Privacy Policy — Syntra Platform
DRAFT FOR COUNSEL REVIEW · v0.9 · [DATE]
This policy explains how [SYNTRA ENTITY] ("Syntra", "we") processes personal data in connection with the Syntra platform and website. It is written for GDPR and applies to all users. Contact: [privacy@syntra…]; [DPO name/contact, if appointed].
1. Two roles — read this first
Where we decide, we are the controller. For platform accounts, billing, support, website visits and marketing, Syntra is the data controller, and this policy applies in full. Where your organisation decides, we are the processor. Assessment content and the evidence vault belong to the client organisation (your employer or its group): the client is the controller, Syntra processes only on its documented instructions under the Data Processing Agreement. For questions about that data — including your rights in evidence documents that mention you — contact the client organisation; we support them in responding.
2. What we collect as controller
- Account data: name, business e-mail, role, organisation, authentication data (MFA), language and preferences.
- Usage events: logins, feature events, error diagnostics. We never analyse the content of assessments or evidence for our own purposes — telemetry is event- and metadata-only.
- Billing data: invoicing details of the client entity; payment card data is handled by our payment processor and never stored by us.
- Support and correspondence: what you send us.
- Website data: see the Cookie Policy — essential cookies plus opt-in, anonymised analytics; no advertising trackers.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the platform, authentication, support | Contract performance (Art. 6(1)(b)) |
| Security, abuse prevention, audit logging | Legitimate interest (Art. 6(1)(f)) — platform and client protection |
| Billing, accounting, tax | Legal obligation (Art. 6(1)(c)) |
| Product analytics (event-level) | Consent (Art. 6(1)(a)), withdrawable in settings |
| Aggregated, anonymised calibration statistics | Consent at tenant level (see DPA); aggregate-only, no identifiers |
| Service announcements | Contract performance; marketing only with consent/soft opt-in, opt-out in every message |
4. Where data lives
All storage, computation and backups are in EU regions. Sub-processors are EU-based or covered by appropriate safeguards (standard contractual clauses with documented transfer assessments); the current list is published in the Sub-Processor Register, with notice before changes.
5. Retention
Account data: for the account's life and [24] months after; billing records: statutory periods; support: [24] months; telemetry: [12] months, then aggregate only. Assessment content and evidence follow the client's configured retention (processor role — see DPA).
6. Your rights
Access, rectification, erasure, restriction, portability, and objection (for legitimate- interest processing), plus withdrawal of any consent — via [privacy@syntra…] or in-product settings. We respond within one month. You may complain to your supervisory authority ([AEPD, Spain / Poverenik, Serbia — align with entity]).
7. Security
Encryption in transit and at rest, per-tenant keys, tenant-sealed evidence vault, mandatory MFA, immutable access logging, EU residency, tested backups, breach response with notification duties honoured without undue delay. Details: Security Annex to the DPA.
8. Automated decision-making
The assessment engine is deterministic software applying a published methodology to inputs your organisation provides; it makes no automated decisions producing legal effects on individuals. Optional AI add-ons operate on anonymised data, assist human users, and never score, classify or conclude.
9. Changes
Material changes are announced in-product and by e-mail at least 30 days in advance.