THEONESHIRT
A brand operated by AMTHENO OÜ
PRIVACY POLICY
GDPR & Estonian Data Protection
Last updated: 3 September 2026
|
DATA CONTROLLER |
This Privacy Policy explains how AMTHENO OÜ, operating the TheOneShirt brand, collects, uses, stores, shares and protects personal data when you visit www.theoneshirt.de, create or use an account where available, place an order, use our made-to-order services, communicate with us, or otherwise interact with TheOneShirt. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), the Estonian Personal Data Protection Act and other applicable data-protection and e-privacy rules.
This Policy is information about our processing practices; use of the website does not by itself constitute consent to processing that legally requires consent. Where consent is required, we request it separately.
• Identity and contact data: name, title, billing and delivery address, email address, telephone number and account details.
• Order and garment data: products ordered, fabric or print selection, standard size, fit, pocket, hem and other available garment options, mandatory monogram details, order history and related instructions.
• Personalisation data: the individual monogram and any other genuine customer-specific personalisation information required for the ordered garment.
• Payment and transaction data: payment status, transaction references, payment method and related fraud-prevention information. Full payment-card details are normally processed by the relevant payment provider rather than stored by AMTHENO OÜ.
• Technical and usage data: IP address, device and browser information, operating system, website activity, referral information and similar technical data.
• Marketing and preference data: newsletter subscriptions, communication preferences and consent records.
• Customer-service data: correspondence, complaints, photographs or other information you choose to provide when requesting support or after-sales assistance.
• To take steps at your request, process and fulfil orders, manufacture and personalise made-to-order garments, manage order specifications, arrange delivery and provide after-sales service — GDPR Article 6(1)(b), performance of a contract or pre-contractual steps.
• To process payments, maintain transaction records and prevent or investigate fraud and misuse — GDPR Article 6(1)(b) and, where applicable, Article 6(1)(f), our legitimate interests.
• To comply with accounting, tax, consumer-protection, legal and regulatory obligations — GDPR Article 6(1)(c).
• To operate, secure, troubleshoot and improve our website, product-visualisation and ordering functions, and related IT infrastructure — GDPR Article 6(1)(f), our legitimate interests, subject to applicable cookie/consent rules.
• To send direct marketing or use non-essential marketing technologies where consent is required — GDPR Article 6(1)(a). You may withdraw consent at any time.
• To establish, exercise or defend legal claims and protect our rights, customers and systems — GDPR Article 6(1)(f), where applicable.
TheOneShirt’s ordering process involves made-to-order garment specifications and personalisation. Depending on the product, this includes standard size and fit, selected design options and the customer’s individual monogram. We use this information to create, manufacture, quality-check and, where necessary, repair or remake the garment ordered by you.
Order and personalisation data is shared only with persons and service providers who need it for the relevant order, production, quality-control, fulfilment or customer-service purpose. A monogram and ordinary garment selections are not treated as special-category personal data under the GDPR unless information provided in a particular case reveals special-category information.
We use cookies and similar technologies for essential website functions and, where permitted, for analytics, performance and marketing. Non-essential technologies that require consent will not be activated until the required consent has been obtained. You can change or withdraw your choices through the cookie settings made available on the website. Further details are provided in our Cookie Policy.
We may disclose personal data, only to the extent necessary, to categories of recipients such as:
• E-commerce, website hosting, cloud, email, IT support and software service providers used to operate the TheOneShirt website and ordering systems.
• Payment, banking and fraud-prevention service providers used to process or support transactions.
• Manufacturing, production and quality-control partners involved in producing your garment, including our production partners in Bangladesh and other partners located outside the EEA where required for fulfilment.
• Logistics, fulfilment and delivery partners used to consolidate, transport and deliver orders.
• Accounting, VAT, tax, legal, corporate-administration and other professional advisers and service providers.
• Marketing and analytics providers, but only where the relevant processing is lawful and any required consent has been obtained.
• Public authorities, courts, regulators or other recipients where disclosure is required by law or necessary to protect legal rights.
Because TheOneShirt operates an international production and fulfilment structure, some personal data needed for an order may be processed outside the European Economic Area (EEA), including by manufacturing or service providers in countries such as Bangladesh. Where the GDPR requires safeguards for such transfers, AMTHENO OÜ uses an applicable lawful transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary measures where appropriate.
We seek to limit transferred data to what is reasonably necessary for the relevant purpose. For example, a production partner may need the garment specifications and monogram required to manufacture the order, but does not need unrelated customer information.
We retain personal data only for as long as necessary for the purpose for which it was collected, to meet legal obligations, and to establish, exercise or defend legal claims. Retention periods may therefore differ by category.
• Accounting, invoice, transaction and other records that must be retained under Estonian accounting or tax law: generally at least seven years, calculated in accordance with the applicable statutory rule.
• Order and personalisation data: for as long as reasonably necessary to fulfil the order, provide after-sales support, handle conformity or warranty matters, and meet legal or evidentiary requirements. Personalisation data that is no longer required may be deleted or anonymised, subject to applicable legal retention obligations.
• Customer-service and complaint records: for as long as reasonably necessary to resolve the matter and protect legal rights.
• Marketing data and consent records: until consent is withdrawn or the data is no longer needed, subject to keeping necessary evidence of consent or withdrawal where legally required.
• Technical and security logs: for periods proportionate to security, troubleshooting, fraud-prevention and legal requirements.
Subject to the conditions and limitations in applicable law, you may have the right to:
• request access to your personal data;
• request correction of inaccurate or incomplete data;
• request erasure of personal data;
• request restriction of processing;
• receive certain personal data in a structured, commonly used and machine-readable format and request data portability;
• object to processing based on legitimate interests and object at any time to direct marketing;
• withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
• lodge a complaint with a competent data-protection supervisory authority.
To exercise your rights, contact dany@annamorgantailoring.com. We may need to verify your identity before acting on a request. Some rights are not absolute, and we may retain information where required by law or where another lawful basis permits continued processing.
AMTHENO OÜ does not currently intend to make decisions producing legal effects or similarly significant effects about customers solely by automated processing. If this changes, we will provide the information and safeguards required by the GDPR.
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Access to customer and measurement data is limited according to operational need. No internet transmission or storage system can, however, be guaranteed to be completely secure.
Our online purchasing services are intended for adults. TheOneShirt also offers garments for children. Where a garment is ordered for a child, the order and any personal data required for that order should be provided by the parent, guardian or other adult authorised to act for the child. We do not knowingly use children’s personal data for direct marketing without an appropriate legal basis.
We may update this Privacy Policy when our services, systems, providers or legal obligations change. The current version and its last-updated date will be published on the website. Where a change materially affects processing for which additional notice or consent is required, we will take the steps required by law.
You have the right to lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, place of work or place of the alleged infringement. For AMTHENO OÜ in Estonia, the supervisory authority is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Website: www.aki.ee
For privacy questions or requests concerning your personal data, please contact AMTHENO OÜ at dany@annamorgantailoring.com. Telephone: (will be filled in later).