What personal information this site and service touch, why, and what your rights are. It describes what actually happens — nothing more.
SyntropyData is the trading name under which NONDUAL E.E. provides its services. NONDUAL E.E. is an EU business established in Greece within the European Union, and is the controller for the personal information described here. It is registered at Othonos 95, 14561, Kifisia, Greece, and is responsible for this site and for the requests it receives.
Registration and company details are on the Legal Information page.
The form on the main page collects only what you type into it: your store URL and work email — both required; without them there is nothing to look at and no way to reply. If your request or our later correspondence includes anything more (your name, your company, details about your catalogue), we use it the same way: to prepare what you asked for and to reply to you. We do not use the form to build a marketing list.
Your browser also sends, as every browser does on every request, the page you came from and your user-agent string. Both are included in the request email so we know which page the request came from.
Submitting the form sends two emails through Resend: one internal notification to our SyntropyData reports inbox, and one acknowledgement to the work email address you submit. Your submission is not written to any database, file, or log by this site — it exists in those emails. Nothing is sold, and nothing is shared with anyone beyond the service providers listed below.
Cloudflare serves this site and runs the code that receives the form; like any hosting provider, it processes your network address to deliver pages and to protect the site from attacks. Our own code uses your network address for exactly one thing: rate-limiting the form so it cannot be used to flood our inbox. To do that without keeping a record of who visited, your network address and email are stored only as a one-way fingerprint (a truncated cryptographic hash) alongside a counter. The count lapses at the end of its window, and shortly afterwards the fingerprint and counter are deleted automatically — that happens on its own, whether or not anyone visits again. The address itself is never stored by us and never written to a log by our code.
If you go on to commission work from us, we keep the working records needed to prepare and deliver it.
To prepare an assessment, and to find stores our service is relevant to, we read what stores publish about themselves. That means we may hold information about you that did not come from you directly:
We use this to assess catalogue readiness, to prepare the reports a merchant asks for, and to make one-to-one contact with stores we believe the service is relevant to. Every such email identifies us and says how to stop hearing from us — and if you object, we stop.
A small number of providers are involved in running this site and service:
Some of the providers above operate infrastructure outside the European Economic Area, notably in the United States. Where personal data is transferred, we rely on the safeguards Chapter V of the GDPR provides for this, such as adequacy decisions and Standard Contractual Clauses.
Different kinds of information have different lifetimes, so we set a period for each rather than one catch-all answer:
These are the periods we work to. You may object to our processing or ask us to erase your information sooner. We will honour your request where applicable, while retaining only any limited information needed to respect an opt-out, comply with a legal obligation, resolve a dispute, or establish, exercise or defend legal claims.
Under the GDPR you can ask us for access to, correction of, or deletion of your personal information; ask us to restrict how it is used; receive what you gave us in a portable form; and object to any processing we base on legitimate interest — including, at any time and without giving a reason, to any use of your details for direct marketing, which we will stop immediately.
You also have the right to complain to the Hellenic Data Protection Authority (dpa.gr). We would appreciate the chance to resolve the issue first, but you do not need our permission to go to them.
This site sets no cookies and runs no analytics, advertising, or tracking scripts of any kind. That is why there is no cookie banner: there is nothing here to consent to and nothing to opt out of.
The interactive example documents (the Merchant Review Pack demonstrations) keep their demonstration state in your browser’s local storage, on your device. That data never leaves your browser and is not transmitted to us or anyone else.
Write to hello@syntropydata.ai and we will answer. If you would rather we erased your enquiry, say so and we will, on the same basis as above.