This policy explains how Syndesi S.M.P.C. ("we", "us") uses personal data when you visit The World Can Be Yours at theworldcanbeyours.com, contact us or use our services. It applies to all our websites (listed in our legal notice); anything that applies to this website only is in the last section of this page. We process personal data under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Greek law (Law 4624/2019 and Law 3471/2006).
+Who is responsible for your data
The controller of your personal data is Syndesi Single Member P.C. (Syndesi S.M.P.C.), Glyfada, Agios Georgios, Chora, 84300 Naxos, Cyclades, Greece, ΓΕΜΗ no. 159024238000, VAT no. EL801553663. The World Can Be Yours is one of its brands.
Email for anything about your personal data: privacy@syndesi-international.com. Phone: +30 693 290 2373.
We have not appointed a Data Protection Officer: the law does not require one for a business of our size and type. We review this every year. Your privacy contact is the address above.
+What we collect, why, and on what legal basis
- Messages you send us (contact form, email, phone, live chat): your name, email, phone if given, your message and any files you attach. Purpose: to answer you and, if you ask, to prepare an offer. Legal basis: steps you ask for before a contract (GDPR Art. 6(1)(b)), or our legitimate interest in answering enquiries (Art. 6(1)(f)).
- Contracts and payments (when you buy a service from us): the details needed to provide the service, invoice and get paid. Legal basis: the contract (Art. 6(1)(b)) and our legal obligations, such as tax and accounting law (Art. 6(1)(c)).
- Spam and security protection: IP address, browser data and server logs. Legal basis: our legitimate interest in keeping the website and forms safe from abuse (Art. 6(1)(f)).
- Your language and cookie choices: see "Cookies" below. Legal basis: strictly necessary storage (Law 3471/2006 Art. 4(5)); outside services only with your consent (Art. 6(1)(a)).
- News and offers by email: only if you ask for them (consent, Art. 6(1)(a)), or, if you are already a customer, about similar services of ours, with a free opt-out in every email (Law 3471/2006 Art. 11).
Our legitimate interests are: answering people who contact us, running our business, and protecting our website. You can object to processing based on legitimate interest at any time (see "Your rights").
You do not have to give us any personal data to visit the website. If you want an answer, an offer or a contract, we need the details marked as required; without them we cannot answer or provide the service.
+Who receives your data
We do not sell your personal data and we do not use it for advertising. We share it only with:
- service providers who work for us under a data-processing agreement (GDPR Art. 28) or who provide a service you use on our website:
- Hostinger (EU): hosts this website and its database. Processor.
- Google Workspace (Google Ireland / Google LLC): our email. Processor.
- Google reCAPTCHA (Google LLC, USA): checks that contact-form submissions come from a person, not a spam robot. It receives your IP address and information about your browser and how you use the page.
- onWebChat: our live chat. Receives what you type in the chat and technical data about your browser.
- Calendly (Calendly LLC, USA): meeting booking. Receives the name, email and answers you give when you book.
- Vimeo (Vimeo.com Inc., USA): our videos.
- YouTube (Google LLC, USA): videos we embed from YouTube.
- Gravatar (Automattic Inc., USA): shows the profile picture linked to the email you use for a comment.
- Google Fonts and jsDelivr: deliver our fonts and slideshow code. They receive your IP address but do not set cookies.
- our accountant and, when the law requires it, tax and other public authorities and courts;
- the partners needed to provide a service you buy from us (listed in the last section of this page, where they apply).
Outside services that run on the page (reCAPTCHA, chat, booking, videos) may also use the data as independent controllers under their own privacy policies.
+Transfers outside the European Economic Area
Some of the providers above are based in the USA or may process data there. Where a provider is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision (Decision (EU) 2023/1795). Otherwise it relies on the European Commission's Standard Contractual Clauses (GDPR Art. 46). You can ask us for a copy of the safeguards at privacy@syndesi-international.com.
+How long we keep your data
- Enquiries that do not lead to a contract: up to 2 years after our last contact.
- Contracts, invoices and accounting records: for the period Greek tax and commercial law requires.
- Server and security logs: up to 6 months.
- Email news: until you unsubscribe.
- Cookies: see "Cookies" below.
Longer only if we need the data to establish or defend a legal claim. Specific periods for this website are in the last section of this page.
+Your rights
You have the right to:
- access your personal data and get a copy (GDPR Art. 15);
- have it corrected (Art. 16) or erased (Art. 17);
- restrict its use (Art. 18);
- receive it in a usable electronic format or have it sent to someone else (Art. 20);
- not be subject to a decision based solely on automated processing that significantly affects you (Art. 22). We do not make such decisions.
Right to object. You can object at any time to processing based on our legitimate interest, for reasons relating to your situation, and at any time and without giving a reason to the use of your data for direct marketing (Art. 21).
Consent. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it. This does not affect what we did before you withdrew it (Art. 7(3)).
To use any of these rights, write to privacy@syndesi-international.com. It is free. We answer within one month; if a request is complex we may need two more months and will tell you within the first month (Art. 12). We may ask you to confirm your identity.
Complaints. You can complain to the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, Greece, tel. +30 210 6475600, contact@dpa.gr, www.dpa.gr (online form on its website), or to the data protection authority of the EU country where you live or work (Art. 77). We would be grateful if you contacted us first.
+Children
Our general website services are not aimed at children under 15. In Greece, a person under 15 cannot consent alone to online services; a parent or guardian must consent for them (GDPR Art. 8, Law 4624/2019 Art. 21). If we learn that we received data from a child under 15 without that consent, we delete it. Programmes for young people have their own rules in the last section of this page.
+Cookies and outside services
We store only what the website needs on your device without asking: your language (wcbw_lang) and your cookie choice (wcbw_consent), each kept for 365 days. Outside services that may set their own cookies load only after you accept them in our cookie banner. You can change your choice at any time with "Cookie settings" at the bottom of every page. Details, including each cookie, are in our cookie policy.
+Security
We protect your data with appropriate technical and organisational measures (GDPR Art. 32): encrypted connections (HTTPS), restricted access, files sent through our forms stored outside the public website, and regular updates. If a breach is likely to put your rights at risk, we will tell the authority and, where the law requires, you.
+New purposes and changes to this policy
If we want to use your data for a purpose other than the one we collected it for, we will tell you first (GDPR Art. 13(3)) and, where needed, ask for your consent. We update this policy when our services or the law change; the date at the top shows the latest version. Important changes are announced on the website.
+Language versions
This policy is available in several languages. If the versions differ, the Greek version prevails.
+If you live outside Greece
+If you live in the United States
We are a Greek company and protect the data of every visitor to the GDPR standard described above, wherever you live. We do not sell or share personal information for cross-context behavioural advertising, and we do not use it for targeted advertising or profiling.
Under the California Online Privacy Protection Act (Business and Professions Code §§ 22575–22579): this policy lists the categories of personal information we collect and who receives them (see the sections above); you can review and correct your information by writing to privacy@syndesi-international.com; changes to this policy are dated at the top.
Do Not Track. Our website does not track you across other websites, so it treats every visitor as if "Do Not Track" were switched on.
Minors in California. If you are under 18 and have posted content on our website (for example a comment), you can ask us to remove it (Business and Professions Code § 22581).
The California Consumer Privacy Act (CCPA) applies only to businesses above certain size thresholds, which we do not meet. We still honour requests to know, correct and delete your information.
State consumer privacy laws (for example in Virginia, Colorado, Connecticut, Texas and Oregon) apply only above volume thresholds we do not meet. You can still use all the rights described in this policy.
Our websites are not directed to children under 13, and we do not knowingly collect their personal information (Children's Online Privacy Protection Act). If a parent believes we have, please write to us and we will delete it.
Every marketing email we send identifies us, gives our postal address and has a free, working unsubscribe link (CAN-SPAM Act). We send them only to people who asked for them.
+If you live in Canada
When we collect personal information from people in Canada in the course of commercial activity, we follow the Personal Information Protection and Electronic Documents Act (PIPEDA) as well as the GDPR. In particular:
- We collect only what we need for the purposes listed in this policy and use it only for those purposes, unless you agree or the law requires otherwise.
- Your information is stored and processed in Greece (European Union) and by the service providers listed above, some of them in the USA. Courts and authorities in those countries may be able to access it under their laws.
- You can ask to see your personal information and to correct it, and you can withdraw consent at any time, subject to legal or contractual limits.
- If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca).
Québec. If you live in Québec, the French version of this page sets out the additional rights you have under Québec law.
We send commercial electronic messages only with your consent, identify ourselves in each one and include a free unsubscribe link that we honour within 10 business days (Canada's Anti-Spam Legislation, CASL).
+If you live in the United Kingdom
For people in the UK, we process personal data under the UK GDPR and the Data Protection Act 2018 as well as the EU GDPR. You have the same rights as described above. The UK recognises the European Economic Area as giving adequate protection, so your data may be sent to us in Greece.
You can complain to the Information Commissioner's Office (ICO), www.ico.org.uk, tel. 0303 123 1113.
+Si vous résidez en France
Nous appliquons également la loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés. En plus des droits décrits ci-dessus, vous pouvez définir des directives sur le sort de vos données après votre décès (article 85 de cette loi), en écrivant à privacy@syndesi-international.com.
En France, un mineur peut consentir seul à un service en ligne à partir de 15 ans ; en dessous, l'accord conjoint de l'enfant et du titulaire de l'autorité parentale est nécessaire (article 45 de la loi Informatique et Libertés).
Vous pouvez introduire une réclamation auprès de la Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
Nous ne vous envoyons des e-mails de prospection qu'avec votre accord préalable, ou, si vous êtes déjà client, pour des services analogues, avec un lien de désinscription gratuit dans chaque message (article L34-5 du Code des postes et des communications électroniques).
+Se você mora no Brasil
Quando oferecemos serviços a pessoas no Brasil, também seguimos a Lei Geral de Proteção de Dados Pessoais (Lei nº 13.709/2018, LGPD) e o Marco Civil da Internet (Lei nº 12.965/2014). O controlador é Syndesi Single Member P.C. (Syndesi S.M.P.C.), Glyfada, Agios Georgios, Chora, 84300 Naxos, Cyclades, Greece.
Canal de atendimento do titular (encarregado): privacy@syndesi-international.com.
Você tem direito a (art. 18 da LGPD): confirmação da existência de tratamento; acesso aos dados; correção de dados incompletos, inexatos ou desatualizados; anonimização, bloqueio ou eliminação de dados desnecessários ou excessivos; portabilidade; eliminação dos dados tratados com seu consentimento; informação sobre com quem compartilhamos seus dados; informação sobre a possibilidade de não dar consentimento e suas consequências; e revogação do consentimento.
Transferência internacional. Seus dados são tratados na Grécia (União Europeia) e pelos fornecedores listados acima, alguns nos Estados Unidos, com as garantias previstas no art. 33 da LGPD, como cláusulas-padrão contratuais.
Crianças e adolescentes. Dados de menores de 18 anos são tratados sempre no seu melhor interesse (art. 14 da LGPD e Estatuto Digital da Criança e do Adolescente).
Você pode apresentar reclamação à Agência Nacional de Proteção de Dados (ANPD), www.gov.br/anpd.
+Specific to The World Can Be Yours: programmes, participants and comments
When you book the Postmodern Leadership Program, the AI Survival Summer Camp or another programme, we collect what we need to organise it: participants' names, dates of birth, nationality, passport or ID details for travel and hotels, contact details, emergency contacts, dietary needs, and payment and invoicing details. Legal basis: the booking contract (GDPR Art. 6(1)(b)) and our tax and travel-law obligations (Art. 6(1)(c)). Without these details we cannot accept the booking.
If a company, school or parent books for someone else, they give us that person's details; we tell the participant what we hold when we first contact them.
For participants under 18, a parent or legal guardian makes the booking, signs the contract and gives any consent needed. Participants aged 15 to 17 may consent alone to online services such as our newsletter (Greek Law 4624/2019 Art. 21); bookings always need a parent or guardian. We write information for young participants in plain language and share it with their parents.
To keep participants safe we ask about allergies, medication and health conditions that matter during the programme. We use this only for safety, share it only with the staff and partners who need it (for example a hotel kitchen or a doctor), and delete it 3 months after the programme ends, unless an incident means we must keep it. Legal basis: the explicit consent of the participant, or of a parent for under-18s (GDPR Art. 9(2)(a)), and, in an emergency, vital interests (Art. 9(2)(c)).
We take photos and videos during programmes. We publish ones in which a participant can be recognised only with their written consent (and a parent's, for under-18s), which can be withdrawn at any time; we then stop using them in new material.
Only the partners needed to run the programme you booked: hotels and accommodation, transport and ferry companies, activity partners and trainers, the insurer of the programme, and our insolvency-protection provider. Each receives only what it needs.
Booking contracts and invoices: for the period Greek tax and commercial law requires. Health information: 3 months after the programme. Everything else: 2 years after the programme, so we can deal with questions and claims.
When you leave a comment we collect the data in the comment form, plus your IP address and browser information to detect spam. An anonymised string created from your email address (a hash) may be sent to the Gravatar service to see if you use it; after approval, your Gravatar picture appears with your comment. Comments and your name stay public until you ask us to remove them. See also our comment policy.