Privacy & GDPR Notice
This notice explains how Synderesis processes personal data when you use synderesis.eu, create an account, manage API keys, or call the Synderesis service. It is written for clarity; it is still a legal notice, not marketing copy.
1. Data we process
2. Purposes and legal bases
- Provide your account, API access, responses, usage information, and support: performance of a contract or steps you ask us to take before entering one (GDPR Article 6(1)(b)).
- Protect accounts, prevent abuse, meter service use, diagnose failures, and establish or defend legal claims: our legitimate interests in operating a secure and reliable service (Article 6(1)(f)).
- Process special-category information you voluntarily place in prompts or stored conversations: your explicit consent (Article 9(2)(a)). You may withdraw consent for future processing by stopping submission of that information and deleting stored conversations or your account.
- Meet tax, accounting, regulatory, or lawful authority requirements: compliance with a legal obligation where applicable (Article 6(1)(c)).
Providing an email address and password is necessary to create an account. Prompt content is necessary only when you ask the service to produce a response. You are not required to include sensitive personal data in a prompt.
3. Recipients and processors
We disclose data only as needed to operate the service. Current categories of recipients include cloud hosting and repository infrastructure (including Hugging Face), upstream model and inference providers selected for the Synderesis backend, and professional advisers or authorities where legally required. Prompt content may be sent to the configured model providers to generate a response.
Where another organisation provides Synderesis to its staff, customers, or members, that organisation may be a separate controller or processor for its use of the API. Its own privacy notice may also apply.
4. International transfers
Some processors may operate outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess supplementary measures as required. You may request information about the safeguard through the privacy contact.
5. Retention
- Account profile, consent record, API-key metadata, usage events, and stored conversations remain until you delete the account or the data is no longer necessary.
- Browser sessions expire after seven days and can be ended earlier by signing out.
- Revoked key hashes remain with the account so status and metering records can be understood; they are erased with account deletion.
- Operational question/answer improvement records are collected only when that server-side feature is expressly enabled and are normally limited to 30 days.
- Security and infrastructure logs are normally retained for no more than 30 days, except where a longer period is necessary to investigate an incident or comply with law. Processor-controlled backup copies, if any, are removed or overwritten under the relevant processor retention schedule.
6. Account deletion and your rights
The account dashboard includes a self-service Delete account action. After password confirmation, it immediately removes the active account record, sessions, API keys, usage events, prompt-improvement rows, quota reservations, and stored conversation messages from the Synderesis application database.
Subject to the conditions in the GDPR, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out lawfully. Contact hello@synderesis.eu. We will respond without undue delay and normally within one month.
You also have the right to lodge a complaint with the data-protection authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.
7. Security
We use transport encryption, Argon2id password hashing, hashed API keys and session tokens, HttpOnly cookies, CSRF protection, rate limiting, access controls, and data minimisation. No internet service is risk-free; please do not submit personal data that is unnecessary for your request.
8. Cookies
We use only strictly necessary first-party cookies for an authenticated browser session and CSRF protection. They expire after seven days or are removed when you sign out. We do not currently use advertising or cross-site tracking cookies.
9. Automated decision-making and children
Synderesis generates text using automated models, but the consumer account service does not make decisions producing legal or similarly significant effects about you. The service is not directed to children, and account holders must be at least 18 years old or have authority under applicable law.
10. Changes
We may update this notice when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service where appropriate.