Synca AB | Privacy Policy
Last updated: 2 July 2026
Synca AB, reg. no. 5594457896 ("Synca", "we", "our", or "us"), operating under the brand name Synca, respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard personal data in connection with your use of our website at www.synca.ai (the "Site") and our product and services (the "Services"), and describes your rights and how to exercise them.
Synca AB is located in Stockholm, Sweden, and operates in compliance with Swedish and European Union data protection law, including the General Data Protection Regulation (GDPR).
For information about the cookies and similar technologies we use on the Site, please see our Cookie Policy.
1. Scope of this Privacy Policy — controller vs. processor
Data protection law distinguishes between a controller (who decides why and how personal data is used) and a processor (who only handles data on a controller's behalf). Synca acts in both roles, and this Privacy Policy only covers the situations where we are the controller:
Visitors and users of the Site;
People who create a Synca account or are invited to one;
Prospective customers and their representatives;
Subscribers to our newsletters and updates;
Attendees of our events and webinars; and
Suppliers, partners, and other business contacts.
This Privacy Policy does not apply to the content you or your organization submit into the Services — including documents, files, audio and video you upload, links you add, prompts and chat messages, generated content, and the profile and company information you enter ("Customer Content"). We process Customer Content as a data processor on behalf of the customer (your employer or organization), who is the controller. Our processing of Customer Content is governed by the agreement and Data Processing Agreement (DPA) with that customer. If you are an individual user and have questions about Customer Content, please contact your organization; if we receive a rights request relating to Customer Content, we will forward it to the relevant customer.
2. Information we collect
2.1 Information you provide to us
Account information: name, email address, password (stored only in hashed form), and, where you provide them, phone number, profile picture, job role, and department.
Profile and personalization information: your role, industry, a description of your work, and preferences you set to personalize the Services — which may include information you choose to enter about your clients, competitors, and company context.
Organization information: organization name, size, departments, description, and target audience entered during onboarding.
Communications: information you provide when you contact us for support, sales, or feedback, or when you respond to our emails.
Sign-in via Google or LinkedIn: if you choose to sign in with Google or LinkedIn, we receive your name, email address, and profile picture from that provider, and (for LinkedIn) an authorization that allows you to publish content to your LinkedIn account when you ask us to.
2.2 Information we collect automatically
Log and device data: IP address, browser type and settings, operating system, device identifiers, and the date, time, and nature of your requests.
Usage data: the pages and features you use, actions you take, and time spent in the Site and Services.
Cookies and similar technologies: collected as described in our Cookie Policy.
2.3 Information from optional AI profile enrichment
If you opt in to AI profile enrichment during onboarding or in settings, we send your name and your employer's name to a third-party AI web-research provider (Perplexity) to gather publicly available professional information, which we use to personalize the Services. This feature is off unless you switch it on, and you can turn it off at any time in your settings.
3. How we use your personal data and the legal basis for it
We use personal data only for the purposes described below. For each purpose we set out the legal basis under the GDPR and how long we keep the data.
Provide and operate the Services
Create and manage your account, authenticate you, and deliver the features you use.
Legal basis: Performance of a contract (Art. 6(1)(b)).
Retention: For as long as you have an account, plus a reasonable period afterwards.
Sign-in via Google/LinkedIn and LinkedIn publishing
Authenticate you and publish content to LinkedIn when you request it.
Legal basis: Performance of a contract (Art. 6(1)(b)).
Retention: Until you disconnect the account or delete your Synca account.
AI profile enrichment (optional)
Enrich your profile using third-party web research, when you enable it.
Legal basis: Consent (Art. 6(1)(a)).
Retention: Until you turn the feature off or delete your account.
Support and communications
Respond to your inquiries and send you service messages.
Legal basis: Performance of a contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)).
Retention: Duration of your account or until the matter is resolved.
Security, fraud prevention, and network integrity
Keep the Services and your account safe.
Legal basis: Legitimate interest (Art. 6(1)(f)).
Retention: For as long as you use the Services.
Product analytics and improvement
Understand how the Site and Services are used so we can improve them.
Legal basis: Consent for non-essential analytics cookies (Art. 6(1)(a)); otherwise legitimate interest (Art. 6(1)(f)).
Retention: Pseudonymized; kept no longer than necessary for the purpose.
Marketing communications
Send newsletters and updates about our products and events.
Legal basis: Consent (Art. 6(1)(a)); legitimate interest for existing customers (Art. 6(1)(f)).
Retention: Until you unsubscribe or withdraw consent.
Legal compliance
Meet accounting, tax, and other legal obligations.
Legal basis: Legal obligation (Art. 6(1)(c)).
Retention: As required by law (generally up to 7 years).
Establish or defend legal claims
Protect our legal rights in the event of a dispute.
Legal basis: Legitimate interest (Art. 6(1)(f)).
Retention: Until relevant limitation periods expire.
We do not use automated decision-making that produces legal or similarly significant effects about you.
4. Artificial intelligence and your data
Synca is an AI product, so being clear about AI matters to us.
Providers we use. To deliver AI features (such as chat, content generation, insight extraction, embeddings, recurring reports, and audio transcription), we send the relevant input to trusted AI sub-processors, which today include Amazon Web Services (Amazon Bedrock), Google, OpenAI, Microsoft Azure, Perplexity, Deepgram, Speechmatics, and fal.ai. See our Sub-processor list for the current, complete list.
No training on your data. We do not use your personal data or Customer Content to train our own AI models, and we contractually require that our AI sub-processors do not use it to train or improve their models.
Optional web research. The AI profile enrichment feature described in Section 2.3 sends your name and employer to a third-party research provider and is off unless you enable it.
5. How we share your personal data
We share personal data only as needed and with appropriate safeguards:
Service providers and sub-processors who host, secure, and operate the Services on our behalf (hosting, storage, email, analytics, AI processing, transcription, and web-data retrieval). Our current sub-processors are listed in our Sub-processor list.
LinkedIn, when you choose to publish content to your LinkedIn account.
Other users in your organization, where collaboration or sharing features make certain content visible within your organization.
Legal and safety — where required by law, or to protect our rights, users, or the public.
Business transfers — in connection with a merger, acquisition, or sale of assets.
We do not sell your personal data.
6. International transfers
We host and process personal data primarily within the EU/EEA (our infrastructure runs in EU AWS regions). Some of our AI and technology sub-processors are located outside the EU/EEA. Where personal data is transferred outside the EU/EEA, we ensure an adequate level of protection through appropriate safeguards such as the European Commission's Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, and additional technical and organizational measures.
7. Cookies and tracking
We use cookies and similar technologies on the Site. Strictly necessary cookies (for example, the session cookie that keeps you signed in) are used on the basis of our legitimate interest. Non-essential cookies — including product analytics — are used only with your consent, obtained through our cookie banner. You can withdraw consent at any time. See our Cookie Policy for details.
8. Your rights
Under the GDPR you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
To exercise your rights, contact us at contact@synca.ai. We may need to verify your identity before acting on a request. If your request concerns Customer Content, we will refer it to the relevant customer (controller).
9. Data security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse, including encryption in transit and at rest, access controls, and network monitoring. No system is perfectly secure; if a breach is likely to affect you materially, we will notify you and the relevant authority as required by law.
10. Children's privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. If changes are significant, we will provide a more prominent notice.
12. Contact us
Synca AB Box 3666, 103 59 Stockholm, Sweden Email: contact@synca.ai

