SYNFIALabs
    Legal

    Privacy Policy

    Last updated: 24 August 2026

    1. Controller and contact details

    Unless stated otherwise below, the controller for the processing described in this Privacy Policy is:

    Synfia Labs FlexCo
    Neubaugasse 36
    1070 Vienna
    Austria
    Email: hello@synfia.ai

    This Privacy Policy applies to the synfia.ai website and associated subdomains, the Synfia web application, publicly available product demos, and communications with Synfia.

    For individuals in Switzerland or the United Kingdom, the applicable national data protection laws also apply. References to GDPR rights and principles apply correspondingly under the Swiss Federal Act on Data Protection or the UK GDPR where relevant.

    2. Roles in surveys and interviews

    Synfia provides businesses and organisations with a platform for conducting and analysing AI-assisted voice and text surveys.

    The relevant customer generally determines the purpose, subject, participants, configuration and use of the results. The customer is the controller for this processing, while Synfia processes survey data as a processor on the customer's instructions. Processing is governed by contract, including an agreement under Article 28 GDPR.

    The customer is responsible for informing participants about its specific processing, the applicable legal basis, any consequences of participation and, where relevant, other recipients. Information provided by Synfia supplements but does not replace the customer's participant notice.

    Synfia acts as controller for processing relating to its own website, product demo, business communications, customer and user accounts, billing, and the security and operation of its services.

    3. Website and technical delivery

    When you visit our website, technically necessary connection and log data are processed. These may include your IP address, access date and time, requested content, referrer URL, browser, operating system, device information and technical error data.

    We process these data to provide the website securely, reliably and without errors and to prevent misuse. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in operating and securing our online services. Access to terminal equipment that is strictly necessary for requested services is carried out under the applicable statutory exemptions.

    Our website and business email communications are provided by a hosting and communications service provider in Europe. Log data are retained only for as long as necessary for operations, security, troubleshooting or investigation of a specific incident, subject to statutory retention and evidence requirements.

    4. Cookies, consent management and web analytics

    We use technically necessary cookies or similar storage technologies where required to provide the website, maintain security or save your privacy settings. Where personal data are processed, the legal basis is Article 6(1)(f) GDPR or, where applicable, Article 6(1)(c) GDPR.

    Non-essential analytics and marketing technologies are activated only with your consent. The legal basis is Article 6(1)(a) GDPR together with applicable terminal-equipment privacy rules. You may change your choices at any time for the future through the Cookie Settings available on the website. Withdrawal does not affect the lawfulness of earlier processing. Consent information is retained where necessary to administer and demonstrate your choice.

    The following services may be used after consent:

    • Google Tag Manager and Google Analytics, provided by Google Ireland Limited, to control approved tags and compile website statistics. We do not use Google Analytics for Google Signals, cross-device recognition or personalised Google advertising. User- and event-level Analytics data are set to a two-month retention period.
    • Meta Pixel, provided by Meta Platforms Ireland Limited, for campaign measurement and personalised advertising or retargeting.
    • LinkedIn Insight Tag, provided by LinkedIn Ireland Unlimited Company, for campaign measurement and personalised advertising or retargeting.

    The data processed may include online identifiers, IP address, browser and device information, pages visited, interactions, referrer information, timestamps and campaign-performance information. In accordance with their own privacy policies, Meta and LinkedIn may combine these data with other information and create usage or advertising profiles. We do not upload our own customer or email lists to these providers to create audiences. Synfia does not make solely automated decisions producing legal or similarly significant effects on the basis of these data.

    Where Synfia and a provider are jointly responsible for the collection and transmission of data, the respective joint-controller arrangement applies. The provider is generally responsible for its subsequent processing.

    5. Contact and business communications

    When you contact us by email, we process the information you provide, in particular your email address, name, message content and, where relevant, company and contractual information, to handle your request.

    The legal basis is Article 6(1)(b) GDPR where the communication concerns pre-contractual steps or a contract with you; otherwise it is our legitimate interest in appropriate business communications under Article 6(1)(f) GDPR. Data are deleted once the matter is closed, unless contractual, statutory or legitimate grounds require continued retention.

    Synfia does not send newsletters. Email service providers are used for survey invitations and necessary account, security, password, contractual and transactional messages.

    6. Customer and user accounts

    The Synfia platform is intended exclusively for businesses and organisations. When an account is registered and used, we may process a name, username, email address, optional company name, authentication data and required usage and security data. Passwords are not stored in plain text but are cryptographically processed through a specialised authentication service.

    Processing is necessary to provide and administer the platform. The legal basis is Article 6(1)(b) GDPR where the data subject is a contracting party. For users acting on behalf of a customer organisation, processing is based on our and the customer's legitimate interests in performing the agreement and securely administering users under Article 6(1)(f) GDPR.

    A user account may be deleted through the available function. Upon deletion, associated production account and project data are deleted as described in Section 12, unless statutory retention obligations apply.

    7. AI-assisted surveys

    Before a survey begins, participants are informed that the survey is conducted by an AI system rather than a human. The sender or commissioning organisation and the relevant survey mode are also displayed. The customer may additionally show a title, short description and logo.

    Depending on the configuration, the following data may be processed:

    • responses and conversation content;
    • text transcripts generated from the conversation;
    • in an attributable mode, an email address or other participant reference provided by the customer;
    • technical connection, usage and security data;
    • contextual information provided by the customer; and
    • themes, patterns, summaries and other analytical results derived from the text.

    The data originate from participants, the commissioning customer or, where other people are mentioned, from participant statements concerning third parties.

    Survey modes

    A survey may be configured as technically unlinked or attributable:

    • In a technically unlinked survey, no technical connection is created between an invitation or email address and the stored transcript. This also applies to email invitations configured as unlinked. Retrospective attribution by Synfia or the customer is not intended.
    • In an attributable survey, the invitation or participant identifier may be linked to the transcript.

    Even in a technically unlinked mode, a person may be indirectly recognisable from the content of an answer, a very small participant group or additional knowledge held by the customer. The designation therefore does not guarantee that identification is impossible in all circumstances. Technically necessary log data may arise separately from interview content.

    8. Voice and AI processing

    During voice surveys, speech is processed to provide the interaction, voice output and transcription. Synfia does not permanently store audio data. Only the text transcript is used for subsequent analysis. Synfia does not create voiceprints or analyse voice, tone or emotions.

    AI systems assist with conversation flow, transcription, translation, structuring and text-based analysis. Under the enterprise-service configurations agreed with the providers, inputs are not used to train public AI models. Persistent prompt and response logging at the AI services is disabled where technically available.

    Synfia does not create individual personality, behavioural, performance or suitability profiles. The platform generates text-related analyses, themes, patterns, summaries and, where applicable, redacted quotations. Results and quotations may be reviewed by the customer before disclosure. Synfia does not carry out solely automated decision-making within the meaning of Article 22 GDPR.

    9. Optional PII filter

    Customers may activate an optional filter to detect and redact directly identifiable personal information in interview transcripts. 

    Where enabled, the text is automatically checked for recognisable identifiers and redacted before permanent storage. The unredacted version is processed only temporarily for this purpose and is not permanently stored as an interview transcript. The filter applies only to interview transcripts, not to reference documents uploaded by customers.

    Automated detection may be incomplete or inaccurate, and the substance of a statement may itself allow a person to be inferred. The filter therefore does not guarantee complete anonymisation.

    10. Special-category data and minors

    The standard service is not designed for the targeted collection of special categories of personal data under Article 9 GDPR. Participants may nevertheless mention such information voluntarily in free-text responses. A customer intending systematic processing of such data must first arrange a separate legal and contractual review, including an appropriate legal basis and participant notice.

    The standard service is intended for adults. Surveys specifically involving minors require a prior separate agreement and appropriate safeguards. Public survey links do not include general age verification.

    11. Access, release, exports and uploads

    Depending on the survey mode and permissions configured within the account, the customer may view individual transcripts and analytical results. Permissions may distinguish between administrative access and restricted views.

    Authorised Synfia personnel access customer data only where necessary for support, troubleshooting, maintenance, security or incident handling and, as a rule, with the customer's approval. Such access is restricted and logged.

    Customers may deliberately export transcripts and results. Following export, the customer is responsible for further storage and use of the exported data. Synfia does not currently make automated transfers to external customer systems.

    Authenticated customers may upload text and PDF files as contextual material. These documents may be processed for AI-assisted surveys or analysis and remain stored until the relevant survey or customer account is deleted. Participants cannot upload files.

    12. Retention and deletion

    • Surveys and project data: Responses, transcripts, analyses, invitation data, mappings and uploaded documents are retained until the customer deletes the relevant survey or project or deletes its account.
    • Individual deletion: For attributable surveys, the customer can delete an individual record and associated information. For technically unlinked surveys, targeted identification and deletion may be impossible because no mapping exists.
    • Account deletion: Deleting a customer account automatically deletes associated production account, survey and project data, unless statutory retention requirements apply.
    • Backups: Deleted data may remain in backups for up to 30 days. Backups are used solely for recovery following technical incidents and are not otherwise processed in normal operations.
    • Audio: Voice recordings are not permanently stored.
    • Public demo: Content and transcripts from the public demo are not permanently stored.
    • Website and security logs: Retained only under the necessity criteria set out in Section 3.
    • Billing records: Tax and accounting documents are generally retained for seven years from the end of the relevant calendar year and, where necessary, for longer while proceedings are pending.
    • Consent records: Retained for as long as necessary to administer and demonstrate consent and to establish, exercise or defend legal claims.

    13. Public product demo

    The public demo can be used without an account or contact details. Voice or text input is temporarily processed by the required voice and AI services to provide the demo. Responses and transcripts are not permanently stored. Technical error and security information may be processed separately from conversation content.

    The legal basis is our legitimate interest under Article 6(1)(f) GDPR in providing interested parties with a functional and secure product demo.

    14. Service providers and recipients

    We engage carefully selected service providers as processors or independent controllers. These include providers of website and email hosting, cloud infrastructure, database and authentication, voice and AI processing, technical error analysis, transactional email delivery and, optionally, payment processing.

    Our current material providers include Hostinger, Supabase, Google Cloud/Gemini Enterprise, ElevenLabs, Sentry, Resend (Plus Five Five, Inc.) and Stripe. The providers listed in Section 4 also apply to website analytics and advertising. Infrastructure providers may act as further subprocessors of the providers directly engaged by us. Business customers receive an up-to-date subprocessor list through the contractual documents or data processing agreement and are notified of relevant changes in accordance with those agreements.

    Data may also be disclosed to professional advisers, authorities, courts or other bodies where necessary to comply with legal obligations or establish, exercise or defend legal claims. Personal data are not sold.

    15. International transfers

    Where possible, we configure our services for processing in the European Economic Area. Providers with international group structures may nevertheless involve access or further processing outside the EEA, particularly in the United States.

    Transfers to third countries take place only where the requirements of Articles 44 et seq. GDPR are met, in particular on the basis of an adequacy decision – including the EU-US Data Privacy Framework where applicable – or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Where required, supplementary measures and a transfer-risk assessment are implemented. Information about safeguards applicable in a particular case may be requested from hello@synfia.ai.

    16. Payment processing

    Most billing takes place outside the platform. We use Stripe for optional self-service payments. Payment and bank details are collected and processed directly by Stripe; Synfia does not receive full card or bank details. We process the billing and transaction information required for contract administration, accounting and payment allocation.

    The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for statutory accounting and retention obligations. Stripe processes certain data as an independent controller for its own regulatory and security purposes.

    17. Data security and personal data breaches

    Taking account of the relevant risks, Synfia implements appropriate technical and organisational measures to protect personal data. These include encryption in transit and at rest, role-based and restricted access, logical separation of customer data, logging of security-relevant access, backups, and procedures for detecting and handling security incidents.

    Where Synfia becomes aware of a personal data breach affecting customer data processed on behalf of a customer, Synfia informs the affected customer without undue delay in accordance with legal and contractual requirements and assists the customer in meeting its obligations.

    18. Your rights

    Where Synfia acts as controller and subject to the applicable statutory conditions, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time for the future.

    If you object to processing based on Article 6(1)(f) GDPR, we will cease that processing unless compelling legitimate grounds or grounds for the establishment, exercise or defence of legal claims apply. You may object to direct marketing at any time without giving reasons.

    To exercise your rights, contact hello@synfia.ai. We may request additional information to verify your identity where necessary.

    For survey data, the commissioning customer is generally the controller. Requests should therefore primarily be directed to the sender identified on the survey start page. You may also contact Synfia, and we will forward the request to the relevant customer. Where a survey is technically unlinked and neither Synfia nor the customer can identify the data subject, fulfilment of certain rights – in particular access or individual deletion – may not be possible in practice.

    You also have the right to lodge a complaint with a competent data protection supervisory authority. The authority particularly responsible for Synfia is:

    Austrian Data Protection Authority
    Barichgasse 40-42
    1030 Vienna
    Austria
    Email: dsb@dsb.gv.at
    Website: www.dsb.gv.at

    Individuals in the United Kingdom or Switzerland may also complain to their competent authority, in particular the UK Information Commissioner's Office (ico.org.uk) or the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch).

    19. Requirement to provide data

    There is no statutory or contractual obligation to provide personal data for a purely informational website visit; however, the website cannot be provided without processing technically necessary connection data. Certain account and contractual data are required to set up and use the platform.

    From Synfia's perspective, participation in a survey is generally voluntary. Any specific obligations or consequences arising between the customer and a participant are determined and explained by the relevant customer.

    20. Changes to this Privacy Policy

    We update this Privacy Policy when our processing activities or legal requirements change. The current version published on this website applies.