GDPR Compliance
General Data Protection Regulation (EU) 2016/679
Last updated: February 28, 2026
1. Data Controller Information
Identity: Byzentine
Contact email: [email protected]
DPO email: [email protected]
Location: Spain / United States
2. Legal Basis for Processing
We process your personal data based on the following GDPR legal grounds:
- Article 6(1)(a) - Consent: When you subscribe to newsletters or create an account
- Article 6(1)(b) - Contract performance: To process purchases, bookings, and deliveries
- Article 6(1)(c) - Legal obligation: To comply with tax and accounting obligations
- Article 6(1)(f) - Legitimate interest: For website analytics and fraud prevention
3. Data Collected
3.1 Identification Data
- First and last name
- Email address
- Postal address (shipping only)
- Phone number (optional, for bookings)
3.2 Transaction Data
- Purchase and payment history
- Order details (products, dates, amounts)
- Billing information (processed by PayPal, not stored by us)
3.3 Technical Data
- IP address
- Browser type and device
- Cookies (see section 8)
- Access logs (server logs)
4. Purpose of Processing
We use your personal data for:
- Order processing: Managing purchases, shipping, and billing
- Booking management: Event coordination and communication
- Marketing communications: Newsletters, releases, events (with your consent)
- Service improvement: Usage analytics, personalization, technical support
- Security: Fraud prevention, account protection
- Legal compliance: Tax, accounting, and regulatory obligations
5. Data Retention
We retain your personal data for the following periods:
- Account data: Until deletion request or 2 years of inactivity
- Transaction data: 7 years (legal tax requirement)
- Marketing data: Until consent withdrawal
- Technical logs: 90 days
- Booking data: 3 years after event
6. Your Rights Under GDPR
You have the following rights regarding your personal data:
6.1 Right of Access (Article 15)
You can request a copy of all personal data we hold about you.
6.2 Right to Rectification (Article 16)
You can request correction of inaccurate or incomplete data.
6.3 Right to Erasure (Article 17 - "Right to be Forgotten")
You can request deletion of your personal data, except when we must retain it for legal obligations.
6.4 Right to Restriction of Processing (Article 18)
You can request that we restrict processing of your data in certain circumstances.
6.5 Right to Data Portability (Article 20)
You can request your data in structured, machine-readable format (JSON, CSV) to transfer to another service.
6.6 Right to Object (Article 21)
You can object to processing of your data for direct marketing at any time.
6.7 Right Not to be Subject to Automated Decisions (Article 22)
We do not use automated decision-making or profiling that produces significant legal effects.
7. How to Exercise Your Rights
To exercise any of the above rights, you can:
- Email: [email protected]
- DPO email: [email protected]
- Account portal: Manage your data from your profile
We will respond to your request within 30 days (GDPR legal deadline).
To verify your identity, we may request additional documentation before processing access or deletion requests.
8. Cookies and Tracking Technologies
8.1 Essential Cookies
Necessary for site functionality (sessions, shopping cart). No consent required.
8.2 Analytics Cookies
We use analytics tools to understand site usage. You can decline them in our cookie banner.
8.3 Cookie Management
You can manage your cookie preferences from:
- Cookie banner when visiting the site
- Browser settings
- Third-party tools (Google Analytics opt-out, etc.)
9. International Data Transfers
Some of our service providers operate outside the EU/EEA:
- PayPal (USA): Payment processing - Standard Contractual Clauses
- Manufacturing partner: Product manufacturing - Adequate safeguards
- Servers (USA/EU): Data hosting - Certified infrastructure
All transfers comply with GDPR Chapter V requirements (Standard Contractual Clauses, Adequacy Decisions).
10. Data Security
We implement technical and organizational measures to protect your data:
- SSL/TLS encryption for transmissions
- Database encryption at rest
- Role-based access control (RBAC)
- Regular security audits
- Staff training on data protection
- Automated retention and deletion policies
11. Data Breaches
In case of personal data breach, we will notify the competent supervisory authority within 72 hours (Article 33 GDPR). If the breach presents high risk to your rights, we will notify you directly (Article 34 GDPR).
12. Minors
Our services are intended for individuals over 16 years old (GDPR minimum age). We do not intentionally collect data from minors without parental consent. If we discover data from minors without authorization, we will delete it immediately.
13. Right to Lodge a Complaint
If you believe we have violated GDPR, you have the right to lodge a complaint with the competent supervisory authority:
Spain: Spanish Data Protection Agency (AEPD)
Website: www.aepd.es
EU: European Data Protection Board
14. Data Protection Officer (DPO) Contact
Our Data Protection Officer is available for GDPR inquiries:
DPO email: [email protected]
Expected response: 48-72 hours
Languages: Spanish, English