following purposes:

  • To process orders and payments

  • To deliver purchased products

  • To manage your user account

  • To provide customer service and respond to inquiries

  • To send transaction-related emails (order confirmations, shipping updates, invoices)

  • To personalise your shopping experience

  • To maintain Website security and detect fraudulent activities

  • To comply with applicable laws and regulatory obligations

  • To conduct analytics, performance evaluation, and service optimization

  • To send newsletters or promotional materials where consent is given

We never sell your personal data to third parties.


6. SHARING OF PERSONAL DATA

We may share your data with trusted third parties who act as processors under strict confidentiality:

  • Payment processors (bank, credit card gateway, financial institutions)

  • Logistics & shipping partners

  • Email marketing service providers

  • Cloud hosting providers and server management

  • WordPress plugins and security modules

  • Analytics providers such as Google Analytics

  • IT support partners including LOOP Digital Marketing LTD (for maintenance only)

LOOP Digital Marketing LTD does not access or process personal data beyond what is required for technical troubleshooting and does not engage in independent processing activities.

All processors are required to adhere to GDPR and implement appropriate security measures.


7. INTERNATIONAL TRANSFERS

If any third-party provider stores or processes data outside the European Economic Area (EEA), such transfers are governed by:

  • Standard Contractual Clauses (SCCs)

  • Adequacy decisions

  • GDPR-compliant safeguards

We ensure that all providers offer an equivalent level of data protection.


8. DATA RETENTION

We retain personal data only for as long as necessary:

  • Order and transaction data: 7–10 years for accounting and legal compliance

  • Account data: retained until you delete your account

  • Newsletter data: until you unsubscribe

  • Technical logs: for security, retained for a limited period

  • Customer service queries: retained for up to 24 months

Once data is no longer required, it is securely deleted or anonymised.


9. YOUR RIGHTS UNDER GDPR

As a data subject, you have the following rights:

  • Right to access

  • Right to rectification

  • Right to erasure (“right to be forgotten”)

  • Right to restrict processing

  • Right to object

  • Right to data portability

  • Right to withdraw consent

  • Right to lodge a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus)

To exercise any right, contact info@decostalabs.com.


10. SECURITY MEASURES

We implement appropriate technical and organizational measures, including:

  • Encrypted HTTPS connections

  • Secure server architecture

  • Password hashing

  • Regular malware scans

  • Firewall protection

  • Plugin integrity monitoring

  • Restricted access to back-end panel

  • Timely updates to WordPress, themes, and plugins

  • Monitoring for suspicious login attempts

No system can be 100% secure, but we take all reasonable steps to safeguard your data.


11. COOKIES POLICY

The Website uses cookies to improve your browsing experience. Types of cookies:

11.1 Strictly Necessary Cookies

Used for:

  • Cart functionality

  • User login sessions

  • Checkout operations

  • Secure site navigation

Cannot be disabled.

11.2 Performance & Analytics Cookies

Used to analyze:

  • Page visits

  • Conversion flows

  • Load speeds

  • User behavior patterns

11.3 Functional Cookies

Used for:

  • Language preferences

  • Saved items

  • Account settings

11.4 Marketing & Advertising Cookies

Used (only with consent) for:

  • Remarketing campaigns

  • Personalized ads

  • Tracking engagement across platforms

You can adjust cookie preferences in your browser settings or through the Website cookie consent tool.


12. CHILDREN’S PRIVACY

Our Website is not intended for children under 16 years of age. We do not knowingly collect data from minors. If you believe a minor has provided data to us, contact us immediately to request deletion.


13. THIRD-PARTY LINKS

Our Website may contain links to external websites. We are not responsible for:

  • The content of third-party sites

  • Their privacy practices

  • Their data handling methods

You should review the policies of any site you visit through external links.


14. E-COMMERCE TERMS

14.1 Product Descriptions

We make every effort to provide accurate product descriptions. However, slight variations may occur due to ingredient sources, product batches, packaging updates, or website display differences.

14.2 Pricing & Availability

Prices may change without notice. Product availability is not guaranteed. If an item is unavailable after an order is placed, we will contact you to offer alternatives or provide a refund.

14.3 Payments

Payments are processed securely using external payment gateways. DECOSTA LABS LIMITED does not store credit card numbers or sensitive payment information.

14.4 Shipping

Shipping methods, fees, and delivery times are displayed during checkout. Delivery delays caused by carriers, customs, or force majeure events are outside our control.

14.5 Returns & Refunds

Returns are accepted in accordance with Cyprus consumer protection regulations. Products must be unopened and in original condition. Refunds may take several business days depending on the payment provider.


15. USER ACCOUNTS

By creating an account, you agree to provide accurate information and maintain the confidentiality of your login credentials. You are responsible for all activities occurring under your account.

We reserve the right to suspend or terminate accounts that:

  • Engage in fraudulent activity

  • Violate our policies

  • Abuse Website features

  • Attempt unauthorized access


16. PROHIBITED USES

You agree not to use the Website for:

  • Illegal or unauthorized activities

  • Data scraping, hacking, or reverse engineering

  • Distribution of harmful software

  • Uploading false or misleading information

  • Impersonation of other users or entities

  • Interference with Website functionality

  • Commercial exploitation without consent

Violations may result in account termination and legal action.


17. INTELLECTUAL PROPERTY

All Website content, including text, images, product descriptions, logos, graphics, and digital assets, is the exclusive property of DECOSTA LABS LIMITED or its licensors.

You may not copy, reproduce, distribute, or create derivative works without explicit written permission.


18. LIMITATION OF LIABILITY

To the fullest extent permitted by Cyprus and EU law:

  • DECOSTA LABS LIMITED shall not be liable for any indirect, incidental, consequential, or punitive damages arising from Website use, delays, errors, or interruptions.

  • We make no guarantees that the Website will be free from malware, vulnerabilities, or technical issues.

  • The Website is provided on an “as-is” and “as-available” basis without warranties of any kind.

Developer Liability Disclaimer

LOOP Digital Marketing LTD, as the independent developer, bears no responsibility for:

  • Content accuracy

  • Data collection methods

  • Business operations

  • Product information

  • E-commerce transactions

  • User data management

  • Legal compliance of DECOSTA LABS LIMITED

All liability rests solely with DECOSTA LABS LIMITED.


19. INDEMNIFICATION

You agree to indemnify DECOSTA LABS LIMITED and its employees, directors, partners, and affiliates against any claims, damages, or liabilities arising from:

  • Your misuse of the Website

  • Violation of this Agreement

  • Breach of intellectual property rights

  • Fraudulent conduct

  • Improper use of purchased products


20. FORCE MAJEURE

We shall not be liable for delays or failure to perform due to events beyond our reasonable control, including:

  • Natural disasters

  • War or civil unrest

  • Power outages

  • Server or hosting failures

  • Pandemic-related disruptions

  • Strikes or labor disputes


21. MODIFICATIONS TO THIS AGREEMENT

We reserve the right to update this Agreement at any time. Changes take effect upon posting to the Website. Continued use of the Website after updates constitutes acceptance of the revised terms.


22. CONTACT INFORMATION

For privacy inquiries, legal matters, or user rights requests, contact:

DECOSTA LABS LIMITED
Email: info@decostalabs.com
Website: decostalabs.com

For development and technical matters:

LOOP Digital Marketing LTD
Email: contact@loopdigitalmarketing.com
Website: loopdigitalmarketing.com


23. GOVERNING LAW & JURISDICTION

This Agreement is governed by the laws of the Republic of Cyprus. Any disputes shall be subject to the exclusive jurisdiction of the competent courts of Cyprus.


24. ACCEPTANCE OF TERMS

By browsing the Website, creating an account, subscribing to the newsletter, or completing a purchase, you acknowledge that you have read, understood, and agreed to this Privacy Policy & Terms of Use.