Privacy Policy

 

Last updated: 01.09.2026

1. Overview

This Privacy Policy explains how Systemic Error processes personal data when you visit our website, use our online shop, place an order, create a customer account, contact us, or use our services.

We process personal data in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG).

2. Controller

The controller responsible for data processing is:

Systemic Error
Kaveh Najafian Razavi
Pulverteich 27
20099 Hamburg
Germany
Email: support@systemicerror.com

3. Website Visits, Hosting, and Security

When you visit our website, technical data may be processed automatically to display, operate, secure, and maintain the website.

This may include:

  • IP address
  • date and time of access
  • browser and device information
  • operating system
  • visited pages
  • referrer URL
  • technical request data
  • server logs and security logs

Website hosting is provided by Bluehost Inc., 5335 Gate Pkwy, 2nd Floor, Jacksonville, FL 32256, USA. In connection with hosting, Bluehost may process technical data such as IP addresses, access data, and server and security logs in order to provide, operate, and secure the website. The legal basis is Art. 6(1)(f) GDPR. Where Bluehost processes personal data on our behalf, processing is governed by a data processing agreement under Art. 28 GDPR. Because Bluehost is based in the United States, personal data may be transferred outside the European Economic Area. Bluehost’s data processing terms provide safeguards for international transfers, including Standard Contractual Clauses.

4. Cookies and Consent

Our website uses cookies and similar technologies.

Some cookies are technically necessary for the website to function, for example for shopping cart functionality, checkout, login sessions, security, and language or consent settings.

Other cookies or similar technologies, such as analytics or marketing cookies, are used only if you have given your consent through our cookie banner, where required.

The storage of information on your device or access to information stored on your device is governed by § 25 TDDDG. Where consent is required, this is based on § 25(1) TDDDG. Technically necessary storage or access is based on § 25(2) TDDDG.

The subsequent processing of personal data is based on the GDPR.

Legal basis:

  • technically necessary storage or access: § 25(2) TDDDG
  • cart, checkout, login, and account functionality: Art. 6(1)(b) GDPR
  • website security, fraud prevention, error analysis, and technical stability: Art. 6(1)(f) GDPR
  • consent-based cookies and similar technologies: § 25(1) TDDDG and Art. 6(1)(a) GDPR

You can change or withdraw your cookie consent at any time through the cookie settings on our website.

We use Complianz | The Privacy Suite for WordPress, provided by Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands, to manage cookie consent and record consent choices. In connection with this function, consent-related information may be stored, including an anonymized IP address and consent status. The processing serves to document and manage consent and to comply with applicable data-protection requirements. The legal basis is Art. 6(1)(c) GDPR. Where Complianz processes personal data on our behalf, processing is governed by a data processing agreement under Art. 28 GDPR.

Sourcebuster JS

We use Sourcebuster JS, an open-source attribution script, to understand how visitors reach our website and to attribute visits and orders to sources such as search engines, referring websites, and campaign links. Sourcebuster stores attribution information in first-party cookies on your device. The script itself does not require an external service provider and does not transmit data to a separate Sourcebuster company merely through its use. Because this processing is not technically necessary, Sourcebuster is used only with your consent. The legal basis for storing or accessing information on your device is § 25(1) TDDDG and for the subsequent processing of personal data Art. 6(1)(a) GDPR.

Automattic / WordPress.com Statistics

We use statistics functionality provided by Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland, and, where applicable, Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA, to understand how our website is used. In this context, technical and usage data such as IP address, browser and device information, referrer information, pages viewed, and time of access may be processed. This service is used only with your consent. The legal basis for storing or accessing information on your device is § 25(1) TDDDG and for the subsequent processing of personal data Art. 6(1)(a) GDPR. Where personal data is transferred outside the European Economic Area, Automattic uses appropriate safeguards, including European Commission-approved Standard Contractual Clauses.

Instagram feed (Smash Balloon)

We use the self-hosted Smash Balloon Instagram Feed plugin to display content from our Instagram account. The plugin retrieves feed content through Meta’s Instagram API. Smash Balloon does not act as a separate recipient of website-visitor data for this feed; the plugin data is stored on our website and exchanged directly with Meta’s services. Where the feed establishes a direct connection to Instagram to load media or interactive content, technical data such as the IP address, browser and device information, and request data may be transmitted to Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Such third-party connections are enabled only after consent through our consent-management system. The legal basis is § 25(1) TDDDG for storing or accessing information on the device and Art. 6(1)(a) GDPR for the subsequent processing of personal data.

The cookie settings provide the current inventory of cookies and similar technologies, including their purpose and duration.

5. Customer Data, Orders, Payments, Delivery, Returns, and Support

When you use our online shop, create a customer account, place an order, contact us, request a return, or exercise your right of withdrawal, we process the personal data necessary for these purposes.

WooCommerce and customer accounts

Our online shop is operated with WooCommerce. Orders can be placed as a guest without creating a customer account. Customers may also create an optional customer account. For orders and accounts, we process data such as name, email address, billing and shipping address, order information and, for registered accounts, account login data. The processing is necessary to provide the shop, process orders and manage customer accounts. The legal basis is Art. 6(1)(b) GDPR. Customer account data is stored until the account is deleted, unless statutory retention obligations apply to particular data. Order and transaction data is retained in accordance with applicable tax and commercial-law requirements.

For payment, delivery, support, returns, and legal documentation, we may also process:

  • payment status
  • invoice and accounting data
  • shipping and tracking information
  • messages, support requests, return requests, and withdrawal requests
  • phone number, if voluntarily provided by you or required for a specific delivery or payment method

Contact form

If you contact us through the contact form, we process the information you enter, such as your name, email address, and message, solely to handle and respond to your inquiry. The contact form is implemented using custom code. Information submitted through the form is not stored in the website database; it is transmitted to us by email. The legal basis is Art. 6(1)(b) GDPR where the inquiry relates to a contract or pre-contractual steps, and Art. 6(1)(f) GDPR for other inquiries. We retain the resulting correspondence only for as long as necessary to handle the inquiry, unless statutory retention obligations require longer storage.

Emails generated by the website are sent through our own server; no external transactional email provider is used.

Electronic withdrawal function

The electronic withdrawal function is implemented using custom code. We process the information entered, such as your name, email address, and order number, solely to receive and process your withdrawal. Information submitted through the function is not stored in the website database; it is transmitted to us by email. The legal basis is Art. 6(1)(c) GDPR in conjunction with § 356a BGB. We retain the resulting correspondence only for as long as necessary to process and document the withdrawal, unless statutory retention obligations require longer storage.

We process the additional data listed above to handle payments, delivery, support, returns and refunds, legal obligations, and business documentation.

Legal basis:

  • Art. 6(1)(b) GDPR, where processing is necessary for orders, customer accounts, payment, delivery, returns, or customer support related to a contract
  • Art. 6(1)(c) GDPR, where processing is necessary to comply with legal, tax, accounting, or consumer-law obligations
  • Art. 6(1)(f) GDPR, where processing is necessary for general communication, documentation, fraud prevention, legal defense, or business administration

6. Payment Providers

We use external payment providers to process payments securely.

Depending on the payment method selected during checkout, payment data may be processed by the relevant payment provider. This may include payment method information, transaction amount, transaction status, billing details, device and technical payment data, and fraud-prevention data.

Payment providers may use automated systems to detect fraud, prevent misuse, and assess transaction risk. This may affect whether a payment method or transaction is accepted. Further information is provided by the respective payment provider.

Payments by credit card, debit card, Apple Pay, and Google Pay are processed through WooPayments. WooPayments is built in partnership with Stripe and uses a Stripe Express account. For these payments, billing and transaction data, technical payment data, and fraud-prevention data may be transmitted to Stripe. Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, and, where applicable, other Stripe entities process payment data. The legal basis is Art. 6(1)(b) GDPR and, where necessary for payment security and fraud prevention, Art. 6(1)(f) GDPR. Stripe processes personal data under its applicable data-protection terms.

PayPal payments are processed by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal processes the data required to handle the payment and is responsible for its own data processing in connection with PayPal accounts and payment services. The legal basis for transmitting the data required for payment is Art. 6(1)(b) GDPR.

7. Shipping and Fulfillment

For shipments handled directly by Systemic Error, we use Sendcloud GmbH, Fürstenrieder Str. 70, 80686 Munich, Germany, to manage shipping. Depending on destination, price, and availability, orders may be shipped with UPS, DHL, or DPD. We transmit the delivery information required for shipment, such as the recipient’s name and shipping address and, where required for delivery, contact details, to Sendcloud and the selected carrier. The legal basis is Art. 6(1)(b) GDPR. Where Sendcloud processes personal data on our behalf, processing is governed by a data processing agreement under Art. 28 GDPR.

Print-on-demand apparel and wall art are fulfilled by Printful Inc., 11025 Westlake Dr, Charlotte, NC 28273, USA. We transmit the customer data required to fulfill the order, in particular name, shipping address, contact details, and order information, so that Printful can produce, pack, and ship the products. The legal basis is Art. 6(1)(b) GDPR. Printful processes this data on our behalf under its Data Processing Terms, which constitute a data processing agreement. Printful may use affiliated companies and subprocessors, including in third countries. Where required, international transfers are safeguarded by the EU Standard Contractual Clauses.

8. Service Providers and International Data Transfers

We use the service providers described in this Privacy Policy to operate the website and shop, process payments, fulfill and ship orders, provide support, meet legal obligations, and maintain our IT systems.

Depending on your use of our website and shop, personal data may be shared with categories of recipients such as:

  • hosting and infrastructure providers
  • payment providers
  • shipping providers
  • fulfillment partners
  • accounting tools and tax advisors
  • IT and website service providers
  • public authorities, where legally required

Where service providers process personal data on our behalf, we conclude data processing agreements in accordance with Art. 28 GDPR where required.

Where a service provider processes personal data outside the European Economic Area, the transfer safeguards described in the relevant provider section of this Privacy Policy apply.

9. Retention Periods

We store personal data only for as long as necessary for the purposes described in this Privacy Policy or as required by law.

Typical retention periods include:

  • server logs: stored for a limited technical period, unless longer storage is required for security reasons
  • customer account data: stored until account deletion, unless legal retention obligations apply
  • order, invoice, payment, and accounting data: stored according to tax and commercial law retention periods
  • support, return, and withdrawal communication: stored as long as necessary to handle the request and document the transaction
  • consent records: stored as long as necessary to document consent and withdrawal

10. Your Rights

You have the following rights under the GDPR:

  • right of access
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object
  • right to withdraw consent at any time
  • right to lodge a complaint with a data protection supervisory authority:

The competent supervisory authority is the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI): datenschutz-hamburg.de

To exercise your rights, contact us at support@systemicerror.com.

If we process personal data based on legitimate interests, you may object to this processing for reasons arising from your particular situation. You may object to direct marketing at any time.

If you withdraw consent, this does not affect the lawfulness of processing carried out before the withdrawal.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our website, services, providers, or legal requirements.

The current version is available on our website.