Privacy policy
Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
E.Syla, trading as ESTK
Gutenbergstrasse 7
4052 Ansfelden
Austria
Email: info@estkshop.com
Telephone: +43 677 624 36241
2. Principles and legal bases of processing
We process personal data only where a legal basis exists, in particular to take steps before entering into a contract and to perform a contract (Article 6(1)(b) GDPR), to comply with legal obligations (Article 6(1)(c) GDPR), on the basis of legitimate interests (Article 6(1)(f) GDPR), or on the basis of consent (Article 6(1)(a) GDPR).
We limit processing to the data required, protect it through appropriate technical and organisational measures, and retain it no longer than necessary for the relevant purpose or to comply with legal obligations.
3. Accessing the shop and technical log data
When the shop is accessed, technically necessary data may be processed, including the IP address, date and time, pages accessed, referrer URL, browser, device and operating-system information, language settings, and error and security logs.
Processing is carried out to operate the shop securely and reliably, analyse errors, prevent misuse, and provide its technical functions. The legal basis is our legitimate interest in a secure and functional online offering (Article 6(1)(f) GDPR), unless another legal basis applies.
4. Shopify
Our shop is operated through Shopify. Within the European Economic Area, Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, is generally involved. Shopify processes customer data for the shop, hosting, checkout, security, and support functions provided, partly as our processor and, for certain additional services, as an independent controller.
Data may be transferred within the Shopify group and to subprocessors outside the EEA, in particular in Canada and the United States. Shopify identifies, among other safeguards, binding corporate rules, standard contractual clauses, and, where applicable, adequacy decisions as transfer mechanisms.
Further information is available at https://www.shopify.com/legal/privacy and https://www.shopify.com/legal/dpa. If Shopify Network Intelligence or Enhanced Services is enabled, this Privacy Policy must be supplemented with Shopify's then-current required disclosures and the Customer Privacy configuration must be adjusted accordingly.
5. Orders, contract performance, and customer accounts
When an order is placed, we process in particular the customer's name, billing and delivery address, email address, telephone number, order and product data, payment status, shipping and tracking data, communications, and, where applicable, tax and customs information.
Processing is necessary to accept the order, process payment and delivery, send order confirmations, handle returns and complaints, prevent fraud, and maintain legally required records. The legal bases are Article 6(1)(b) and (c) GDPR and, for security and misuse checks, Article 6(1)(f) GDPR.
Where a customer account is offered and created voluntarily, we process login details, contact details, and order history to provide the account. The account may be deleted subject to statutory retention requirements.
6. Payment processing
For payment processing, we transmit the required data to the payment service provider selected at checkout. That provider may process data under its own responsibility for payment authorisation, fraud prevention, and compliance with its own legal obligations. As a rule, we do not receive full credit-card or bank-access details, but receive payment status and transaction references.
SHOPIFY PAYMENTS / STRIPE, KLARNA, APPLE PAY, GOOGLE PAY, SHOP PAY, EPS, CREDIT-CARD. The respective privacy notices are provided at checkout or by the payment provider.
7. Shipping, fulfilment, and direct shipping
For delivery, we provide necessary recipient, contact, order, and shipping data to carriers, warehouse operators, and fulfilment partners. The legal basis is performance of the contract under Article 6(1)(b) GDPR.
For identified direct shipping, a supply or fulfilment partner outside the EEA, particularly in China, may receive the recipient's name, delivery address, telephone number, email address, ordered products, and delivery instructions. Transfers are limited to what is necessary.
Where no adequacy decision applies to the recipient country, appropriate safeguards under Article 46 GDPR - generally EU Standard Contractual Clauses together with an assessment of supplementary safeguards - or another valid legal basis must be used.
8. Contact, support, complaints, and withdrawal
When you contact us by email, telephone, form, or an available online withdrawal function, we process the information provided to respond to the enquiry, handle the relevant rights, and document the communication.
Depending on the matter, the legal basis is Article 6(1)(b), (c), or (f) GDPR. When the online withdrawal function is used, we process in particular the customer's name, contract or order identifier, preferred electronic means of communication, and the content, date, and time of the statement, and we send an acknowledgement of receipt.
9. Newsletters and direct marketing
As a rule, we send newsletters and promotional emails only with consent or where a statutory exception applies to an existing customer relationship. Where consent is used, the email address, subscription time, confirmation status, language, and interaction data may be processed.
Consent may be withdrawn at any time through the unsubscribe link or by contacting info@estkshop.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
10. Product reviews and user-generated content
Where reviews, photographs, or other contributions are submitted voluntarily, we process the submitted content, display name, product reference, and technical evidence for publication, moderation, and prevention of misuse. The legal basis is Article 6(1)(b) or (f) GDPR; consent is obtained where required.
11. Cookies and similar technologies
We use technically necessary cookies and similar storage or access technologies so that the shop, cart, checkout, security features, language settings, and consent management function properly. Where access is strictly necessary for a service expressly requested by the user, it is carried out without separate consent in accordance with applicable law; the subsequent processing of personal data is based on the appropriate GDPR legal basis.
Analytics, personalisation, and marketing technologies are generally activated in the EEA only after voluntary consent. Choices can be changed at any time through "Cookie Settings" in the footer. Withdrawal applies for the future.
The cookie banner must control the technologies actually used. Manually installed scripts or apps must not load before consent where consent is required.
12. Analytics and marketing
SHOPIFY ANALYTICS, GOOGLE ANALYTICS 4, GOOGLE ADS, META PIXEL / CONVERSIONS API.
Where these services are used, online identifiers, cookie IDs, IP and device information, page views, cart and purchase events, and campaign attribution may be processed. Non-essential analytics and marketing processing takes place only with consent (Article 6(1)(a) GDPR) and can be withdrawn through Cookie Settings.
Appropriate transfer mechanisms and, where necessary, supplementary safeguards are required for recipients in third countries. The specific providers, purposes, categories of data, retention periods, and transfer grounds must be added in accordance with the shop's actual configuration.
13. Fraud prevention and security
To identify abusive orders, payment fraud, account takeovers, and technical attacks, order data, payment status, device, network, and risk data may be analysed and compared with information held by payment or security providers.
The legal basis is our legitimate interest in preventing fraud and protecting customers and the business (Article 6(1)(f) GDPR) and, where applicable, compliance with legal obligations. Decisions producing legal or similarly significant effects are not made solely by automated means unless the requirements of Article 22 GDPR are met.
14. Categories of recipients
Data is received only by parties that require it for the relevant purpose. These may include Shopify and its subprocessors, payment providers, banks, carriers, warehouse and fulfilment partners, direct-shipping suppliers, IT and security providers, newsletter, analytics and marketing providers, tax advisers, legal advisers, insurers, and public authorities or courts to the extent required by law.
We enter into the required agreements under Article 28 GDPR with processors. Independent controllers process data in accordance with their own legal obligations.
15. Transfers to third countries
Where data is processed outside the EEA, we assess whether an adequacy decision applies or whether appropriate safeguards, such as EU Standard Contractual Clauses, can be used. Where required, we assess the level of protection and supplementary technical or organisational measures. Copies of relevant safeguards may be requested at [[ESTK EMAIL ADDRESS]] to the extent legally permissible.
16. Retention periods
We retain data only for as long as required for the relevant purpose. Due to Austrian statutory retention obligations, order, invoice, and accounting records are generally retained for seven years from the end of the relevant calendar year. Longer retention may be necessary for pending proceedings or specific legal obligations.
Communication and complaint data is retained while the matter is handled and thereafter for the relevant warranty and limitation periods. Evidence of consent is retained for as long as required to demonstrate compliance. Following withdrawal, newsletter data is removed from active mailing lists unless evidence must be retained.
Specific retention periods for cookies and providers are stated in Cookie Settings and in the notices of the services used.
17. Rights of data subjects
Subject to the statutory requirements, data subjects have the right of access, rectification, erasure, restriction of processing, data portability, and objection. Consent may be withdrawn at any time with effect for the future.
Requests may be sent to info@estkshop.com. To prevent unauthorised disclosure, we may request appropriate proof of identity. Requests are generally handled within one month; the legally permitted extension for complex or numerous requests remains reserved.
18. Right to lodge a complaint
Data subjects may lodge a complaint with a data-protection supervisory authority. In Austria, the competent authority is: Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, email: dsb@dsb.gv.at, https://www.dsb.gv.at.
19. Minors
Our shop is not specifically directed at children. Where special age limits apply to consent-based processing, we obtain the required consent from a person with parental responsibility or refrain from carrying out the processing.
20. Changes to this Privacy Policy
We update this Privacy Policy when the legal position, shop functions, providers, or processing activities change. The version published in the shop is authoritative. Version: 23 July 2026.