THE DEN
Home Story Vision Founding Circle FAQ Join the Circle
Legal information

Privacy Policy

How THE DEN collects, uses and protects personal data across our website, Founding Circle form and bank-transfer process.

Last updated: 31 July 2026

1. Controller

The controller responsible for processing personal data through this website is:

dot Creative UG (haftungsbeschränkt) i.G.
trading as THE DEN
Represented by the Managing Director: Nazia Hossain Jamee
Herzogstraße 90
40215 Düsseldorf
Germany
Email: ourden@web.de

We have not appointed a data protection officer because the statutory requirements for mandatory appointment are currently not met.

2. Scope

This policy explains how we process personal data when you visit the website, contact us, submit the Founding Circle form, reserve a reward, receive transactional emails or make a related bank transfer.

We do not currently use Google Analytics, Meta Pixel, Microsoft Clarity, Hotjar, advertising networks, behavioural profiling or comparable tracking services.

3. Hosting and server logs

This website and its MySQL database are hosted by Hostinger. Technical data needed to deliver and secure the website may include your IP address, access time, requested page, referrer, browser, operating system, device information, status codes and error information.

The purposes are reliable delivery, security, troubleshooting and prevention of misuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure and stable website operation.

Hosting is provided by Hostinger International Limited, 61 Lordou Vironos Street, Lumiel Building, 4th Floor, 6023 Larnaca, Cyprus, under a data-processing arrangement. Hostinger and authorised providers may process data in the EEA and, where necessary, elsewhere subject to applicable safeguards.

Logs are deleted or anonymised when no longer required unless a security incident or legal duty requires longer retention.

4. Founding Circle form

Depending on your entries and choices, we may process your name, email address, optional telephone number, selected tier and amount, selected reward, preferred public display name, notes, consent choices, reservation reference, payment reference, submission time and limited security data.

We use this information to create and manage your reservation, send payment instructions, match your transfer, provide rewards, communicate about fulfilment and maintain business records.

The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and contract performance, Article 6(1)(c) GDPR for accounting, tax and legal duties, and Article 6(1)(f) GDPR for security and fraud prevention.

5. Database and security

Form submissions are stored in our own MySQL database within the hosting environment. Access is limited to authorised persons who need the data for reservations, payments, rewards, support, accounting or security.

Measures include access controls, server-side validation, CSRF protection, a honeypot field, secure session handling and encrypted HTTPS transmission where enabled. No internet system can be guaranteed completely secure.

6. Email communication

We use your email address for transactional messages such as payment instructions, confirmations, fulfilment updates and replies. Messages pass through the mail servers and delivery providers involved in transmission.

The legal basis is Article 6(1)(b) GDPR where the communication concerns your reservation or contract, and Article 6(1)(f) GDPR for general business correspondence and reliable delivery.

We do not currently operate a marketing newsletter. Submitting the Founding Circle form does not subscribe you to one. Any future newsletter will use separate voluntary consent and this policy will be updated before activation.

7. Bank transfers

To identify and reconcile a bank transfer, we may process the transfer reference and information visible on the relevant account statement, such as payer name, IBAN, date and amount.

The legal bases are Article 6(1)(b) and Article 6(1)(c) GDPR. Banks involved in the transfer act under their own legal responsibilities.

8. Contact enquiries

When you contact us, we process your contact details, message and correspondence to respond and manage the matter. The legal basis is Article 6(1)(b) GDPR for contractual matters and otherwise Article 6(1)(f) GDPR.

9. Cookies

We currently use only technically necessary session functionality. A PHP session cookie may maintain a CSRF token or securely pass confirmation information between the form and thank-you page.

It is not used for advertising or analytics. See our Cookie Policy.

10. Recipients

Where necessary, data may be disclosed to Hostinger and infrastructure providers, email-delivery providers, banks, professional advisers, authorities and service providers needed to fulfil a selected reward. Processors acting for us are contractually bound where required.

11. International transfers

We aim to process website and reservation data within the EEA. If a provider processes data outside the EEA, the transfer must rely on a recognised mechanism such as an adequacy decision or appropriate contractual safeguards.

12. Retention

  • Unpaid reservations may expire after 72 hours; related records may be retained for up to six months for support, reconciliation and fraud prevention.
  • Contract, payment, invoice and accounting records are kept for applicable statutory periods, generally six, eight or ten years depending on record type.
  • General correspondence is deleted when no longer needed, normally within three years after the relevant matter ends unless longer retention is justified.
  • Technical logs are kept only as needed for security and troubleshooting.

13. Your rights

Subject to legal requirements, you may request access, correction, deletion, restriction, data portability, object to legitimate-interest processing, withdraw consent for the future and complain to a supervisory authority.

Contact ourden@web.de. We may request information needed to verify your identity.

14. Right to object

Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop unless compelling legitimate grounds override your interests, rights and freedoms, or processing is needed for legal claims.

15. Supervisory authority

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

16. Automated decisions and updates

We do not use automated decision-making or profiling producing legal or similarly significant effects.

We may update this policy when our website, providers, legal obligations or processing change. See also our Imprint and Founding Circle Terms & Conditions.

Legal information
Privacy Policy Imprint Founding Circle Terms Cookie Policy
THE DEN

A Room You Belong To.
Independent. Community-funded. Made in Düsseldorf.

THE DEN © 2026
a Brand of dot Creative UG (haftungsbeschränkt) i.G.

Instagram Facebook Email Privacy Policy Imprint Founding Circle Terms Cookie Policy