1. Data Controller
Snyxaronouax.world, operating the Vorexo brand, is the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and applicable national legislation.
We take our responsibilities seriously and are committed to handling your information with the highest standards of care and integrity. Our approach to data protection reflects our dedication to transparency and accountability.
Contact Information
Address: Frölunda Torg, 421 42 Västra Frölunda, Sweden
Country: Sweden
Email: admin@snyxaronouax.world
2. Purposes of Data Processing
We process your personal data only for specified, explicit, and legitimate purposes. Our processing activities include:
- Order fulfilment: Processing and fulfilling orders and inquiries submitted through our contact and order forms, including payment processing, shipping, and delivery coordination
- Customer communication: Communicating with you regarding your order status, delivery updates, and general customer support inquiries
- Legal compliance: Meeting our legal obligations including tax reporting, accounting requirements, and consumer protection laws
- Service improvement: Analysing website usage to improve our services, user experience, and product offerings (with your consent where required by law)
- Marketing: Sending marketing communications, newsletters, and promotional materials only where we have obtained your explicit consent
- Fraud prevention: Detecting and preventing fraudulent transactions and protecting the security of our platform
- Quality assurance: Conducting quality control and ensuring the integrity of our products and services
3. Legal Basis for Processing
Under the GDPR, we process your personal data only when we have a valid legal basis. Our processing relies on the following:
- Contract performance (Article 6(1)(b)): Processing necessary to enter into or perform a contract with you, such as processing orders and providing customer support
- Legitimate interests (Article 6(1)(f)): Processing necessary for our legitimate interests, including improving our services, fraud prevention, network security, and internal administrative purposes, where such interests are not overridden by your rights
- Consent (Article 6(1)(a)): Where you have given clear consent for specific processing activities, including marketing communications and non-essential cookies
- Legal obligation (Article 6(1)(c)): Processing required to comply with applicable laws, including tax and regulatory requirements
4. Categories of Data Collected
We collect only the data necessary for our stated purposes. The categories of personal data we may process include:
- Identity data: Name, title, and contact details provided when you place an order or get in touch
- Contact data: Email address, telephone number, and postal address for delivery and communication
- Transaction data: Details of purchases, payment information (processed securely by payment providers), and order history
- Technical data: IP address, browser type and version, device information, time zone, and operating system when you access our website
- Usage data: Information about how you use our website, including pages visited and interaction patterns
- Cookie data: As described in our Cookie Policy, including preference and analytics data where you have consented
- Communication data: Correspondence content when you contact us via email or contact forms
5. Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods include:
- Order and customer data: Up to seven years from the end of the financial year in which the transaction occurred, to comply with accounting and tax regulations
- Marketing data: Until you withdraw consent or opt out of marketing communications
- Analytics data: As specified in our Cookie Policy, typically up to 24 months
- Support correspondence: Up to three years after the resolution of your inquiry
- Website logs: Up to 12 months for security and operational purposes
- Legal claims: Where data may be relevant to legal proceedings, we may retain it for the duration of the claim and any applicable limitation periods
6. Your Rights (GDPR)
Under the GDPR, you have comprehensive rights regarding your personal data. These include:
- Right of access (Article 15): Request a copy of your personal data and information about how we process it
- Right to rectification (Article 16): Request correction of inaccurate or incomplete personal data
- Right to erasure (Article 17): Request deletion of your data in certain circumstances, subject to legal exceptions
- Right to restriction (Article 18): Request that we limit how we process your data in certain situations
- Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller
- Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes
- Right to withdraw consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal
- Right to lodge a complaint: Lodge a complaint with your supervisory authority; in Sweden, this is Integritetsskyddsmyndigheten (IMY)
To exercise any of these rights, please contact us at admin@snyxaronouax.world. We will respond within one month. We may need to verify your identity before processing your request.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
- Encryption of data in transit using TLS/HTTPS protocols
- Secure storage and access controls limiting data access to authorized personnel
- Regular security assessments and monitoring
- Staff training on data protection and confidentiality
- Incident response procedures for potential breaches
We do not sell your personal data to third parties. We share data only with trusted service providers who assist our operations under strict contractual obligations.
8. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). Where we do so, we ensure adequate safeguards are in place, including:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions by the European Commission where applicable
- Binding corporate rules for group entities
You may request information about the safeguards we use for international transfers by contacting us.
9. Children
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us and we will take steps to delete such information.
10. Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or our services. We will post the updated policy on this page and update the "Last updated" date. We encourage you to review this policy periodically. Material changes may be communicated via email where appropriate.