Privacy Policy
Updated: July 6 2020
By visiting synthesisretreat.com (“Site”), you consent to the following Privacy Policy.
Overview
Synthesis Institute B.V. (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy online. This Privacy Policy applies to any services, material, content, or resources made available through the Site (collectively, the “Services”).
This Privacy Policy describes the personal data that we collect through the Site, and how we collect and use that data. The term “personal data” means data that you voluntarily provide to us that personally identifies you or pieces of data that collectively can lead to the identification of a particular person including, but not limited to, first and last name, phone number, email address, mailing address, location data, or online identifiers, including an Internet protocol (“IP”) address or cookies. Synthesis Institute B.V. processes personal data as a “data controller” as that term is defined in the General Data Protection Regulation 2016/679 (“GDPR”).
Use of synthesisretreat.com, including all materials presented herein and all online Services provided by Synthesis Institute B.V., is subject to the following Privacy Policy. This Privacy Policy applies to all site visitors, customers, and all other users of the Site. By using the Site or Services, you agree to this Privacy Policy, without modification, and acknowledge reading it.
About Us
Synthesis Institute B.V. (henceforth, “Owner”) is a provider of retreat experiences involving the use of psychotropic substances, including psilocybin containing truffles, provided by legal smartshops in the Netherlands. We care about protecting the personal information of our customers and visitors who use our website, products or services (collectively, our “Users”).
If you have any questions about this privacy policy or the practices described herein, you may contact support@synthesisretreat.com or Synthesis Institute B.V., Korte Leidsedwarsstraat 12, 1017 RC Amsterdam, The Netherlands.
Data Protection Officer
Synthesis Institute B.V. has appointed a data protection officer that you may contact with any questions or concerns about our personal data practices or policies. The data protection officer’s name and contact information are:
Martijn Schirp
Synthesis Institute B.V.
Korte Leidsedwarsstraat 12
1017 RC Amsterdam
Netherlands
Information Covered By This Privacy Policy
Our Privacy Policy was posted in August 2018 and last updated on July 6 2020. It governs the privacy terms of our website, located at https://synthesisretreat.com, and the tools we provide you (the "Website" or the "Services"). Any capitalized terms not defined in our Privacy Policy, have the meaning as specified in our Terms of Service accessible at https://synthesisretreat.com/terms-conditions/. This privacy policy covers personal information, including any information we collect, use and share from you, as described further below. When you purchase a Service from us, your personal information will be collected, used, and shared consistent with the provisions of this privacy policy.
Your Privacy
Our Website follows all legal requirements to protect your privacy. Our Privacy Policy is a legal statement that explains how we may collect information from you, how we may share your information, and how you can limit our sharing of your information. You will see terms in our Privacy Policy that are capitalized. These terms have meanings as described in the Definitions section below.
Definitions
Personal Data:
Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
Usage Data:
Information collected automatically through this Website (or third-party services employed in this Website), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Website) and the details about the path followed within the Website with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
Cookies:
Cookies are small pieces of data stored on a User's device.
Data Controller:
Data Controller means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data.
Data Processors (or Service Providers):
Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
Data Subject:
Data Subject is any living individual who is the subject of Personal Data.
User:
The User is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.
This Website:
The means by which the Personal Data of the User is collected and processed.
Information Collection And Use
We collect several different types of information for various purposes to provide and improve our Service to you.
Types of Data Collected:
Personal Data
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to: Email address, Name, Address, State, Province, ZIP/Postal code, City, Cookies and Usage Data.
We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.
Usage Data
We may also collect information about how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (i.e. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
Tracking & Cookies Data
We use cookies and similar tracking technologies to track the activity and to improve the quality of our Service and hold certain information.
Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
Examples of Cookies we use: session cookies (we use these cookies to operate our Service) and preference cookies (we use these cookies to remember your preferences and various settings).
Social Media
We collect information from third party social networking sites, including information that social networking sites provide to us if you use your credentials at such social networking sites to opt in for some of our Services (such as your name and email address to pre-populate our sign-up form). The information you allow us to access varies by social networking site, and depends on the level of privacy settings you have in place at the social networking site. You can control and find out more about these privacy settings at the applicable social networking site. We are not responsible for the privacy policies or practices of third party social networking sites.
MODE AND PLACE OF PROCESSING THE DATA:
Methods of processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this website (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Legal basis of processing
The Owner may process Personal Data relating to Users if one of the following applies:
-
Users have given their consent for one or more specific purposes. Note: In some jurisdictions, the Owner may be allowed to process Personal Data until the User objects to such processing (“opt-out”), without having to rely on consent or any other of the following legal bases. This, however, does not apply, whenever the processing of Personal Data is subject to European data protection law;
-
Provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
-
Processing is necessary for compliance with a legal obligation to which the Owner is subject;
-
Processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
-
Processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data.
If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.
Use of Data
The Data concerning the User may be used for one or more of the following purposes:
-
To provide and maintain our Services
-
To notify you about changes to our Services
-
To allow you to participate in interactive features of our Service when you choose to do so
-
To provide customer support
-
To gather analysis or valuable information so that we can improve our Services
-
To monitor the usage of our Services
-
To detect, prevent and address technical issues
-
To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or inquired about unless you have opted not to receive such information
Users can find further detailed information about such purposes of processing and about the specific Personal Data used for each purpose in the respective sections of this Privacy Policy.
Retention of Data
Personal Data shall be processed and stored for as long as required by the purpose they have been collected for.
Therefore:
-
Personal Data collected for purposes related to the performance of a contract between the Owner and the User shall be retained until such contract has been fully performed.
-
Personal Data collected for the purposes of the Owner’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the Owner within the relevant sections of this document or by contacting the Owner.
The Owner may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Owner may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation, upon order of a competent authority, or as otherwise required by law.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
Transfer Of Data
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Disclosure Of Data
Business Transaction. If we are involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
Disclosure for Law Enforcement. Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Security Of Data
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
Legal Basis for Processing Personal Data Under General Data Protection Regulation (GDPR)
If you are from the European Economic Area (EEA), The Owner’s legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it.
The Owner may process your Personal Data because:
-
We need to perform a contract with you
-
You have given us permission to do so
-
The processing is in our legitimate interests and it's not overridden by your rights
-
For payment processing purposes
-
To comply with the law
Your Data Protection Rights Under General Data Protection Regulation (GDPR)
Where the European Union’s General Data Protection Regulation 2016/679, or GDPR, applies, in certain circumstances and subject to data processing agreements, you have rights in relation to the personal information we hold about you. We set out below an outline of those rights and how to exercise those rights. Please note that we will require you to verify your identity before responding to any requests to exercise your rights by providing details only known to the account holder. To exercise any of your rights, please send an email to privacy@synthesisretreat.com. Please note that for each of the rights below we may have valid legal reasons to refuse your request and, in such instances, we will let you know if that is the case.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
In certain circumstances, you have the following data protection rights:
-
The right to access, update or to delete the information we have on you.
-
The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
-
The right to object. You have the right to object to our processing of your Personal Data.
-
The right of restriction. You have the right to request that we restrict the processing of your personal information.
-
The right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable and commonly used format.
-
The right to withdraw consent. You also have the right to withdraw your consent at any time where the Owner relied on your consent to process your personal information.
Please note that we may ask you to verify your identity before responding to such requests.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
Service Providers
We may employ third party companies and individuals to facilitate our Service ("Service Providers"), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
PLATFORM SERVICES AND HOSTING
These services have the purpose of hosting and running key components of this website, therefore allowing the provision of this website from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data. Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Hubspot (HubSpot, Inc.)
Hubspot is a Customer Relationship Management platform that allows the Owner to build, run and host this website.
Personal Data collected: various types of Data as specified in the privacy policy of the service.
Place of processing: Ireland – Privacy Policy.
ADVERTISING
We may use Google to remarket to Website Visitors. For example, if you previously visited our website and expressed interest in a product, we may serve you advertisements containing a discount when you visit Google or other websites in the Google Audience Network.
-
Note that third-party vendors, including Google, may show our ads on their websites based on information gathered during your visit.
-
Note that third-party vendors, including Google, use cookies to serve ads based on Website Visitors past visits to us.
-
You may opt out of Google's use of cookies by visiting Google's Ads Settings. Alternatively, you can visit the Network Advertising Initiative opt-out page, or read this guide to anti-tracking browser extensions.
We use Facebook Custom Audiences to deliver advertisements to Website Visitors on Facebook based on email addresses that you have shared with us, providing you have granted us permission to do so. You may learn more about Facebook Custom Audiences by visiting the Facebook help center.
We also may use information associated with Visitor social media accounts, such as demographic and other information about an individual's title, industry or organization, to improve our marketing efforts.
We may use the information we have collected from you to enable us to display advertisements. As an example, we may purchase advertisements which are presented selectively to users who have expressed an interest in participating on live workshops.
DATA PROCESSING SOLUTIONS
Zapier
Zapier is an API service that connects various Websites that we work with (Squarespace, ActiveCampaign, Google Sheets, etc.). With Zapier, we process data between these Websites (full name and email).
Personal Data collected with Zapier: None.
All personal data are provided to Zapier from different other Websites as specified in our privacy policy.
Personal Data processed with Zapier: various types of Data as specified in our privacy policy
Website: https://zapier.com/
USER DATABASE MANAGEMENT
This type of service allows the Owner to build user profiles by starting from an email address, a personal name, or other information that the User provides to this website, as well as to track User activities through analytics features. This Personal Data may also be matched with publicly available information about the User (such as social networking profiles) and used to build private profiles that the Owner can display and use for improving this website.
Some of these services may also enable the sending of timed messages to the User, such as emails based on specific actions performed on this website.
Hubspot (HubSpot, Inc.)
Hubspot provides an online Subscription Service that allows users (typically small to medium size businesses) to create and share marketing, sales and customer service content. The Subscription Service can also be used to help organize sales data about a company’s sales pipeline (e.g., leads, customers, deals, etc.). The information added to the Subscription Service, either by site visitors providing their contact information or when a Subscription Service user adds the information, is stored and managed on servers of Hubspot’s service providers.
Place of processing: Ireland – Privacy Policy.
USER DATABASE MANAGEMENT - HEALTH DATA
Help Scout (Help Scout Bcorp.)
Help Scout offers shared inbox and service desk software with features used to collect, manage, act, and report upon customer communications by multiple team members at once.
Place of processing: US – Privacy Policy and GDPR handbook.
Chino.io (Chino Srls)
Chino.io offers data storage that is GDPR and HIPAA by design. Owner uses this service to store health-related data.
Place of processing: Italy – Privacy Policy.
Hellosign (JN PROJECTS Inc.)
HelloSign provides on-demand electronic signature services, which includes the ability to upload, display, deliver, receive, and acknowledge documents for electronic signature.
Place of processing: US – Privacy Policy.
CALLS AND SCHEDULING
The services contained in this section enable the Owner to schedule and facilitate online calls as a part of the Service.
Timekit.io (Timekit Inc.)
Place of processing: Europe – Privacy Policy.
Zoom (Zoom Inc.)
Zoom is a provider of secure, video-first unified communications.
Place of processing: US – Privacy Policy.
ANALYTICS
We may use third-party Service Providers to monitor and analyze the use of our Service.
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics (Google Inc.)
Google Analytics is a web analysis service provided by Google Inc. (“Google”). Google utilizes the Data collected to track and examine the use of this website, to prepare reports on its activities and share them with other Google services.
Google may use the Data collected to contextualize and personalize the ads of its own advertising network.
Personal Data collected: Cookies and Usage Data.
Place of processing: US – Privacy Policy – Opt Out.
HotJar
We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices (in particular device's IP address (captured and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), preferred language used to display our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user.
Place of processing: US – Privacy Policy – Opt Out.
Hubspot (HubSpot, Inc.)
Hubspot provides an online Subscription Service that allows users (typically small to medium size businesses) to create and share marketing, sales and customer service content. The Subscription Service can also be used to help organize sales data about a company’s sales pipeline (e.g., leads, customers, deals, etc.). The information added to the Subscription Service, either by site visitors providing their contact information or when a Subscription Service user adds the information, is stored and managed on servers of Hubspot’s service providers.
Place of processing: Ireland – Privacy Policy.
PAYMENTS
We may provide paid products and/or services within the Service. In that case, we use third-party services for payment processing (e.g. payment processors).
We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
The payment processors we work with are:
Retreat Booking Guru™ (Retreat Guru Enterprises Inc.)
RetreatGuru facilitates retreat bookings, communication and offers payment processing services which we use for our regular retreat bookings.
Place of processing: US – Terms of Service and Privacy Policy.
Stripe
Stripe offers payment processing services, which we use for payments.
Place of processing: US – Privacy Policy.
EventBrite
EventBrite offers a ticketing and registration platform for live events, which we use for workshop registration and payment.
Place of processing: Netherlands – Privacy Policy.
TRAFFIC OPTIMIZATION AND DISTRIBUTION
This type of service allows this website to distribute their content using servers located across different countries and to optimize their performance.
Which Personal Data are processed depends on the characteristics and the way these services are implemented. Their function is to filter communications between this website and the User's browser.
Considering the widespread distribution of this system, it is difficult to determine the locations to which the contents that may contain Personal Information User are transferred.
DISPLAYING CONTENT FROM EXTERNAL PLATFORMS
This type of service allows you to view content hosted on external platforms directly from the pages of this website and interact with them.
This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.
Google Fonts (Google Inc.)
Google Fonts is a typeface visualization service provided by Google Inc. that allows this website to incorporate content of this kind on its pages.
Personal Data collected: Usage Data and various types of Data as specified in the privacy policy of the service.
Place of processing: US – Privacy Policy. Privacy Shield participant.
YouTube video widget (Google Inc.)
YouTube is a video content visualization service provided by Google Inc. that allows this website to incorporate content of this kind on its pages.
Personal Data collected: Cookies and Usage Data.
Place of processing: US – Privacy Policy.
Additional Information About Data Collection And Processing
LEGAL ACTION
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Website or the related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
ADDITIONAL INFORMATION ABOUT USER'S PERSONAL DATA
In addition to the information contained in this privacy policy, this Website may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.
SYSTEM LOGS AND MAINTENANCE
For operation and maintenance purposes, this Website and any third-party services may collect files that record interaction with this Website (System logs) use other Personal Data (such as the IP Address) for this purpose.
INFORMATION NOT CONTAINED IN THIS POLICY
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.
HOW “DO NOT TRACK” REQUESTS ARE HANDLED
This Website does not support “Do Not Track” requests. To determine whether any of the third-party services it uses honor the “Do Not Track” requests, please read their privacy policies.
LINKS TO OTHER SITES
Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
CHILDREN'S PRIVACY
Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
CHANGES TO THIS PRIVACY POLICY
We may update our Privacy Policy from time to time. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us by using the contact information we provided on our Contact page.