This Privacy Policy explains what personal data Syntra collects, how we use and share it, and the choices and rights you have - both when we act as a controller for our website and direct customers, and when we act as a processor for the data our customers route through the Services.
This Privacy Policy explains how SYNTRA LLC ("Syntra", "we", "us" or "our"), of 8 The Green, Dover, Delaware 19901, collects, uses, shares and protects personal data. It applies to our website, our platform and applications, and our AI-powered services (together, the "Services"), including the AI Agent that makes and answers calls, sends messages, takes bookings and handles enquiries on our customers' behalf.
Throughout this policy, "Customer" ("you" or "your") means the business or individual that registers for or uses the Services, and "End User" means a customer, client, patient, contact or other person who interacts with a Customer through the Services. This policy should be read together with our Terms of Service, our Cookie Policy and, where we act as a processor, our Data Processing Addendum.
The way we handle personal data, and our responsibilities for it, depend on the context in which we process it.
If you are an End User and want to understand how your personal data is used, please refer in the first instance to the privacy notice of the Customer you interacted with, as they are the controller of that data.
We collect the following categories of personal data, depending on how you use the Services:
When a Customer configures the AI Agent to communicate with its End Users, personal data about those End Users is routed through the Services. This may include names, contact details, the content and recordings of calls and messages, booking and appointment details, enquiry details and any other information an End User shares during an interaction.
We process End User personal data as a processor, on the relevant Customer's behalf and on its instructions, in order to provide the Services. The Customer is the controller of that data and is responsible for having a lawful basis to collect it, for providing End Users with appropriate privacy notices, and for obtaining any consents required, including for the recording of calls where applicable.
Where we act as a controller, we use personal data for the following purposes:
Where we process End User personal data as a processor, we use it only to provide the Services to the relevant Customer and on that Customer's instructions.
Where the GDPR, UK GDPR or similar laws apply, we rely on the following legal bases when we act as a controller:
Delivering the AI Agent involves processing content by artificial-intelligence and machine-learning models, including models provided by trusted third parties. When the AI Agent handles a call, message, enquiry or booking, the relevant content may be sent to and processed by these models to understand the interaction, generate a response and carry out the task the Customer has configured.
The Services are designed to support, not replace, human judgement, and Customers control how the AI Agent behaves and can review and oversee its activity. We do not use personal data contained in Customer Data to train models made available to other customers except in aggregated or de-identified form, or with permission. For more on how we approach responsible and safe use of AI, including human oversight, see our Responsible AI page.
We and our service providers may process personal data in countries other than the one in which it was collected, including the United States. Where we transfer personal data across borders, we put appropriate safeguards in place as required by applicable law, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional technical and organisational measures where needed. You may contact us to request more information about these safeguards.
We keep personal data for as long as needed to provide the Services, maintain your account, and fulfil the purposes described in this policy, and thereafter as required to comply with our legal obligations, resolve disputes and enforce our agreements. Retention periods vary depending on the type of data and the reason we hold it. Where we process Customer Data as a processor, we retain it in line with the Customer's instructions and our agreement with the Customer. When personal data is no longer needed, we delete it or anonymise it so it can no longer be associated with an individual.
We use technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration and destruction, including encryption in transit, access controls and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continually to protect your data. You can read more about our approach on our Security page.
Depending on where you live and the applicable law, you may have some or all of the following rights over your personal data:
To exercise these rights where we act as controller, contact us at hello@syntra.ai. We may need to verify your identity before responding. If you are an End User, your personal data is usually processed by us on behalf of the Customer you interacted with, who is the controller; please direct your request to that Customer, and we will support them in responding. You also have the right to lodge a complaint with your local data protection authority.
The Services are intended for business use and are not directed to children. We do not knowingly collect personal data directly from children under 16 (or under 18 where a higher age applies in your jurisdiction) through our website or account sign-up. If you believe a child has provided us with personal data in this way, please contact us at hello@syntra.ai and we will take appropriate steps to delete it. Where End User information routed through the Services relates to a minor, the relevant Customer is responsible, as controller, for the lawful basis and any consents required.
The Services may contain links to, or integrate with, third-party websites and services that we do not control. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party website or service you use, including any you connect to the Services.
We may update this Privacy Policy from time to time to reflect changes to the Services, our practices or applicable law. If we make material changes, we will provide reasonable notice, such as by posting the updated policy with a new "last updated" date or by notifying you through the Services. Your continued use of the Services after the changes take effect indicates your acceptance of the updated policy.
If you have any questions about this Privacy Policy or how we handle personal data, please contact us:
SYNTRA LLC
8 The Green, Dover, Delaware 19901
hello@syntra.ai