Privacy Policy

Last updated: March 5, 2026

1. Data Controller

Synks ("we", "us", "our") is the data controller for personal data processed through our platform. If you have questions about how we handle your data, contact us at hello@synks.io.

2. Information We Collect

We collect the following categories of personal data: • Account information: Name, email address, profile data, and role/permissions you provide when creating an account or being invited to a team workspace. • Content data: Files (images, videos, documents, websites, 3D models, Figma designs), comments, annotations, drawings, voice recordings, chat messages, checklists, and other content you upload or create on our platform. • Project data: Project names, descriptions, customer names, file statuses, approval workflows, time entries, revenue data, invoices, and Gantt timeline tasks. • Team data: Workspace names, team member roles, permissions, and invitation records. • Integration data: Connection tokens and configuration for third-party services you link (Google Drive, Dropbox, Slack, Microsoft Teams, Discord, Monday.com, Gmail, Google Calendar, Figma). We store OAuth tokens to maintain your connections. • Usage data: IP addresses, browser type, device information, pages visited, features used, and interaction data. • Payment data: Billing information processed securely through our payment provider (Stripe). We do not store full credit card numbers. • Communication data: Messages you send us through support or contact forms. • Guest reviewer data: Name and optional avatar selection provided by guest reviewers when leaving feedback via shared review links. • AI interactions: Prompts and responses when using the AI assistant feature. • Cookies and similar technologies: See our Cookie Policy for full details.

3. Legal Basis for Processing (GDPR Article 6)

We process your personal data based on the following legal grounds: • Contract performance (Art. 6(1)(b)): Processing necessary to provide our services, manage your account, process payments, deliver integrations, and provide the features you use. • Legitimate interest (Art. 6(1)(f)): Processing for security, fraud prevention, service improvement, and aggregated analytics. We balance our interests against your rights and freedoms. • Consent (Art. 6(1)(a)): For optional analytics cookies, marketing communications, and non-essential data processing. You can withdraw consent at any time. • Legal obligation (Art. 6(1)(c)): Where we are required to retain data by law (e.g., tax and accounting records).

4. How We Use Your Information

We use your personal data to: • Provide, maintain, and improve our platform and services • Process transactions and manage your subscription (Free, Pro, and Business plans) • Facilitate team collaboration, project management, and client review workflows • Connect and sync with third-party integrations you authorize • Send notifications about comments, approvals, team invitations, and project updates • Power the AI assistant to help manage your projects and tasks • Communicate with you about your account, updates, and support requests • Ensure the security and integrity of our platform • Comply with legal obligations • Generate aggregated, anonymized analytics (which are no longer personal data)

5. Data Sharing & Third-Party Processors

We do not sell your personal data. We share data only with trusted third-party service providers ("data processors") who assist in operating our platform: • Hosting & infrastructure: Cloud hosting providers (data stored within the EU/EEA where possible) • Payment processing: Stripe (PCI-DSS compliant) • Email services: For transactional emails (comment notifications, team invitations, invoice delivery, approved file notifications) • AI providers: For processing AI assistant requests (prompts are sent to third-party AI models) • Analytics: Only when you have given consent via our cookie banner When you connect third-party integrations, data is exchanged directly between Synks and that service using your authorized OAuth credentials: • Google (Drive, Gmail, Calendar): File imports, email sending, calendar events • Dropbox: File imports and sync • Slack, Microsoft Teams, Discord: Notification delivery to channels • Monday.com: Task and subitem synchronization • Figma: Design file imports All processors are bound by Data Processing Agreements (DPAs) that require them to protect your data in accordance with GDPR. We do not share your data with third parties for their own marketing purposes.

6. Guest Reviewers & Shared Links

When project owners share review links, guest reviewers can leave feedback without creating an account. We collect minimal data from guest reviewers: • Display name (self-provided) • Avatar selection • Comments, annotations, and drawing data Guest reviewer data is stored in association with the project. Project owners are responsible for informing their guests about this data collection. Shared review links may optionally be password-protected.

7. International Data Transfers

Some of our service providers may process data outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place: • Standard Contractual Clauses (SCCs) approved by the European Commission • Adequacy decisions where applicable • Additional technical and organizational measures as needed You may request details about the safeguards in place by contacting us at hello@synks.io.

8. Data Retention

We retain your personal data only for as long as necessary: • Active accounts: Data is retained for the duration of your account. • Deleted accounts: Upon account deletion, we remove your personal data within 30 days. Some data may be retained longer where required by law (e.g., invoicing records for up to 5 years). • Integration tokens: OAuth tokens are deleted when you disconnect an integration or delete your account. • Guest reviewer data: Retained for as long as the associated project exists. • Backup data: May persist in encrypted backups for up to 90 days after deletion. • Anonymized data: Aggregated, anonymized data (which cannot identify you) may be retained indefinitely for analytics.

9. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights: • Right of access (Art. 15): Request a copy of the personal data we hold about you. • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data. • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"). You can delete your account via Settings → Danger Zone, or contact us. • Right to restriction (Art. 18): Request that we limit how we use your data. • Right to data portability (Art. 20): Request your data in a structured, machine-readable format. • Right to object (Art. 21): Object to processing based on legitimate interest or direct marketing. • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. To exercise any of these rights, email us at hello@synks.io. We will respond within 30 days. If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local Data Protection Authority (in Norway: Datatilsynet, datatilsynet.no).

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data: • Encryption in transit (TLS/HTTPS) and at rest • OAuth-based authentication for third-party integrations (no third-party passwords stored) • Role-based access controls and team permissions • Access controls and authentication • Regular security reviews • Incident response procedures In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in accordance with GDPR Articles 33 and 34.

11. Cookies

We use cookies and similar technologies on our platform. Essential cookies are necessary for the platform to function (including authentication, payment processing, and integration connections). Analytics and preference cookies are only set with your explicit consent via our cookie consent banner. You can change your preferences at any time. See our Cookie Policy for full details.

12. Children's Privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or through our platform at least 30 days before they take effect. Continued use of our services after the changes constitutes acceptance of the updated policy.

14. Contact & Data Protection

If you have questions about this Privacy Policy or wish to exercise your data rights: Email: hello@synks.io For complaints, you may also contact the Norwegian Data Protection Authority (Datatilsynet): datatilsynet.no