Privacy policy

Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

SYNLESS WRLD
Franz-Hitze-Straße 29
33102 Paderborn
Germany

Phone: +49 (0) 152 190 81456
Email: info@synlesswrld.com


2. General Information

We operate our online store via the e-commerce platform Shopify. In this privacy policy, we inform you about how we collect, process, and use personal data when you visit our website, place an order, create a customer account, or otherwise contact us.

Personal data is any information relating to an identified or identifiable natural person.


3. Collection and Processing of Personal Data

In particular, we process the following categories of personal data:

Contact data: Name, billing and shipping address, telephone number, email address

Payment and transaction data: Payment method, payment status, order and transaction details
(Payment data such as credit card numbers are processed exclusively by payment service providers)

Customer data: User account, settings

Order data: Purchased products, shopping cart, order history

Communication data: Support inquiries, email communication

Technical data: IP address, browser type, device, operating system

Usage data: Interactions with the store


4. Sources of Data

Processing is carried out on the basis of data:

  • that you provide to us directly
  • that is collected automatically when you visit the website
  • that is collected via service providers acting on our behalf

5. Legal Bases for Processing

The processing of personal data is carried out in accordance with Article 6 GDPR on the following legal bases:

  • Art. 6(1)(b) GDPR – Performance of a contract (orders, shipping, payment)
  • Art. 6(1)(c) GDPR – Legal obligations (tax and commercial law)
  • Art. 6(1)(a) GDPR – Consent (newsletter, tracking, marketing)
  • Art. 6(1)(f) GDPR – Legitimate interest (IT security, fraud prevention, shop optimization)

Consents may be revoked at any time with effect for the future.


6. Purpose of Data Processing

Processing is carried out in particular for the following purposes:

  • Processing orders, payments, and shipping
  • Managing customer accounts
  • Customer communication and support
  • Sending newsletters and marketing information
  • Analysis and optimization of our online store
  • Fraud prevention and security

7. Newsletter & Marketing (Klaviyo)

Newsletters are sent via Klaviyo.

  • Newsletters are sent via Klaviyo.
  • Newsletters are sent exclusively after explicit consent
  • We use the double opt-in procedure

Legal basis: Art. 6(1)(a) GDPR


8. Cookies & Tracking Technologies

We use cookies and similar technologies.

  • Technically necessary cookies pursuant to Section 25(2) TTDSG
  • Analytics and marketing cookies only after consent
    (Section 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR)

Consent management is handled via a cookie consent tool.


9. Payment Service Providers

For payment processing, we use the following providers:

  • Shopify Payments (credit card)
  • PayPal
  • Klarna
  • Apple Pay
  • Google Pay

Processing is carried out by the respective payment service providers as independent controllers. Their respective privacy policies apply.


10. Shipping Service Provider

Shipping is carried out via DHL.
For this purpose, name and delivery address are transmitted to DHL.

Legal basis: Art. 6(1)(b) GDPR


11. Shopify & Data Processing Agreement

Our store is operated via Shopify Inc.

  • Shopify processes data as a processor pursuant to Art. 28 GDPR
  • In certain cases, Shopify processes data as an independent controller

Further information: https://privacy.shopify.com


12. Transfers to Third Countries

Data may be transferred to countries outside the EU/EEA.
This is carried out exclusively on the basis of the European Commission’s Standard Contractual Clauses or an adequacy decision.


13. Data Retention Period

Personal data is stored only for as long as necessary for the respective purposes or as required by statutory retention obligations.


14. Rights of Data Subjects

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to direct marketing (Art. 21 GDPR)
  • Withdrawal of consent

Response period: maximum 1 month (Art. 12 GDPR)


15. Right to Lodge a Complaint

Competent supervisory authority:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
https://www.ldi.nrw.de


16. Data Security

We implement appropriate technical and organizational security measures. However, complete protection cannot be guaranteed.


17. Amendments

This privacy policy may be amended if necessary. The current version is available on our website.


18. Contact

For data protection inquiries, please contact:

SYNLESS WRLD
Franz-Hitze-Straße 29
33102 Paderborn
Germany

Phone: +49 (0) 152 190 81456
Email: info@synlesswrld.com