Official notice · Effective 11 July 2026

Privacy & GDPR Notice

This notice explains how Synderesis processes personal data when you use synderesis.eu, create an account, manage API keys, or call the Synderesis service. It is written for clarity; it is still a legal notice, not marketing copy.

Controller: Synderesis, the operator of synderesis.eu

Privacy contact: hello@synderesis.eu

Data Protection Officer: no DPO has been appointed at this stage; use the privacy contact above.

Related reading: Resources · Catholic AI FAQ · Home

1. Data we process

Account dataEmail address and, if supplied, name and organisation. We retain an irreversible password hash, never the password itself.
Security credentialsHashed browser-session identifiers, CSRF-protection values, API-key hashes, key prefixes, status, and expiry information. A plaintext API key is displayed only when created.
Service contentQuestions, instructions, source references, model responses, and conversation identifiers you send. Stored conversation content is retained only when the relevant request enables conversation storage.
Usage and security dataRequest time, endpoint, model, token and request counts, cost estimates, response status, latency, and limited infrastructure logs such as IP address and user agent processed by hosting providers.
Consent recordThe time at which you explicitly consented to processing sensitive information you choose to submit, including information that may reveal religious beliefs.

2. Purposes and legal bases

Providing an email address and password is necessary to create an account. Prompt content is necessary only when you ask the service to produce a response. You are not required to include sensitive personal data in a prompt.

3. Recipients and processors

We disclose data only as needed to operate the service. Current categories of recipients include cloud hosting and repository infrastructure (including Hugging Face), upstream model and inference providers selected for the Synderesis backend, and professional advisers or authorities where legally required. Prompt content may be sent to the configured model providers to generate a response.

Where another organisation provides Synderesis to its staff, customers, or members, that organisation may be a separate controller or processor for its use of the API. Its own privacy notice may also apply.

4. International transfers

Some processors may operate outside the European Economic Area. Where personal data is transferred to a country without an EU adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and assess supplementary measures as required. You may request information about the safeguard through the privacy contact.

5. Retention

6. Account deletion and your rights

The account dashboard includes a self-service Delete account action. After password confirmation, it immediately removes the active account record, sessions, API keys, usage events, prompt-improvement rows, quota reservations, and stored conversation messages from the Synderesis application database.

Subject to the conditions in the GDPR, you may ask for access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out lawfully. Contact hello@synderesis.eu. We will respond without undue delay and normally within one month.

You also have the right to lodge a complaint with the data-protection authority in the EU/EEA country of your habitual residence, place of work, or the place of the alleged infringement.

7. Security

We use transport encryption, Argon2id password hashing, hashed API keys and session tokens, HttpOnly cookies, CSRF protection, rate limiting, access controls, and data minimisation. No internet service is risk-free; please do not submit personal data that is unnecessary for your request.

8. Cookies

We use only strictly necessary first-party cookies for an authenticated browser session and CSRF protection. They expire after seven days or are removed when you sign out. We do not currently use advertising or cross-site tracking cookies.

9. Automated decision-making and children

Synderesis generates text using automated models, but the consumer account service does not make decisions producing legal or similarly significant effects about you. The service is not directed to children, and account holders must be at least 18 years old or have authority under applicable law.

10. Changes

We may update this notice when the service, processors, or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through the service where appropriate.