Política de Privacidade

Questions: support@syndie.io.

1. Who we are

Syndie is run by Upturn Consultancy LLC, Sharjah Media City (Shams) Free Zone, Sharjah, UAE ("Syndie", "we"). This policy explains how we handle personal data when you visit our sites, use Syndie and Syd, contact our support team, or receive outreach sent through Syndie by one of our customers.

If you use the Service under a partner's brand, the partner's white-labelled version of this policy applies too, and the partner may also process your data.

2. Our role

Whose dataOur roleWho decides how it's used
Users, workspace members, website visitors, support contactsControllerSyndie
Prospects a customer uploads, imports, enriches, or messages, and their repliesProcessorThe customer
Prospects found through Native Prospect SearchControllerSyndie and the customer

If a Syndie customer contacted you, ask that customer first about your data. We'll help them answer. Section 6 explains your options.

3. Data we collect

CategoryExamplesWhere it comes from
AccountName, email, photo, password hash, Google sign-in details, sign-in historyYou, Google
WorkspaceWorkspace name and logo, team members, roles, seat access, settingsYou
BillingBilling name and address, tax ID, card brand and last 4 digits, invoices, payment statusYou, Stripe
LinkedIn accountsProfile, account type, connections, invitations, messages, InMails, attachments, post activityLinkedIn, via the account you connect
Mailboxes and calendarsEmails and headers in campaign threads, attachments, calendar free/busy times, meetings and inviteesGmail or Outlook, via the account you connect
Knowledge baseWebsite pages you choose to read, uploaded files, pasted text, drafted company overview and audienceYou
Prospect dataName, headline, title, company, location, LinkedIn URL, public profile details, work and personal email, phone number, messages, replies, tags, notes, meeting statusNative Prospect Search, LinkedIn searches you run, enrichment lookups, CSV imports, CRMs, the public API, n8n
Email engagementWhether an email was opened and which tracked links were clickedTracking in emails sent through Syndie
Syd chatsYour messages to Syd, its answers, and actions it tookYou
UsageIP address, device and browser, pages viewed, features used, API and integration calls, logsAutomatically
SupportSupport chats and emails, the Syd chat attached to a request, and Contact Us form details (name, work email, company, job title, phone)You
CookiesSee section 13Automatically

We don't knowingly collect sensitive data such as health, religion, or ethnicity. Please don't upload it.

4. How we use data

PurposeData usedLegal basis (EU/UK GDPR)
Run the Service: Syd, campaigns, Unibox, meetings, integrationsAccount, workspace, connected accounts, knowledge base, prospect dataContract; for prospect data, the customer's instructions
Find emails and phone numbers when a user asksProspect name, company, LinkedIn URLThe customer's instructions
Check Syd's replies against your knowledge baseKnowledge base, draftsContract
Enforce sending limits and protect connected accountsUsage, connected accountsLegitimate interests
Billing, tax, fraud preventionBilling, usageContract; legal obligation; legitimate interests
Support, including signing in to your account to help (logged)Support, account, workspaceContract; legitimate interests
Security and abuse preventionUsage, logsLegitimate interests
Improve Syndie, including your ratings of Syd's answersUsage, de-identified Output signalsLegitimate interests
Product updates and marketing to customersAccountLegitimate interests, or consent where required. Opt out any time.
Legal complianceAs neededLegal obligation

Under the UAE PDPL, India's DPDP Act, and Brazil's LGPD we rely on the matching grounds in those laws, including consent where they require it.

5. How Syd uses AI

  • Syd uses large language models from OpenAI, Anthropic, and Moonshot AI (Kimi) to read your knowledge base, draft your company overview and audience, suggest lists, write messages and comments, answer prospects' replies, and answer you in chat.
  • We send each provider only what a task needs. OpenAI and Anthropic don't train their models on data we send through their APIs, and neither do the Kimi models we host for customers in the EU and US. For other customers, Moonshot AI may use the data it receives to improve its models.
  • We do not train our own models on your Customer Data. We may use aggregated, de-identified signals, such as which drafts are approved without edits, to improve Syd.
  • Syd's choices about whom to contact and what to say follow rules our customers set. They don't produce legal or similarly significant effects on prospects.

6. If you were contacted through Syndie

Our customers use Syndie to find and contact business professionals on LinkedIn and by email. If you received a message sent through Syndie, the person or company named in it chose to contact you.

  • Where your data came from: publicly available professional profile information, found through Syndie's prospect search or the customer's own LinkedIn account; email and phone lookups from our data providers; or lists the customer uploaded or imported from its CRM or other tools.
  • What we hold: work profile details (name, title, company, location, LinkedIn URL), an email address or phone number if found, and the messages, replies, and meetings exchanged.
  • Why: the customer's legitimate interest, and for Syndie's prospect search ours, in reaching professionals about matters relevant to their role.
  • Email tracking: emails sent through Syndie may record whether you opened them and clicked their links.
  • To stop hearing from a sender: reply asking them to stop, use the unsubscribe link, or report the email as spam. Syndie then blocks your address in that customer's workspace.
  • Your other rights: email support@syndie.io to ask what we hold or to have it deleted. Opt-outs and blocks apply per customer workspace. We'll pass your request to every customer workspace that holds your data.

7. Who we share data with

We don't sell personal data, and we don't share it for cross-context behavioural advertising.

Sub-processors (vendors that process data for us). Rows in brackets need confirming.

ProviderWhat they doData
UnipileConnects LinkedIn accounts and mailboxes (through its Google and Microsoft apps); sends messages and emailsConnected account data, emails, prospect data
OpenAIAI models for writing, replies, list building, chatKnowledge base, prospect data, messages
AnthropicAI models for writing, replies, list building, chatKnowledge base, prospect data, messages
Moonshot AI (Kimi)AI models for writing, replies, list building, chatKnowledge base, prospect data, messages
DigitalOceanHosts Kimi models for customers in the EU and USKnowledge base, prospect data, messages
ApolloFinding work emails and phone numbersProspect name, company, LinkedIn URL
Amazon Web ServicesHosting, database, file storageAll Service data
VercelWeb app hosting and deliveryUsage data, data shown in the app
StripePayments and invoicesBilling data
Google AnalyticsWebsite and product analyticsUsage data, cookie identifiers
Amazon SESVerification codes, invitations, notificationsName, email

Sign-in, support chat, and the calendar connection are run by Syndie itself.

Customers can get the current list, with where each provider processes data, from support@syndie.io. We tell customers at least 30 days before adding a new one.

Accounts and tools you connect. LinkedIn, Google, and Microsoft process data under their own terms when you connect accounts. When you connect HubSpot, GoHighLevel, n8n, Apollo, Clay, a webhook, the public API, or an outside assistant, we send data there because you told us to. Those providers aren't our sub-processors, and their own policies apply.

Others who may see data:

  • Your workspace. Owners and Admins see everything in the workspace. Members see the seats they're given. Agencies see the client workspaces they run.
  • Partner brands and country partners. Partners who offer Syndie under their brand may access data for the customers they serve. Country partners who sell and support Syndie in markets such as Brazil and Vietnam may access campaign and prospect list data, only to resolve their customers' issues, under confidentiality obligations.
  • Legal reasons. Authorities, when the law requires it, or to protect our rights, users, or the public.
  • Business transfers. A buyer or successor if we merge, are acquired, or sell the Syndie brand or assets.

8. International transfers

We and our providers process data in several countries, including the UAE, the US, India, and France, and in other countries where our providers operate. Our team in India may access data for engineering and support.

  • Out of the EEA or UK: we use the EU Standard Contractual Clauses and the UK Addendum.
  • Out of the UAE: we transfer to countries with adequate protection or under appropriate safeguards, as the PDPL requires.
  • Out of India: we don't transfer to any country the Indian government restricts.
  • Out of Brazil: we use the ANPD's standard contractual clauses.

9. How long we keep data

DataHow long
AccountUntil you ask support to delete your account
Workspace data (contacts, campaigns, messages, knowledge bases)Until the Owner deletes it, or 6 months after the subscription ends, whichever comes first. Deleting a campaign or workspace removes its data at once. Backups roll off within 30 days.
Connected-account accessEnds when the account is disconnected, or when the subscription ends
Syd chatsUntil you delete the conversation
Syd chat attached to a support requestDeleted 90 days after the request closes
In-app notifications30 days
Blacklist and blocked addresses (unsubscribed, bounced, spam reports)Kept while the workspace exists, so opt-outs keep working
Billing and invoicesAs long as UAE tax law requires
Logs12 months

10. Security

We encrypt data in transit (TLS) and at rest. Passwords and API keys are stored in a form that can't be read back. Access tokens for connected accounts are encrypted. Events we send to n8n are signed. Staff access is role-based, limited to what each role needs, and protected with multi-factor authentication.

When our support team signs in to your account to help, the session is logged and listed in Settings › Your profile › Support access.

If a breach affects your data, we'll tell you without undue delay, and within 72 hours of confirming it.

11. Your rights

Depending on where you live, you can ask us to:

  • Show you the data we hold about you, or give you a copy in a portable format.
  • Correct it, delete it, or restrict how we use it.
  • Stop using it for direct marketing. We'll always honour this.
  • Object to other uses based on legitimate interests.
  • Withdraw consent you gave earlier.

You can do some of this yourself: edit your profile, export contacts as CSV, delete Syd chats, and delete campaigns or workspaces you own. To change your sign-in email or delete your account, contact support.

California residents also have the right to know, delete, and correct data, and to opt out of sale or sharing (we do neither). We won't treat you differently for using these rights. An authorised agent can ask for you.

To use a right, email support@syndie.io. We'll verify who you are and reply within 30 days (45 days for California requests). If we hold the data as a customer's processor, we'll pass your request to that customer.

You can also complain to your regulator: the UAE Data Office, your EU data protection authority, the UK ICO, Brazil's ANPD, or India's Data Protection Board.

12. Google and Microsoft account data

You can sign in with Google, and connect Gmail and Google Calendar or Outlook and Microsoft calendars. We use this access only to send and receive campaign email, read free/busy times, create the Syndie calendar, and book, move, or cancel meetings.

Our use of data received from Google APIs, and any transfer of it to other apps, follows the Google API Services User Data Policy, including its Limited Use requirements. We don't use that data to train general AI models or for advertising, and people at Syndie don't read it except with your permission, for security, or where the law requires.

Microsoft account data is handled the same way.

13. Cookies and tracking

TypePurposeExamples
EssentialSign-in, security, remembering your workspaceSession cookies
PreferencesYour table layout and view choices, kept in your browserLocal storage
AnalyticsUnderstanding how the site and app are usedGoogle Analytics
MarketingMeasuring ads on syndie.ioAd platform pixels, where used
Email trackingRecording opens and link clicks on emails sent through SyndieTracking pixel and tracked links

Visitors in the EU and UK see a cookie banner, and non-essential cookies stay off until accepted. Change your choice any time from the cookie banner.

14. Children

Syndie is for business users aged 18 or over. We don't knowingly collect data about children.

15. Changes

We'll update the date at the top when this policy changes, and tell customers by email or in the app about material changes.

16. Contact

Upturn Consultancy LLC, Sharjah Media City (Shams) Free Zone, Sharjah, UAE. Email: support@syndie.io.