Privacy Policy
Who We Are - Data Controller
This Privacy Policy explains how Maveda collects, uses, stores, and protects your personal data when you visit our website or place an order. Maveda is operated by Ecomvest LLC, which is the data controller for all personal data processed in connection with orders placed on maveda.nl.
Data controller
Ecomvest LLC - trading as Maveda
As data controller, Ecomvest LLC determines the purposes and means of processing your personal data in connection with the maveda.nl online store. We process your data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet Algemene Verordening Gegevensbescherming, UAVG).
Data controller details
Ecomvest LLC
30 North Gould Street
Sheridan, Wyoming 82801
United States of America
Registration number: 32-0819180
Privacy contact
For all privacy-related requests:
contact@maveda.nl
+1 740 272-5703
Applicability of the GDPR
The EU General Data Protection Regulation (GDPR) (Regulation 2016/679) applies to the processing of personal data of individuals in the EU, including the Netherlands, regardless of where the data controller is established. Because we sell to consumers in the Netherlands, the GDPR fully applies to our processing of your personal data, even though Ecomvest LLC is established in the United States (Wyoming). We are committed to full GDPR compliance when processing the data of EU residents.
Data We Collect
We collect only the personal data that is necessary for the purposes described in this policy. We do not collect data we do not need, and we do not retain data for longer than necessary.
What we do not collect
We do not collect special categories of personal data (sensitive data under the GDPR) such as health data, race or ethnic origin, religious beliefs, or biometric data. We do not knowingly collect data from children under 16. If you believe a minor has provided us with their personal data, please contact us and we will delete it immediately.
How We Use Your Data
We use your personal data only for the purposes listed below. We do not use your data for automated decision-making or profiling that has significant legal effects on you.
Order fulfilment
Processing and confirming your order
Arranging shipping via PostNL or DHL and providing tracking information
Managing returns, refunds, and exchanges
Complying with customs and import documentation requirements where applicable
Customer service
Responding to your questions, complaints, and support requests
Handling warranty claims under the statutory warranty
Providing after-sales service and follow-up
Legal & compliance
Meeting tax and accounting obligations
Detecting and preventing fraud and payment abuse
Responding to legal requests from courts or supervisory authorities
Defending legal claims and disputes
Marketing (with consent)
Sending promotional emails, newsletters, and product updates - only where you have opted in
You can unsubscribe at any time via the link in any marketing email or by contacting us
We do not send marketing without your prior consent
Legal Basis for Processing
Under the GDPR, every processing activity must have a lawful basis. The table below sets out the legal basis we rely on for each category of processing.
Legitimate interest assessment
Where we rely on legitimate interest as a legal basis, we have assessed that our interests do not override your fundamental rights and freedoms as a data subject. For fraud prevention, processing is proportionate and necessary. For website analytics, data is aggregated and you are not individually profiled in a way that constitutes a disproportionate intrusion on your privacy. You can object to processing based on legitimate interest at any time - see section 07.
Data Sharing & International Transfers
We do not sell your personal data to third parties. We share data only with the service providers essential to fulfilling your order and operating our store. All third parties are bound by confidentiality and data processing agreements.
Essential service providers
Shopify Inc. - our e-commerce platform. Processes order, customer, and payment data on our behalf. Shopify is a certified processor under the GDPR. Servers may be located in the US and the EU.
PostNL & DHL - our delivery carriers. Receive your name and delivery address to fulfil shipment and provide tracking.
Payment processors (such as Stripe, Mollie, or similar) - process your payment securely. We share only what is necessary to authorize and complete your transaction.
We do not share with
Data brokers or data aggregators
Social media platforms for ad targeting without your consent
Any third party for their own marketing purposes
Any party outside the scope of order fulfilment and support without your explicit consent or a legal obligation
International data transfers (EU to US)
Our data controller is based in the US. We ensure appropriate safeguards are in place.
Ecomvest LLC, the data controller behind Maveda, is established in Sheridan, Wyoming, United States. Shopify and some payment processors may also process data in the US. For transfers of personal data from the EU/Netherlands to the United States, we apply appropriate safeguards as required by Chapter V of the GDPR.
Safeguards in place
We base transfers to the US on the European Commission's approved Standard Contractual Clauses (SCCs) with our service providers, supplemented by technical and organisational measures that provide a level of protection equivalent to that within the EEA.
Your right to information
You can request information about international transfers and the applicable safeguards by contacting us at contact@maveda.nl. We will provide this information free of charge within one month of your request.
Retention Periods
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. When data is no longer needed, it is securely deleted or anonymised.
Order & transaction data
Retained for 7 years from the date of the transaction to comply with accounting and tax obligations (which generally require data to be kept for several years). After this period, data is securely deleted.
Customer service communications
Retained for 3 years from the date of the last communication. This allows us to handle any follow-up to a complaint, warranty claim, or dispute within applicable limitation periods.
Marketing data
Email marketing data (your opt-in consent and preference) is retained for as long as you remain subscribed. If you unsubscribe, we keep a record of your opt-out to ensure we do not email you again. If no email has been sent for 3 years, we delete the marketing record unless you are also a customer.
Website analytics
Aggregated analytics data is retained for 26 months in line with the standard retention policy of Shopify Analytics. IP addresses used for fraud prevention are retained for 12 months from the date of the relevant transaction.
Deletion requests
You can request deletion of your personal data at any time (see section 07 - your right to erasure). We will delete your data promptly unless we are legally required to retain it (e.g. for tax records). In that case, we will explain the basis for retention and delete the data once the legal obligation expires.
Your GDPR Rights
As a data subject in the Netherlands, you have the following rights under the GDPR, regardless of the fact that the data controller is established in the United States. All requests are free of charge and answered within one month (extendable by two months for complex cases, with notice).
How to exercise your rights
Send your request to contact@maveda.nl with the subject line "GDPR Request - [Right you wish to exercise]". Include your full name, email address, and a brief description of your request. We may ask you to verify your identity before processing the request. We confirm receipt within 3 business days and provide a full response within one month.
Cookies & Tracking
We use cookies and similar technologies on maveda.nl. Under the EU ePrivacy Directive (implemented in the Dutch Telecommunications Act) and the GDPR, we ask for your consent before placing non-essential cookies.
Essential cookies (no consent required)
Session cookies: Keep your shopping cart and login status during your visit
Security cookies: Prevent cross-site request forgery (CSRF) and detect fraud
Preference cookies: Remember your cookie preference and currency preference
Non-essential cookies (consent required)
Analytics cookies: Shopify Analytics to understand how visitors use our site (page views, referral sources, device types). Data is aggregated.
Marketing cookies: Placed only when you have explicitly consented to targeted advertising.
We do not place marketing cookies without explicit opt-in consent.
Managing your cookie preferences
You can manage your cookie preferences at any time via the cookie preference banner shown on your first visit to our website, or by adjusting your browser settings to block or delete cookies. Please note that disabling essential cookies may affect website functionality (e.g. your shopping cart may not work). You can also opt out of analytics tracking by enabling the "Do Not Track" signal in your browser where supported.
Data Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction.
Security measures in place
Your data is protected by industry-standard technical and organisational measures.
We work with Shopify, a leading e-commerce platform with robust security infrastructure, to store and process your data. Payment data is processed exclusively by PCI-DSS certified processors - we never see or store your full card details.
Technical measures
HTTPS / TLS 1.2+ encryption on all pages. PCI-DSS compliant payment processing. Access controls and authentication for internal systems. Regular security monitoring via the Shopify platform.
Organisational measures
Access to personal data limited to staff who need it to fulfil orders or provide support. Data processing agreements with all external processors. Incident response procedures in place.
Data breach notification
In the event of a data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by GDPR Article 34. We will also notify the Dutch Data Protection Authority (see section 10) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Notifications include details of the breach, the data involved, the likely consequences, and the measures we have taken or intend to take.
Contact & Supervisory Authorities
For all privacy-related questions, requests, or complaints, we ask that you contact us first. You also have the right at any time to lodge a complaint with the Dutch supervisory data protection authority.
Contact us for privacy matters
Email: contact@maveda.nl
Phone: +1 740 272-5703
Subject line: "Privacy Request" or "GDPR Request". We answer all privacy requests within one month (GDPR Article 12). Complex requests may be extended by up to two months, with notice to you.
Policy updates
We review and update this Privacy Policy periodically. For material changes, we will notify you by email (if you are a customer) or post a prominent notice on the website before the changes take effect. The "Last updated" date at the top of this page always reflects the current version. We encourage you to review this policy periodically.
Data protection - Dutch Data Protection Authority (AP)
The Autoriteit Persoonsgegevens (AP) is the Dutch supervisory authority for data protection. You can lodge a complaint here about our processing of your personal data.
Postbus 93374
2509 AJ The Hague, Netherlands
Consumer matters - Authority for Consumers & Markets (ACM)
For general consumer-rights matters (outside of data protection), the Autoriteit Consument & Markt (ACM) is the competent Dutch regulator.
Postbus 16326
2500 BH The Hague, Netherlands
We would rather resolve it directly
We take all privacy concerns seriously and do our best to answer your question quickly and fairly. While you always have the right to contact the Dutch Data Protection Authority, we ask that you contact us first at contact@maveda.nl, so that we have the opportunity to resolve your concern directly before escalation.
Questions about privacy?
We answer all GDPR requests within one month.
contact@maveda.nlThis Privacy Policy applies to the processing of personal data of individuals in the Netherlands by Maveda (Ecomvest LLC) via maveda.nl. It has been prepared in accordance with EU Regulation 2016/679 (GDPR) and the Dutch GDPR Implementation Act (UAVG). Ecomvest LLC, 30 North Gould Street, Sheridan, Wyoming 82801, United States of America. Registration number 32-0819180.