Last updated 2026-07-01
Scope
This policy describes how Synthesis Cyber Technologies ("we", "us") handles personal data when you visit our website, create an account, or use the SYNTHESIS CYBER application. It applies to all users regardless of location. Where local law grants you stronger rights than this policy describes, that law applies.
Data we collect
We group the data we hold into four categories.
- Account data: email address, display name, password hash, authentication factors, and plan status. This is required to operate an account.
- Encrypted content: vault items, notes, files, incident records. We store these as ciphertext produced on your device. We do not hold the key and cannot read the contents.
- Operational metadata: timestamps, item counts, storage totals, IP address and user agent for security events, and error diagnostics. This exists to keep the service running and to detect abuse.
- Optional analytics: aggregated product usage collected only after you consent through the cookie banner. You can withdraw consent at any time.
Why we process it
We process account data to perform our contract with you. We process operational metadata on the basis of legitimate interests in securing and maintaining the service, balanced against your privacy — which is why that data is minimised and short-lived. We process optional analytics only on the basis of your consent. We do not process special category data and we do not carry out automated decision-making that produces legal effects.
What we do not do
We do not sell personal data. We do not share it with advertising networks or data brokers. We do not use the content of your vault, notes, or files for any purpose, including product improvement or model training — it is not readable by us.
Retention
Account data is retained while your account is active. Security event logs are retained for 12 months. Aggregated analytics are retained for 24 months in a form that does not identify you. After account deletion, data is removed on the schedule set out in our Data Retention Policy and Data Deletion Policy.
Your rights
Depending on your jurisdiction you may have the right to access, correct, delete, restrict, or port your personal data, to object to processing based on legitimate interests, and to withdraw consent. Account settings provide self-service export and deletion. For anything else, contact privacy@synthesiscyber.app; we respond within 30 days. You also have the right to complain to your local data protection authority.
International transfers
Our infrastructure and subprocessors may process data outside your country. Where personal data leaves the European Economic Area or the United Kingdom, transfers rely on the applicable Standard Contractual Clauses together with supplementary technical measures, including the client-side encryption described in our Trust Center.
Changes
We will post material changes to this policy on this page and notify account holders by email at least 14 days before they take effect. This document is provided as an accurate description of current practice and should be reviewed by your own counsel before being relied on for compliance purposes.