POLICY
Digital privacy and security
Protecting your personal and financial information

Purpose and scope
First and foremost, the purpose of this policy is to protect your personal and financial information, as users of our software applications. In the digital world, the truth is that privacy and security are always at risk. That said, rigorously implementing the latest best practices reduces such risk to acceptable levels. These best practices center on the user’s rights and the responsibilities we take on as a result.
This policy is meant, therefore, to clearly and transparently communicate to you, in plain language, how your data is collected, stored, used, shared, and protected; what rights you enjoy as users of our software; which mechanisms are at your disposal to access, correct, and delete your data.
This policy ensures that our software applications comply with relevant laws, regulations, and standards in relation to privacy and security. In particular, this policy covers the requirements of the European Union’s General Data Protection Regulation (GDPR), which provides robust protection for personal data, ensuring that organizations handle it lawfully, transparently, and securely. By virtue of the financial activities performed by some of our software, Synaps also implements the provisions of the United States’ Gramm-Leach-Bliley Act.
By using our software, users agree to the practices outlined in this policy. For questions, concerns, or requests regarding this policy or the practices it describes, you can contact Synaps at inbox@synaps.world.
Definitions
Personal information: data that relates to you as an identified or identifiable individual, such as your name, contact details, identification numbers, and other personal identifiers.
Non-personal information: anonymized or aggregated data, unless it can be re-identified as belonging to specific individuals.
Financial information: data related to financial transactions, bank account details, credit card information, invoices, payroll records, and other financial documents and records.
Usage data: information on how you access and use our software, such as IP addresses, browser type, operating system, access times, pages viewed, and buttons clicked.
Data breach: the accidental or unlawful destruction, loss, alteration, or disclosure of your data as it is transmitted, stored, or otherwise processed by us.
Rights and principles
As a user of our software, you enjoy rights that govern how we interact with all the data you input. These rights are defined by GDPR as the following:
- Right to be informed. How is your personal data collected, used, stored, and shared? This policy answers those questions in a spirit of transparency and accountability which is key to responsible data processing.
- Right of access. As a user, you can request access to all the personal and financial data we collected on your behalf, to include any data that may not be visible to you as a user.
- Right to rectification. You can request that corrections be made to inaccurate or incomplete data.
- Right to erasure, also known as the right to be forgotten. You can request the deletion of your personal and financial data, subject to obligations stated in our software’s license or other legal obligations. For instance, an organization subscribing to our software may refuse to give an employee the right to delete data that is essential to said organization.
- Right to data portability. You can request a copy of your data in a structured, commonly used format.
- Right to object. You can request the suspension of your personal data’s processing in relation to marketing or research purposes, or by evoking other specific concerns.
- Right to restrict processing. You can ask to exclude some of your data from processing, pending clarifications on how your data is being processed, corrections to your data, decisions related to legal claims, and so forth. In these cases, such data is stored but no longer processed, until the issues at stake are resolved.
- Rights related to automated decision-making and profiling. You can invoke these rights to protect yourself against decisions and assessments that do not involve human intervention yet significantly affect you.
In recognition of these rights, Synaps implements the following principles, which correspond to best practices in relation to data privacy and security:
- Lawfulness, fairness, and transparency. Your data is processed within a valid legal framework (see below). Our data processing is fair to our users, because it serves only to deliver and improve the services they explicitly subscribe to. And it is done transparently, in accordance with the principles and processes communicated through this notice.
- Purpose limitation. Your data is collected only for specific, explicit, and legitimate purposes.
- Data minimization. We collect the minimum amount of data necessary for the provision of our services.
- Accuracy. We attach great importance to the accuracy of the data we collect, and will therefore promptly delete or correct any data proven to be inaccurate.
- Storage limitation. We retain your data only as long as required for service delivery and legal compliance. Beyond that point, your data will be deleted, fully anonymized, or otherwise disposed of securely.
- Integrity and confidentiality. Your personal data will be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage (per the security measures described below).
- Accountability. We take responsibility for the data we collect and process on your behalf, by implementing all the principles and procedures described in this notice.
Data collection and processing
Depending on your usage of our software, we are likely to collect and process the following types of data:
- Personal information: your name, contact details, and identification information.
- Non-personal information: the other data you input by filling forms featured in our software.
- Financial information: your bank account details, transaction history, invoices, and other financial records.
- Usage data: your clicks on buttons featured in our software, which provide essential information for optimization and debugging.
Our data processing is conducted within a legal framework that rests on:
- Your consent, as a user
- Our software’s license
- Our compliance with legal obligations
- Our legitimate interest in improving the quality and security of our software applications
Our data collection methods are limited to:
- Data you input by filling the information fields in our software (registration form, other forms, uploads, possibly customer support)
- Data your device shares automatically to enable the functionalities you subscribed to (IP address, any cookies you explicitly consented to, and some technical details about your hardware, operating system, and browser which any software needs to function)
- User activity tracking in the form of a log of actions (namely clicks on buttons featured in our software) with related timestamps.
Our processing activities are restricted to:
- Account management: creating and authenticating users, storing and changing your login credentials and other account data, facilitating secure billing, and deleting or exporting data at your request.
- Service delivery: storing, correcting, retrieving, computing, and displaying the data you submit as you interact with our software.
- Communication: using your contact details to send you important messages, such as software updates or security concerns. (We do not process your data for marketing purposes.)
- User experience: analyzing your usage data to improve our service.
- Compliance: responding to legal requests.
Data storage and security
Synaps stores your data on cloud servers provided by Digital Ocean. We opted for a service that is reliable, efficient, secure, and affordable. We opted against the three dominant cloud service providers (owned by Amazon, Microsoft, and Google), to avoid reinforcing the market’s tendency to become an oligopoly. We also opted against small companies as well as our own servers, to reduce to the extent possible the risks related to hacking, technological failure, natural disasters, bankruptcy, and so forth.
Synaps, given its relatively small size, is not officially certified ISO/IEC 27001, a widely recognized standard for information security management. However, we closely follow the logic set out in this standard.
We implement comprehensive security measures to protect all our users’ data, including:
- Data encryption. We encrypt data at rest and in transit using industry-standard protocols, meaning that your data exists on our database and during communication over the Internet in a coded format that is unreadable without a decryption key.
- Multi-factor authentication. We use more than one method of authentication to verify our users’ identity, whether they are logging into their user accounts or attempting to access administrative functionalities.
- Access controls. We restrict access to all data and functionalities to authorized users only, based on their specific roles and responsibilities. In other words, all users see only the data that is relevant to them.
- Anonymization and pseudonymization. We remove personal information from broader datasets, so that the individuals whom the data describe remain anonymous: For example, we do not include names in a dataset unless such information is absolutely needed. Pseudonymization consists in replacing explicit identifiers, such as your name, with artificial identifiers, for instance a reference number.
- Secure development practices. We tackle your security long before you sign up to our software, by following best practices in software development. As a user, you may request more detail on the processes we implement.
- Security audits and penetration testing. We commission external experts to implement periodic procedures to proactively identify and mitigate vulnerabilities.
In addition, we do more than encourage you to follow best practices at your end: We enforce strong passwords, login timeouts, and automated updates, to reduce vulnerabilities at your end. However, not all such vulnerabilities are in our hands: Your privacy and security also depend on how you behave in the digital world more generally. Please take a moment to review our “cybersecurity checklist for non-nerds”.
Data sharing
As a rule, Synaps does not share your data with third parties. We do not sell your data or share it for free. We do not upload your data to third party services, such as the providers of technologies which our software draws upon.
Exceptions are limited, justified, and disclosed transparently. Indeed, Synaps may provide third parties with restricted access to your data for specific purposes, under the following conditions:
- Debugging, with software engineers commissioned and vetted by Synaps
- Legal compliance, if sharing is legitimately required by law or regulatory authorities following due process, for instance in the context of an investigation or a lawsuit
- User consent, as part of specific functionalities you authorize, such as providing access to a subset of your data to your external partners or financial auditors
Data breaches
Because we are committed to protecting the security of your data, we take the risk of a data breach seriously. Indeed, the worst way to prevent such an outcome would be to assume it simply can’t happen. Therefore, in the unlikely event of a data breach, we will abide by the following procedure:
- Assess the scope and impact of the breach, through a preliminary investigation.
- Contain and mitigate, by taking immediate measures to secure our systems and data.
- Inform the concerned, namely relevant authorities and affected users.
We will notify you in ways that are transparent and as helpful as possible, using different methods such as email, telephone, and in-app messages. Content-wise, we will:
- Explain the nature of the breach, per our preliminary investigation
- Assess the likely causes and consequences of the breach
- Detail the steps we have already taken to contain these effects
- Propose other steps we will take to further secure our systems
- Suggest immediate steps you can take protect yourself
- Provide you with a contact person to follow up with
Continuous improvement
We are committed to continually improving our privacy and security practices. To do so, we conduct reviews and updates of this policy, to reflect complaints or emerging best practices. Here also, we will notify you using different methods, both by email and through in-app messages.