SYLS Privacy Policy — syls.eu

Effective from 26 July 2026.

1. Controller and contact

The controller of personal data relating to visitors of syls.eu, prospective customers, SYLS Customers and platform account users is kowal sp. z o.o., ul. Przekopna 6/1, 38-100 Strzyżów, Poland, VAT ID PL8191670708, REGON 383765987, KRS 0000793162, registered by the District Court in Rzeszów, 12th Commercial Division of the National Court Register, share capital PLN 5,000 (“SYLS”, “we”).

Privacy requests may be sent to hello@syls.eu or to our registered address. If a data protection officer is appointed, their contact details will be published here.

2. Our controller and processor roles

  1. SYLS is controller for data concerning its website, subscription purchase, Customer accounts, payments, invoicing, support, security and Service communications.
  2. The merchant operating a Store is controller for personal data of Store buyers, delivery recipients, staff and business contacts. SYLS processes that data on the merchant's behalf under the Data Processing Addendum to the Terms.
  3. A person whose data appears in a particular Store should normally contact the merchant identified in that Store first. We assist the merchant with valid requests.

3. Personal data we process

Depending on the relationship, we may process:

  • identity and contact details, including name, company, email and telephone;
  • registration and billing data, including address and VAT ID;
  • account data, including login, role, settings, Store identifier and subdomain;
  • contract data, including Plan, billing cycle, price, consents, accepted Terms version and subscription status;
  • payment information received from Stripe, including customer, session and subscription identifiers, limited payment-method details, status, amount and currency; we do not store full card numbers;
  • support data, including requests, messages, attachments and resolution history;
  • technical and security data, including IP address, time, browser, device, requested URL, session identifiers, logins and administrative activity;
  • information in forms, orders, DSA notices and correspondence;
  • Store data processed for merchants as described in the Data Processing Addendum.

We obtain data from the person or organisation, Authorised Users, service logs and providers such as Stripe.

4. Purposes and legal bases

Purpose GDPR legal basis
answering enquiries and taking pre-contract steps Article 6(1)(b)
creating accounts, providing support, performing and ending the contract Article 6(1)(b)
accounting, tax, consumer-law and authority-order obligations Article 6(1)(c)
security, abuse prevention, logs, legal claims and service reliability Article 6(1)(f) — legitimate interests of SYLS and Customers
communications about similar own services where permitted, with an opt-out Article 6(1)(f) and applicable e-privacy law
newsletters, consent-based marketing and optional analytics or advertising cookies Article 6(1)(a) and consent required by e-privacy law
illegal-content notices and actions required by the DSA Article 6(1)(c), and where relevant Article 6(1)(f)

Data marked as required in checkout is necessary to enter into and perform the contract. Optional data is voluntary, but without it a requested feature may not work.

5. Cookies and similar technologies

  1. We use cookies or browser storage necessary for website operation, security, sessions, sign-in, preferences and checkout. These are used to provide a service requested by the user.
  2. Analytics, personalisation or advertising technologies may be enabled only after obtaining legally required consent. Refusal must not block core use of the site.
  3. Consent can be changed or withdrawn as easily as it was given through the settings provided on the website. Withdrawal does not affect prior lawful processing.
  4. A current list of cookies, providers, purposes and lifetimes must be displayed in the consent panel before this Policy is published.

6. Recipients

Data may be disclosed only as necessary to:

  • Hetzner Online GmbH — EU hosting infrastructure;
  • Stripe — subscription payment, billing and fraud prevention; Stripe may act as an independent controller for activities described in its own privacy notice;
  • wFirma and accounting providers — invoices and tax compliance;
  • the Provider's own email infrastructure at mx.kowal.co;
  • external monitoring, support or backup providers — only after they are added to the public provider list;
  • legal and tax advisers, auditors and insurers;
  • public authorities and other authorised recipients where required by law;
  • a purchaser of all or part of the business, subject to appropriate safeguards.

We do not sell personal data.

7. Transfers outside the EEA

Core Store infrastructure is hosted in the EU. Global providers, particularly Stripe, may process data outside the EEA. Such transfers rely on a European Commission adequacy decision, Standard Contractual Clauses or another GDPR transfer mechanism. Information on the relevant safeguards may be requested through the privacy contact.

8. Retention

The following criteria and proposed periods apply:

  • enquiries that do not result in a contract — up to 12 months after contact ends;
  • account and operational data — for the contract and up to 30 days for export or closure;
  • tax and accounting records — for the legally required period, generally five years from the end of the relevant tax year under Polish law;
  • evidence of contract, acceptance and payments — until limitation periods expire, generally no more than six years;
  • support and complaints — while handled and up to three years after closure, longer if a dispute continues;
  • security and administrative logs — up to 12 months unless an incident requires longer preservation;
  • data processed for merchants — on their instructions; after termination, production data for up to 30 days and backups for up to 90 days through rotation;
  • consent-based data — until consent is withdrawn, followed only by records needed to demonstrate compliance or defend claims.

Data may be anonymised and used statistically where no person can be identified.

9. Individual rights

Subject to the GDPR, individuals may request:

  • access and a copy;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection to legitimate-interest processing, including direct marketing;
  • withdrawal of consent at any time;
  • information about international-transfer safeguards.

Requests may be sent to hello@syls.eu. We may ask for information reasonably needed to verify identity securely. Individuals may complain to the President of the Polish Personal Data Protection Office (uodo.gov.pl) or to the supervisory authority in the EU/EEA country of habitual residence, place of work or alleged infringement.

10. Automated decisions

SYLS does not make decisions based solely on automated processing that produce legal or similarly significant effects for users. Stripe may perform its own automated payment-risk assessment under its privacy information and legal obligations.

11. Security

We use safeguards appropriate to risk, including encryption in transit, access controls, Store-environment separation, patching, monitoring, administrative logs, backups and incident-response procedures. No system can guarantee absolute security; suspected incidents should be reported promptly to the contact address.

12. Children

The Service is intended for persons able to enter into a binding business or consumer contract and is not directed to children. Store merchants are responsible for assessing and implementing any rules that apply when their own Store targets or collects data from children.

13. Changes to this Policy

We may update this Policy when the law, Service, providers or processing change. The revision date will be shown at the top. Active Customers will be informed on a durable medium before a material change takes effect where the nature of the change requires it.