Last updated: September 2026
This Privacy Policy covers all online services operated by Tentacle Sync GmbH:
Website — tentaclesync.com, running on Statamic
Online shop — shop.tentaclesync.com, running on Odoo 19 on Odoo.sh
Support and knowledge base — support.tentaclesync.com, running on Zendesk
Newsletter — sent by email through Brevo, formerly Newsletter2Go
Where processing differs between these services, this is indicated in the relevant section.
The German version of this Privacy Policy is authoritative. This English text is provided for information; in case of discrepancies, the German version prevails.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Tentacle Sync GmbH, Wilhelm-Mauser-Strasse 55b, 50827 Cologne, Germany
Phone: +49 221 6778320 32
Email: info@tentaclesync.com
Managing Directors: Ulrich Esser, Maximilian Kaiser
Commercial register: Cologne Local Court, HRB 87105
VAT ID: DE305922358
We have appointed a Data Protection Officer, who can be reached independently of our other contact channels:
By email: privacy@tentaclesync.com
By post: Tentacle Sync GmbH, — Data Protection Officer —, Wilhelm-Mauser-Strasse 55b, 50827 Cologne, Germany
You may contact the Data Protection Officer directly at any time with questions about the processing of your data or to exercise your rights under section 20.
We process personal data only to the extent necessary to provide our websites, our online shop and our support, or where you have given consent.
The legal bases we rely on:
Art. 6(1)(a) GDPR — consent: newsletter, consent-based cookies, Google Maps
Art. 6(1)(b) GDPR — contract: order processing, customer account, support, returns
Art. 6(1)(c) GDPR — legal obligation: invoicing, commercial and tax retention, customs declarations
Art. 6(1)(f) GDPR — legitimate interests: IT security, fraud prevention, audience measurement, responding to enquiries
Recipients: where we pass data to service providers, we do so under a data processing agreement pursuant to Art. 28 GDPR; those providers act solely on our instructions. Payment and shipping providers additionally process part of the data under their own responsibility — this is noted in the relevant section. Beyond the recipients named in this policy, we do not disclose your data unless we are legally required to do so.
No automated decision-making: no automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Our payment provider’s fraud screening (section 12) may flag a payment for manual review, but does not replace a decision about entering into a contract.
Each time our services are accessed, our system automatically records:
IP address
date and time of access
page or file requested
volume of data transferred and HTTP status code
referrer URL
browser type, browser version and operating system
Purpose: delivering the pages, system stability, detecting and defending against attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in secure and uninterrupted operation.
Retention: log files are deleted after 30 days at the latest. Beyond that we retain them only where a specific security incident needs to be investigated.
Logging for the shop takes place on the Odoo.sh infrastructure (section 11) and for support at Zendesk (section 16).
Cookies that are not strictly necessary for operation are set only with your express consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). You may withdraw your consent at any time with effect for the future.
Strictly necessary cookies — no consent required (Section 25(2) no. 2 TDDDG):
CM_SESSIONID (website) — session management. Duration: session
INGRESSCOOKIE (website) — load balancing. Duration: session
i18n_redirected (website) — language preference. Duration: up to 12 months
cookie-banner and cookie-allow-necessary (website) — storing your cookie choice. Duration: up to 12 months
session_id (shop) — login and shopping cart. Duration: session
frontend_lang (shop) — language preference. Duration: up to 12 months
Consent-based cookies:
cookie-allow-tracking (website) — documenting your consent. Duration: up to 12 months
The shop uses the cookie notice built into Odoo. On the website, you manage your choice through our cookie banner. We ask for your consent before any consent-based service is loaded; you can change it at any time through the banner.
You can also delete or block cookies in your browser. If you block them entirely, the shopping cart and login in the shop will not work.
We use Umami to analyse how our website is used. Umami runs on our own infrastructure. No data is transferred to third parties and no transfer to third countries takes place.
Umami works without cookies and without identifiers that persist beyond the session. IP addresses are processed solely to derive anonymous metrics such as country and approximate region, and are not stored. The data collected does not allow individuals to be identified.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in designing our offering to meet demand. Because Umami neither sets cookies nor accesses information on your device, consent under Section 25 TDDDG is not required.
You may object to audience measurement at any time under Art. 21 GDPR — an informal message to privacy@tentaclesync.com is sufficient.
On individual pages we embed map material from Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The map loads only after you have given consent. When it loads, your IP address is transmitted to Google; a transfer to Google LLC in the United States cannot be ruled out. If you are logged into your Google account at the same time, Google may associate the request with your account.
Legal basis: Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
Google privacy notice: policies.google.com/privacy
Fonts are served from our own servers. No connection is made to Google Fonts or any other external font service.
Changed from the previous version: Google Analytics is no longer used and has been removed from this policy. Google Fonts are served locally; the earlier section on them has likewise been removed.
Our online shop at shop.tentaclesync.com is directed exclusively at entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB). Sections 10 to 15 below describe the processing connected with the shop.
We process:
company name and the contact person’s first and last name
billing and delivery address
email address and telephone number
VAT ID, where provided
order, payment and invoice data, and order history
for a customer account, additionally login credentials; passwords are stored solely as a cryptographic hash
Purposes: conclusion and performance of the contract, delivery, invoicing, customer service, handling of complaints and returns.
Legal basis: Art. 6(1)(b) GDPR; for invoicing and retention additionally Art. 6(1)(c) GDPR in conjunction with Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB).
A customer account is optional. You may have it deleted at any time; statutory retention periods for orders already completed remain unaffected (section 18).
The shop, order management and invoicing run on Odoo 19, operated on the Odoo.sh platform. The platform is operated by Odoo S.A., Chaussée de Namur 40, 1367 Grand-Rosière, Belgium.
Odoo processes on our behalf all order, customer and invoice data arising in the shop, including the server log files of the shop instance. A data processing agreement pursuant to Art. 28 GDPR is in place.
Data is processed exclusively in a data centre within the European Union. No transfer to a third country takes place for the operation of the shop.
Legal basis: Art. 6(1)(b) GDPR; for operational security and logging, Art. 6(1)(f) GDPR.
Odoo privacy notice: odoo.com/privacy
Depending on the payment method you choose, we pass the data required for processing to the payment service provider. We never collect, process or store full card numbers or comparable payment credentials — these are transmitted directly to the payment service provider.
Stripe for credit and debit card payments. The provider for the European Economic Area is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
Transmitted data includes name, billing address, email address and order and amount data
Stripe processes part of this data as an independent controller, in particular to meet anti-money-laundering and regulatory obligations and for fraud prevention
A transfer to Stripe, Inc., USA, cannot be ruled out
Privacy notice: stripe.com/privacy
PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
Transmitted data includes name, address, email address and order and amount data
PayPal is an independent controller for payment processing and may obtain a credit assessment
Privacy notice: paypal.com/uk/webapps/mpp/ua/privacy-full
Legal basis: Art. 6(1)(b) GDPR; for fraud prevention Art. 6(1)(f) GDPR; for anti-money-laundering checks Art. 6(1)(c) GDPR.
To deliver your order we transmit the recipient’s name and delivery address and — where required for tracking or delivery notification — email address and telephone number to the appointed carrier:
DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany. Privacy notice: dhl.de/de/privatkunden/hilfe-und-kontakt/datenschutz.html
FedEx Express Deutschland GmbH, Langer Kornweg 34 k, 65451 Kelsterbach, Germany; parent company: FedEx Corporation, USA. Privacy notice: fedex.com/en-de/trust-center/privacy-policy.html
For shipments to third countries we additionally transmit the information required for customs purposes to the competent customs and tax authorities.
Shipping data is handed over directly from our shop system; we do not use intermediate shipping software.
Legal basis: Art. 6(1)(b) GDPR; for customs declarations Art. 6(1)(c) GDPR.
For returns under our Return Policy we process the order number, product details, billing and shipping address, and the correspondence relating to the case.
Legal basis: Art. 6(1)(b) GDPR.
We pass invoice and payment data to our external tax advisory firm and to the tax authorities in order to meet our tax obligations.
Transmission to the firm takes place through the data centre services of DATEV eG, Paumgartnerstrasse 6-14, 90429 Nuremberg, Germany. DATEV eG processes the data on our instructions under a data processing agreement pursuant to Art. 28 GDPR in data centres located in Germany.
Legal basis: Art. 6(1)(c) GDPR.
DATEV eG privacy notice: datev.de/web/de/datev.de/datenschutz/
For a support request through support.tentaclesync.com we process your contact details, the content of your request and any subsequent correspondence, together with — where you provide them — details of your product and your order.
Our support runs on Zendesk. The provider for the European Economic Area is Zendesk International Ltd., 55 Charlemont Place, Saint Kevin’s, Dublin, D02 F985, Ireland; the parent company is Zendesk, Inc., USA.
Zendesk processes the data on our instructions under a data processing agreement pursuant to Art. 28 GDPR
Access by the US parent company in the course of support and maintenance cannot be ruled out; see section 19
The knowledge base can be read without signing in
If you create a support account, Zendesk additionally stores your login credentials and your ticket history
Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR as a legitimate interest in responding to enquiries.
Zendesk privacy notice: zendesk.com/company/agreements-and-terms/privacy-notice/
If you subscribe to our newsletter, we process your email address and any further details you provide voluntarily.
Double opt-in: after you sign up we send you a confirmation email. You are added to the distribution list only after you confirm. We log the time of sign-up, the time of confirmation and the IP address as evidence of consent.
The sending provider is Brevo, formerly Newsletter2Go. The contracting party is Sendinblue SAS, 9–17 rue Salneuve, 75017 Paris, France, registered with the Paris commercial register under 498 019 298, trading under the Brevo brand. Processing takes place on our instructions under a data processing agreement pursuant to Art. 28 GDPR on servers within the European Union.
Performance measurement: where you have consented, we analyse whether a message was opened and which links were clicked, in order to align the newsletter with recipients’ interests.
Legal basis: Art. 6(1)(a) GDPR. For existing customers we base sending in respect of our own similar goods in the alternative on Section 7(3) UWG in conjunction with Art. 6(1)(f) GDPR.
Unsubscribing is possible at any time via the link in every email or informally to privacy@tentaclesync.com. Withdrawal does not affect the lawfulness of processing carried out up to that point. After you unsubscribe we retain the record of consent as evidence and add your address to a suppression list so that you receive no further messages.
Brevo privacy notice: brevo.com/legal/privacypolicy/
We store personal data only for as long as required for the relevant purpose or for as long as statutory retention obligations apply.
Server log files — 30 days
Accounting records and invoices — 8 years under Section 147(3) AO and Section 257(4) HGB as amended by the Fourth Bureaucracy Relief Act
Commercial and business correspondence and contract documents — 6 years under Section 147(3) AO and Section 257(4) HGB
Customer account in the shop — until you delete it; the periods above apply thereafter
Support tickets — 36 months after the case is closed, matching the standard limitation period under Section 195 BGB
Contact enquiries without contractual relevance — deleted once the matter has been fully dealt with
Newsletter data — until withdrawal; record of consent and suppression-list entry are kept beyond that
Cookie choices — see section 5
Statutory periods begin at the end of the calendar year in which the transaction was completed. Where data is retained solely because a retention period is still running, we otherwise restrict its processing (Art. 18 GDPR).
Our contractual partners for shop operation, payment, shipping, support and the newsletter are companies established in the European Union. For some services, access by group companies established in the United States nonetheless cannot be entirely ruled out — this concerns Stripe, FedEx, Zendesk and Google.
Where a transfer to a third country without an adequacy decision takes place, we base it on the European Commission’s Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR and have agreed supplementary technical and organisational safeguards. We have carried out a Transfer Impact Assessment for the processing operations concerned.
On the EU-US Data Privacy Framework: the European Commission’s adequacy decision of 10 July 2023 formally remains in force. Its durability has, however, been legally contested since the US Supreme Court’s ruling in Trump v. Slaughter of 29 June 2026, which calls into question the underlying assumption of an independent Federal Trade Commission. As a precaution we therefore base third-country transfers primarily on Standard Contractual Clauses and are monitoring further developments.
Despite these measures, access by US authorities under surveillance legislation there cannot be excluded with absolute certainty. We expressly draw your attention to this residual risk.
Changed from the previous version: the reference to the EU-US Privacy Shield has been removed. It was declared invalid by the Court of Justice of the European Union on 16 July 2020 in Schrems II, C-311/18, and is no longer a valid basis for third-country transfers.
You have the following rights against us:
Access under Art. 15 GDPR to the data we process about you
Rectification under Art. 16 GDPR of inaccurate or incomplete data
Erasure under Art. 17 GDPR, where no retention obligation applies
Restriction of processing under Art. 18 GDPR
Data portability under Art. 20 GDPR in a structured, commonly used, machine-readable format
Objection under Art. 21 GDPR to processing based on Art. 6(1)(f) GDPR
Withdrawal of consent given under Art. 7(3) GDPR, at any time with effect for the future
An informal message to privacy@tentaclesync.com is sufficient. We respond within one month; if that period is exceptionally extended, we will tell you.
Right to lodge a complaint: you may also complain to a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestrasse 2–4, 40213 Düsseldorf, Germany, ldi.nrw.de
We implement technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. Transmission across all our services is encrypted throughout using TLS. Within our company, access to personal data is limited to those who need it for the purposes described.
To conclude a contract through our shop we need the data listed in section 10. Without it we cannot process your order. All other details are voluntary.
We update this policy when the legal situation, our services or the nature of our processing changes. The version published on our websites at the relevant time applies.
The German version of this Privacy Policy is authoritative. This English translation is provided for information; in case of discrepancies, the German text prevails.
© 2026 Tentacle Sync. Cologne, Germany