Privacy Policy
Scope. This policy describes the personal data Synorix processes as a controller: data about visitors to synorix.ai and about people who submit a beta enrollment request. Personal data that Synorix processes on behalf of a customer organisation inside the platform — the content its users submit, and anything an agent reads or writes on a connected service at their instruction — is processed as a processor, on that organisation’s documented instructions, under the Data Processing Agreement and its Annex III. This policy does not govern that processing. Section 13 below describes what is collected when an individual user connects a third-party account.
1. Data Controller and Contact
SynorixAI OÜ (registry code 17519396), Telliskivi tn 57, 10412 Tallinn, Estonia. Email: [email protected]. We aim to respond to all privacy requests within 30 days.
2. Types of Data We Collect
We collect two categories of data: (a) Website interaction data: IP address, browser type, pages visited, and interaction patterns (collected via standard web server logs and analytics tools, only with consent). (b) Enrollment data: when you submit a beta enrollment request, we collect company name, your name, work email, phone number, job title, and any details you provide in your message. Neither category includes your organization’s operational or internal business data: Synorix does not collect such data as a controller, and nothing on this website reads your files, systems, workflows or databases. Where your organization’s data is processed inside the platform, Synorix acts as a processor under the DPA — see Scope above and section 13.
3. Legal Basis for Processing (GDPR Art. 6)
(a) Consent — enrollment form submission and analytics cookies. (b) Legitimate interest — website security and service improvement. (c) Contractual necessity — delivering the beta service to accepted participants.
4. How We Use Your Data
Website interaction data: analytics and security monitoring only. Enrollment data: evaluating your application, communicating enrollment decisions, delivering the beta service. We do NOT use your data for marketing, profiling, or selling to third parties.
5. Data Retention
Website interaction logs: 90 days, then automatically deleted. Enrollment data: duration of beta participation + 30 days after termination or rejection, then permanently deleted. During the 30-day period, you may request a data export at no cost.
6. Data Sharing and Third Parties
We do NOT sell your data. We may share data only with: (a) Essential service providers (cloud hosting, email delivery) who are contractually bound to protect your data. (b) Legal authorities, if required by law or court order. (c) A successor entity, in case of acquisition or merger (you will be notified in advance). These are the recipients of the data covered by this policy. The sub-processors Synorix engages for the platform — including AI model providers — are a separate matter, governed by the DPA and listed in its Annex III.
7. Data Security
We apply industry-standard technical and organizational measures: encryption in transit (TLS), secure storage, and access controls. In case of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
8. Your Rights (GDPR)
You have the right to: access, rectify, erase, restrict processing, data portability, and object. To exercise any right, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee) or your local supervisory authority.
9. Cookies and Tracking
We use: Essential cookies: required for site functionality. Analytics cookies: only loaded after your consent via the cookie banner. We do NOT use advertising cookies, cross-site tracking, fingerprinting, or pixel tracking. You can withdraw consent at any time by clicking “Essential only” in the cookie banner.
10. International Data Transfers
The website and enrollment data covered by this policy is processed within the EU/EEA. Any transfer of that data outside the EU/EEA is made under an appropriate safeguard pursuant to Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses. Transfers arising from the platform’s sub-processors are outside this policy: they are governed by the DPA, which states the safeguard applicable to each and does not represent a safeguard as in place where it is still pending.
11. Changes to This Policy
We may update this policy periodically. The “last updated” date at the top reflects any changes. For material changes, beta participants will be notified by email.
12. Supervisory Authority
Data protection matters are handled by the controller named in section 1 and can be raised at [email protected]. Residents of the EU/EEA have the right to lodge a complaint with their local data protection authority if they believe we are not complying with their privacy rights.
13. Third-Party Integrations
When you connect a third-party account or service (for example Google, Microsoft 365, LinkedIn, Notion, Slack, or any other connector we offer now or in the future) through the platform settings, the following applies to each such integration. Data collected via OAuth: the account profile information that the provider exposes (which may include your name, email address, account or member ID, and profile URL) and the access and refresh tokens issued by that provider. How we use this data: to identify the connected account within the platform, to display its connection status, and to perform actions on that service only when you explicitly instruct a Synorix AI agent to do so (for example sending a message, publishing content, or reading a document you point it to). Storage: access tokens are encrypted at rest using AES-256-GCM on servers hosted within the EU. Revocation: you can disconnect any integration at any time from Settings → Integrations → [provider] → Disconnect. Upon disconnection, the associated tokens and profile data are permanently deleted. What we do not do: we do not sell, share, or transfer your integration data to any third party; we do not access your data beyond what is required to carry out the specific action you request; and we never act on a connected service without an explicit instruction from you.
14. Contact
SynorixAI OÜ · [email protected] · Telliskivi tn 57, 10412 Tallinn, Estonia