Controller
Who is responsible
The data controller for processing related to this website and direct Evera orders is Vorzelyneashodea.world, located at 260 Queen Street W, Toronto, ON M5V 1Z8, Canada. You can reach the privacy desk at talk@vorzelyneashodea.world. Postal correspondence should include “Privacy” on the envelope or subject line so routing stays efficient.
Where we appoint processors (for example payment providers or email delivery), we remain accountable for selecting vendors with adequate safeguards and contractual obligations that mirror the commitments described here.
Scope
What this policy covers
The policy applies to personal data collected through https://vorzelyneashodea.world, official Evera marketing properties we control, and offline communications that reference this document. It does not cover third-party sites that link to us; their practices are governed by their own statements.
If you interact with us only through a marketplace partner, that partner may also process your data under separate terms. We still honor rights requests that relate to information we hold.
Categories
Data we may process
- Identity and contact: name, email, phone number, shipping and billing addresses, account identifiers.
- Transaction data: order contents, payment confirmation tokens, delivery status, refund history.
- Communications: free-text messages, chat transcripts, survey answers, and customer support notes.
- Technical data: IP address, device type, browser version, approximate region, referring URL, timestamps.
- Preference data: cookie consent choices, newsletter topics, language selection.
- Marketing metrics: aggregated engagement statistics when optional marketing cookies are enabled.
We avoid collecting sensitive categories unless you voluntarily provide them and we have a clear legal basis to retain the information.
Purposes
Why we use personal data
We process data to operate the storefront, fulfill contracts, communicate service updates, improve site reliability, comply with accounting and tax rules, defend legal claims, and—only with appropriate consent—send promotional messages or run analytics that help us understand aggregate traffic patterns.
Automated decision-making does not occur in a way that produces legal effects about you without human review. If that ever changes, we will describe the logic and your rights in an updated notice.
Lawful bases
GDPR alignment
Where the GDPR applies, we rely on contract when processing is necessary to deliver what you purchased or requested; legitimate interests for fraud prevention, network security, and lightweight product analytics that do not override your rights; consent for optional cookies and certain marketing channels; and legal obligation when statutes require recordkeeping or disclosure.
You may withdraw consent at any time without affecting processing that occurred beforehand. Withdrawal might limit features that depend on optional data.
Retention
How long we keep information
Marketing contact details remain until you unsubscribe or delete your account, subject to suppression lists that prove compliance. Order and tax records may be retained for up to seven years depending on jurisdiction. Support tickets typically roll off active systems after twenty-four months but may persist longer if linked to disputes.
Logs with IP addresses rotate on a shorter cadence unless security investigations require preservation. When retention ends, we delete or irreversibly anonymize records.
Sharing
Recipients and transfers
We share data with payment processors, fulfillment warehouses, shipping carriers, cloud hosting providers, email services, and professional advisers under confidentiality duties. Some subprocessors operate in the United States or the European Union; when data leaves Canada or the EEA we implement standard contractual clauses, adequacy decisions, or supplementary measures as required.
We do not sell personal data for money. Partnered analytics or advertising providers only receive pseudonymous identifiers when you opt in through the cookie banner.
Security
Protection measures
We deploy HTTPS encryption, role-based access controls, multi-factor authentication for administrative accounts, vulnerability monitoring, and periodic vendor reviews. Employees receive privacy training and access data on a need-to-know basis.
No system is perfectly secure. If we discover an incident that poses a risk to your rights, we will notify regulators and affected individuals as required by law.
Your rights
Requests you can make
Depending on your location, you may request access, correction, deletion, restriction, objection, or portability. EU and UK residents may lodge complaints with supervisory authorities. Canadian residents may challenge our compliance with PIPEDA or provincial equivalents.
To exercise rights, email talk@vorzelyneashodea.world with a description of the request and verification information. We respond within statutory timelines, usually within thirty days.
Children
Age limits
Our services target adults. We do not knowingly collect data from anyone under sixteen. If you believe a minor submitted information, contact us so we can delete it promptly.
Updates
Changes to this policy
We revise this page when our practices evolve. Material updates appear with a refreshed effective date at the top. Continued use after changes constitutes acceptance unless applicable law requires explicit consent.