Last updated: 1 October 2026
This policy explains how Syndesi S.M.P.C. ("we", "us") uses personal data when you visit The World Can Be Yours at theworldcanbeyours.com, contact us or use our services. It applies to all our websites; anything that applies to this website only is in the last section of this page. We process personal data under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Greek law (Law 4624/2019 and Law 3471/2006).
+Who is responsible for your data
The controller of your personal data is Syndesi Single-Member Private Company (Syndesi S.M.P.C.), [to fill: street and number, Chora, 84300 Naxos, Cyclades, Greece], ΓΕΜΗ no. [to fill: ΓΕΜΗ number]. The World Can Be Yours is a brand of Syndesi S.M.P.C..
Email for anything about your personal data: privacy@syndesi-international.com. Phone: +30 693 290 2373.
We have not appointed a Data Protection Officer: the law does not require one for a business of our size and type. We review this every year. Your privacy contact is the address above.
+What we collect, why, and on what legal basis
- Messages you send us (contact form, email, phone, live chat): your name, email, phone if given, your message and any files you attach. Purpose: to answer you and, if you ask, to prepare an offer. Legal basis: steps you ask for before a contract (GDPR Art. 6(1)(b)), or our legitimate interest in answering enquiries (Art. 6(1)(f)).
- Contracts and payments (when you buy a service from us): the details needed to provide the service, invoice and get paid. Legal basis: the contract (Art. 6(1)(b)) and our legal obligations, such as tax and accounting law (Art. 6(1)(c)).
- Spam and security protection: IP address, browser data and server logs. Legal basis: our legitimate interest in keeping the website and forms safe from abuse (Art. 6(1)(f)).
- Your language and cookie choices: see "Cookies" below. Legal basis: strictly necessary storage (Law 3471/2006 Art. 4(5)); outside services only with your consent (Art. 6(1)(a)).
- News and offers by email: only if you ask for them (consent, Art. 6(1)(a)), or, if you are already a customer, about similar services of ours, with a free opt-out in every email (Law 3471/2006 Art. 11).
Our legitimate interests are: answering people who contact us, running our business, and protecting our website. You can object to processing based on legitimate interest at any time (see "Your rights").
You do not have to give us any personal data to visit the website. If you want an answer, an offer or a contract, we need the details marked as required; without them we cannot answer or provide the service.
+Who receives your data
We do not sell your personal data and we do not use it for advertising. We share it only with:
- service providers who work for us under a data-processing agreement (GDPR Art. 28) or who provide a service you use on our website:
- Hostinger (EU): hosts this website and its database. Processor.
- Google Workspace (Google Ireland / Google LLC): our email. Processor.
- Google reCAPTCHA (Google LLC, USA): checks that contact-form submissions come from a person, not a spam robot. It receives your IP address and information about your browser and how you use the page.
- onWebChat: our live chat. Receives what you type in the chat and technical data about your browser.
- Calendly (Calendly LLC, USA): meeting booking. Receives the name, email and answers you give when you book.
- Vimeo (Vimeo.com Inc., USA): our videos.
- YouTube (Google LLC, USA): videos we embed from YouTube.
- Gravatar (Automattic Inc., USA): shows the profile picture linked to the email you use for a comment.
- Google Fonts and jsDelivr: deliver our fonts and slideshow code. They receive your IP address but do not set cookies.
- our accountant and, when the law requires it, tax and other public authorities and courts;
- the partners needed to provide a service you buy from us (listed in the last section of this page, where they apply).
Outside services that run on the page (reCAPTCHA, chat, booking, videos) may also use the data as independent controllers under their own privacy policies.
+Transfers outside the European Economic Area
Some of the providers above are based in the USA or may process data there. Where a provider is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision (Decision (EU) 2023/1795). Otherwise it relies on the European Commission's Standard Contractual Clauses (GDPR Art. 46). You can ask us for a copy of the safeguards at privacy@syndesi-international.com.
+How long we keep your data
- Enquiries that do not lead to a contract: up to 2 years after our last contact.
- Contracts, invoices and accounting records: for the period Greek tax and commercial law requires.
- Server and security logs: up to 6 months.
- Email news: until you unsubscribe.
- Cookies: see "Cookies" below.
Longer only if we need the data to establish or defend a legal claim. Specific periods for this website are in the last section of this page.
+Your rights
You have the right to:
- access your personal data and get a copy (GDPR Art. 15);
- have it corrected (Art. 16) or erased (Art. 17);
- restrict its use (Art. 18);
- receive it in a usable electronic format or have it sent to someone else (Art. 20);
- not be subject to a decision based solely on automated processing that significantly affects you (Art. 22). We do not make such decisions.
Right to object. You can object at any time to processing based on our legitimate interest, for reasons relating to your situation, and at any time and without giving a reason to the use of your data for direct marketing (Art. 21).
Consent. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it. This does not affect what we did before you withdrew it (Art. 7(3)).
To use any of these rights, write to privacy@syndesi-international.com. It is free. We answer within one month; if a request is complex we may need two more months and will tell you within the first month (Art. 12). We may ask you to confirm your identity.
Complaints. You can complain to the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, Greece, tel. +30 210 6475600, contact@dpa.gr, www.dpa.gr (online form on its website), or to the data protection authority of the EU country where you live or work (Art. 77). We would be grateful if you contacted us first.
+Children
Our general website services are not aimed at children under 15. In Greece, a person under 15 cannot consent alone to online services; a parent or guardian must consent for them (GDPR Art. 8, Law 4624/2019 Art. 21). If we learn that we received data from a child under 15 without that consent, we delete it. Programmes for young people have their own rules in the last section of this page.
+Cookies and outside services
We store only what the website needs on your device without asking: your language (wcbw_lang) and your cookie choice (wcbw_consent), each kept for 365 days. Outside services that may set their own cookies load only after you accept them in our cookie banner. You can change your choice at any time with "Cookie settings" at the bottom of every page. Details, including each cookie, are in our cookie policy.
+Security
We protect your data with appropriate technical and organisational measures (GDPR Art. 32): encrypted connections (HTTPS), restricted access, files sent through our forms stored outside the public website, and regular updates. If a breach is likely to put your rights at risk, we will tell the authority and, where the law requires, you.
+New purposes and changes to this policy
If we want to use your data for a purpose other than the one we collected it for, we will tell you first (GDPR Art. 13(3)) and, where needed, ask for your consent. We update this policy when our services or the law change; the date at the top shows the latest version. Important changes are announced on the website.
+Language versions
This policy is available in several languages. If the versions differ, the Greek version prevails.
+Specific to The World Can Be Yours: programmes, participants and comments
When you book the Postmodern Leadership Program, the AI Survival Summer Camp or another programme, we collect what we need to organise it: participants' names, dates of birth, nationality, passport or ID details for travel and hotels, contact details, emergency contacts, dietary needs, and payment and invoicing details. Legal basis: the booking contract (GDPR Art. 6(1)(b)) and our tax and travel-law obligations (Art. 6(1)(c)). Without these details we cannot accept the booking.
If a company, school or parent books for someone else, they give us that person's details; we tell the participant what we hold when we first contact them.
For participants under 18, a parent or legal guardian makes the booking, signs the contract and gives any consent needed. Participants aged 15 to 17 may consent alone to online services such as our newsletter (Greek Law 4624/2019 Art. 21); bookings always need a parent or guardian. We write information for young participants in plain language and share it with their parents.
To keep participants safe we ask about allergies, medication and health conditions that matter during the programme. We use this only for safety, share it only with the staff and partners who need it (for example a hotel kitchen or a doctor), and delete it 3 months after the programme ends, unless an incident means we must keep it. Legal basis: the explicit consent of the participant, or of a parent for under-18s (GDPR Art. 9(2)(a)), and, in an emergency, vital interests (Art. 9(2)(c)).
We take photos and videos during programmes. We publish ones in which a participant can be recognised only with their written consent (and a parent's, for under-18s), which can be withdrawn at any time; we then stop using them in new material.
Only the partners needed to run the programme you booked: hotels and accommodation, transport and ferry companies, activity partners and trainers, the insurer of the programme, and our insolvency-protection provider. Each receives only what it needs.
Booking contracts and invoices: for the period Greek tax and commercial law requires. Health information: 3 months after the programme. Everything else: 2 years after the programme, so we can deal with questions and claims.
When you leave a comment we collect the data in the comment form, plus your IP address and browser information to detect spam. An anonymised string created from your email address (a hash) may be sent to the Gravatar service to see if you use it; after approval, your Gravatar picture appears with your comment. Comments and your name stay public until you ask us to remove them. See also our comment policy.