Logo

Privacy Policy

Last updated: September 2026

This Privacy Policy covers all online services operated by Tentacle Sync GmbH:

  • Website — tentaclesync.com, running on Statamic

  • Online shop — shop.tentaclesync.com, running on Odoo 19 on Odoo.sh

  • Support and knowledge base — support.tentaclesync.com, running on Zendesk

  • Newsletter — sent by email through Brevo, formerly Newsletter2Go

Where processing differs between these services, this is indicated in the relevant section.

The German version of this Privacy Policy is authoritative. This English text is provided for information; in case of discrepancies, the German version prevails.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Tentacle Sync GmbH, Wilhelm-Mauser-Strasse 55b, 50827 Cologne, Germany

  • Phone: +49 221 6778320 32

  • Email: info@tentaclesync.com

  • Managing Directors: Ulrich Esser, Maximilian Kaiser

  • Commercial register: Cologne Local Court, HRB 87105

  • VAT ID: DE305922358

2. Data Protection Officer

We have appointed a Data Protection Officer, who can be reached independently of our other contact channels:

  • By email: privacy@tentaclesync.com

  • By post: Tentacle Sync GmbH, — Data Protection Officer —, Wilhelm-Mauser-Strasse 55b, 50827 Cologne, Germany

You may contact the Data Protection Officer directly at any time with questions about the processing of your data or to exercise your rights under section 20.

3. Principles of Our Processing

We process personal data only to the extent necessary to provide our websites, our online shop and our support, or where you have given consent.

The legal bases we rely on:

  • Art. 6(1)(a) GDPR — consent: newsletter, consent-based cookies, Google Maps

  • Art. 6(1)(b) GDPR — contract: order processing, customer account, support, returns

  • Art. 6(1)(c) GDPR — legal obligation: invoicing, commercial and tax retention, customs declarations

  • Art. 6(1)(f) GDPR — legitimate interests: IT security, fraud prevention, audience measurement, responding to enquiries

Recipients: where we pass data to service providers, we do so under a data processing agreement pursuant to Art. 28 GDPR; those providers act solely on our instructions. Payment and shipping providers additionally process part of the data under their own responsibility — this is noted in the relevant section. Beyond the recipients named in this policy, we do not disclose your data unless we are legally required to do so.

No automated decision-making: no automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Our payment provider’s fraud screening (section 12) may flag a payment for manual review, but does not replace a decision about entering into a contract.

4. Website Delivery and Server Log Files

Each time our services are accessed, our system automatically records:

  • IP address

  • date and time of access

  • page or file requested

  • volume of data transferred and HTTP status code

  • referrer URL

  • browser type, browser version and operating system

Purpose: delivering the pages, system stability, detecting and defending against attacks.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in secure and uninterrupted operation.

Retention: log files are deleted after 30 days at the latest. Beyond that we retain them only where a specific security incident needs to be investigated.

Logging for the shop takes place on the Odoo.sh infrastructure (section 11) and for support at Zendesk (section 16).

5. Cookies and Similar Technologies

Cookies that are not strictly necessary for operation are set only with your express consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). You may withdraw your consent at any time with effect for the future.

Strictly necessary cookies — no consent required (Section 25(2) no. 2 TDDDG):

  • CM_SESSIONID (website) — session management. Duration: session

  • INGRESSCOOKIE (website) — load balancing. Duration: session

  • i18n_redirected (website) — language preference. Duration: up to 12 months

  • cookie-banner and cookie-allow-necessary (website) — storing your cookie choice. Duration: up to 12 months

  • session_id (shop) — login and shopping cart. Duration: session

  • frontend_lang (shop) — language preference. Duration: up to 12 months

Consent-based cookies:

  • cookie-allow-tracking (website) — documenting your consent. Duration: up to 12 months

The shop uses the cookie notice built into Odoo. On the website, you manage your choice through our cookie banner. We ask for your consent before any consent-based service is loaded; you can change it at any time through the banner.

You can also delete or block cookies in your browser. If you block them entirely, the shopping cart and login in the shop will not work.

6. Audience Measurement with Umami

We use Umami to analyse how our website is used. Umami runs on our own infrastructure. No data is transferred to third parties and no transfer to third countries takes place.

Umami works without cookies and without identifiers that persist beyond the session. IP addresses are processed solely to derive anonymous metrics such as country and approximate region, and are not stored. The data collected does not allow individuals to be identified.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in designing our offering to meet demand. Because Umami neither sets cookies nor accesses information on your device, consent under Section 25 TDDDG is not required.

You may object to audience measurement at any time under Art. 21 GDPR — an informal message to privacy@tentaclesync.com is sufficient.

7. Google Maps

On individual pages we embed map material from Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The map loads only after you have given consent. When it loads, your IP address is transmitted to Google; a transfer to Google LLC in the United States cannot be ruled out. If you are logged into your Google account at the same time, Google may associate the request with your account.

Legal basis: Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Google privacy notice: policies.google.com/privacy

8. Fonts

Fonts are served from our own servers. No connection is made to Google Fonts or any other external font service.

Changed from the previous version: Google Analytics is no longer used and has been removed from this policy. Google Fonts are served locally; the earlier section on them has likewise been removed.

9. Online Shop — Scope

Our online shop at shop.tentaclesync.com is directed exclusively at entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB). Sections 10 to 15 below describe the processing connected with the shop.

10. Orders and Customer Account

We process:

  • company name and the contact person’s first and last name

  • billing and delivery address

  • email address and telephone number

  • VAT ID, where provided

  • order, payment and invoice data, and order history

  • for a customer account, additionally login credentials; passwords are stored solely as a cryptographic hash

Purposes: conclusion and performance of the contract, delivery, invoicing, customer service, handling of complaints and returns.

Legal basis: Art. 6(1)(b) GDPR; for invoicing and retention additionally Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).

A customer account is optional. You may have it deleted at any time; statutory retention periods for orders already completed remain unaffected (section 18).

11. Shop Operation

The shop, order management and invoicing run on Odoo 19, operated on the Odoo.sh platform. The platform is operated by Odoo S.A., Chaussée de Namur 40, 1367 Grand-Rosière, Belgium.

Odoo processes on our behalf all order, customer and invoice data arising in the shop, including the server log files of the shop instance. A data processing agreement pursuant to Art. 28 GDPR is in place.

Data is processed exclusively in a data centre within the European Union. No transfer to a third country takes place for the operation of the shop.

Legal basis: Art. 6(1)(b) GDPR; for operational security and logging, Art. 6(1)(f) GDPR.

Odoo privacy notice: odoo.com/privacy

12. Payment Processing

Depending on the payment method you choose, we pass the data required for processing to the payment service provider. We never collect, process or store full card numbers or comparable payment credentials — these are transmitted directly to the payment service provider.

Stripe for credit and debit card payments. The provider for the European Economic Area is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.

  • Transmitted data includes name, billing address, email address and order and amount data

  • Stripe processes part of this data as an independent controller, in particular to meet anti-money-laundering and regulatory obligations and for fraud prevention

  • A transfer to Stripe, Inc., USA, cannot be ruled out

  • Privacy notice: stripe.com/privacy

PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

  • Transmitted data includes name, address, email address and order and amount data

  • PayPal is an independent controller for payment processing and may obtain a credit assessment

  • Privacy notice: paypal.com/uk/webapps/mpp/ua/privacy-full

Legal basis: Art. 6(1)(b) GDPR; for fraud prevention Art. 6(1)(f) GDPR; for anti-money-laundering checks Art. 6(1)(c) GDPR.

13. Shipping

To deliver your order we transmit the recipient’s name and delivery address and — where required for tracking or delivery notification — email address and telephone number to the appointed carrier:

  • DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany. Privacy notice: dhl.de/de/privatkunden/hilfe-und-kontakt/datenschutz.html

  • FedEx Express Deutschland GmbH, Langer Kornweg 34 k, 65451 Kelsterbach, Germany; parent company: FedEx Corporation, USA. Privacy notice: fedex.com/en-de/trust-center/privacy-policy.html

For shipments to third countries we additionally transmit the information required for customs purposes to the competent customs and tax authorities.

Shipping data is handed over directly from our shop system; we do not use intermediate shipping software.

Legal basis: Art. 6(1)(b) GDPR; for customs declarations Art. 6(1)(c) GDPR.

14. Returns

For returns under our Return Policy we process the order number, product details, billing and shipping address, and the correspondence relating to the case.

Legal basis: Art. 6(1)(b) GDPR.

15. Accounting and Tax

We pass invoice and payment data to our external tax advisory firm and to the tax authorities in order to meet our tax obligations.

Transmission to the firm takes place through the data centre services of DATEV eG, Paumgartnerstrasse 6-14, 90429 Nuremberg, Germany. DATEV eG processes the data on our instructions under a data processing agreement pursuant to Art. 28 GDPR in data centres located in Germany.

Legal basis: Art. 6(1)(c) GDPR.

DATEV eG privacy notice: datev.de/web/de/datev.de/datenschutz/

16. Support and Knowledge Base

For a support request through support.tentaclesync.com we process your contact details, the content of your request and any subsequent correspondence, together with — where you provide them — details of your product and your order.

Our support runs on Zendesk. The provider for the European Economic Area is Zendesk International Ltd., 55 Charlemont Place, Saint Kevin’s, Dublin, D02 F985, Ireland; the parent company is Zendesk, Inc., USA.

  • Zendesk processes the data on our instructions under a data processing agreement pursuant to Art. 28 GDPR

  • Access by the US parent company in the course of support and maintenance cannot be ruled out; see section 19

  • The knowledge base can be read without signing in

  • If you create a support account, Zendesk additionally stores your login credentials and your ticket history

Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR as a legitimate interest in responding to enquiries.

Zendesk privacy notice: zendesk.com/company/agreements-and-terms/privacy-notice/

17. Newsletter

If you subscribe to our newsletter, we process your email address and any further details you provide voluntarily.

Double opt-in: after you sign up we send you a confirmation email. You are added to the distribution list only after you confirm. We log the time of sign-up, the time of confirmation and the IP address as evidence of consent.

The sending provider is Brevo, formerly Newsletter2Go. The contracting party is Sendinblue SAS, 9–17 rue Salneuve, 75017 Paris, France, registered with the Paris commercial register under 498 019 298, trading under the Brevo brand. Processing takes place on our instructions under a data processing agreement pursuant to Art. 28 GDPR on servers within the European Union.

Performance measurement: where you have consented, we analyse whether a message was opened and which links were clicked, in order to align the newsletter with recipients’ interests.

Legal basis: Art. 6(1)(a) GDPR. For existing customers we base sending in respect of our own similar goods in the alternative on Section 7(3) UWG in conjunction with Art. 6(1)(f) GDPR.

Unsubscribing is possible at any time via the link in every email or informally to privacy@tentaclesync.com. Withdrawal does not affect the lawfulness of processing carried out up to that point. After you unsubscribe we retain the record of consent as evidence and add your address to a suppression list so that you receive no further messages.

Brevo privacy notice: brevo.com/legal/privacypolicy/

18. Retention Periods

We store personal data only for as long as required for the relevant purpose or for as long as statutory retention obligations apply.

  • Server log files — 30 days

  • Accounting records and invoices — 8 years under Section 147(3) AO and Section 257(4) HGB as amended by the Fourth Bureaucracy Relief Act

  • Commercial and business correspondence and contract documents — 6 years under Section 147(3) AO and Section 257(4) HGB

  • Customer account in the shop — until you delete it; the periods above apply thereafter

  • Support tickets — 36 months after the case is closed, matching the standard limitation period under Section 195 BGB

  • Contact enquiries without contractual relevance — deleted once the matter has been fully dealt with

  • Newsletter data — until withdrawal; record of consent and suppression-list entry are kept beyond that

  • Cookie choices — see section 5

Statutory periods begin at the end of the calendar year in which the transaction was completed. Where data is retained solely because a retention period is still running, we otherwise restrict its processing (Art. 18 GDPR).

19. Transfers to Third Countries

Our contractual partners for shop operation, payment, shipping, support and the newsletter are companies established in the European Union. For some services, access by group companies established in the United States nonetheless cannot be entirely ruled out — this concerns Stripe, FedEx, Zendesk and Google.

Where a transfer to a third country without an adequacy decision takes place, we base it on the European Commission’s Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and have agreed supplementary technical and organisational safeguards. We have carried out a Transfer Impact Assessment for the processing operations concerned.

On the EU-US Data Privacy Framework: the European Commission’s adequacy decision of 10 July 2023 formally remains in force. Its durability has, however, been legally contested since the US Supreme Court’s ruling in Trump v. Slaughter of 29 June 2026, which calls into question the underlying assumption of an independent Federal Trade Commission. As a precaution we therefore base third-country transfers primarily on Standard Contractual Clauses and are monitoring further developments.

Despite these measures, access by US authorities under surveillance legislation there cannot be excluded with absolute certainty. We expressly draw your attention to this residual risk.

Changed from the previous version: the reference to the EU-US Privacy Shield has been removed. It was declared invalid by the Court of Justice of the European Union on 16 July 2020 in Schrems II, C-311/18, and is no longer a valid basis for third-country transfers.

20. Your Rights

You have the following rights against us:

  • Access under Art. 15 GDPR to the data we process about you

  • Rectification under Art. 16 GDPR of inaccurate or incomplete data

  • Erasure under Art. 17 GDPR, where no retention obligation applies

  • Restriction of processing under Art. 18 GDPR

  • Data portability under Art. 20 GDPR in a structured, commonly used, machine-readable format

  • Objection under Art. 21 GDPR to processing based on Art. 6(1)(f) GDPR

  • Withdrawal of consent given under Art. 7(3) GDPR, at any time with effect for the future

An informal message to privacy@tentaclesync.com is sufficient. We respond within one month; if that period is exceptionally extended, we will tell you.

Right to lodge a complaint: you may also complain to a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestrasse 2–4, 40213 Düsseldorf, Germany, ldi.nrw.de

21. Data Security

We implement technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. Transmission across all our services is encrypted throughout using TLS. Within our company, access to personal data is limited to those who need it for the purposes described.

22. Obligation to Provide Data

To conclude a contract through our shop we need the data listed in section 10. Without it we cannot process your order. All other details are voluntary.

23. Changes to This Privacy Policy

We update this policy when the legal situation, our services or the nature of our processing changes. The version published on our websites at the relevant time applies.

The German version of this Privacy Policy is authoritative. This English translation is provided for information; in case of discrepancies, the German text prevails.