Personal Data Processing Policy
Version dated July 29, 2026
This document explains what data Syneps actually processes, where it is stored, which external services participate in the processing, and how users can exercise control over their data.
This document is still being completed
This version identifies both service owners and provides an email address for privacy requests. Before the policy is finalized, the controllers' legal details and allocation of responsibilities must be completed, together with the remaining legal and technical work.
1. Controllers and scope
This policy applies to Syneps, a B2B service for working with LLM agents, boards, chats, and documents, available at syneps.ai, www.syneps.ai, and staging.syneps.ai. The staging environment may contain data belonging to real users.
The owners of the Syneps service and the personal data controllers identified under this policy are:
- Individual Entrepreneur Vera Petrovna Abramovich, Russian TIN 237303038177, individual entrepreneur registration number 326237500157737; registered in Krasnodar Krai according to the Russian register of individual entrepreneurs.
- Nikita Aleksandrovich Romanov, Russian TIN 366320584539; contact address: 6 Kushelevskaya Road, Building 1, Structure 1, Kalininsky District, Saint Petersburg, Russian Federation.
According to the Russian register of individual entrepreneurs, Nikita A. Romanov ceased operating under individual entrepreneur registration number 322366800034102 on June 27, 2026. Before this policy is finalized, his current legal status must be confirmed, a full contact address for Vera P. Abramovich must be added, and the allocation of responsibilities between the controllers must be documented in writing.
Privacy and personal data protection requests may be sent by email to: romanov.bcz@gmail.com
An additional Syneps contact channel is available on Telegram: @synepswaitlistbot
2. Data we process
The data processed depends on the features used. Syneps may process:
- Account and organization data: internal user and company identifiers, email address, username, first and last name, profile image, company name, description and industry, roles, and access permissions. Google data is also processed when a user signs in with Google; the server technically supports email and password sign-in.
- Workspace content: boards, connections and operations, prompts, system instructions, notes, custom agents, chats and chat history, model outputs, email invitations, and collaboration and presence data.
- Files and documents: uploaded documents, images and attachments, file name, MIME type, size, SHA-256 checksum, extracted text, document fragments, and technical vector representations used for document search. Semantic search is enabled in staging; it is not yet operational in production.
- Voice data: the complete recording of a voice request, up to 120 seconds long, and the resulting transcript.
- Technical data: IP address, browser and device information, cookies and session data, request times, service events, errors, server logs, and authentication data.
- Usage data: selected AI models, token volume and cost, request statistics, operation status, and other information required to measure service usage.
- Payment data is not currently processed in the product. Syneps does not store bank card numbers, CVV/CVC codes, or payment tokens; if payments are enabled, such data must be processed by the payment provider.
3. Data sources and processing purposes
Data is received:
- directly from the user when signing in, completing a profile, working with boards and chats, uploading files, or recording voice input;
- from Google when a user authenticates with a Google account;
- from an organization administrator or another user who invites a person to a workspace or board;
- automatically from the browser, servers, and connected services when the product is used.
Data is used to:
- create and maintain an account, sign users in, verify permissions, and provide invitation-based access;
- store boards, chats, documents, and settings, and provide collaboration and Data Room functionality;
- process requests with language models, recognize speech, search uploaded documents in staging, search public sources for analytical agents, and create images;
- maintain security, prevent abuse, investigate errors, and keep the service operational;
- measure model usage and prepare the product for billing without processing bank card details;
- respond to requests and meet contractual and applicable legal obligations.
4. Legal bases
Depending on the particular scenario, the intended legal bases for processing are:
- the data subject's consent where consent is required by law;
- entering into or performing a contract with a user or corporate customer, or taking steps at the user's request before entering into a contract;
- compliance with legal obligations imposed on the controllers.
Where a corporate customer uploads data to Syneps, that customer may act as an independent controller and Syneps as its processor. The customer is responsible for having a lawful basis to transfer data relating to employees, customers, and other people.
Before this policy is finalized, the service owners must confirm the basis for each processing activity, implement separate consent where required, and document the parties' roles in their contracts.
5. Storage locations and retention
The primary servers, databases, Keycloak authentication system, cache, and user files are hosted on Hetzner infrastructure in Falkenstein, Germany. Files are kept in Hetzner Object Storage in the same region.
Traffic may pass through Timeweb proxy servers in Russia. According to the currently available technical information, these proxies relay traffic and do not retain user data.
Initial collection and storage of Russian citizens' data in a database located in Russia is not currently configured: the operational database is in Germany. There is also no confirmation of the required notifications to Roskomnadzor concerning processing and cross-border transfers. This framework must be brought into compliance with Russian law before the policy is finalized.
The following retention periods are configured for certain technical data:
- account and profile — indefinitely, until deletion is requested;
- authentication session — up to 24 hours;
- signed file link — up to 10 minutes;
- image cache — up to 24 hours;
- vector representation cache — up to 30 days;
- boards and change history, chats, documents, invitations, and statistics — indefinitely, until manual deletion or deletion on request; no automatic period is configured;
- server logs — no configured rotation or automatic deletion period.
Files and documents have no automatic deletion period. When a user or the Syneps team deletes a file, its content is removed from object storage immediately and the technical file record is deleted after 30 days.
Backups are created daily and retained for up to 7 days; Hetzner server snapshots are also used. After operational data is deleted, it may remain in backups for no more than 7 days.
6. External services and cross-border transfers
To perform a feature selected by the user, Syneps may send data to:
- Google — Google authentication and Gemini models;
- OpenAI, Anthropic, and xAI — language model request processing;
- Deepgram — speech recognition; the complete voice recording is sent to the service;
- Google Vertex and Black Forest Labs — image generation;
- xAI — searches public web sources and X (Twitter) for the Analyst, Trend Researcher, and Competitor Content Analyst agents; the search request text is sent to xAI to perform the search.
Depending on the feature, the external service may receive the user's request, system instructions, chat history, board content, fragments of uploaded documents, attachments, and images. When an analytical agent is used, the search request text is also used to search public sources and X. Users should avoid including unnecessary personal or confidential information in requests.
Storage and processing take place in Germany, the United States, and other countries where the selected providers operate. Cross-border transfers are already occurring; there is currently no confirmed record that the required Roskomnadzor notifications have been filed.
Zero-retention settings, a contractual prohibition on training with submitted data, and separate data processing agreements with AI providers have not yet been confirmed. The relevant provider's standard settings and terms apply, so Syneps does not promise that every provider immediately deletes data or refrains from using it to improve its services.
As of publication, Sentry monitoring, invitation email delivery, and production payment processing are not active. DeepSeek is configured in code but is not actually connected.
7. Cookies and browser data
Syneps uses a technical httpOnly session cookie required to sign users in, maintain authentication, and operate the product. It is not used for advertising profiling and cannot be accessed by page JavaScript.
Access and refresh tokens are handled by the server-side BFF and are not stored in browser localStorage or sessionStorage. Up to 40 chat drafts may be stored in localStorage without a separate automatic expiry; users can remove them through their browser settings.
Google Analytics, Yandex Metrica, PostHog, and other marketing analytics systems were not identified in the current version and are not used.
8. User rights and deletion
To the extent provided by applicable law, a user may:
- obtain information about the processing of their personal data and access that data;
- request the correction, restriction, or blocking of inaccurate data;
- request that processing stop and data be deleted where no lawful basis exists to continue processing;
- withdraw consent where processing is based on consent;
- submit a complaint to the controllers, Roskomnadzor, or a court.
There is currently no self-service account deletion control. Requests are handled manually and may require identity verification; data is removed from the authentication system, operational databases, object storage, and caches unless continued retention is required by law. Residual copies of deleted data may remain in backups for up to 7 days.
Requests may be sent to romanov.bcz@gmail.com. The controllers may request information needed to verify the applicant's identity and connection to a Syneps account. Responses will be provided within the time limits established by Russian law.
9. How data is protected
The product uses organizational and technical measures supported by its current architecture:
- HTTPS-encrypted data transfer and restrictive web application security headers;
- Keycloak authentication and role and permission checks;
- access separation between companies, workspaces, and boards;
- short-lived signed links for file access.
No security measure eliminates risk completely. The current framework still requires improvements to log retention, centralized deletion, and contractual safeguards from external providers.
10. AI, sensitive data, and limitations
AI responses are generated automatically and may be incomplete or incorrect. Users must verify results before making legal, financial, medical, or otherwise significant decisions.
Syneps is not intended for the deliberate processing of special categories of personal data or biometric data. Health information, political or religious beliefs, intimate life, criminal records, and biometric templates should not be uploaded without a confirmed need and lawful basis.
The service is intended for business use by adults and is not directed at children.
Users and corporate customers must have a lawful basis for uploading third-party data and must not provide more data than is necessary for the task.
11. Changes to this policy
Syneps will update this policy as features, connected providers, retention periods, and legal arrangements change. A new version will be published at the same address and will apply from the date stated in it.
Until the final version is available, users should check the document date before using the service.