Privacy Policy
Last updated: 23/08/2026
1) Introduction
This Privacy Policy explains how New kenshi collects, uses, stores, shares and protects personal data relating to users and customers of New kenshi.
NOITAKY Matthieu is established in France and is the data controller for the processing activities described in this Policy. Personal data processed in the context of this French establishment is subject to the EU General Data Protection Regulation (“GDPR”), the French Data Protection Act and other applicable European data-protection requirements.
Where the Singapore Personal Data Protection Act 2012 (“PDPA”) applies to the collection, use, disclosure, protection or other handling of personal data relating to individuals in Singapore, New kenshi will also comply with the applicable requirements of the PDPA.
The Singapore PDPA applies to organisations broadly defined under Singapore law, including in certain circumstances organisations that are not formed, resident or physically established in Singapore.
By using the website, you acknowledge that you have been provided with this Privacy Policy. Where consent is legally required for a particular processing activity, that consent will be obtained separately.
2) Data Controller and Data Protection Contact
Data controller / organisation: NOITAKY Matthieu
Trading name: New kenshi
Address: 17 rue de l'Amazone, 44470 Carquefou, France
Email / data protection contact: contact@kenshiblades.com
Questions concerning the collection, use, disclosure, protection or other handling of personal data may be sent to contact@kenshiblades.com.
Where the Singapore PDPA applies, this contact may also be used for enquiries directed to the organisation's data-protection function.
3) Personal Data We Collect
New kenshi collects personal data reasonably necessary for operating the website, processing orders, providing customer service, protecting transactions, complying with legal obligations and improving the services offered.
The categories of personal data may include:
- Identification and contact data: first name, surname, postal address, email address and telephone number;
- Order and transaction data: products purchased, order history, payment method, amounts, currency, billing address, delivery address, refunds and returns;
- Account data: account identifiers, preferences and saved information where a customer account is available;
- Technical and browsing data: IP address, device information, browser type, operating system, visited pages, session information, referral source and cookie identifiers;
- Communication data: messages, questions, complaints, reviews and information submitted through forms, email or customer support;
- Marketing data: newsletter subscriptions, marketing preferences, consent records and interactions with promotional communications;
- Security and fraud-prevention data: authentication information, transaction-risk indicators and information used to detect suspicious, fraudulent or unlawful activity.
Some information is necessary to enter into or perform a sales contract. If necessary order, payment or delivery information is not provided, we may be unable to process the transaction.
Please do not provide sensitive personal information through free-text fields unless it is genuinely necessary for your request.
4) Sources of Personal Data
Personal data may be collected:
- Directly from you when you place an order, create an account, contact us, submit a form, subscribe to marketing or publish a review;
- Automatically when you use the website or interact with cookies and similar technologies;
- From payment providers, delivery providers, fraud-prevention services, analytics providers and other service providers involved in a transaction or website operation;
- From publicly available or lawfully accessible sources where permitted by applicable law.
5) Purposes for Which We Process Personal Data
Personal data may be collected, used or disclosed for purposes including:
- Processing orders, payments, deliveries, returns and refunds;
- Managing customer accounts and purchase history;
- Providing customer support and responding to requests or complaints;
- Sending order confirmations, tracking information and service communications;
- Operating, maintaining, securing and troubleshooting the website;
- Detecting and preventing fraud, abuse, chargebacks and unlawful activity;
- Improving products, website performance, services and customer experience;
- Measuring website traffic and performance;
- Sending marketing communications where permitted;
- Managing consent and marketing preferences;
- Complying with tax, accounting, consumer-protection, regulatory and legal obligations;
- Establishing, exercising or defending legal claims.
We will not use personal data for a materially incompatible purpose without an appropriate legal basis, notification or consent where required.
6) Legal Grounds, Consent and Permitted Processing
European Union / GDPR
Where the GDPR applies, processing may rely on one or more of the following legal bases:
- Performance of a contract: including processing necessary for orders, payments, deliveries, returns and customer requests;
- Legal obligation: including tax, accounting, regulatory and record-keeping requirements;
- Consent: including certain marketing, cookies or optional processing activities;
- Legitimate interests: including website security, fraud prevention, service improvement and dispute management where those interests are not overridden by the individual's rights;
- Establishment, exercise or defence of legal claims: where applicable.
Singapore / PDPA
Where the Singapore PDPA applies, personal data may be collected, used or disclosed with the individual's consent, deemed consent where the statutory conditions are satisfied, or without consent where an applicable exception under the PDPA permits such processing.
New kenshi will notify individuals of the relevant purposes as required and will not require consent for purposes beyond what is reasonable for providing a requested product or service where the PDPA prohibits doing so.
Where processing relies on consent, an individual may withdraw that consent by giving reasonable notice, subject to legal or contractual consequences that will be explained where relevant.
Withdrawal of consent does not affect processing that was lawful before withdrawal or processing that remains permitted or required by law.
7) Data Recipients and Service Providers
Personal data is accessible only to authorised persons and service providers that require it for the purposes described in this Policy.
- E-commerce platform and hosting: Shopify International Limited, relevant Shopify affiliates and subprocessors;
- Domain name services: HOSTINGER operations, UAB;
- Payment providers: providers displayed during checkout, which may include Stripe, PayPal, Klarna, Apple Pay or Google Pay;
- Logistics providers: carriers, delivery partners, fulfilment centres and customs intermediaries;
- Technical providers: email, customer-support, security, fraud-prevention, analytics, consent-management and website-service providers;
- Professional advisers and authorities: accountants, lawyers, insurers, banks, courts, regulators, tax authorities and law-enforcement bodies where legally required or reasonably necessary.
Shopify processes information relating to customers and merchants in accordance with its applicable privacy and data-processing terms. Further information is available in Shopify's Consumer Privacy Policy.
New kenshi does not sell personal data for monetary consideration.
Service providers are required to process personal data under appropriate contractual, security and confidentiality arrangements where required by applicable law.
8) Data Retention
Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected and for applicable legal, accounting, tax, fraud-prevention, contractual and dispute-resolution requirements.
Where the Singapore PDPA applies, New kenshi will cease retaining personal data, or remove the means by which it can be associated with an identifiable individual, when it is reasonable to assume that:
- The purpose for which the personal data was collected is no longer served by retaining it; and
- Retention is no longer necessary for legal or business purposes.
| Data category | Indicative retention approach |
|---|---|
| Orders, invoices and accounting records | For the period required by applicable French, European or other legal and accounting obligations, which may extend to 10 years for certain records |
| Customer account data | For the life of the account and thereafter for the period reasonably necessary for legal, contractual, fraud-prevention or dispute purposes |
| Customer-service communications | For as long as reasonably necessary to manage the request, complaint, warranty claim or related dispute |
| Fraud-prevention and security information | For the period reasonably necessary to identify, investigate and prevent fraudulent or unlawful activity |
| Cookie and analytics identifiers | For the periods described in the Cookie Policy, consent tool or applicable provider settings, subject to applicable law |
| Marketing subscriptions | Until the individual unsubscribes, withdraws relevant consent or the processing is otherwise discontinued, with limited suppression records retained where appropriate |
| Privacy requests and complaints | For the period necessary to respond to the request and demonstrate compliance with applicable legal obligations |
At the end of the applicable retention period, personal data may be securely deleted, anonymised or archived where continued retention is legally necessary.
9) Privacy Rights
Privacy rights depend on the law applicable to the individual and processing activity.
Requests may be sent to contact@kenshiblades.com. We may take reasonable steps to verify the identity and authority of the person making a request.
9.1) Rights under the Singapore PDPA
Where the Singapore PDPA applies and subject to its exceptions, an individual may request:
- Access to personal data about the individual that is in our possession or under our control;
- Information about the ways in which such personal data has been used or disclosed during the applicable preceding period;
- Correction of an error or omission in personal data held by us.
We will respond to valid access and correction requests in accordance with the timeframes and procedures prescribed by the PDPA and applicable regulations.
Where appropriate, corrected information may also be transmitted to organisations to which the relevant personal data was previously disclosed, as required by the PDPA.
9.2) Withdrawal of Consent
Where processing under the Singapore PDPA relies on consent, an individual may withdraw that consent by giving reasonable notice.
We will inform the individual of the likely consequences of withdrawal where required and will cease the relevant collection, use or disclosure unless continued processing is permitted or required by law.
9.3) GDPR Rights
Where the GDPR applies, individuals may also have rights of:
- Access;
- Rectification;
- Erasure;
- Restriction of processing;
- Objection;
- Data portability where applicable;
- Withdrawal of consent;
- Protection in relation to certain automated decisions;
- Complaint to a competent supervisory authority.
GDPR requests are normally answered within one month, subject to extensions permitted by law.
How to exercise your rights: contact contact@kenshiblades.com and describe your request. Please do not send identity documents unless specifically requested through an appropriate secure method.
10) Data Security and Data Breaches
New kenshi implements reasonable technical and organisational measures designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss or similar risks.
Measures may include HTTPS encryption, access controls, authentication, restricted permissions, secure service providers, monitoring, backups, fraud-prevention systems and confidentiality obligations.
No internet-based service can guarantee absolute security.
Singapore PDPA
Where the Singapore PDPA applies and a data breach occurs, New kenshi will assess whether the breach is notifiable under the applicable statutory criteria.
If a breach is determined to be notifiable to the Personal Data Protection Commission (“PDPC”), notification will be made as soon as practicable and in any event no later than three calendar days after the relevant determination, as required by Singapore law.
Affected individuals will also be notified as soon as practicable where the applicable statutory threshold requiring individual notification is met.
GDPR
Where the GDPR applies and a personal-data breach is likely to result in a risk to individuals' rights and freedoms, the competent supervisory authority will be notified without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Affected individuals will also be informed where the breach is likely to result in a high risk and notification is required by the GDPR.
11) Payment Security
Payments are processed by the payment providers displayed during checkout, which may include Stripe, PayPal, Klarna, Apple Pay or Google Pay.
Payment information is transmitted using secure technologies appropriate to the relevant payment system.
Full payment-card details are not ordinarily stored directly on the New kenshi website servers and are handled by the relevant payment service provider under its own privacy and security terms.
Payment providers may act as independent organisations or controllers for certain processing activities, including fraud prevention, transaction authentication and compliance with legal obligations.
12) Cookies and Similar Technologies
New kenshi may use cookies, pixels, local storage and similar technologies to:
- Provide essential website, security, cart and checkout functions;
- Remember preferences;
- Measure website traffic and performance;
- Detect fraud and security threats;
- Personalise content or advertising where permitted.
Where prior consent is required under the law applicable to a particular technology or processing activity, non-essential technologies subject to that requirement will not be activated before the necessary consent has been obtained.
Where the Singapore PDPA applies, personal data collected through cookies and similar technologies is handled in accordance with the applicable notification, consent, purpose-limitation and protection requirements.
Cookie preferences can be managed through the cookie-management controls available on the website where provided.
For more information, see our Cookie Policy.
13) International Data Transfers
Because NOITAKY Matthieu is established in France and uses international service providers, personal data may be processed in countries other than the country in which the customer is located.
Singapore PDPA
Where the Singapore PDPA's Transfer Limitation Obligation applies to a transfer of personal data outside Singapore, reasonable steps and appropriate legally recognised arrangements will be used to ensure that the transferred personal data receives a standard of protection comparable to the protection required under the PDPA, unless an applicable exception applies.
GDPR
Where personal data subject to the GDPR is transferred outside the European Economic Area to a country that does not benefit from an applicable adequacy decision, an appropriate mechanism under Chapter V of the GDPR will be used where required.
Such mechanisms may include:
- An adequacy decision;
- European Commission Standard Contractual Clauses;
- Binding corporate rules where applicable;
- Another lawful transfer mechanism or applicable derogation.
Additional information about applicable international-transfer safeguards may be requested through contact@kenshiblades.com.
14) Automated Processing and Fraud Prevention
Automated tools may be used to identify suspicious transactions, prevent fraud, protect payments or secure the website.
These tools may be provided by Shopify, payment service providers or specialist fraud-prevention services.
New kenshi does not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects on an individual unless such processing is permitted by applicable law and any required safeguards are provided.
15) Direct Marketing and Singapore Do Not Call Registry
New kenshi may send promotional communications where permitted by applicable law and according to the preferences provided by the recipient.
Marketing emails will include an appropriate means of unsubscribing where required.
For telemarketing messages directed to Singapore telephone numbers, New kenshi will comply with the applicable Do Not Call (“DNC”) provisions of the Singapore PDPA where those provisions apply.
This may include checking the relevant DNC Register before sending specified marketing messages unless a statutory exception applies or the individual has provided the form of clear and unambiguous consent recognised by the PDPA.
Where required, telemarketing communications will identify the organisation and will not deliberately conceal the originating telephone number.
Service communications relating to an existing order, delivery, safety notice, warranty matter or other transaction may be treated differently from promotional marketing under applicable law.
You may also contact contact@kenshiblades.com at any time to request that New kenshi stop sending marketing communications to you.
16) Children's Privacy
The website is not directed specifically at children and is intended for persons with the legal capacity to make purchases.
New kenshi does not knowingly seek to collect personal data from children in circumstances prohibited by applicable law.
A parent or legal guardian who believes that a child has provided personal data improperly may contact contact@kenshiblades.com.
17) Complaints and Regulatory Authorities
If you have a concern about how your personal data has been handled, please contact contact@kenshiblades.com so that we can investigate and attempt to resolve the issue.
Singapore
Personal Data Protection Commission (PDPC)
Address: 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438
An individual may raise an eligible data-protection concern with the PDPC where the Singapore PDPA applies.
The PDPC generally encourages individuals to approach the organisation concerned first to seek clarification or resolution before lodging a complaint.
France / European Union
Commission nationale de l'informatique et des libertés (CNIL)
Website: https://www.cnil.fr/
Because NOITAKY Matthieu is established in France, the CNIL may also be the relevant supervisory authority for processing carried out in the context of that establishment under the GDPR.
18) Additional Privacy Protections for Singapore
Nothing in this Privacy Policy excludes or restricts a privacy right or data-protection obligation that cannot lawfully be excluded where the Singapore PDPA applies.
18.1) Notification
Individuals will be informed of the purposes for which their personal data is collected, used or disclosed where notification is required under the PDPA.
18.2) Purpose Limitation
Personal data will be collected, used and disclosed only for purposes that are reasonable in the circumstances and permitted under the PDPA.
18.3) Accuracy
Reasonable efforts will be made to ensure that personal data is accurate and complete where it is likely to be used to make a decision affecting the individual or disclosed to another organisation.
18.4) Protection
Reasonable security arrangements will be maintained to protect personal data in our possession or under our control.
18.5) Retention Limitation
Personal data will not be retained indefinitely when it is no longer required for the purpose for which it was collected and is no longer required for legal or business purposes.
18.6) Overseas Transfers
Where the Transfer Limitation Obligation applies, overseas transfers will be handled in accordance with the requirements prescribed under the PDPA to provide a comparable standard of protection.
18.7) Access and Correction
Eligible individuals may request access to and correction of their personal data in accordance with the PDPA and applicable exceptions.
18.8) Withdrawal of Consent
Where processing relies on consent under the PDPA, individuals may withdraw consent with reasonable notice. We will explain the likely consequences of withdrawal where required.
18.9) Data Breach Notification
Notifiable data breaches will be reported to the PDPC and affected individuals in accordance with the applicable statutory thresholds and deadlines.
18.10) Seller Established in France
NOITAKY Matthieu is established in France.
The application of particular Singapore PDPA provisions to a cross-border activity depends on the circumstances and scope of the legislation.
Nothing in this Policy is intended to exclude a mandatory Singapore data-protection obligation that applies to the relevant processing activity.
19) Policy Updates
New kenshi may update this Privacy Policy to reflect changes in applicable laws, website functionality, service providers or data-processing practices.
The date of the latest update appears at the top of this page.
Where an amendment requires additional notice, consent or another measure under applicable law, that measure will be implemented as required.
20) Contact
Data controller / organisation: NOITAKY Matthieu
Trading name: New kenshi
Address: 17 rue de l'Amazone, 44470 Carquefou, France
Email / data protection contact: contact@kenshiblades.com