Privacy Policy
Last updated: February 28, 2026
1. Data Controller
Legal name: Te Voy a Decir Algo, S.R.L.
Trade name: Byzentine
Email: [email protected]
Data Protection Officer (DPO): [email protected]
Registered office: Carrer SN81, Urbanización Isla Blanca, 176, E1, 3 · 07815 Sant Miquel de Balansat, Balearic Islands (Spain)
Website: https://byzentine.es
In compliance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD), we inform you about how we process your personal data.
2. Personal Data Collected
2.1 Data provided voluntarily
- Full name
- Email address
- Postal address (physical orders only)
- Phone number (optional, for booking confirmation)
- Free-form message (contact form)
2.2 Automatically generated data
- IP address
- Browser type/version and operating system
- Pages visited and session duration
- Server access logs
- Technical and analytics cookies (see section 9)
2.3 Third-party provider data
Payment data is processed entirely by PayPal Holdings, Inc.; Byzentine does not store or have access to full credit/debit card details.
3. Purposes and Legal Basis for Processing
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Order management, shipping, and invoicing | Art. 6.1.b — Contract performance |
| Booking and event coordination | Art. 6.1.b — Contract performance |
| Responding to enquiries and support | Art. 6.1.b — Contract performance / Art. 6.1.f — Legitimate interest |
| Marketing communications and newsletters | Art. 6.1.a — Consent (withdrawable at any time) |
| Website usage analytics | Art. 6.1.f — Legitimate interest (anonymised analysis) |
| Fraud prevention and security | Art. 6.1.f — Legitimate interest |
| Tax and accounting obligations | Art. 6.1.c — Legal obligation |
4. Recipients and Data Processors
Your data may be shared with the following processors, with whom Byzentine has entered into Data Processing Agreements under Art. 28 GDPR:
- PayPal Holdings, Inc. — Secure payment processing (USA; Standard Contractual Clauses)
- Print-on-demand manufacturing and shipping (global; Standard Contractual Clauses)
- Resend / transactional email providers — Sending confirmations and notifications
- Hosting / infrastructure providers — Servers in EU or with appropriate safeguards
Byzentine does not sell, rent, or transfer personal data to third parties for their own commercial purposes.
5. International Data Transfers
Some providers operate outside the European Economic Area (EEA). All transfers are carried out under one of the following Chapter V GDPR safeguards:
- European Commission adequacy decision
- Standard Contractual Clauses (SCCs) adopted by the Commission
- Binding Corporate Rules (BCRs)
You may request details of the specific safeguards applied by writing to [email protected].
6. Data Retention Periods
| Data category | Retention period |
|---|---|
| Customer and account data | Duration of relationship + 5 years after termination |
| Transaction and billing data | 7 years (legal tax requirement) |
| Booking and event data | 3 years after event date |
| Marketing / newsletter data | Until consent withdrawal |
| Technical logs | 90 days |
| Contact and enquiry data | 2 years from last contact |
After these periods, data will be deleted or anonymised.
7. Data Subject Rights (Arts. 15–22 GDPR)
You may exercise the following rights at any time:
- Access (Art. 15): Obtain confirmation of whether we process your data and receive a copy.
- Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Erasure / "right to be forgotten" (Art. 17): Request deletion when data is no longer necessary, consent is withdrawn, or other grounds apply.
- Restriction of processing (Art. 18): Request suspension of processing in specific circumstances.
- Data portability (Art. 20): Receive your data in a structured, machine-readable format (JSON/CSV).
- Objection (Art. 21): Object to processing based on legitimate interest or for direct marketing purposes.
- Not to be subject to automated decisions (Art. 22): Byzentine does not apply profiling or automated decision-making with significant legal effects.
- Withdrawal of consent (Art. 7.3): Revoke consent at any time without affecting the lawfulness of prior processing.
To exercise your rights, send a request to [email protected] with your full name and a copy of your ID. We will respond within 1 month (extendable to 3 months for complex cases, with prior notification).
8. Right to Lodge a Complaint with the AEPD
If you believe the processing of your data infringes applicable law, you have the right to lodge a complaint with the Spanish supervisory authority:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6 · 28001 Madrid, Spain
Website: www.aepd.es
Online portal: sedeagpd.gob.es
You may also contact the European Data Protection Board (EDPB) or the supervisory authority in your Member State of residence.
9. Cookie Policy
9.1 Types of cookies used
| Type | Purpose | Requires consent |
|---|---|---|
| Technical / strictly necessary | Site functionality, shopping cart, session security | No |
| Analytics | Anonymous usage statistics to improve the service | Yes |
| Preference | Remembering language and user settings | Yes |
9.2 Managing consent
A cookie banner will be displayed on your first visit. You may withdraw or modify your consent at any time via your browser settings or the site's cookie management tool.
10. Data Security
Byzentine implements appropriate technical and organisational measures under Art. 32 GDPR:
- TLS 1.2/1.3 encryption in transit
- Database encryption at rest
- Role-based access control (RBAC) and two-factor authentication
- Regular backups and disaster recovery plan
- Security incident monitoring and logging
- Data breach management policy (Art. 33 GDPR — 72-hour notification to supervisory authority)
11. Minors
Byzentine's services are intended exclusively for individuals aged 14 and over. If you believe a minor has provided personal data without parental consent, please contact [email protected] so we can delete it immediately.
12. Changes to This Privacy Policy
Byzentine reserves the right to update this policy to reflect legislative changes or updates to our services. The current version will always be available on this page with the date of last update. Registered users will be notified of material changes by email at least 30 days in advance.
13. Contact and Data Protection Officer
For any privacy enquiries, rights requests, or data protection issues:
Byzentine — Data Controller
[email protected]
Data Protection Officer (DPO)
[email protected]
Estimated response time: 48–72 business hours
Languages: Spanish, English