Synfia Labs FlexCo · Last updated: 24 August 2026
These General Terms and Conditions ("Terms") apply exclusively to entrepreneurs within the meaning of section 1 of the Austrian Commercial Code (UGB) and to legal entities under public law. They are not intended for contracts with consumers.
Synfia Labs FlexCo, Neubaugasse 36, 1070 Vienna, Austria ("Synfia"), provides companies and organisations with a platform for AI-supported voice and text-based interviews as well as related research, analysis and advisory services. Depending on the offer, the client receives access to the Synfia platform and/or a managed service supported by Synfia.
Depending on the offer, the services include in particular:
The specific scope of services, timeline, group of recipients, participant mode and result formats follow from the individual offer, the service description and the configuration made or approved by the client.
Synfia performs the agreed services in accordance with the state of the art available at the time the offer is made and with recognised professional methods. Synfia owes the professional performance of the agreed services and expressly promised work results, but not any particular economic, organisational or other decision-making outcome.
Synfia may use and replace equivalent technologies, models, methods or components provided that the purpose of the contract, essential functions and the agreed level of protection are not materially impaired. Reasonably separable partial services may be provided, accepted and invoiced separately.
Unless otherwise agreed in the offer, the following principles apply:
Synfia may engage suitable hosting, communication, database, authentication, transcription, AI, analytics, translation, error analysis and other service providers. Sub-processors under data protection law are engaged exclusively in accordance with Section 9.
The client is responsible for systems, data sources, distribution lists, interfaces and communication channels selected or provided by the client. Changes to such systems may result in additional effort and schedule changes. Automated transfers to the client's external systems only take place if expressly agreed.
Synfia endeavours to ensure high availability and low-disruption performance. A specific availability, response time or recovery time is owed only if expressly agreed in a service level agreement or offer. Synfia may further develop functions provided that the usability essential to the contract is not materially impaired.
The contractual basis, in the following order of precedence, consists of: (1) the individual offer or order form, (2) the project-specific service description, (3) the data processing agreement under Section 9 including the respective agreed TOMs, and (4) these Terms. The more specific provision prevails over the more general one. Section 9 takes precedence for data processing.
The privacy policy published at https://synfia.ai/datenschutz provides information on processing for which Synfia is itself the controller and on the general allocation of roles in interviews. It does not extend the contractual scope of services and does not replace the client's information obligations towards participants.
Offers from Synfia are non-binding unless expressly designated as binding. An order binds the client for 14 calendar days. The contract is concluded upon order confirmation, countersignature of the offer, completion of an electronic ordering process, or the recognisable commencement of performance by Synfia.
Contractual declarations, approvals and instructions may be made in text form, in particular by email or via an agreed system, unless a stricter form is prescribed. Automatic acknowledgements of receipt do not constitute acceptance.
Change or additional requests are treated as such. Synfia informs the client before implementation about material effects on remuneration and deadlines. Without agreement, the previously agreed scope remains applicable. Synfia may implement urgent security or compliance measures after informing the client.
The client's terms and conditions apply only if Synfia expressly agrees to them in text form. Service-related specifications, order numbers or portal processes do not in themselves constitute consent.
The invalidity of individual provisions does not affect the validity of the remaining provisions. They shall be replaced by the statutory provisions. Where necessary, the parties will agree on a permissible provision that comes as close as possible to the economic purpose.
All rights to technology, software, methods, models, prompt and evaluation logic, templates, taxonomies, documentation, know-how and pre-existing materials remain with Synfia or its licensors. This also applies to generic further developments arising from client projects.
Upon full payment, the client receives an unlimited (in time and territory), non-exclusive right to internally use, reproduce, adapt and share within the agreed group of recipients the reports, presentations, dashboard exports, interview guides and other work results expressly created for and delivered to the client. Publication, commercial sub-licensing or use as a competing product requires Synfia's prior consent.
The rights of data subjects, rights of third parties and purpose limitations under data protection law remain unaffected. The granting of rights of use does not constitute a data protection permission to process personal data.
Rights to the client's data, trademarks and materials remain with the client. The client grants Synfia the rights required to perform the contract for the term of the contract and warrants that it is entitled to do so.
Synfia may reuse non-personal and non-confidential know-how gained from performing the services. Client data, conversation content and confidential results may not be used for other clients or for model training. Mandatory licence terms of third-party software and open source components apply in addition.
There is no claim to the release of source code, model weights, system prompts, internal evaluation logic, development documents or interim results unless expressly agreed. Synfia may use the client's name, logo or project description as a reference only with the client's prior consent.
The client provides all necessary information, decisions, approvals, data, access and contact persons in good time and coordinates its internal stakeholders, in particular the business department, IT, information security, data protection and – where necessary – the works council or staff representation.
The client determines the purpose, topic, group of participants, interview mode and use of the results. The client is responsible for selecting and approaching participants and for the lawfulness of the processing it initiates. In particular, the client ensures:
Synfia provides product-related information on the interview start page, in particular a notice regarding the use of AI, the sender and the configured interview mode. This information does not replace the client's own information obligations. Synfia provides support within the agreed scope but does not provide legal advice.
The client warrants that content, data, distribution lists, contact information, PDF and text files, trademarks, access credentials and instructions provided are accurate, complete, secure and lawfully usable. The client uploads documents and initiates their AI-supported processing only if entitled to do so and if the data subjects have been duly informed.
The client takes into account that the optional PII filter is applied only to interview transcripts and not to uploaded reference documents. The client informs Synfia before the project starts about special confidentiality requirements and other increased risks.
The client keeps user accounts and access credentials confidential, grants permissions on a need-to-know basis and promptly removes access that is no longer required. Actions taken via a user account are attributed to the client insofar as the client is responsible for the misuse. Actual or suspected unauthorised access must be reported to Synfia without undue delay.
The client decides which of its users may access all data within the client account as administrators and which users may view only released analyses or excerpts.
In the event of delayed or insufficient cooperation, deadlines are extended appropriately. Synfia may suspend affected services and, after prior notice, invoice demonstrable additional effort at the agreed or, failing that, customary rates.
AI-supported conversations, translations and analyses may be incorrect, incomplete, probabilistic or ambiguous. Before any use with significant impact, the client reviews results professionally and with human judgement and remains responsible for its decisions and for the lawfulness of further use.
In the standard service Synfia does not create individual personality, behaviour, performance or aptitude scores and does not make automated decisions about participants. If the client intends such further processing outside the standard service, the client is responsible for its independent legal assessment and implementation; such processing is not part of the agreed Synfia service.
If the client culpably infringes third-party rights or statutory obligations through content provided, unlawful instructions, missing participant information or use of the platform or results in breach of contract, the client indemnifies Synfia against justified third-party claims and reasonable costs of legal defence. Synfia informs the client without undue delay about such claims and, where reasonable, enables the client to participate in the legal defence.
Synfia may be used only for lawful, agreed business purposes. Prohibited are in particular unlawful surveillance, deception about the use of AI, discrimination, harassment, manipulation and infringements of personality, copyright, data protection or confidentiality rights. The client may not process unlawful, harmful or security-endangering content or use the platform to circumvent technical protection measures.
For each interview the client selects either a technically non-attributable or an attributable mode. The client may communicate a technically non-attributable mode only as such and may not present an attributable mode as anonymous or technically non-attributable.
In technically non-attributable interviews, no link is established between the invitation or email address and the stored transcript. The client refrains from attempting to circumvent this technical separation or to specifically re-identify participants contrary to the information provided to them.
The client is aware that a person's identity may be indirectly recognisable due to the content of their answers, a very small participant group or additional knowledge. The client takes this risk into account when selecting the participant group, framing questions, analysing and publishing. Results about small groups may not be combined or disclosed in a way that identifies protected individuals contrary to the announced mode.
In an attributable mode, the client may use invitation or participant data only if this is lawful and transparently communicated to participants.
The standard service is not intended for the targeted collection of special categories of personal data under Art. 9 GDPR or personal data relating to criminal convictions and offences under Art. 10 GDPR. The client may initiate such systematic processing only after prior agreement in text form. Prerequisites include in particular an appropriate legal basis, complete participant information, an agreed protection and deletion concept and – where necessary – a data protection impact assessment.
Synfia may refuse or suspend such processing or require additional protective measures. Voluntary disclosures by a participant in a free-text answer do not affect the client's responsibility for handling such data.
The standard service is aimed at persons of legal age. The client may specifically include minors only after prior agreement in text form and must first ensure the relevant legal bases, information and consent requirements and appropriate protective measures. Synfia does not carry out general age verification for public interview links.
Each party fulfils the obligations applicable to its role under applicable AI and data protection law, in particular Regulation (EU) 2024/1689. Before the interview begins, Synfia indicates that the interaction is with an AI system and not with a human. The client may not remove, obscure or contradict this notice and provides all further information required.
Synfia provides the client, within the agreed scope, with information on how the platform works and how to use it responsibly. The final assessment of the admissibility of the specific use case and of the client's decisions remains with the client.
The optional PII filter is deactivated by default. If activated by the client, this is displayed to participants before the interview begins. The filter is intended to redact directly recognisable personal information in the text transcript before it is permanently stored. The unredacted version is processed only temporarily for this operation and is not permanently stored as an interview transcript.
The client acknowledges that automated detection may be faulty or incomplete and that conversation content may allow conclusions about individuals even without direct identifiers. The filter therefore does not guarantee complete anonymisation and does not release the client from its legal obligations.
As part of agreed analyses, Synfia may propose redacted or not directly attributable quotes. Before publishing or sharing, the client reviews quotes and results and ensures that no unlawful identification, disclosure of special categories of data or infringement of third-party rights occurs.
Timeline, alignment meetings, approvals and contact persons follow from the offer or project plan. Synfia informs the client about material delays and project-related disruptions without undue delay.
Synfia may maintain, secure and further develop the infrastructure used to provide the services. Plannable measures with material impact on an ongoing interview field are announced in advance where possible. Emergency and security measures may be carried out immediately.
Project and support requests should be directed to the agreed contact person or to hello@synfia.ai. Standard service hours are Monday to Thursday 08:00-17:00 and Friday 08:00-12:00 Central European Time, excluding public holidays at Synfia's registered office. Individual response times apply only if expressly agreed.
Where access to client data is required for support, error analysis, maintenance, security or incident handling, such access is carried out by authorised persons, limited in time and scope and generally after the client's approval. Access is logged to the extent technically possible. In urgent security cases Synfia may take the necessary measures without prior approval and informs the client afterwards without undue delay, insofar as legally and factually possible.
The prices stated in the offer, order form or electronic ordering process apply in euros plus statutory VAT. Travel, translation, communication, third-party and other ancillary costs are charged only if agreed or approved.
Managed services are invoiced as a project fee, by milestones or on a time and materials basis. An effort estimate is not a fixed price. Synfia may invoice according to agreed milestones or in line with the progress of performance.
For self-service offerings, the price, billing period, scope of functions and, where applicable, the minimum term stated in the ordering process apply. Automatic renewal takes place only if expressly stated in the ordering process or offer.
Services outside the agreed scope, in particular additional languages, participant groups, analysis variants, workshops, integrations or repetitions due to changed requirements, are remunerated following a confirmed change request.
Invoices are due without deduction within 14 calendar days of receipt unless the offer or ordering process provides otherwise. In the event of default, statutory default interest and collection costs apply. After an unsuccessful reminder with a reasonable grace period, Synfia may suspend affected services.
For optional self-service payments, payment data is processed directly by the payment service provider used. Synfia does not receive complete card or bank details.
The client may set off only with undisputed or legally established claims. A right of retention may be exercised only for claims arising from the same contractual relationship.
The project period and deadlines follow from the offer. The contract ends upon full performance of the agreed services, without the need for termination.
Where ongoing services are agreed for an indefinite period, they may be terminated with three months' notice to the end of a month, unless the offer or ordering process provides otherwise. For self-service subscriptions, the notice periods stated there apply.
Each party may terminate for cause. Prior to termination due to a remediable breach of duty, a reasonable grace period must generally be set. A grace period is not required in the case of a serious security breach, unlawful use, wilful damage, final refusal to perform or other unreasonableness.
Before the contract ends, the client may export the transcripts and results available under the agreed scope of functions. After the contract ends, Synfia provides agreed work results and exports, provided that all due fees have been paid and the client requests this in good time. Personal data is returned or deleted in accordance with Section 9.13.
Neither party is liable for delays due to events beyond its reasonable control. The affected party informs the other party without undue delay and mitigates the effects. If the impediment lasts longer than 60 days, either party may terminate the affected part of the services.
This Section 9 contains the data processing agreement pursuant to Art. 28 GDPR ("DPA") and forms part of every contract insofar as Synfia processes personal data on behalf of the client. The client is the controller and Synfia the processor. Where the client is itself a processor, Synfia processes as a further processor; the client warrants that it is entitled to engage Synfia.
Insofar as the data protection law of the United Kingdom or Switzerland applies to the processing, this Section also serves as the corresponding data processing agreement; references to the GDPR shall be read as referring to the functionally equivalent provisions of the applicable law.
Insofar as Synfia processes personal data for its own purposes, in particular for contract administration, billing, security of its own services, abuse prevention or legal enforcement, Synfia acts as an independent controller to the extent permitted by law. Details are set out in Synfia's privacy policy.
Subject matter: provision and performance of the agreed AI-supported voice and text interview, research and analysis services, including participant communication, transcription, analysis, provision of results, storage, support and – where agreed – processing of uploaded context materials.
Duration: the term of the main contract, including the export, return, deletion and backup periods required under Section 9.13.
Nature and purposes: receiving and, where applicable, collecting, transmitting, temporary voice processing, transcribing, translating, structuring, organising, redacting, pseudonymising, storing, querying, analysing, aggregating, visualising, providing, exporting, restricting and deleting for the purpose of conducting and evaluating the interviews defined by the client as well as for security, support and error correction.
Categories of data:
Special categories of personal data under Art. 9 GDPR or data under Art. 10 GDPR are not part of the standard service and may be processed systematically only under the conditions of Sections 5.3 and 9.3.
Categories of data subjects: in particular employees, applicants, customers, prospects, suppliers, partners, members, citizens or other stakeholders selected by the client, as well as the client's contact persons and users.
Scope and frequency: one-off, periodic or continuous in accordance with the offer and project configuration; the number of participants, regions, languages and data volumes follow from the service description and usage.
The client determines the purposes and essential means of the processing and is responsible in particular for:
Before processing begins, the client informs Synfia about special categories of personal data, data under Art. 10 GDPR, the targeted inclusion of minors, high risks and mandatory deviating deletion requirements. The client does not issue instructions that violate applicable data protection law.
Synfia processes personal data exclusively on the documented instructions of the client, including with regard to transfers to third countries, unless required to do so by law. The main contract, offer, project configuration and use of the provided functions constitute the initial instructions. Further instructions must be issued in text form.
If Synfia is legally obliged to carry out processing, Synfia informs the client in advance unless the law prohibits this on important grounds of public interest. If Synfia considers an instruction to be unlawful, Synfia informs the client without undue delay and may suspend its execution pending clarification.
Synfia engages only persons who are bound to confidentiality or subject to an appropriate statutory duty of secrecy. Permissions are granted and reviewed according to the need-to-know and least-privilege principles.
Taking into account the state of the art, implementation costs and the nature and risk of the processing, Synfia ensures an appropriate level of protection pursuant to Art. 32 GDPR. The measures include in particular:
The current detailed description of the technical and organisational measures is made available to the client on a confidential basis in the Data Security Overview or separate TOM documentation and, in the version provided at the time of contract conclusion, forms part of this DPA. Synfia may change individual measures provided that the contractually promised level of protection is not reduced.
The client grants Synfia general written authorisation to engage the sub-processors listed below. Synfia concludes agreements with them that ensure a substantially equivalent level of data protection and the requirements of Art. 28(4) GDPR. Synfia remains responsible to the client for the fulfilment of its sub-processors' obligations.
The sub-processors currently material for processed data are:
| Provider | Location | Task | Typical scope and place of processing |
|---|---|---|---|
| Supabase Pte. Ltd. | Singapore | Platform database, file storage and authentication | Account, interview, transcript, analysis and upload data; primary productive storage in Frankfurt, Germany |
| Amazon Web Services, Inc. | USA | Cloud infrastructure as a further sub-processor of Supabase | Infrastructure processing for the productive platform in the Frankfurt region |
| Google Cloud EMEA Limited | Ireland | Enterprise AI for conversation management, translation, text analysis and the optional PII filter | Required text and context data; processing for Synfia in the configured European region; no use for training public models |
| Eleven Labs, Inc. | USA | Voice processing, transcription and speech output | Temporary voice and text processing; no permanent storage of audio data in the Synfia configuration |
| Functional Software, Inc. (Sentry) | USA | Technical error analysis and monitoring | Technical error, device and usage data; no systematic transfer of interview answers, transcripts, participant email addresses or upload content; Germany region |
| Plus Five Five, Inc. (Resend) | USA | Sending interview invitations and transactional emails | Email addresses, message content and delivery metadata; processing may take place in the USA |
On request, Synfia provides the client with the current identity and contact information of the sub-processors engaged and, where necessary, of relevant further sub-processors.
Synfia generally informs the client at least 30 days before adding or replacing a sub-processor. Within 14 days of receiving this information, the client may object on demonstrable, objectively justified data protection grounds. The parties will seek a reasonable solution. If none is possible, Synfia may refrain from using the sub-processor concerned or either party may terminate the objectively affected part of the services as of the date of deployment. An objection to a provider necessary for the service does not create a claim to a technically or economically unreasonable alternative solution.
Primary productive storage takes place within the European Economic Area. Due to the international group structures of individual providers, access or further processing may take place in third countries, in particular in the USA.
Synfia and its sub-processors transfer personal data only in compliance with Art. 44 et seq. GDPR or the functionally equivalent provisions of applicable UK or Swiss data protection law. Depending on the provider and the processing, an adequacy decision – including the EU-US Data Privacy Framework where applicable – appropriate safeguards such as the European Commission's Standard Contractual Clauses, or applicable UK or Swiss transfer addenda including any required supplementary measures are used. Synfia provides the client with information on the safeguards relevant in the individual case upon request.
Taking into account the nature of the processing, Synfia assists the client by appropriate technical and organisational measures with requests for access, rectification, erasure, restriction, objection and data portability. Synfia forwards requests from data subjects to the client unless there is a legal obligation to respond directly.
In technically non-attributable interviews there is no link between the invitation or email address and the stored transcript. Insofar as a data subject cannot be identified on the basis of the available data, fulfilling a request relating to a specific transcript may factually be impossible. Synfia is not obliged to collect additional identifying attributes solely to enable such attribution.
Taking into account the nature of the processing and the information available, Synfia assists the client with the obligations under Art. 32 to 36 GDPR, in particular through security information and appropriate contributions to data protection impact assessments and prior consultations. The legal assessment and decision remain with the client.
Synfia informs the client without undue delay after becoming aware of a breach of the protection of personal data processed by Synfia on the client's behalf. The notification includes, where available, a description of the nature of the incident, the data and persons affected, the likely consequences, the measures taken or proposed and a point of contact. Missing information is provided subsequently without undue delay.
Synfia provides the client with the information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to the legally required reviews, including inspections. Suitable audit reports, certificates, security documentation and questionnaires may be used as a first resort.
Where there is justified need, the client may – generally once per year and with 20 working days' advance notice – conduct an audit through an independent, qualified auditor bound to confidentiality. These time restrictions do not apply in the event of a specific security incident, justified suspicion of a material breach or an official order. Audits take place without avoidable disruption to operations and without disclosing data of other clients or information whose disclosure would jeopardise the security of the services. Extraordinary effort on Synfia's part is subject to remuneration unless a material breach by Synfia is established.
During the term of the contract, the client may delete individual attributable records, interviews, projects or the client account using the functions provided for this purpose. When an interview is deleted, the associated answers, transcripts, analyses, invitation and attribution data and uploaded context documents are deleted from the productive systems insofar as attribution is possible. In technically non-attributable interviews, targeted individual deletion may be impossible due to the lack of attribution.
After the end of the processing, Synfia returns the personal data in an available standard format or deletes it, at the client's choice, unless a statutory retention obligation applies. The client must request any desired return no later than the end of the contract and retrieve the provided data within the communicated period. Upon deletion or closure of the client account, the associated productive account, interview and project data are deleted automatically.
Deleted data may remain in backup copies for up to 30 days. Backup copies serve exclusively to restore operations after technical faults, are not processed for other purposes in regular operation and are subsequently overwritten as part of the regular cycle. Audio recordings are not permanently stored.
Synfia informs the client about binding requests from authorities insofar as legally permissible, reviews their formal lawfulness and limits disclosure to what is necessary. Synfia will not voluntarily recognise or comply with requests from a third-country authority unless an applicable legal obligation exists.
Assistance within the scope of the standard functions and the fulfilment of Synfia's statutory minimum obligations are covered by the agreed remuneration. Extraordinary effort due to additional instructions, complex data subject requests, impact assessments or audits may be reasonably remunerated after prior notice, unless the effort is due to a breach by Synfia.
This Section applies for the duration of the processing. Section 10 applies to liability unless Art. 82 GDPR or other mandatory law provides otherwise. In the event of conflicts, this Section takes precedence for the processing. Synfia informs the client without undue delay if Synfia can no longer meet the requirements of this Section and takes appropriate measures to restore compliance.
For results expressly agreed as work performance, the client reviews them within ten working days of provision. The client declares acceptance or notifies material, comprehensible deviations. Immaterial defects do not prevent acceptance. Ongoing services are not subject to formal acceptance.
In the event of defects, Synfia is initially entitled to rectify or provide a replacement. If this fails or is unreasonable, statutory rights apply. Towards entrepreneurs, the warranty period is twelve months from handover or acceptance, to the extent legally permissible.
Synfia does not warrant the absolute accuracy, completeness or reproducibility of AI-generated conversations, translations or analyses. This does not release Synfia from its obligation to configure professionally, ensure quality and perform the agreed services.
The PII filter supports the detection and redaction of directly recognisable personal information but guarantees neither freedom from error nor complete anonymisation.
Synfia is liable without limitation for intent, gross negligence, personal injury, fraudulent concealment, assumed guarantees and under mandatory law. In the case of slight negligence, Synfia is liable only for breach of material contractual obligations and limited to the damage typically foreseeable at the time the contract was concluded.
To the extent legally permissible, liability for slight negligence is limited per damage event and in aggregate to the net remuneration of the affected project or, for ongoing services, to the net remuneration paid in the twelve months preceding the event giving rise to the damage. Mandatory claims, in particular under Art. 82 GDPR, remain unaffected.
To the extent legally permissible, Synfia is not liable in cases of slight negligence for lost profits, missed savings or pure consequential damages. Synfia is liable for disruptions to third-party services in accordance with the above rules insofar as Synfia is responsible for their selection, management or its own breach of duty.
To the extent legally permissible, claims for damages become time-barred twelve months after knowledge of the damage and the party causing it, and no later than three years after the event. This does not apply to claims based on intent, gross negligence, personal injury, data protection breaches or other mandatory claims.
Each party treats non-public commercial, technical, methodological, organisational and personal information of the other party as confidential and uses it only to perform the contract. This includes in particular business questions, conversation content, results, strategies, security concepts, models, prompts, system architectures and the Data Security Overview or TOM documentation provided in confidence.
Information is not confidential if it is demonstrably publicly known, lawfully obtained from third parties, independently developed or was already lawfully known. Legally required disclosures are permitted; where allowed, the affected party is informed in advance.
Access is limited to persons with a legitimate need to know and an appropriate confidentiality obligation. The obligation continues for five years after the end of the contract; for trade secrets and personal data for as long as their need for protection or statutory obligations exist.
The place of performance is Vienna, Austria, unless the nature of the service dictates otherwise.
Austrian law applies, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. Mandatory data protection provisions, in particular for processing in the European Economic Area, the United Kingdom or Switzerland, remain unaffected.
To the extent legally permissible, the competent court in Vienna has exclusive jurisdiction over disputes arising from or in connection with the contract. Synfia may also bring an action at the client's general place of jurisdiction.
The client may assign the contract only with Synfia's consent. Synfia may assign the contract to an affiliated company or as part of a business transfer, provided that the client's legitimate interests are preserved. The engagement of subcontractors is additionally governed by Section 1.5 and, for data processing, by Section 9.7.
Legally relevant notices are sent to the contact details stated in the offer or last communicated in text form. Terminations require text form unless a stricter form is prescribed.
The contract contains the entire agreement on the subject matter. There are no verbal side agreements. Individual agreements take precedence.
Contact
Synfia Labs FlexCo
Neubaugasse 36
1070 Vienna, Austria
Email: hello@synfia.ai
Commercial register number: FN 675642 t
Commercial register court: Commercial Court Vienna