GDPR
Last Updated: August 24, 2026
This GDPR Terms and Conditions document supplements our Privacy Policy and applies specifically to individuals located in the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK). Stolen Demand, operated by Shreyas Kafle, is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable UK data protection legislation.
Data Controller
For the purposes of the GDPR, the data controller responsible for your personal data is:
- Shreyas Kafle, operating as Stolen Demand
- Email: kafle@arizona.edu
- Website: stolendemand.com
Personal Data We Process
We process the following categories of personal data from EU/EEA/UK data subjects:
- Name
- Email address
- Company or brand name
We do not process special categories of personal data (e.g., health data, biometric data, political opinions, or religious beliefs).
Lawful Basis for Processing
We process your personal data under the following lawful bases as defined by Article 6 of the GDPR:
- Consent (Article 6(1)(a)): Where you have provided your explicit consent for us to process your data, such as when you opt in to receive marketing communications.
- Performance of a Contract (Article 6(1)(b)): Where processing is necessary to perform a contract with you or to take pre-contractual steps at your request, such as providing Meta advertising services.
- Legitimate Interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, such as improving our services or communicating with prospective clients, provided those interests are not overridden by your rights and freedoms.
Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you and information about how we process it.
- Right to Rectification (Article 16): You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
- Right to Erasure (Article 17): You have the right to request deletion of your personal data where there is no compelling reason for us to continue processing it (also known as the "right to be forgotten").
- Right to Restriction of Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
- Right to Object (Article 21): You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where we rely on consent as the lawful basis for processing, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us using the details provided below. We will respond to your request within one (1) month, as required by the GDPR. In complex cases, this period may be extended by an additional two (2) months, and we will inform you of any such extension.
Data Retention
We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by law. Specifically:
- Client data: Retained for the duration of the service relationship and for a reasonable period thereafter to satisfy legal and accounting obligations.
- Prospective client/inquiry data: Retained for up to 24 months from the date of last interaction, unless you request earlier deletion.
- Marketing consent records: Retained for as long as the consent remains active, plus a reasonable period for compliance records.
When personal data is no longer required, it will be securely deleted or anonymized.
International Data Transfers
Stolen Demand operates in the United States. If you are located in the EU/EEA/UK, your personal data may be transferred to and processed in the United States. We will ensure that any such transfer is carried out in compliance with the GDPR, including by relying on:
- Your explicit consent to the transfer
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable
- Any other lawful transfer mechanism recognized under the GDPR
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures are reviewed periodically and updated as appropriate.
Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority in the EU/EEA Member State of your habitual residence, place of work, or place of the alleged infringement.
Contact for Data Protection Inquiries
Changes to This Document
We may update this GDPR Terms and Conditions document from time to time. Changes will be posted on our website with an updated "Last Updated" date. We encourage you to review this document periodically.