Privacy Policy
This Privacy Policy explains how SynergiX collects, uses, protects and shares personal data, and the rights you have under the GDPR and applicable law.
Contents
1. Introduction 2. Who We Are 3. Scope 4. Data Controller 5. Definitions 6. Our Privacy Principles 7. Contacting Us 8. Categories of Personal Data We Collect 9. How We Collect Personal Data 10. Why We Process Personal Data 11. Legal Basis for Processing (GDPR) 12. Automated Decision Making 13. Sharing of Personal Data 14. International Data Transfers 15. Data Retention 16. Security Measures 17. Your Rights 18. Marketing Communications 19. Children's Privacy 20. Cookies 21. Changes to this Privacy Policy 22. Contact Information1. Introduction
SynergiX OÜ ("SynergiX", "we", "our", or "us") is committed to protecting the privacy, confidentiality, and security of personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, store, protect, and otherwise process personal data when you:
- visit our websites;
- use our software;
- purchase our services;
- subscribe to our SaaS platforms;
- interact with our APIs;
- communicate with us;
- request information;
- receive consulting services;
- use artificial intelligence solutions;
- participate in demonstrations, trials, or beta programs.
Our objective is to process personal data lawfully, fairly, transparently, and securely while complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Estonian legislation, and other applicable privacy laws.
2. Who We Are
This Privacy Policy applies to:
SynergiX OÜ
Registry Code:
17546909
VAT Number:
EE103004563
Registered Office:
Tööstuse tn 75-71
10416 Tallinn
Harju County
Estonia
Website
https://synergix.app
General Contact
hello@synergix.app
Privacy Requests
privacy@synergix.app
Customer Support
support@synergix.app
3. Scope
This Privacy Policy applies to all services operated by SynergiX, including:
- https://synergix.app
- client portals
- SaaS platforms
- AI platforms
- APIs
- automation services
- consulting services
- software development
- cloud infrastructure
- hosted applications
- customer support
- payment processing
- subscription management
- marketing communications
- demonstrations
- beta services
It also applies to all future digital services offered by SynergiX unless expressly stated otherwise.
4. Data Controller
Unless otherwise specified,
SynergiX OÜ acts as the Data Controller regarding personal data collected through our websites and services.
Where we process personal data exclusively on behalf of customers,
our customers may act as Data Controllers,
while SynergiX acts as a Data Processor under applicable Data Processing Agreements.
5. Definitions
For purposes of this Privacy Policy:
Personal Data
means any information relating to an identified or identifiable natural person.
Processing
means any operation performed on Personal Data,
including collection,
storage,
organisation,
analysis,
transfer,
consultation,
modification,
deletion,
or destruction.
Customer
means any individual,
company,
organisation,
or other legal entity using our Services.
User
means any individual accessing our Services,
whether as a visitor,
customer,
employee,
contractor,
or authorised representative.
Services
means every product,
software platform,
AI service,
API,
website,
application,
automation,
consulting engagement,
subscription,
or digital solution offered by SynergiX.
6. Our Privacy Principles
SynergiX processes Personal Data according to the following principles:
- lawfulness;
- fairness;
- transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity;
- confidentiality;
- accountability.
These principles guide every aspect of our data processing activities.
7. Contacting Us
General enquiries may be sent to:
hello@synergix.app
Customer support requests may be submitted to:
support@synergix.app
8. Categories of Personal Data We Collect
Depending on the nature of your interaction with SynergiX, we may collect the following categories of Personal Data.
8.1 Identity Information
We may collect information such as:
- full name;
- company name;
- job title;
- username;
- account identifier;
- government-issued identification where legally required;
- VAT identification numbers where applicable.
8.2 Contact Information
Including:
- email address;
- telephone number;
- billing address;
- registered business address;
- country;
- state or province;
- city;
- postal code.
8.3 Account Information
When you create an account or subscribe to our Services we may collect:
- account credentials;
- authentication information;
- security settings;
- account preferences;
- subscription details;
- customer identifiers.
Passwords are never stored in plain text.
8.4 Payment Information
Payments are processed by regulated payment providers such as Stripe.
Depending on the transaction we may receive:
- payment status;
- invoice information;
- billing country;
- VAT information;
- payment identifiers;
- transaction references.
SynergiX does not store complete payment card numbers or card security codes.
8.5 Technical Information
When accessing our Services we may automatically collect technical information including:
- IP address;
- browser type;
- browser version;
- operating system;
- language preferences;
- time zone;
- device identifiers;
- session identifiers;
- network information;
- error logs;
- diagnostic information.
8.6 Usage Information
We may collect information regarding how our Services are used, including:
- pages visited;
- navigation paths;
- session duration;
- clicks;
- features used;
- API requests;
- software usage;
- subscription activity;
- service interactions.
8.7 Communications
When communicating with SynergiX we may process:
- emails;
- support tickets;
- live chat conversations;
- contact forms;
- telephone communications;
- meeting invitations;
- project documentation.
8.8 Artificial Intelligence Interactions
Where Customers use AI-powered Services, we may process:
- prompts;
- instructions;
- uploaded documents;
- generated outputs;
- conversation history where necessary to provide the Service.
Customers should avoid submitting confidential or regulated information unless the Service has been specifically designed for that purpose.
8.9 Customer Content
Customers may voluntarily upload:
- documents;
- databases;
- images;
- spreadsheets;
- presentations;
- source code;
- contracts;
- business records;
- datasets;
- configuration files.
Ownership of Customer Content remains with the Customer.
9. How We Collect Personal Data
We collect Personal Data through multiple channels.
9.1 Information You Provide
Including when you:
- contact us;
- request information;
- request a quotation;
- purchase Services;
- subscribe;
- register an account;
- upload files;
- request support;
- communicate with us.
9.2 Automatic Collection
Certain technical information is collected automatically through:
- cookies;
- server logs;
- security monitoring;
- authentication systems;
- browser technologies;
- APIs.
9.3 Third Parties
We may receive information from trusted third parties including:
- payment processors;
- cloud providers;
- CRM platforms;
- authentication providers;
- analytics providers;
- fraud prevention services;
- public business registries where legally permitted.
10. Why We Process Personal Data
We process Personal Data only where necessary for legitimate business purposes.
Purposes include:
- providing Services;
- creating customer accounts;
- authenticating users;
- processing payments;
- issuing invoices;
- managing subscriptions;
- delivering software;
- providing technical support;
- communicating with Customers;
- improving our Services;
- maintaining security;
- preventing fraud;
- complying with legal obligations;
- enforcing contractual rights;
- developing new Services;
- training internal systems where legally permitted.
11. Legal Basis for Processing (GDPR)
Where the GDPR applies, SynergiX processes Personal Data under one or more of the following legal bases.
Performance of a Contract
Processing necessary to:
- deliver purchased Services;
- provide customer support;
- process subscriptions;
- manage accounts;
- fulfil contractual obligations.
Legitimate Interests
Processing necessary for legitimate interests including:
- improving Services;
- cybersecurity;
- fraud prevention;
- product development;
- business administration;
- internal analytics;
- service optimisation.
Where required, legitimate interest assessments are performed.
Legal Obligations
Processing necessary to comply with:
- accounting obligations;
- tax obligations;
- anti-money laundering requirements;
- court orders;
- regulatory requirements.
Consent
Where required,
processing is based upon your consent,
including:
- marketing communications;
- optional cookies;
- newsletters;
- promotional emails.
Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
Protection of Vital Interests
In exceptional circumstances,
Personal Data may be processed where necessary to protect the vital interests of an individual.
Public Interest
Where applicable,
processing may occur where authorised by law for reasons of substantial public interest.
12. Automated Decision Making
SynergiX does not make decisions producing legal or similarly significant effects based solely on automated processing unless:
- legally authorised;
- contractually necessary;
- or based upon your explicit consent where required.
Where AI technologies assist decision-making, appropriate human oversight is maintained whenever reasonably necessary.
13. Sharing of Personal Data
SynergiX respects the confidentiality of Personal Data and does not sell, rent, trade, or otherwise commercialize Personal Data to third parties.
Personal Data is disclosed only where necessary to provide our Services, comply with legal obligations, protect our legitimate interests, or where disclosure has been authorized by the Customer.
Depending on the Services requested, Personal Data may be shared with carefully selected service providers acting on our behalf.
13.1 Payment Processing
To securely process payments, subscriptions, invoices, and financial transactions, SynergiX uses regulated payment service providers.
These providers may process:
- Customer name
- Billing address
- Company information
- VAT number
- Payment amount
- Currency
- Transaction identifiers
- Payment status
- Fraud prevention information
Payment card information is processed directly by the payment processor.
SynergiX never stores complete payment card numbers, CVV codes, or sensitive authentication data.
Our primary payment processor is:
Stripe, Inc.
https://stripe.com
Stripe operates as an independent Data Controller regarding payment processing and applies its own Privacy Policy and security controls.
13.2 Cloud Infrastructure
To provide reliable Services, SynergiX may host data and applications using enterprise cloud providers including:
- Amazon Web Services (AWS)
- Google Cloud Platform (GCP)
- Microsoft Azure
- Vercel
depending on the specific product or service.
These providers may process infrastructure-related information necessary to:
- host applications;
- maintain availability;
- provide backups;
- improve performance;
- ensure disaster recovery;
- maintain network security.
13.3 Artificial Intelligence Providers
Certain Services incorporate Artificial Intelligence technologies.
Depending on the solution selected by the Customer, Personal Data may be processed using providers including:
- OpenAI
- Anthropic
- other enterprise AI providers approved by SynergiX.
Such providers may process prompts, uploaded documents, instructions and generated outputs exclusively for the purpose of providing the requested AI functionality.
Customers are responsible for ensuring they have the legal authority to submit any information entered into AI-powered Services.
SynergiX recommends that Customers avoid submitting highly confidential or regulated information unless the Service has been specifically designed and contracted for that purpose.
13.4 Communication Providers
Business communications may be processed through providers including:
- Google Workspace
- Microsoft 365
- Resend
- Brevo
or equivalent enterprise communication platforms.
These providers may process:
- email addresses;
- message content;
- delivery confirmations;
- technical delivery logs;
solely for communication and operational purposes.
13.5 Security Providers
To protect our infrastructure, Personal Data may be processed by security providers including:
- Cloudflare
- authentication providers;
- firewall providers;
- monitoring platforms;
- logging systems;
- fraud detection providers.
Such processing helps us detect:
- malicious activity;
- unauthorized access;
- cyberattacks;
- abuse of our Services;
- fraud.
13.6 Analytics
Where analytics are enabled, SynergiX may use privacy-conscious analytics providers including:
- Google Analytics;
- privacy-focused analytics platforms;
- internal analytics systems.
Analytics information may include:
- pages visited;
- session duration;
- browser information;
- operating system;
- referring pages;
- interactions with Services.
Where legally required, analytics cookies are only activated after obtaining valid consent.
13.7 Professional Advisors
Personal Data may be shared where reasonably necessary with:
- legal counsel;
- accountants;
- auditors;
- tax advisors;
- compliance consultants;
provided such parties are subject to appropriate confidentiality obligations.
13.8 Regulatory Authorities
Personal Data may be disclosed where required:
- by applicable law;
- court order;
- governmental authority;
- tax authority;
- regulatory investigation;
- anti-money laundering obligations;
- fraud investigations.
Only the minimum information necessary will be disclosed.
13.9 Corporate Transactions
If SynergiX undergoes:
- merger;
- acquisition;
- restructuring;
- financing;
- investment transaction;
- sale of assets;
Personal Data may be transferred as part of that transaction subject to appropriate confidentiality obligations and applicable law.
14. International Data Transfers
Because SynergiX provides Services internationally, Personal Data may be processed in countries outside the European Economic Area ("EEA").
Whenever Personal Data is transferred internationally, SynergiX ensures that an appropriate legal transfer mechanism is in place.
Depending on the destination country, these safeguards may include:
- European Commission Adequacy Decisions;
- Standard Contractual Clauses ("SCCs");
- approved contractual safeguards;
- technical and organizational security measures;
- encryption;
- contractual confidentiality obligations.
SynergiX continuously monitors international transfer requirements and updates its practices where necessary to remain compliant with applicable privacy legislation.
15. Data Retention
SynergiX retains Personal Data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, and protect legitimate business interests.
Retention periods may vary depending on the type of information processed.
As a general guideline:
When retention is no longer required, Personal Data is securely deleted, anonymized, or otherwise rendered permanently inaccessible.
16. Security Measures
Protecting Personal Data is one of SynergiX's highest priorities.
We maintain commercially reasonable technical and organizational measures designed to safeguard Personal Data against unauthorized access, accidental loss, alteration, disclosure, or destruction.
Depending on the Service, these measures may include:
- encrypted communications (TLS);
- encryption of data at rest where appropriate;
- multi-factor authentication (MFA);
- role-based access controls;
- least-privilege access principles;
- infrastructure monitoring;
- audit logging;
- vulnerability management;
- backup procedures;
- disaster recovery planning;
- endpoint protection;
- periodic security reviews.
While we continuously improve our security posture, no Internet-connected system can be guaranteed to be completely secure. Customers are also responsible for implementing appropriate security measures within their own environments.
17. Your Rights
Subject to applicable law, you may have the right to:
- access your Personal Data;
- request correction of inaccurate information;
- request deletion of Personal Data;
- restrict processing;
- object to certain processing activities;
- request portability of your data;
- withdraw consent where processing is based on consent;
- lodge a complaint with the competent supervisory authority.
Requests may be submitted to:
privacy@synergix.app
We will respond within the timeframes required by applicable law.
18. Marketing Communications
Where legally permitted, SynergiX may send information regarding:
- new Services;
- product updates;
- educational materials;
- security notifications;
- newsletters;
- commercial offers.
Recipients may unsubscribe at any time using the unsubscribe link included in our communications or by contacting us directly.
Operational communications relating to active Services, security, billing, or contractual obligations may continue where necessary.
19. Children's Privacy
Our Services are intended primarily for businesses and professionals.
They are not directed toward children under the age required by applicable law.
SynergiX does not knowingly collect Personal Data from children.
If we become aware that Personal Data relating to a child has been collected without appropriate authorization, we will take reasonable steps to delete such information promptly.
20. Cookies
Our use of cookies and similar technologies is governed by our separate Cookie Policy available at:
https://synergix.app/cookies
21. Changes to this Privacy Policy
SynergiX may update this Privacy Policy from time to time to reflect changes in:
- legislation;
- regulatory requirements;
- technology;
- business operations;
- new Services.
Material changes will be published on our website together with an updated Effective Date.
Continued use of the Services following publication constitutes acceptance of the updated Privacy Policy where permitted by law.
22. Contact Information
For any questions regarding this Privacy Policy or the processing of Personal Data, please contact:
SynergiX OÜ
Website: https://synergix.app
General Enquiries: hello@synergix.app
Customer Support: support@synergix.app
Registered Office:
Tööstuse tn 75-71
10416 Tallinn
Harju County
Estonia
Registry Code: 17546909
VAT Number: EE103004563
Questions about this document? Contact hello@synergix.app.