SYNFIALabs
    Legal

    General Terms and Conditions

    Synfia Labs FlexCo · Last updated: 24 August 2026

    These General Terms and Conditions ("Terms") apply exclusively to entrepreneurs within the meaning of section 1 of the Austrian Commercial Code (UGB) and to legal entities under public law. They are not intended for contracts with consumers.

    1. Subject Matter and Scope of Services

    1.1 Service

    Synfia Labs FlexCo, Neubaugasse 36, 1070 Vienna, Austria ("Synfia"), provides companies and organisations with a platform for AI-supported voice and text-based interviews as well as related research, analysis and advisory services. Depending on the offer, the client receives access to the Synfia platform and/or a managed service supported by Synfia.

    1.2 Service Phases

    Depending on the offer, the services include in particular:

    • set-up and alignment with the designated business, IT, data protection and other stakeholders;
    • research and conversation design, interview guide, field concept and configuration of the AI interviewer;
    • participant communication and rollout support, localisation and field monitoring;
    • conducting the conversations and agreed quality control;
    • structured analysis and preparation of executive summaries, deep dives, dashboards or other agreed deliverables;
    • result presentations, workshops and agreed follow-up analyses;
    • provision of self-service functions for configuring, conducting, evaluating and managing interviews.

    The specific scope of services, timeline, group of recipients, participant mode and result formats follow from the individual offer, the service description and the configuration made or approved by the client.

    1.3 Service Standard and Outcome

    Synfia performs the agreed services in accordance with the state of the art available at the time the offer is made and with recognised professional methods. Synfia owes the professional performance of the agreed services and expressly promised work results, but not any particular economic, organisational or other decision-making outcome.

    Synfia may use and replace equivalent technologies, models, methods or components provided that the purpose of the contract, essential functions and the agreed level of protection are not materially impaired. Reasonably separable partial services may be provided, accepted and invoiced separately.

    1.4 Technical and Methodological Principles

    Unless otherwise agreed in the offer, the following principles apply:

    • Primary productive storage of platform, account and interview data takes place within the European Economic Area. Permissible international processing and access are governed by Section 9.8.
    • Voice data is processed only temporarily for conversation management, speech output and transcription; Synfia does not permanently store audio recordings.
    • Only the text transcript is used for further analysis. Synfia does not create voice profiles and does not analyse tone of voice or emotions.
    • Interviews can be configured as technically non-attributable or attributable. The selected mode is displayed before the interview begins.
    • Client and participant data are not used to train generally available or third-party AI models.
    • Synfia does not create personality, behaviour, performance or aptitude profiles of individual participants.
    • Automatically generated results may undergo professional quality assurance within the agreed managed service. Where access to interview data is required for this purpose, commissioning the corresponding scope of services shall be deemed the client's approval.

    1.5 Third-Party Providers and Client-Side Systems

    Synfia may engage suitable hosting, communication, database, authentication, transcription, AI, analytics, translation, error analysis and other service providers. Sub-processors under data protection law are engaged exclusively in accordance with Section 9.

    The client is responsible for systems, data sources, distribution lists, interfaces and communication channels selected or provided by the client. Changes to such systems may result in additional effort and schedule changes. Automated transfers to the client's external systems only take place if expressly agreed.

    1.6 Availability and Further Development

    Synfia endeavours to ensure high availability and low-disruption performance. A specific availability, response time or recovery time is owed only if expressly agreed in a service level agreement or offer. Synfia may further develop functions provided that the usability essential to the contract is not materially impaired.

    2. Conclusion and Amendment of the Contract

    2.1 Contractual Basis and Order of Precedence

    The contractual basis, in the following order of precedence, consists of: (1) the individual offer or order form, (2) the project-specific service description, (3) the data processing agreement under Section 9 including the respective agreed TOMs, and (4) these Terms. The more specific provision prevails over the more general one. Section 9 takes precedence for data processing.

    The privacy policy published at https://synfia.ai/datenschutz provides information on processing for which Synfia is itself the controller and on the general allocation of roles in interviews. It does not extend the contractual scope of services and does not replace the client's information obligations towards participants.

    2.2 Conclusion of Contract

    Offers from Synfia are non-binding unless expressly designated as binding. An order binds the client for 14 calendar days. The contract is concluded upon order confirmation, countersignature of the offer, completion of an electronic ordering process, or the recognisable commencement of performance by Synfia.

    2.3 Text Form

    Contractual declarations, approvals and instructions may be made in text form, in particular by email or via an agreed system, unless a stricter form is prescribed. Automatic acknowledgements of receipt do not constitute acceptance.

    2.4 Changes to Services

    Change or additional requests are treated as such. Synfia informs the client before implementation about material effects on remuneration and deadlines. Without agreement, the previously agreed scope remains applicable. Synfia may implement urgent security or compliance measures after informing the client.

    2.5 Client's Terms

    The client's terms and conditions apply only if Synfia expressly agrees to them in text form. Service-related specifications, order numbers or portal processes do not in themselves constitute consent.

    2.6 Invalid Provisions

    The invalidity of individual provisions does not affect the validity of the remaining provisions. They shall be replaced by the statutory provisions. Where necessary, the parties will agree on a permissible provision that comes as close as possible to the economic purpose.

    3. Rights of Use and Intellectual Property

    3.1 Synfia's Rights

    All rights to technology, software, methods, models, prompt and evaluation logic, templates, taxonomies, documentation, know-how and pre-existing materials remain with Synfia or its licensors. This also applies to generic further developments arising from client projects.

    3.2 Client-Specific Results

    Upon full payment, the client receives an unlimited (in time and territory), non-exclusive right to internally use, reproduce, adapt and share within the agreed group of recipients the reports, presentations, dashboard exports, interview guides and other work results expressly created for and delivered to the client. Publication, commercial sub-licensing or use as a competing product requires Synfia's prior consent.

    The rights of data subjects, rights of third parties and purpose limitations under data protection law remain unaffected. The granting of rights of use does not constitute a data protection permission to process personal data.

    3.3 Client Materials

    Rights to the client's data, trademarks and materials remain with the client. The client grants Synfia the rights required to perform the contract for the term of the contract and warrants that it is entitled to do so.

    3.4 Generic Know-How and Third-Party Components

    Synfia may reuse non-personal and non-confidential know-how gained from performing the services. Client data, conversation content and confidential results may not be used for other clients or for model training. Mandatory licence terms of third-party software and open source components apply in addition.

    3.5 Technical Foundations and References

    There is no claim to the release of source code, model weights, system prompts, internal evaluation logic, development documents or interim results unless expressly agreed. Synfia may use the client's name, logo or project description as a reference only with the client's prior consent.

    4. Client's Obligations and Responsibility

    4.1 Cooperation

    The client provides all necessary information, decisions, approvals, data, access and contact persons in good time and coordinates its internal stakeholders, in particular the business department, IT, information security, data protection and – where necessary – the works council or staff representation.

    4.2 Participants, Purposes and Legal Bases

    The client determines the purpose, topic, group of participants, interview mode and use of the results. The client is responsible for selecting and approaching participants and for the lawfulness of the processing it initiates. In particular, the client ensures:

    • an appropriate legal basis for each processing operation;
    • complete and timely information to participants in accordance with applicable data protection law;
    • any required consents, co-determination rights and, where applicable, a data protection impact assessment;
    • the lawfulness of the invitation and communication with participants;
    • the admissibility of the participant group, the questions asked and the subsequent use or sharing of results.

    Synfia provides product-related information on the interview start page, in particular a notice regarding the use of AI, the sender and the configured interview mode. This information does not replace the client's own information obligations. Synfia provides support within the agreed scope but does not provide legal advice.

    4.3 Content, Uploads and Systems

    The client warrants that content, data, distribution lists, contact information, PDF and text files, trademarks, access credentials and instructions provided are accurate, complete, secure and lawfully usable. The client uploads documents and initiates their AI-supported processing only if entitled to do so and if the data subjects have been duly informed.

    The client takes into account that the optional PII filter is applied only to interview transcripts and not to uploaded reference documents. The client informs Synfia before the project starts about special confidentiality requirements and other increased risks.

    4.4 Accounts and Permissions

    The client keeps user accounts and access credentials confidential, grants permissions on a need-to-know basis and promptly removes access that is no longer required. Actions taken via a user account are attributed to the client insofar as the client is responsible for the misuse. Actual or suspected unauthorised access must be reported to Synfia without undue delay.

    The client decides which of its users may access all data within the client account as administrators and which users may view only released analyses or excerpts.

    4.5 Delayed Cooperation

    In the event of delayed or insufficient cooperation, deadlines are extended appropriately. Synfia may suspend affected services and, after prior notice, invoice demonstrable additional effort at the agreed or, failing that, customary rates.

    4.6 Review and Use of Results

    AI-supported conversations, translations and analyses may be incorrect, incomplete, probabilistic or ambiguous. Before any use with significant impact, the client reviews results professionally and with human judgement and remains responsible for its decisions and for the lawfulness of further use.

    In the standard service Synfia does not create individual personality, behaviour, performance or aptitude scores and does not make automated decisions about participants. If the client intends such further processing outside the standard service, the client is responsible for its independent legal assessment and implementation; such processing is not part of the agreed Synfia service.

    4.7 Indemnification

    If the client culpably infringes third-party rights or statutory obligations through content provided, unlawful instructions, missing participant information or use of the platform or results in breach of contract, the client indemnifies Synfia against justified third-party claims and reasonable costs of legal defence. Synfia informs the client without undue delay about such claims and, where reasonable, enables the client to participate in the legal defence.

    5. Specific Requirements for Interviews and AI Use

    5.1 Permitted Project Purpose

    Synfia may be used only for lawful, agreed business purposes. Prohibited are in particular unlawful surveillance, deception about the use of AI, discrimination, harassment, manipulation and infringements of personality, copyright, data protection or confidentiality rights. The client may not process unlawful, harmful or security-endangering content or use the platform to circumvent technical protection measures.

    5.2 Interview Modes and Protection of Participants

    For each interview the client selects either a technically non-attributable or an attributable mode. The client may communicate a technically non-attributable mode only as such and may not present an attributable mode as anonymous or technically non-attributable.

    In technically non-attributable interviews, no link is established between the invitation or email address and the stored transcript. The client refrains from attempting to circumvent this technical separation or to specifically re-identify participants contrary to the information provided to them.

    The client is aware that a person's identity may be indirectly recognisable due to the content of their answers, a very small participant group or additional knowledge. The client takes this risk into account when selecting the participant group, framing questions, analysing and publishing. Results about small groups may not be combined or disclosed in a way that identifies protected individuals contrary to the announced mode.

    In an attributable mode, the client may use invitation or participant data only if this is lawful and transparently communicated to participants.

    5.3 Special Categories of Personal Data

    The standard service is not intended for the targeted collection of special categories of personal data under Art. 9 GDPR or personal data relating to criminal convictions and offences under Art. 10 GDPR. The client may initiate such systematic processing only after prior agreement in text form. Prerequisites include in particular an appropriate legal basis, complete participant information, an agreed protection and deletion concept and – where necessary – a data protection impact assessment.

    Synfia may refuse or suspend such processing or require additional protective measures. Voluntary disclosures by a participant in a free-text answer do not affect the client's responsibility for handling such data.

    5.4 Minors

    The standard service is aimed at persons of legal age. The client may specifically include minors only after prior agreement in text form and must first ensure the relevant legal bases, information and consent requirements and appropriate protective measures. Synfia does not carry out general age verification for public interview links.

    5.5 Transparency and AI Regulation

    Each party fulfils the obligations applicable to its role under applicable AI and data protection law, in particular Regulation (EU) 2024/1689. Before the interview begins, Synfia indicates that the interaction is with an AI system and not with a human. The client may not remove, obscure or contradict this notice and provides all further information required.

    Synfia provides the client, within the agreed scope, with information on how the platform works and how to use it responsibly. The final assessment of the admissibility of the specific use case and of the client's decisions remains with the client.

    5.6 Optional PII Filter

    The optional PII filter is deactivated by default. If activated by the client, this is displayed to participants before the interview begins. The filter is intended to redact directly recognisable personal information in the text transcript before it is permanently stored. The unredacted version is processed only temporarily for this operation and is not permanently stored as an interview transcript.

    The client acknowledges that automated detection may be faulty or incomplete and that conversation content may allow conclusions about individuals even without direct identifiers. The filter therefore does not guarantee complete anonymisation and does not release the client from its legal obligations.

    5.7 Quotes and Publications

    As part of agreed analyses, Synfia may propose redacted or not directly attributable quotes. Before publishing or sharing, the client reviews quotes and results and ensures that no unlawful identification, disclosure of special categories of data or infringement of third-party rights occurs.

    6. Project Management, Maintenance and Support

    6.1 Project Communication

    Timeline, alignment meetings, approvals and contact persons follow from the offer or project plan. Synfia informs the client about material delays and project-related disruptions without undue delay.

    6.2 Maintenance and Technical Changes

    Synfia may maintain, secure and further develop the infrastructure used to provide the services. Plannable measures with material impact on an ongoing interview field are announced in advance where possible. Emergency and security measures may be carried out immediately.

    6.3 Support

    Project and support requests should be directed to the agreed contact person or to hello@synfia.ai. Standard service hours are Monday to Thursday 08:00-17:00 and Friday 08:00-12:00 Central European Time, excluding public holidays at Synfia's registered office. Individual response times apply only if expressly agreed.

    6.4 Support Access

    Where access to client data is required for support, error analysis, maintenance, security or incident handling, such access is carried out by authorised persons, limited in time and scope and generally after the client's approval. Access is logged to the extent technically possible. In urgent security cases Synfia may take the necessary measures without prior approval and informs the client afterwards without undue delay, insofar as legally and factually possible.

    7. Remuneration and Payment Terms

    7.1 Prices and Additional Costs

    The prices stated in the offer, order form or electronic ordering process apply in euros plus statutory VAT. Travel, translation, communication, third-party and other ancillary costs are charged only if agreed or approved.

    7.2 Invoicing

    Managed services are invoiced as a project fee, by milestones or on a time and materials basis. An effort estimate is not a fixed price. Synfia may invoice according to agreed milestones or in line with the progress of performance.

    For self-service offerings, the price, billing period, scope of functions and, where applicable, the minimum term stated in the ordering process apply. Automatic renewal takes place only if expressly stated in the ordering process or offer.

    7.3 Additional Services

    Services outside the agreed scope, in particular additional languages, participant groups, analysis variants, workshops, integrations or repetitions due to changed requirements, are remunerated following a confirmed change request.

    7.4 Due Date and Default

    Invoices are due without deduction within 14 calendar days of receipt unless the offer or ordering process provides otherwise. In the event of default, statutory default interest and collection costs apply. After an unsuccessful reminder with a reasonable grace period, Synfia may suspend affected services.

    For optional self-service payments, payment data is processed directly by the payment service provider used. Synfia does not receive complete card or bank details.

    7.5 Set-Off

    The client may set off only with undisputed or legally established claims. A right of retention may be exercised only for claims arising from the same contractual relationship.

    8. Term and Termination

    8.1 Project Term

    The project period and deadlines follow from the offer. The contract ends upon full performance of the agreed services, without the need for termination.

    8.2 Termination of Ongoing Services

    Where ongoing services are agreed for an indefinite period, they may be terminated with three months' notice to the end of a month, unless the offer or ordering process provides otherwise. For self-service subscriptions, the notice periods stated there apply.

    8.3 Termination for Cause

    Each party may terminate for cause. Prior to termination due to a remediable breach of duty, a reasonable grace period must generally be set. A grace period is not required in the case of a serious security breach, unlawful use, wilful damage, final refusal to perform or other unreasonableness.

    8.4 Consequences of Termination

    Before the contract ends, the client may export the transcripts and results available under the agreed scope of functions. After the contract ends, Synfia provides agreed work results and exports, provided that all due fees have been paid and the client requests this in good time. Personal data is returned or deleted in accordance with Section 9.13.

    8.5 Force Majeure

    Neither party is liable for delays due to events beyond its reasonable control. The affected party informs the other party without undue delay and mitigates the effects. If the impediment lasts longer than 60 days, either party may terminate the affected part of the services.

    9. Data Protection and Processing under Art. 28 GDPR

    9.1 Integral Part, Roles and Scope

    This Section 9 contains the data processing agreement pursuant to Art. 28 GDPR ("DPA") and forms part of every contract insofar as Synfia processes personal data on behalf of the client. The client is the controller and Synfia the processor. Where the client is itself a processor, Synfia processes as a further processor; the client warrants that it is entitled to engage Synfia.

    Insofar as the data protection law of the United Kingdom or Switzerland applies to the processing, this Section also serves as the corresponding data processing agreement; references to the GDPR shall be read as referring to the functionally equivalent provisions of the applicable law.

    Insofar as Synfia processes personal data for its own purposes, in particular for contract administration, billing, security of its own services, abuse prevention or legal enforcement, Synfia acts as an independent controller to the extent permitted by law. Details are set out in Synfia's privacy policy.

    9.2 Subject Matter, Duration, Nature and Purpose

    Subject matter: provision and performance of the agreed AI-supported voice and text interview, research and analysis services, including participant communication, transcription, analysis, provision of results, storage, support and – where agreed – processing of uploaded context materials.

    Duration: the term of the main contract, including the export, return, deletion and backup periods required under Section 9.13.

    Nature and purposes: receiving and, where applicable, collecting, transmitting, temporary voice processing, transcribing, translating, structuring, organising, redacting, pseudonymising, storing, querying, analysing, aggregating, visualising, providing, exporting, restricting and deleting for the purpose of conducting and evaluating the interviews defined by the client as well as for security, support and error correction.

    Categories of data:

    • contact and invitation data, in particular email addresses;
    • participant identifiers, attributions or pseudonyms, insofar as the selected mode provides for this;
    • conversation and answer content as well as the text transcripts generated from it;
    • audio data processed temporarily during the interaction without permanent audio storage;
    • language, localisation, participation and interaction metadata;
    • organisational, segment and context information provided by the client;
    • uploaded text and PDF files;
    • analysis, aggregate, reporting, export, log and necessary support data.

    Special categories of personal data under Art. 9 GDPR or data under Art. 10 GDPR are not part of the standard service and may be processed systematically only under the conditions of Sections 5.3 and 9.3.

    Categories of data subjects: in particular employees, applicants, customers, prospects, suppliers, partners, members, citizens or other stakeholders selected by the client, as well as the client's contact persons and users.

    Scope and frequency: one-off, periodic or continuous in accordance with the offer and project configuration; the number of participants, regions, languages and data volumes follow from the service description and usage.

    9.3 Client's Obligations and Rights

    The client determines the purposes and essential means of the processing and is responsible in particular for:

    • lawfulness, transparency, purpose limitation, data minimisation and accuracy;
    • selection and approach of participants and the chosen attributability;
    • fulfilment of information, co-determination, documentation and data subject obligations;
    • the existence of a legal basis and, where applicable, required consents;
    • the admissibility of uploaded context documents and information about third parties;
    • defining and implementing required deletions;
    • carrying out any required data protection impact assessment and prior consultation.

    Before processing begins, the client informs Synfia about special categories of personal data, data under Art. 10 GDPR, the targeted inclusion of minors, high risks and mandatory deviating deletion requirements. The client does not issue instructions that violate applicable data protection law.

    9.4 Instructions

    Synfia processes personal data exclusively on the documented instructions of the client, including with regard to transfers to third countries, unless required to do so by law. The main contract, offer, project configuration and use of the provided functions constitute the initial instructions. Further instructions must be issued in text form.

    If Synfia is legally obliged to carry out processing, Synfia informs the client in advance unless the law prohibits this on important grounds of public interest. If Synfia considers an instruction to be unlawful, Synfia informs the client without undue delay and may suspend its execution pending clarification.

    9.5 Confidentiality

    Synfia engages only persons who are bound to confidentiality or subject to an appropriate statutory duty of secrecy. Permissions are granted and reviewed according to the need-to-know and least-privilege principles.

    9.6 Technical and Organisational Measures

    Taking into account the state of the art, implementation costs and the nature and risk of the processing, Synfia ensures an appropriate level of protection pursuant to Art. 32 GDPR. The measures include in particular:

    • encryption of personal data in transit and at rest;
    • role-based, restricted access rights and strong authentication for administrative access;
    • logical separation of data belonging to different clients;
    • logging and monitoring of security-relevant access and technical errors;
    • governed development, change, vulnerability and incident processes;
    • backup and recovery procedures;
    • data minimisation and, where agreed, pseudonymisation or redaction;
    • no permanent storage of audio recordings;
    • no use of processed data to train generally available or third-party AI models;
    • governed deletion procedures and risk-based selection of service providers.

    The current detailed description of the technical and organisational measures is made available to the client on a confidential basis in the Data Security Overview or separate TOM documentation and, in the version provided at the time of contract conclusion, forms part of this DPA. Synfia may change individual measures provided that the contractually promised level of protection is not reduced.

    9.7 Sub-Processors

    The client grants Synfia general written authorisation to engage the sub-processors listed below. Synfia concludes agreements with them that ensure a substantially equivalent level of data protection and the requirements of Art. 28(4) GDPR. Synfia remains responsible to the client for the fulfilment of its sub-processors' obligations.

    The sub-processors currently material for processed data are:

    ProviderLocationTaskTypical scope and place of processing
    Supabase Pte. Ltd.SingaporePlatform database, file storage and authenticationAccount, interview, transcript, analysis and upload data; primary productive storage in Frankfurt, Germany
    Amazon Web Services, Inc.USACloud infrastructure as a further sub-processor of SupabaseInfrastructure processing for the productive platform in the Frankfurt region
    Google Cloud EMEA LimitedIrelandEnterprise AI for conversation management, translation, text analysis and the optional PII filterRequired text and context data; processing for Synfia in the configured European region; no use for training public models
    Eleven Labs, Inc.USAVoice processing, transcription and speech outputTemporary voice and text processing; no permanent storage of audio data in the Synfia configuration
    Functional Software, Inc. (Sentry)USATechnical error analysis and monitoringTechnical error, device and usage data; no systematic transfer of interview answers, transcripts, participant email addresses or upload content; Germany region
    Plus Five Five, Inc. (Resend)USASending interview invitations and transactional emailsEmail addresses, message content and delivery metadata; processing may take place in the USA

    On request, Synfia provides the client with the current identity and contact information of the sub-processors engaged and, where necessary, of relevant further sub-processors.

    Synfia generally informs the client at least 30 days before adding or replacing a sub-processor. Within 14 days of receiving this information, the client may object on demonstrable, objectively justified data protection grounds. The parties will seek a reasonable solution. If none is possible, Synfia may refrain from using the sub-processor concerned or either party may terminate the objectively affected part of the services as of the date of deployment. An objection to a provider necessary for the service does not create a claim to a technically or economically unreasonable alternative solution.

    9.8 International Data Transfers

    Primary productive storage takes place within the European Economic Area. Due to the international group structures of individual providers, access or further processing may take place in third countries, in particular in the USA.

    Synfia and its sub-processors transfer personal data only in compliance with Art. 44 et seq. GDPR or the functionally equivalent provisions of applicable UK or Swiss data protection law. Depending on the provider and the processing, an adequacy decision – including the EU-US Data Privacy Framework where applicable – appropriate safeguards such as the European Commission's Standard Contractual Clauses, or applicable UK or Swiss transfer addenda including any required supplementary measures are used. Synfia provides the client with information on the safeguards relevant in the individual case upon request.

    9.9 Data Subject Rights and Non-Attributable Interviews

    Taking into account the nature of the processing, Synfia assists the client by appropriate technical and organisational measures with requests for access, rectification, erasure, restriction, objection and data portability. Synfia forwards requests from data subjects to the client unless there is a legal obligation to respond directly.

    In technically non-attributable interviews there is no link between the invitation or email address and the stored transcript. Insofar as a data subject cannot be identified on the basis of the available data, fulfilling a request relating to a specific transcript may factually be impossible. Synfia is not obliged to collect additional identifying attributes solely to enable such attribution.

    9.10 Assistance Obligations

    Taking into account the nature of the processing and the information available, Synfia assists the client with the obligations under Art. 32 to 36 GDPR, in particular through security information and appropriate contributions to data protection impact assessments and prior consultations. The legal assessment and decision remain with the client.

    9.11 Personal Data Breaches

    Synfia informs the client without undue delay after becoming aware of a breach of the protection of personal data processed by Synfia on the client's behalf. The notification includes, where available, a description of the nature of the incident, the data and persons affected, the likely consequences, the measures taken or proposed and a point of contact. Missing information is provided subsequently without undue delay.

    9.12 Evidence and Audits

    Synfia provides the client with the information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to the legally required reviews, including inspections. Suitable audit reports, certificates, security documentation and questionnaires may be used as a first resort.

    Where there is justified need, the client may – generally once per year and with 20 working days' advance notice – conduct an audit through an independent, qualified auditor bound to confidentiality. These time restrictions do not apply in the event of a specific security incident, justified suspicion of a material breach or an official order. Audits take place without avoidable disruption to operations and without disclosing data of other clients or information whose disclosure would jeopardise the security of the services. Extraordinary effort on Synfia's part is subject to remuneration unless a material breach by Synfia is established.

    9.13 Return and Deletion

    During the term of the contract, the client may delete individual attributable records, interviews, projects or the client account using the functions provided for this purpose. When an interview is deleted, the associated answers, transcripts, analyses, invitation and attribution data and uploaded context documents are deleted from the productive systems insofar as attribution is possible. In technically non-attributable interviews, targeted individual deletion may be impossible due to the lack of attribution.

    After the end of the processing, Synfia returns the personal data in an available standard format or deletes it, at the client's choice, unless a statutory retention obligation applies. The client must request any desired return no later than the end of the contract and retrieve the provided data within the communicated period. Upon deletion or closure of the client account, the associated productive account, interview and project data are deleted automatically.

    Deleted data may remain in backup copies for up to 30 days. Backup copies serve exclusively to restore operations after technical faults, are not processed for other purposes in regular operation and are subsequently overwritten as part of the regular cycle. Audio recordings are not permanently stored.

    9.14 Requests from Authorities

    Synfia informs the client about binding requests from authorities insofar as legally permissible, reviews their formal lawfulness and limits disclosure to what is necessary. Synfia will not voluntarily recognise or comply with requests from a third-country authority unless an applicable legal obligation exists.

    9.15 Remuneration for Assistance

    Assistance within the scope of the standard functions and the fulfilment of Synfia's statutory minimum obligations are covered by the agreed remuneration. Extraordinary effort due to additional instructions, complex data subject requests, impact assessments or audits may be reasonably remunerated after prior notice, unless the effort is due to a breach by Synfia.

    9.16 Termination, Liability and Precedence

    This Section applies for the duration of the processing. Section 10 applies to liability unless Art. 82 GDPR or other mandatory law provides otherwise. In the event of conflicts, this Section takes precedence for the processing. Synfia informs the client without undue delay if Synfia can no longer meet the requirements of this Section and takes appropriate measures to restore compliance.

    10. Liability and Warranty

    10.1 Acceptance and Warranty

    For results expressly agreed as work performance, the client reviews them within ten working days of provision. The client declares acceptance or notifies material, comprehensible deviations. Immaterial defects do not prevent acceptance. Ongoing services are not subject to formal acceptance.

    In the event of defects, Synfia is initially entitled to rectify or provide a replacement. If this fails or is unreasonable, statutory rights apply. Towards entrepreneurs, the warranty period is twelve months from handover or acceptance, to the extent legally permissible.

    10.2 AI-Specific Limits

    Synfia does not warrant the absolute accuracy, completeness or reproducibility of AI-generated conversations, translations or analyses. This does not release Synfia from its obligation to configure professionally, ensure quality and perform the agreed services.

    The PII filter supports the detection and redaction of directly recognisable personal information but guarantees neither freedom from error nor complete anonymisation.

    10.3 Standard of Liability

    Synfia is liable without limitation for intent, gross negligence, personal injury, fraudulent concealment, assumed guarantees and under mandatory law. In the case of slight negligence, Synfia is liable only for breach of material contractual obligations and limited to the damage typically foreseeable at the time the contract was concluded.

    10.4 Liability Cap

    To the extent legally permissible, liability for slight negligence is limited per damage event and in aggregate to the net remuneration of the affected project or, for ongoing services, to the net remuneration paid in the twelve months preceding the event giving rise to the damage. Mandatory claims, in particular under Art. 82 GDPR, remain unaffected.

    10.5 Indirect Damages and Third-Party Services

    To the extent legally permissible, Synfia is not liable in cases of slight negligence for lost profits, missed savings or pure consequential damages. Synfia is liable for disruptions to third-party services in accordance with the above rules insofar as Synfia is responsible for their selection, management or its own breach of duty.

    10.6 Limitation Period

    To the extent legally permissible, claims for damages become time-barred twelve months after knowledge of the damage and the party causing it, and no later than three years after the event. This does not apply to claims based on intent, gross negligence, personal injury, data protection breaches or other mandatory claims.

    11. Confidentiality and Protection of Trade Secrets

    11.1 Confidential Information

    Each party treats non-public commercial, technical, methodological, organisational and personal information of the other party as confidential and uses it only to perform the contract. This includes in particular business questions, conversation content, results, strategies, security concepts, models, prompts, system architectures and the Data Security Overview or TOM documentation provided in confidence.

    11.2 Exceptions

    Information is not confidential if it is demonstrably publicly known, lawfully obtained from third parties, independently developed or was already lawfully known. Legally required disclosures are permitted; where allowed, the affected party is informed in advance.

    11.3 Protection and Duration

    Access is limited to persons with a legitimate need to know and an appropriate confidentiality obligation. The obligation continues for five years after the end of the contract; for trade secrets and personal data for as long as their need for protection or statutory obligations exist.

    12. Final Provisions

    12.1 Place of Performance

    The place of performance is Vienna, Austria, unless the nature of the service dictates otherwise.

    12.2 Applicable Law

    Austrian law applies, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. Mandatory data protection provisions, in particular for processing in the European Economic Area, the United Kingdom or Switzerland, remain unaffected.

    12.3 Place of Jurisdiction

    To the extent legally permissible, the competent court in Vienna has exclusive jurisdiction over disputes arising from or in connection with the contract. Synfia may also bring an action at the client's general place of jurisdiction.

    12.4 Assignment and Subcontracting

    The client may assign the contract only with Synfia's consent. Synfia may assign the contract to an affiliated company or as part of a business transfer, provided that the client's legitimate interests are preserved. The engagement of subcontractors is additionally governed by Section 1.5 and, for data processing, by Section 9.7.

    12.5 Notices

    Legally relevant notices are sent to the contact details stated in the offer or last communicated in text form. Terminations require text form unless a stricter form is prescribed.

    12.6 Entire Agreement

    The contract contains the entire agreement on the subject matter. There are no verbal side agreements. Individual agreements take precedence.

    Contact
    Synfia Labs FlexCo
    Neubaugasse 36
    1070 Vienna, Austria
    Email: hello@synfia.ai
    Commercial register number: FN 675642 t
    Commercial register court: Commercial Court Vienna