SynectGEO · Legal
Privacy Policy
Last updated: 30 September 2026
This Privacy Policy explains how SYNECT LIMITED (“we”, “us”) collects, uses, and protects personal data when you use SynectGEO at synectgeo.io. We are the data controller for that processing and are committed to the EU General Data Protection Regulation (GDPR) and Irish data-protection law.
1. Data Controller
The controller responsible for your personal data is:
The Tara Building, 11-15 Tara Street, Dublin 2, D02 RY83, Ireland
Contact: hello@synectgroup.com
2. What Personal Data We Collect
- Account / sign-up data: name and email address (collected at Early Access sign-up).
- Usage data: the brand name, website URL, custom prompts, and prompt-generation instructions you submit, the names you give any brand projects you create to group your reports, and the reports generated for you.
- Free-check data: if you request the free 3-prompt check, the work email address, brand name and website you enter, the three generated prompts and the AI answers to them, and a one-way hash of your IP address (used only to limit repeat requests). The link we email runs the check once; nothing runs without that click, and the address is not used for anything else.
- Technical data: IP address, browser type, device identifiers, and session logs.
- Analytics data: page views and feature usage, collected via Google Analytics 4 only after you opt in through the cookie banner.
- Team member data: if you invite a teammate to your workspace, we process the email address you provide solely to send the invitation and set up their membership. Within a shared workspace, members can see each other’s email and role, and owners/admins can see members’ usage and manage their access.
- Billing & tax data (once paid billing is live): your name, billing address, VAT/tax ID, and payment metadata needed to process a purchase and issue a compliant invoice. Card details are entered directly with our payment processor (Stripe) and are never seen or stored by us.
3. Why We Collect It (Lawful Basis: GDPR Article 6)
| Processing activity | Lawful basis |
|---|---|
| Early Access sign-up (email) | Consent |
| Delivering the AI visibility report | Contract (performance of service) |
| Running the free 3-prompt check you requested (reading the website, generating three prompts, sending them to two AI engines, emailing you the single-use link) | Contract (steps taken at your request before any agreement; GDPR Art 6(1)(b)) |
| Sending transactional emails (report ready, account updates) | Contract |
| Product analytics / usage tracking | Consent |
| Marketing emails (if any) | Consent (separate, opt-in) |
| Security monitoring, fraud detection | Legitimate interests |
| Screening a new sign-up for business use. Sign-ups with a personal or temporary email address are not accepted (this is stated on the form; email us for an exception). For work addresses we check the domain, including one automated check of the domain by an AI model; the result and a one-line reason are kept with your workspace. The automated step can only approve the workspace or send it to a person for review; a refusal is always a human decision. | Legitimate interests (keeping the service to business use) |
| Team invitations (inviting a teammate by email) | Legitimate interests of the workspace |
| Processing payments (subscriptions, credit top-ups) | Contract (performance of service) |
| Issuing and retaining invoices / VAT records | Legal obligation (Irish tax law) |
4. How the Product Works: Data Flow
The “Ask SynectGEO” assistant on our home page is a separate flow, and you do not need an account to use it. It is an AI assistant, not a person. What you type is sent to OpenAI to generate a reply, and the conversation is stored for up to 24 hours so we can rate-limit abuse, then deleted automatically. We also store a one-way hash of your IP address and your browser’s user-agent string for the same purpose (the hash, never the address itself). We ask you not to enter personal or confidential information, and nothing you type there is added to your account, used for marketing, or used to train any model. The lawful basis is our legitimate interest in answering product questions and protecting the service from abuse.
Emails you send us. Messages sent to hello@synectgroup.com are sorted, and some replies drafted, by an AI service (Anthropic, USA). A person reads every message and writes or approves every reply.
A SynectGEO workspace can have more than one member. The person who invites a teammate is responsible for having a lawful basis to share that person’s email with us. Members of the same workspace share access to that workspace’s projects and reports; owners and admins can manage members and set per-member daily usage limits.
5. Sub-Processors
We share data with the following sub-processors to operate the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenAI (ChatGPT) | AI visibility queries (when enabled); page-context extraction and prompt generation on EVERY report; the public “Ask SynectGEO” assistant; one advisory check of the sign-up email domain (the domain only, never the address) when a workspace is created | Outside the EEA, including the USA (SCCs apply) |
| Google (Gemini) | AI visibility queries (when enabled) | Outside the EEA, including the USA (SCCs apply) |
| Anthropic (Claude) | AI visibility queries (when enabled); scoring of every engine’s answers and the written analysis (competitor gaps, Content and Off-page reports, recommendations) on EVERY report; sorting emails sent to hello@synectgroup.com and drafting some replies (a person reads every message and writes or approves every reply) | Outside the EEA, including the USA (SCCs apply) |
| Perplexity AI | AI visibility queries (when enabled) | Outside the EEA, including the USA (SCCs apply) |
| Zyte | Website crawling for market & prompt detection (customer and competitor pages) | Ireland/EU (SCCs where applicable) |
| Serper | Search-engine results data (SERP lookups) | USA (SCCs apply) |
| DataForSEO (Dataforseo OÜ) | Google AI Overview results + cited sources for reports (public search-results data; runs only when Google AI Overview is enabled for the workspace) | EU (Estonia / Germany) 🇪🇺 |
| Supabase | Database, authentication | Stored in Ireland (AWS eu-west-1); Singapore company, logs and support can be handled outside the EEA (SCCs apply) |
| Vercel / Cloudflare | Hosting, CDN | EU/USA (SCCs apply) |
| Upstash | Abuse / rate-limit protection (short-lived request counters keyed to a one-way hash of an account ID, IP address, email address or website domain, never the value itself; each counter is deleted automatically, at most about 60 days after it is created) | Ireland (AWS eu-west-1); US company (SCCs apply) |
| Brevo | Transactional email | EU |
| GlitchTip (EU instance) | Error monitoring: technical error reports (stack traces and request metadata) | EU (Frankfurt, Germany) 🇪🇺 |
| Google Analytics 4 | Usage analytics (only after consent) | USA (SCCs apply) |
| Stripe | Payment processing (when billing goes live) | USA/EU (SCCs apply) |
For all sub-processors based outside the EEA, transfers rely on the EU Standard Contractual Clauses (SCCs) as the transfer mechanism under GDPR Chapter V.
6. Data Retention
- Account data: retained for the duration of your account. When you delete your account, your account and workspace data are erased immediately; any residual copies in routine, encrypted infrastructure backups are removed as those backups expire.
- Report data: retained for 12 months, after which it is deleted; you may request earlier deletion at any time.
- Free-check data: deleted 30 days after the check was requested (the result link stops working at the same time); you may request earlier deletion at any time.
- Analytics data: retained per the Google Analytics 4 default (up to 14 months), or shorter where configured.
- Unsolicited CVs and job applications sent to us by email: kept for 30 days, then deleted at our next monthly clear-out.
- Invoices & tax records: retained for 6 years as required by Irish tax law, even after account deletion.
- Requests, cancellations, refunds and complaints: the record of the request (a case reference, your account id, what you asked for, the dates and what we decided) is kept for 6 years from the day the case closes, because that is how long a related legal claim can be brought. The emails themselves are deleted 24 months after it closes, and a copy of your data sent in answer to an access request is not kept once delivery is confirmed. We keep the case record even if you ask us to erase your data, because we may need it to establish or defend a legal claim (Article 17(3)(e)).
7. Your Rights (GDPR Articles 15 to 22)
You have the right to:
- Access your data (Article 15)
- Rectify inaccurate data (Article 16)
- Erasure, the “right to be forgotten” (Article 17)
- Data portability (Article 20)
- Object to processing (Article 21)
- Withdraw consent at any time (Article 7)
To exercise any right, contact hello@synectgroup.com. We respond to all rights requests within 30 days.
9. Data Breach Notification
In the event of a data breach likely to result in a risk to your rights, SYNECT LIMITED will notify the Irish Data Protection Commission within 72 hours and notify affected users without undue delay.
10. Supervisory Authority
If you believe your data-protection rights have been infringed, you may lodge a complaint with the Irish supervisory authority:
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above. Continued use of SynectGEO after an update constitutes acceptance of the revised policy.