Privacy policy
Last updated: September 24, 2026
Who we are
SynqAI (the founder inbox) is operated by GTG Technology Private Limited, DLF Cyber Greens, DLF Cyber City, DLF Phase 2, Sector 24, Gurugram, Haryana 122002, India (“SynqAI”, “we”). We are the data controller (data fiduciary under Indian law) for the personal data described here. Privacy questions, requests and complaints go to swastik@synqflow.ai. This address also reaches our grievance officer under India’s Digital Personal Data Protection Act.
Who this covers
This policy covers three groups of people: founders and team members who sign in to a workspace (“members”), people who send a request through a company’s public SynqAI page (“submitters”), and visitors to synqai pages. Where a member’s company uses SynqAI to handle submissions, that company decides what it does with them and we act on its instructions for that data.
What we collect
- Account data. Name, email address and profile picture from Google sign-in, plus the workspace, company name, slug and priorities you set up.
- Submissions. What a submitter enters on a public page: name, email, links, category, request text and relevance claim. If a company connects WhatsApp through Interakt, messages sent to that number and the sender’s phone number.
- Working data. Private notes, ranking evidence, reply drafts, feedback on rankings and invites you send.
- Billing data. Plan, subscription status and payment identifiers from Razorpay. Card and bank details go to Razorpay directly and never reach our servers.
- Usage and device data. Pages viewed, actions taken, browser type, approximate location from IP address, and session replays with all inputs and other people’s messages masked. Collected only if you accept analytics cookies (see cookies).
- Technical logs. IP address, timestamps, request paths and error traces, kept to run and secure the service.
Why we use it and on what basis
Under the EU and UK GDPR each use rests on a legal basis. The same purposes apply under India’s DPDP Act, California’s CCPA/CPRA, Brazil’s LGPD and similar laws.
- To provide the service (collect submissions, rank them, draft replies, run the workspace, take payment): performance of our contract with you.
- To keep it secure and working (fraud and abuse prevention, rate limits, diagnosing failures): our legitimate interest in running a safe service.
- To improve ranking from your explicit feedback: our legitimate interest, using your own workspace’s data.
- Analytics and session replay: your consent, which you can withdraw at any time on the cookies page.
- Service emails and WhatsApp notifications about your account and submissions: performance of the contract. We do not send marketing email without a separate opt-in.
- To meet legal obligations such as tax records and lawful requests.
We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it for automated decisions with legal or similarly significant effects. Ranking is decision support; a member reads and decides.
AI processing
Deterministic ranking works without an AI provider. Where AI enrichment is enabled, we send the submission category, request text, relevance claim, active priorities and deterministic score to OpenAI to produce summaries, scores and reply drafts. Submitter names, emails and contact links are stripped before that call. Our AI providers act as processors under contract, and we use API terms under which inputs are not used to train their models.
Who we share it with
Only processors that run the service for us, each under a data processing agreement:
- Hosting and compute: Vercel (web app) and Render (background workers).
- Database: Neon (managed Postgres).
- Sign-in: Google.
- Payments: Razorpay.
- Product analytics: PostHog, only with your consent.
- WhatsApp messaging: Interakt (Meta Business Partner), only for companies that connect it.
- AI: OpenAI, as described above.
Beyond that we disclose personal data only when the law requires it, to protect our rights or users’ safety, or as part of a merger or acquisition, with notice to you.
International transfers
We are based in India and our processors run in the United States and the European Union, so your data crosses borders. For transfers out of the EEA, UK and Switzerland we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), and where a processor is certified we rely on the EU-US Data Privacy Framework. Transfers out of India follow the DPDP Act, which permits transfer to any country the Indian government has not restricted. You can ask us for a copy of the safeguards in place.
How long we keep it
- Account and workspace data: for as long as the workspace exists, then deleted within 30 days of deletion or account closure.
- Submissions, notes and drafts: for as long as the company keeps them; deleted with the workspace.
- Billing records: 8 years, as Indian tax law requires.
- Analytics and session replays: 12 months, or sooner if you withdraw consent.
- Technical logs: 30 days.
Your rights
Wherever you live, you can ask us to access, correct, delete or export your personal data, to restrict or object to how we use it, and you can withdraw consent at any time without affecting what was done before. Write to swastik@synqflow.ai. We reply within 30 days (45 days where California law applies) and may ask you to verify your identity first. Founders can also delete their account and company from the account page, which removes the workspace and everything in it.
- EEA, UK and Switzerland. You also have the right to data portability and to complain to your local supervisory authority, for example the ICO in the UK. You can contact us first and we will try to resolve it.
- California. Under the CCPA/CPRA you have the right to know, delete, correct, and to opt out of sale or sharing. We do not sell or share personal data, so there is nothing to opt out of. We will not discriminate against you for exercising a right. An authorised agent may act for you with written permission.
- India. Under the DPDP Act you may access a summary of your data, correct or erase it, nominate a person to exercise your rights if you are unable to, and raise a grievance with us. If we do not resolve it, you may approach the Data Protection Board of India.
- Brazil. Under the LGPD you have the rights listed above and may complain to the ANPD.
- Submitters. If you sent a request to a company through SynqAI, that company holds your submission. Contact them first; we will help them respond, and will act directly on your request where we are able to.
Cookies
We use one strictly necessary cookie to keep you signed in and, with your consent, analytics cookies. Which ones, why, and how to change your choice are in the cookie policy.
Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. We use authenticated sessions, tenant-scoped database policies, server-side validation, rate limits and least-privilege access for staff. No internet service can promise absolute security; if a breach affects you we will notify you and the relevant authority as the law requires.
Children
SynqAI is a business tool for people 18 and over. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
Changes
We will post changes here and update the date at the top. For material changes we will email members before they take effect.