Last updated: November 5, 2025
Sylphium molecular ecology (“Sylphium”, “we”, “us”, or “our”) is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, and protect personal information in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Dutch data protection laws.
1. Who we are
Sylphium molecular ecology is a Tradename of Eelco Wallaart B.V., established in The Netherlands. If you have any questions about this Privacy Policy or the way we process your personal data, please contact us at:
Email: info@sylphium.com
2. What personal data we collect
Depending on how you interact with us, we may collect the following information:
Webshop
- Name
- Email address
- Telephone number
- Billing and shipping address
- Company or institution
- Order and payment information
- Account details (if you create an account)
We may also collect technical information such as your IP address, browser type, device information, and website usage statistics through cookies and analytics tools.
Sample submission and laboratory services
- Contact details
- Company or institution
- Sample identification numbers
- Shipping information (including optional tracking information)
- Target species
- Project or reference numbers
- Notes or additional information you provide
Direct communication
If you contact us by email, telephone, or during meetings, we may process the information necessary to respond to your enquiry and provide our services.
We do not intentionally collect special categories of personal data, such as health information. Should such data become necessary for a specific purpose, we will request your explicit consent and process it only where legally permitted.
3. Why we process your personal data
We process personal data on one or more of the following legal grounds:
Performance of a contract
- Register and analyse samples
- Process webshop orders
- Deliver laboratory reports
- Provide customer support
Legal obligations
To comply with legal and regulatory requirements, including tax and accounting obligations.
interests
- Maintain quality assurance and laboratory traceability
- Improve our products and services
- Secure our website and IT systems
- Prevent fraud and misuse
Where we rely on legitimate interests, we carefully balance these interests against your rights and freedoms.
Consent
Where required by law, such as for marketing communications, we will request your consent. You may withdraw your consent at any time.
4. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected or to comply with legal obligations. Typical retention periods include:
- Sample registration and laboratory data: up to 5 years
- Order and invoice records: 7 years (Dutch tax legislation)
- Website and analytics logs: generally up to 12 months
- General correspondence: up to 2 years after our last contact
After the applicable retention period, personal data is securely deleted or anonymised unless a longer retention period is required by law or necessary for the establishment, exercise, or defence of legal claims.
5. Sharing your personal data
We never sell or rent your personal data.
Where necessary, we may share information with carefully selected third parties that assist us in providing our services. These parties process data only under appropriate confidentiality and data-processing agreements. This may include:
- Laboratory partners or subcontractors involved in analyses
- IT, hosting, and cybersecurity providers
- Payment service providers
- Professional advisers
- Government authorities where disclosure is required by law
6. International data transfers
We primarily store and process personal data within the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as the European Commission’s Standard Contractual Clauses or other legally recognised transfer mechanisms.
7. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure. These measures include, among others:
- Encrypted data transmission (HTTPS)
- Access controls
- Role-based permissions
- Secure data storage
- Regular software updates
- System backups
Although we strive to protect your information, no method of transmission or storage can be guaranteed to be completely secure.
8. Your rights
Under the GDPR, you have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion of your data
- Restrict processing
- Object to processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, please contact us at info@sylphium.com. We will respond within one month, unless a longer response period is permitted under applicable law.
9. Cookies and analytics
Our website uses cookies that are necessary for its operation, as well as cookies that help us analyse website traffic and improve user experience. You can manage or disable cookies through your browser settings.
For more information, please refer to our Cookie Policy.
10. Children’s privacy
Our services are not intended for children under the age of 16. If you believe that a child has provided personal data to us, please contact us so that we can remove the information where appropriate.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legislation, technology, or our business practices. The most recent version will always be published on this page with the date it became effective shown at the top of the page.
12. Contact and complaints
If you have any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, please contact us at info@sylphium.com. If you believe your personal data has been processed unlawfully, you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
