Privacy Policy
Comprehensive details on data collection, processing, user rights under GDPR, CCPA, and the Indian DPDP Act 2023.
Privacy Policy
Effective Date: July 26, 2026
1. Introduction
Welcome to Synaps ("Company", "we", "us", or "our"). Synaps is an Enterprise Intelligence Platform and Digital Twin system. We are committed to protecting your organizational and personal privacy in accordance with applicable global privacy laws, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and the Indian Digital Personal Data Protection Act (DPDP Act 2023).
This Privacy Policy explains how we collect, process, store, and safeguard your data when you use our SaaS application, enterprise memory graph, and related services (collectively, the "Services").
2. Information We Collect
We collect data directly provided by your organization, automatically logged through application telemetry, or submitted via third-party integrations:
- Account & Identity Data: Full name, corporate email address, role, organization name, authentication credentials (managed via secure Firebase Auth and SSO tokens).
- Uploaded Enterprise Content: Documents (PDFs, DOCX, CSVs), meeting transcripts, proposals, contracts, SOPs, and decisions uploaded to the Enterprise Memory Graph.
- Usage & Telemetry Data: IP addresses, browser user-agent, session timestamps, feature usage, API requests, and audit logs.
- Billing Information: Corporate billing contact details, invoice addresses, and payment references (processed via PCI-DSS compliant third-party payment gateways).
3. Legal Basis & How We Use Data
We process your personal data under the following legal bases:
- Performance of Contract: To operate the Synaps Enterprise Digital Twin OS, fulfill customer queries, and manage enterprise tenants.
- Legitimate Interests: To prevent security vulnerabilities, optimize graph RAG performance, and audit compliance.
- Legal Obligations: To maintain audit records for tax, financial reporting, and regulatory disclosures.
Zero Model Training Promise: Synaps does NOT use customer's uploaded enterprise documents, proprietary knowledge graphs, or private data to train public LLM models.
4. Regional Privacy Rights (Global Compliance)
A. European Union & United Kingdom (GDPR / UK GDPR)
Under GDPR Articles 15-22 and UK GDPR, EU and UK data subjects have the right to:
- Access personal data we hold about you (Article 15).
- Rectify inaccurate data (Article 16).
- Erase personal data ("Right to be Forgotten") (Article 17).
- Restrict processing in certain circumstances (Article 18).
- Data portability in JSON/CSV format (Article 20).
- Object to processing based on legitimate interests (Article 21).
- Lodge a complaint with your national supervisory authority or the UK ICO.
B. California Residents (CCPA / CPRA)
California residents have the right to know what personal information is collected, request deletion, opt-out of the sale/sharing of personal data (Synaps does NOT sell personal data), correct inaccurate data, and receive non-discriminatory treatment. Exercise rights: novaecosystems@gmail.com — Subject: "CCPA Privacy Request".
C. Other US States (Virginia, Colorado, Connecticut, Texas)
Residents of these states have similar rights to access, delete, correct, and opt out of targeted advertising under their respective state privacy laws.
D. India (DPDP Act 2023)
Pursuant to the Digital Personal Data Protection Act 2023, Indian Data Principals have the right to obtain a summary of personal data processed, correct or erase personal data, nominate a representative, withdraw consent at any time, and register grievances with our Grievance Officer (72-hour acknowledgement, 30-day resolution).
E. Canada (PIPEDA + Quebec Law 25)
Canadian residents have the right to access, correct, and request deletion of personal information, and lodge complaints with the Office of the Privacy Commissioner of Canada (OPC).
F. Australia (Privacy Act 1988 - Australian Privacy Principles)
Australian individuals have the right to access (APP 12) and correct (APP 13) personal information, and lodge complaints with the Office of the Australian Information Commissioner (OAIC).
G. Singapore (PDPA 2012)
Singapore residents have the right to access, correct, and withdraw consent for data collection, and lodge complaints with the Personal Data Protection Commission (PDPC).
5. Data Retention & Deletion
We retain enterprise data only for the duration of your active subscription or as legally required:
- Active Customer Data: Retained for the lifecycle of the enterprise organization account.
- Deleted Tenant Data: Permanently purged within 30 days of account termination.
- Audit Logs: Preserved for 365 days for legal and regulatory compliance.
- Payment Records: Retained for 7 years as required by financial regulations across India, EU, USA, and Australia.
To request early data deletion, email: novaecosystems@gmail.com — Subject: "Data Deletion Request".
6. Sub-Processors & Integrations
Synaps partners with verified sub-processors (see our full Data Processing Agreement):
- Cloud Infrastructure: Google Cloud Platform (GCP) — primary compute and database hosting.
- Authentication: Firebase Authentication (Google Cloud) — session management.
- Storage: Supabase Inc. — encrypted document blob storage.
- Payments: LemonSqueezy (Merchant of Record) — PCI-DSS Level 1 compliant.
- AI Inference: Groq Inc. & Google Gemini — zero data retention API usage.
- Analytics: Vercel Web Analytics — anonymised, aggregate usage data only.
7. Contacting Our Data Protection Officer (DPO)
To exercise your rights or ask questions about this Privacy Policy:
- Email: novaecosystems@gmail.com
- Subject Line: "Privacy Request — [Your Right] — [Your Country]"
- Postal Address: Synaps AI Legal & Compliance Dept., Pune, Maharashtra 411001, India
- Response SLA: 72-hour acknowledgement — 30-day resolution (GDPR/DPDP) — 45 days (CCPA)