← Back to home

Your data

Privacy policy

This English version is provided for convenience only. The contract is concluded in French, and the French version alone is legally binding.

Last updated: 19 September 2026.

This page explains what personal data Sylorkey collects when you visit this site or place an order, why, how long it is kept, and what you can require of us. It is written to be read, not to hide behind jargon. If anything seems unclear, write to us and we will rephrase it.

1. WHO IS RESPONSIBLE FOR YOUR DATA

The data controller is:

SYLORKEY, a société par actions simplifiée à associé unique (a French simplified joint-stock company with a sole shareholder) with a share capital of 100 euros Registered office: 25 boulevard des Dames, 13002 Marseille, France RCS Marseille 989 266 549 — SIRET of the registered office 989 266 549 00017

Contact for any question about your personal data: contact@sylorkey.com, or by post to the registered office above.

Sylorkey has not appointed a data protection officer: the law does not require one for a company of this size whose activity rests neither on the systematic monitoring of individuals nor on the processing of sensitive data. Your requests are handled directly by the company's management.

2. WHAT DATA, WHY, ON WHAT BASIS, AND FOR HOW LONG

— HANDLING YOUR ORDER AND ITS DELIVERY Data: first name, last name, email address, delivery and billing address, country, telephone if you provide it, details of the items ordered, amount, order reference, and where applicable the moment you enter in the "For whom, for when?" field together with your message. Why: to record your order, acknowledge it, prepare and ship your Guardian, keep you informed of the schedule, send you your unique code and your access to the digital experience, and handle returns, withdrawals and complaints. Legal basis: performance of the contract of sale you enter into with us (article 6(1)(b) GDPR). This data is necessary: without it we cannot fulfil the order. Retention: for the whole duration of the commercial relationship, then in restricted-access archiving. The elements that make up the contract and its supporting documents are kept for ten years, on the terms set out in the next point. You may ask us at any time for a copy of the archived contract.

— INVOICING, ACCOUNTING AND ARCHIVING OF THE CONTRACT Data: identity, billing address, details and amount of the order, date, reference. Why: to issue your invoice, keep our accounts and retain the contract. Legal basis: compliance with legal obligations to which we are subject (article 6(1)(c) GDPR). Retention: ten years. Accounting records and supporting documents are kept for ten years under article L. 123-22 of the French Commercial Code. Where the amount of the contract reaches the threshold set by article D. 213-1 of the French Consumer Code, the electronic contract is additionally archived for ten years from delivery. These records are kept in our accounting system, with restricted access, and are no longer used for any other purpose.

— PAYMENT Data: amount, currency, date, transaction status, payment identifier, last four digits of the card. Sylorkey never sees, never receives and never keeps your full card number, its expiry date or its security code: the payment fields are provided and hosted by Stripe, and this information does not pass through our servers. Why: to collect the price of your order, and to handle refunds and payment disputes. Legal basis: performance of the contract (article 6(1)(b) GDPR). Retention: for as long as needed to follow up the order and keep our accounts. Data held by Stripe follows Stripe's own retention periods, set out in its own policy.

— PAYMENT FRAUD PREVENTION AND AUTOMATED DECISION-MAKING Data: technical elements relating to the transaction and to the device used, analysed by our payment provider. Why: to detect and block fraudulent payments. Legal basis: our legitimate interest in protecting the company and its customers against fraud (article 6(1)(f) GDPR), together with the legal obligations imposed on our payment provider. What you should know: this check is automated. A payment may be refused without human intervention, on the basis of a risk score calculated by our provider. If your payment is refused and you believe the refusal is unjustified, write to us at contact@sylorkey.com: we will carry out a human review of the situation. You may also object to this processing on grounds relating to your particular situation; we will then consider whether compelling legitimate grounds justify continuing it, bearing in mind that a card payment cannot in practice be accepted without fraud screening. Retention: according to our payment provider's rules.

— NEWSLETTER Data: email address, first name, date and time of your consent, exact wording of the box you ticked. Why: to send you our news, new Guardians and the opening of new worlds, if and only if you asked for it. Legal basis: your consent (article 6(1)(a) GDPR). You are never required to subscribe in order to place an order, and refusing has no effect whatsoever on your order. Retention: until you unsubscribe, and at most three years from your last contact with us. You may withdraw your consent at any time, with one click on the unsubscribe link in every message, or by writing to us. Withdrawal does not affect messages already sent.

— REPLYING TO YOUR MESSAGES AND AFTER-SALES SERVICE Data: whatever you send us in your message, and your email address. Why: to reply to you and keep a record of the exchange. Legal basis: performance of the contract where the message concerns an order; our legitimate interest in replying to those who write to us in other cases. Retention: three years from the last exchange, or the retention period of the order concerned if that is longer.

— WITHDRAWALS Data: name, first name, elements identifying the contract, electronic means of receiving the acknowledgement, time stamp of the declaration. Why: to process your withdrawal, send you the acknowledgement of receipt the law requires of us, and make the refund. Legal basis: compliance with a legal obligation (article 6(1)(c) GDPR). Retention: with the file of the order concerned.

— SITE SECURITY Data: IP address, time stamp of requests, technical information about the browser. Why: to limit automated submissions, block bots and attempted abuse, and keep the site working properly. Legal basis: our legitimate interest in protecting our site and our customers (article 6(1)(f) GDPR). Retention: a few minutes for the anti-spam counters, six months at most for the server's technical logs.

3. WHO HAS ACCESS TO YOUR DATA

Your data is neither sold, nor rented, nor exchanged. No one receives it for advertising purposes.

The following have access, strictly limited to what they need:

• STRIPE PAYMENTS EUROPE, LIMITED (Ireland) — card payment processing. See section 4. • Hostinger International Ltd, 61 Lordou Vironos Street, 6023 Larnaca, Chypre — hosting of the site and of order data (data centre: Lithuania, European Union).

Finally, your data may be disclosed to administrative or judicial authorities where a legal provision requires us to do so.

4. CARD PAYMENT: STRIPE'S ROLE

Payments on this site are processed by Stripe. For a merchant established in the European Economic Area, the contracting entity is STRIPE PAYMENTS EUROPE, LIMITED, a company incorporated under Irish law and established in Dublin.

Stripe acts in two distinct capacities, and it matters that you know it:

1) As a PROCESSOR for Sylorkey, when it carries out on our behalf the payment you requested. In that capacity Stripe acts on our instructions, on the terms of its data processing agreement.

2) As an INDEPENDENT CONTROLLER, for its own purposes: fraud prevention, compliance with its legal obligations on anti-money laundering and knowing its customers, compliance with card network rules, and improving its services. In that capacity Stripe alone determines the purposes and means of the processing, and Sylorkey has no control over it.

To find out how Stripe processes your data in that second capacity, see its privacy policy at stripe.com/privacy and its privacy centre at stripe.com/legal/privacy-center.

We say it again because it is the question we are asked most often: Sylorkey never has access to your card number.

5. TRANSFERS OUTSIDE THE EUROPEAN UNION

The site's hosting and the sending of our emails take place in France. No transfer outside the Union is planned for this processing.

Only payment may give rise to a transfer of data to the United States, since Stripe has its parent company and part of its infrastructure there. That transfer is framed by two cumulative mechanisms provided for in Chapter V GDPR:

You may obtain a copy of the safeguards in place by writing to us.

6. COOKIES AND OTHER TRACKERS

This site uses no advertising cookies, no social network cookies, and no audience measurement tool. We do not track your browsing and we share nothing with advertising networks. The site's fonts are served from our own domain: no request is made to a third party when you view a page.

We use your browser's local storage to remember your basket from one page to the next and from one visit to the next. That information stays on your device, is not sent to us, and you can erase it by clearing your browser's site data.

We also set a single cookie, named sylorkey_langue, which remembers the language you chose to read the site in, so as to bring you back to it on your next visit. It contains only "fr" or "en", is never read by code running in your browser, and serves no audience measurement purpose.

Remembering a shopping basket and remembering a language preference are among the trackers expressly exempted from consent by the CNIL under article 82 of the French Data Protection Act: that is why this site does not impose a cookie banner on you.

Payment takes place on a page hosted by Stripe. The trackers needed for the security of the transaction are set there on Stripe's domain and under its responsibility, not ours.

If we ever installed an audience measurement tool or any other tracker that is not strictly necessary, we would obtain your consent beforehand, and refusing would be as simple as accepting.

7. MINORS

This site is intended for adults. If you are under fifteen, subscribing to our newsletter requires the joint agreement of the holder of parental responsibility, in accordance with article 45 of the French Act of 6 January 1978 as amended. If we discover that an address was subscribed in those circumstances without that agreement, we remove it.

8. YOUR RIGHTS

You have the following rights over the data concerning you:

Exercising these rights is free of charge. Only if a request is manifestly unfounded or excessive, in particular because of its repetitive character, could we require a reasonable contribution towards costs or refuse to act on it, explaining why.

HOW TO EXERCISE THEM: write to us at contact@sylorkey.com, or by post to SYLORKEY, 25 boulevard des Dames, 13002 Marseille, France. State your request and, if you can, an order reference: it helps us identify you. We will only ask for proof of identity if reasonable doubt remains as to who you are.

We reply within one month of receiving your request. That period may be extended to three months if the request is complex or if we receive several from you; we would tell you within the first month, explaining why.

IF OUR REPLY DOES NOT SATISFY YOU, you may lodge a complaint with the French supervisory authority: Commission nationale de l'informatique et des libertés (CNIL) 3 place de Fontenoy — TSA 80715 — 75334 PARIS CEDEX 07 Telephone: +33 1 53 73 22 22 — www.cnil.fr

9. SECURITY

We take technical and organisational measures to protect your data: encryption of exchanges between your browser and the site, access to data limited to the people who need it and protected by authentication, hosting with a French provider, backups, and no storage of card data whatsoever on our side.

No system is invulnerable. Should a personal data breach likely to result in a high risk to your rights occur, we would notify the CNIL within seventy-two hours and inform you individually, as articles 33 and 34 GDPR require of us.

10. CHANGES TO THIS POLICY

We may update this policy, in particular when the site changes or a new provider is involved. The date of the last update appears at the top of the page. In the event of a substantial change affecting processing based on your consent, we will inform you and, if necessary, obtain fresh consent.