Política de Privacidade
Questions: support@syndie.io.
1. Who we are
Syndie is run by Upturn Consultancy LLC, Sharjah Media City (Shams) Free Zone, Sharjah, UAE ("Syndie", "we"). This policy explains how we handle personal data when you visit our sites, use Syndie and Syd, contact our support team, or receive outreach sent through Syndie by one of our customers.
If you use the Service under a partner's brand, the partner's white-labelled version of this policy applies too, and the partner may also process your data.
2. Our role
| Whose data | Our role | Who decides how it's used |
|---|---|---|
| Users, workspace members, website visitors, support contacts | Controller | Syndie |
| Prospects a customer uploads, imports, enriches, or messages, and their replies | Processor | The customer |
| Prospects found through Native Prospect Search | Controller | Syndie and the customer |
If a Syndie customer contacted you, ask that customer first about your data. We'll help them answer. Section 6 explains your options.
3. Data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | Name, email, photo, password hash, Google sign-in details, sign-in history | You, Google |
| Workspace | Workspace name and logo, team members, roles, seat access, settings | You |
| Billing | Billing name and address, tax ID, card brand and last 4 digits, invoices, payment status | You, Stripe |
| LinkedIn accounts | Profile, account type, connections, invitations, messages, InMails, attachments, post activity | LinkedIn, via the account you connect |
| Mailboxes and calendars | Emails and headers in campaign threads, attachments, calendar free/busy times, meetings and invitees | Gmail or Outlook, via the account you connect |
| Knowledge base | Website pages you choose to read, uploaded files, pasted text, drafted company overview and audience | You |
| Prospect data | Name, headline, title, company, location, LinkedIn URL, public profile details, work and personal email, phone number, messages, replies, tags, notes, meeting status | Native Prospect Search, LinkedIn searches you run, enrichment lookups, CSV imports, CRMs, the public API, n8n |
| Email engagement | Whether an email was opened and which tracked links were clicked | Tracking in emails sent through Syndie |
| Syd chats | Your messages to Syd, its answers, and actions it took | You |
| Usage | IP address, device and browser, pages viewed, features used, API and integration calls, logs | Automatically |
| Support | Support chats and emails, the Syd chat attached to a request, and Contact Us form details (name, work email, company, job title, phone) | You |
| Cookies | See section 13 | Automatically |
We don't knowingly collect sensitive data such as health, religion, or ethnicity. Please don't upload it.
4. How we use data
| Purpose | Data used | Legal basis (EU/UK GDPR) |
|---|---|---|
| Run the Service: Syd, campaigns, Unibox, meetings, integrations | Account, workspace, connected accounts, knowledge base, prospect data | Contract; for prospect data, the customer's instructions |
| Find emails and phone numbers when a user asks | Prospect name, company, LinkedIn URL | The customer's instructions |
| Check Syd's replies against your knowledge base | Knowledge base, drafts | Contract |
| Enforce sending limits and protect connected accounts | Usage, connected accounts | Legitimate interests |
| Billing, tax, fraud prevention | Billing, usage | Contract; legal obligation; legitimate interests |
| Support, including signing in to your account to help (logged) | Support, account, workspace | Contract; legitimate interests |
| Security and abuse prevention | Usage, logs | Legitimate interests |
| Improve Syndie, including your ratings of Syd's answers | Usage, de-identified Output signals | Legitimate interests |
| Product updates and marketing to customers | Account | Legitimate interests, or consent where required. Opt out any time. |
| Legal compliance | As needed | Legal obligation |
Under the UAE PDPL, India's DPDP Act, and Brazil's LGPD we rely on the matching grounds in those laws, including consent where they require it.
5. How Syd uses AI
- Syd uses large language models from OpenAI, Anthropic, and Moonshot AI (Kimi) to read your knowledge base, draft your company overview and audience, suggest lists, write messages and comments, answer prospects' replies, and answer you in chat.
- We send each provider only what a task needs. OpenAI and Anthropic don't train their models on data we send through their APIs, and neither do the Kimi models we host for customers in the EU and US. For other customers, Moonshot AI may use the data it receives to improve its models.
- We do not train our own models on your Customer Data. We may use aggregated, de-identified signals, such as which drafts are approved without edits, to improve Syd.
- Syd's choices about whom to contact and what to say follow rules our customers set. They don't produce legal or similarly significant effects on prospects.
6. If you were contacted through Syndie
Our customers use Syndie to find and contact business professionals on LinkedIn and by email. If you received a message sent through Syndie, the person or company named in it chose to contact you.
- Where your data came from: publicly available professional profile information, found through Syndie's prospect search or the customer's own LinkedIn account; email and phone lookups from our data providers; or lists the customer uploaded or imported from its CRM or other tools.
- What we hold: work profile details (name, title, company, location, LinkedIn URL), an email address or phone number if found, and the messages, replies, and meetings exchanged.
- Why: the customer's legitimate interest, and for Syndie's prospect search ours, in reaching professionals about matters relevant to their role.
- Email tracking: emails sent through Syndie may record whether you opened them and clicked their links.
- To stop hearing from a sender: reply asking them to stop, use the unsubscribe link, or report the email as spam. Syndie then blocks your address in that customer's workspace.
- Your other rights: email support@syndie.io to ask what we hold or to have it deleted. Opt-outs and blocks apply per customer workspace. We'll pass your request to every customer workspace that holds your data.
7. Who we share data with
We don't sell personal data, and we don't share it for cross-context behavioural advertising.
Sub-processors (vendors that process data for us). Rows in brackets need confirming.
| Provider | What they do | Data |
|---|---|---|
| Unipile | Connects LinkedIn accounts and mailboxes (through its Google and Microsoft apps); sends messages and emails | Connected account data, emails, prospect data |
| OpenAI | AI models for writing, replies, list building, chat | Knowledge base, prospect data, messages |
| Anthropic | AI models for writing, replies, list building, chat | Knowledge base, prospect data, messages |
| Moonshot AI (Kimi) | AI models for writing, replies, list building, chat | Knowledge base, prospect data, messages |
| DigitalOcean | Hosts Kimi models for customers in the EU and US | Knowledge base, prospect data, messages |
| Apollo | Finding work emails and phone numbers | Prospect name, company, LinkedIn URL |
| Amazon Web Services | Hosting, database, file storage | All Service data |
| Vercel | Web app hosting and delivery | Usage data, data shown in the app |
| Stripe | Payments and invoices | Billing data |
| Google Analytics | Website and product analytics | Usage data, cookie identifiers |
| Amazon SES | Verification codes, invitations, notifications | Name, email |
Sign-in, support chat, and the calendar connection are run by Syndie itself.
Customers can get the current list, with where each provider processes data, from support@syndie.io. We tell customers at least 30 days before adding a new one.
Accounts and tools you connect. LinkedIn, Google, and Microsoft process data under their own terms when you connect accounts. When you connect HubSpot, GoHighLevel, n8n, Apollo, Clay, a webhook, the public API, or an outside assistant, we send data there because you told us to. Those providers aren't our sub-processors, and their own policies apply.
Others who may see data:
- Your workspace. Owners and Admins see everything in the workspace. Members see the seats they're given. Agencies see the client workspaces they run.
- Partner brands and country partners. Partners who offer Syndie under their brand may access data for the customers they serve. Country partners who sell and support Syndie in markets such as Brazil and Vietnam may access campaign and prospect list data, only to resolve their customers' issues, under confidentiality obligations.
- Legal reasons. Authorities, when the law requires it, or to protect our rights, users, or the public.
- Business transfers. A buyer or successor if we merge, are acquired, or sell the Syndie brand or assets.
8. International transfers
We and our providers process data in several countries, including the UAE, the US, India, and France, and in other countries where our providers operate. Our team in India may access data for engineering and support.
- Out of the EEA or UK: we use the EU Standard Contractual Clauses and the UK Addendum.
- Out of the UAE: we transfer to countries with adequate protection or under appropriate safeguards, as the PDPL requires.
- Out of India: we don't transfer to any country the Indian government restricts.
- Out of Brazil: we use the ANPD's standard contractual clauses.
9. How long we keep data
| Data | How long |
|---|---|
| Account | Until you ask support to delete your account |
| Workspace data (contacts, campaigns, messages, knowledge bases) | Until the Owner deletes it, or 6 months after the subscription ends, whichever comes first. Deleting a campaign or workspace removes its data at once. Backups roll off within 30 days. |
| Connected-account access | Ends when the account is disconnected, or when the subscription ends |
| Syd chats | Until you delete the conversation |
| Syd chat attached to a support request | Deleted 90 days after the request closes |
| In-app notifications | 30 days |
| Blacklist and blocked addresses (unsubscribed, bounced, spam reports) | Kept while the workspace exists, so opt-outs keep working |
| Billing and invoices | As long as UAE tax law requires |
| Logs | 12 months |
10. Security
We encrypt data in transit (TLS) and at rest. Passwords and API keys are stored in a form that can't be read back. Access tokens for connected accounts are encrypted. Events we send to n8n are signed. Staff access is role-based, limited to what each role needs, and protected with multi-factor authentication.
When our support team signs in to your account to help, the session is logged and listed in Settings › Your profile › Support access.
If a breach affects your data, we'll tell you without undue delay, and within 72 hours of confirming it.
11. Your rights
Depending on where you live, you can ask us to:
- Show you the data we hold about you, or give you a copy in a portable format.
- Correct it, delete it, or restrict how we use it.
- Stop using it for direct marketing. We'll always honour this.
- Object to other uses based on legitimate interests.
- Withdraw consent you gave earlier.
You can do some of this yourself: edit your profile, export contacts as CSV, delete Syd chats, and delete campaigns or workspaces you own. To change your sign-in email or delete your account, contact support.
California residents also have the right to know, delete, and correct data, and to opt out of sale or sharing (we do neither). We won't treat you differently for using these rights. An authorised agent can ask for you.
To use a right, email support@syndie.io. We'll verify who you are and reply within 30 days (45 days for California requests). If we hold the data as a customer's processor, we'll pass your request to that customer.
You can also complain to your regulator: the UAE Data Office, your EU data protection authority, the UK ICO, Brazil's ANPD, or India's Data Protection Board.
12. Google and Microsoft account data
You can sign in with Google, and connect Gmail and Google Calendar or Outlook and Microsoft calendars. We use this access only to send and receive campaign email, read free/busy times, create the Syndie calendar, and book, move, or cancel meetings.
Our use of data received from Google APIs, and any transfer of it to other apps, follows the Google API Services User Data Policy, including its Limited Use requirements. We don't use that data to train general AI models or for advertising, and people at Syndie don't read it except with your permission, for security, or where the law requires.
Microsoft account data is handled the same way.
13. Cookies and tracking
| Type | Purpose | Examples |
|---|---|---|
| Essential | Sign-in, security, remembering your workspace | Session cookies |
| Preferences | Your table layout and view choices, kept in your browser | Local storage |
| Analytics | Understanding how the site and app are used | Google Analytics |
| Marketing | Measuring ads on syndie.io | Ad platform pixels, where used |
| Email tracking | Recording opens and link clicks on emails sent through Syndie | Tracking pixel and tracked links |
Visitors in the EU and UK see a cookie banner, and non-essential cookies stay off until accepted. Change your choice any time from the cookie banner.
14. Children
Syndie is for business users aged 18 or over. We don't knowingly collect data about children.
15. Changes
We'll update the date at the top when this policy changes, and tell customers by email or in the app about material changes.
16. Contact
Upturn Consultancy LLC, Sharjah Media City (Shams) Free Zone, Sharjah, UAE. Email: support@syndie.io.