Last updated: 24 August 2026
Unless stated otherwise below, the controller for the processing described in this Privacy Policy is:
Synfia Labs FlexCo
Neubaugasse 36
1070 Vienna
Austria
Email: hello@synfia.ai
This Privacy Policy applies to the synfia.ai website and associated subdomains, the Synfia web application, publicly available product demos, and communications with Synfia.
For individuals in Switzerland or the United Kingdom, the applicable national data protection laws also apply. References to GDPR rights and principles apply correspondingly under the Swiss Federal Act on Data Protection or the UK GDPR where relevant.
Synfia provides businesses and organisations with a platform for conducting and analysing AI-assisted voice and text surveys.
The relevant customer generally determines the purpose, subject, participants, configuration and use of the results. The customer is the controller for this processing, while Synfia processes survey data as a processor on the customer's instructions. Processing is governed by contract, including an agreement under Article 28 GDPR.
The customer is responsible for informing participants about its specific processing, the applicable legal basis, any consequences of participation and, where relevant, other recipients. Information provided by Synfia supplements but does not replace the customer's participant notice.
Synfia acts as controller for processing relating to its own website, product demo, business communications, customer and user accounts, billing, and the security and operation of its services.
When you visit our website, technically necessary connection and log data are processed. These may include your IP address, access date and time, requested content, referrer URL, browser, operating system, device information and technical error data.
We process these data to provide the website securely, reliably and without errors and to prevent misuse. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in operating and securing our online services. Access to terminal equipment that is strictly necessary for requested services is carried out under the applicable statutory exemptions.
Our website and business email communications are provided by a hosting and communications service provider in Europe. Log data are retained only for as long as necessary for operations, security, troubleshooting or investigation of a specific incident, subject to statutory retention and evidence requirements.
We use technically necessary cookies or similar storage technologies where required to provide the website, maintain security or save your privacy settings. Where personal data are processed, the legal basis is Article 6(1)(f) GDPR or, where applicable, Article 6(1)(c) GDPR.
Non-essential analytics and marketing technologies are activated only with your consent. The legal basis is Article 6(1)(a) GDPR together with applicable terminal-equipment privacy rules. You may change your choices at any time for the future through the Cookie Settings available on the website. Withdrawal does not affect the lawfulness of earlier processing. Consent information is retained where necessary to administer and demonstrate your choice.
The following services may be used after consent:
The data processed may include online identifiers, IP address, browser and device information, pages visited, interactions, referrer information, timestamps and campaign-performance information. In accordance with their own privacy policies, Meta and LinkedIn may combine these data with other information and create usage or advertising profiles. We do not upload our own customer or email lists to these providers to create audiences. Synfia does not make solely automated decisions producing legal or similarly significant effects on the basis of these data.
Where Synfia and a provider are jointly responsible for the collection and transmission of data, the respective joint-controller arrangement applies. The provider is generally responsible for its subsequent processing.
When you contact us by email, we process the information you provide, in particular your email address, name, message content and, where relevant, company and contractual information, to handle your request.
The legal basis is Article 6(1)(b) GDPR where the communication concerns pre-contractual steps or a contract with you; otherwise it is our legitimate interest in appropriate business communications under Article 6(1)(f) GDPR. Data are deleted once the matter is closed, unless contractual, statutory or legitimate grounds require continued retention.
Synfia does not send newsletters. Email service providers are used for survey invitations and necessary account, security, password, contractual and transactional messages.
The Synfia platform is intended exclusively for businesses and organisations. When an account is registered and used, we may process a name, username, email address, optional company name, authentication data and required usage and security data. Passwords are not stored in plain text but are cryptographically processed through a specialised authentication service.
Processing is necessary to provide and administer the platform. The legal basis is Article 6(1)(b) GDPR where the data subject is a contracting party. For users acting on behalf of a customer organisation, processing is based on our and the customer's legitimate interests in performing the agreement and securely administering users under Article 6(1)(f) GDPR.
A user account may be deleted through the available function. Upon deletion, associated production account and project data are deleted as described in Section 12, unless statutory retention obligations apply.
Before a survey begins, participants are informed that the survey is conducted by an AI system rather than a human. The sender or commissioning organisation and the relevant survey mode are also displayed. The customer may additionally show a title, short description and logo.
Depending on the configuration, the following data may be processed:
The data originate from participants, the commissioning customer or, where other people are mentioned, from participant statements concerning third parties.
A survey may be configured as technically unlinked or attributable:
Even in a technically unlinked mode, a person may be indirectly recognisable from the content of an answer, a very small participant group or additional knowledge held by the customer. The designation therefore does not guarantee that identification is impossible in all circumstances. Technically necessary log data may arise separately from interview content.
During voice surveys, speech is processed to provide the interaction, voice output and transcription. Synfia does not permanently store audio data. Only the text transcript is used for subsequent analysis. Synfia does not create voiceprints or analyse voice, tone or emotions.
AI systems assist with conversation flow, transcription, translation, structuring and text-based analysis. Under the enterprise-service configurations agreed with the providers, inputs are not used to train public AI models. Persistent prompt and response logging at the AI services is disabled where technically available.
Synfia does not create individual personality, behavioural, performance or suitability profiles. The platform generates text-related analyses, themes, patterns, summaries and, where applicable, redacted quotations. Results and quotations may be reviewed by the customer before disclosure. Synfia does not carry out solely automated decision-making within the meaning of Article 22 GDPR.
Customers may activate an optional filter to detect and redact directly identifiable personal information in interview transcripts.
Where enabled, the text is automatically checked for recognisable identifiers and redacted before permanent storage. The unredacted version is processed only temporarily for this purpose and is not permanently stored as an interview transcript. The filter applies only to interview transcripts, not to reference documents uploaded by customers.
Automated detection may be incomplete or inaccurate, and the substance of a statement may itself allow a person to be inferred. The filter therefore does not guarantee complete anonymisation.
The standard service is not designed for the targeted collection of special categories of personal data under Article 9 GDPR. Participants may nevertheless mention such information voluntarily in free-text responses. A customer intending systematic processing of such data must first arrange a separate legal and contractual review, including an appropriate legal basis and participant notice.
The standard service is intended for adults. Surveys specifically involving minors require a prior separate agreement and appropriate safeguards. Public survey links do not include general age verification.
Depending on the survey mode and permissions configured within the account, the customer may view individual transcripts and analytical results. Permissions may distinguish between administrative access and restricted views.
Authorised Synfia personnel access customer data only where necessary for support, troubleshooting, maintenance, security or incident handling and, as a rule, with the customer's approval. Such access is restricted and logged.
Customers may deliberately export transcripts and results. Following export, the customer is responsible for further storage and use of the exported data. Synfia does not currently make automated transfers to external customer systems.
Authenticated customers may upload text and PDF files as contextual material. These documents may be processed for AI-assisted surveys or analysis and remain stored until the relevant survey or customer account is deleted. Participants cannot upload files.
The public demo can be used without an account or contact details. Voice or text input is temporarily processed by the required voice and AI services to provide the demo. Responses and transcripts are not permanently stored. Technical error and security information may be processed separately from conversation content.
The legal basis is our legitimate interest under Article 6(1)(f) GDPR in providing interested parties with a functional and secure product demo.
We engage carefully selected service providers as processors or independent controllers. These include providers of website and email hosting, cloud infrastructure, database and authentication, voice and AI processing, technical error analysis, transactional email delivery and, optionally, payment processing.
Our current material providers include Hostinger, Supabase, Google Cloud/Gemini Enterprise, ElevenLabs, Sentry, Resend (Plus Five Five, Inc.) and Stripe. The providers listed in Section 4 also apply to website analytics and advertising. Infrastructure providers may act as further subprocessors of the providers directly engaged by us. Business customers receive an up-to-date subprocessor list through the contractual documents or data processing agreement and are notified of relevant changes in accordance with those agreements.
Data may also be disclosed to professional advisers, authorities, courts or other bodies where necessary to comply with legal obligations or establish, exercise or defend legal claims. Personal data are not sold.
Where possible, we configure our services for processing in the European Economic Area. Providers with international group structures may nevertheless involve access or further processing outside the EEA, particularly in the United States.
Transfers to third countries take place only where the requirements of Articles 44 et seq. GDPR are met, in particular on the basis of an adequacy decision – including the EU-US Data Privacy Framework where applicable – or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Where required, supplementary measures and a transfer-risk assessment are implemented. Information about safeguards applicable in a particular case may be requested from hello@synfia.ai.
Most billing takes place outside the platform. We use Stripe for optional self-service payments. Payment and bank details are collected and processed directly by Stripe; Synfia does not receive full card or bank details. We process the billing and transaction information required for contract administration, accounting and payment allocation.
The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for statutory accounting and retention obligations. Stripe processes certain data as an independent controller for its own regulatory and security purposes.
Taking account of the relevant risks, Synfia implements appropriate technical and organisational measures to protect personal data. These include encryption in transit and at rest, role-based and restricted access, logical separation of customer data, logging of security-relevant access, backups, and procedures for detecting and handling security incidents.
Where Synfia becomes aware of a personal data breach affecting customer data processed on behalf of a customer, Synfia informs the affected customer without undue delay in accordance with legal and contractual requirements and assists the customer in meeting its obligations.
Where Synfia acts as controller and subject to the applicable statutory conditions, you have rights of access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw consent at any time for the future.
If you object to processing based on Article 6(1)(f) GDPR, we will cease that processing unless compelling legitimate grounds or grounds for the establishment, exercise or defence of legal claims apply. You may object to direct marketing at any time without giving reasons.
To exercise your rights, contact hello@synfia.ai. We may request additional information to verify your identity where necessary.
For survey data, the commissioning customer is generally the controller. Requests should therefore primarily be directed to the sender identified on the survey start page. You may also contact Synfia, and we will forward the request to the relevant customer. Where a survey is technically unlinked and neither Synfia nor the customer can identify the data subject, fulfilment of certain rights – in particular access or individual deletion – may not be possible in practice.
You also have the right to lodge a complaint with a competent data protection supervisory authority. The authority particularly responsible for Synfia is:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
Email: dsb@dsb.gv.at
Website: www.dsb.gv.at
Individuals in the United Kingdom or Switzerland may also complain to their competent authority, in particular the UK Information Commissioner's Office (ico.org.uk) or the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch).
There is no statutory or contractual obligation to provide personal data for a purely informational website visit; however, the website cannot be provided without processing technically necessary connection data. Certain account and contractual data are required to set up and use the platform.
From Synfia's perspective, participation in a survey is generally voluntary. Any specific obligations or consequences arising between the customer and a participant are determined and explained by the relevant customer.
We update this Privacy Policy when our processing activities or legal requirements change. The current version published on this website applies.