Privacy Policy
Last updated: June 19, 2026
Introductory Notes
Synexly DOO Beograd, company incorporated under the laws of the Republic of Serbia, with headquarters located in Belgrade, 231 Jurija Gagarina Street, Apartment 329, New Belgrade, unique registration number 22037064, TIN 114540868 (hereinafter referred to as “Synexly”, “we”, “us”, or “our”).
We respect your privacy and are strongly committed to keeping any information we collect from or about you secure. This Privacy Policy outlines how Synexly collects, uses, shares, stores, protects, and discloses your Personal Data through our Synnect Platform, Website, and related services. By accessing or using our Synnect Platform, Website or related services, you agree to abide by this Privacy Policy. If you do not agree with its terms, please refrain from using our Synnect Platform and Website. We highly recommend that you review this policy carefully before engaging in any transactions on our Website.
Relationship Between This Privacy Policy and Client-Specific Data Processing Terms
Where Synexly processes Personal Data on behalf of its Client, such processing is governed by this Privacy Policy together with the applicable data processing terms agreed between Synexly and the relevant Client, as set out in the Client Data Processing Terms available at https://synnect.app/legal/client-data-processing-terms. By accessing or using the Synnect Platform, Website, or related services, Client acknowledges and agrees that the processing of Personal Data carried out by Synexly shall be performed in accordance with this Privacy Policy and the Client Data Processing Terms.
This Privacy Policy and any documents incorporated by reference are intended to supplement, and not replace or override, any separate agreement entered into between Synexly and a Client, unless explicitly stated otherwise in such agreement.
Definitions and Key Terms
- “Synnect Platform”
- is a B2B software-as-a-service (SaaS) platform that enables companies to create, deploy, and manage AI-powered agents for both customer-facing and internal business use. The platform combines AI automation, data integrations, and business analytics to help organizations improve efficiency, streamline support, and gain insights from their data.
- “Subscription”
- means the Client’s time-limited, paid right to access and use the Synnect Platform, including its standard features, functionalities, usage limits, and entitlements associated with the selected Subscription Plan, as made available by Synexly, in accordance with these Terms.
- “Services / Customizations”
- means any services provided by Synexly relating to the customization, enhancement, addition of new features, or other modifications of the Synnect Platform that are not included in the standard features, and which are governed by a separate written agreement between the Client and Synexly. For the avoidance of doubt, any processing of Personal Data carried out in connection with the Services / Customizations shall be deemed part of, and included within, the processing of Personal Data under the Synnect Platform, as the Services / Customizations constitute an integral part of and are incorporated into the Synnect Platform. Accordingly, references to the Synnect Platform in this Privacy Policy shall be deemed to include the Services / Customizations.
- “Client”
- refers to a legal entity, such as a company or organization, that registers or subscribes to the Synnect Platform and/or enters into a separate written agreement for the use of Services or Customizations offered by Synexly, for both customer-facing and internal business use.
- “You” or “user”
- means the individual (Data Subject) who accesses or uses the Synnect Platform or Website, whether personally or on behalf of an organization, and whose Personal Data is processed under this Privacy Policy.
- “Data Subjects”
- are the natural persons whose Personal Data is processed through the Synnect Platform in connection with the Client’s use of the Synnect Platform or through the Website, namely:
- Employees, contractors, representatives, or any other persons engaged by the Client on any work-related basis who access or use the Synnect Platform in the course of their work;
- Third-party natural persons who are customers or end-users of the Client, interacting with the Client through the Synnect Platform, for example via AI-powered agents or chatbots; and
- Visitors to the Website who are natural persons and whose interactions with the Website result in the collection or processing of their Personal Data.
- “Users via the Client”
- refers to the following:
- Employees, contractors, representatives, or any other persons engaged by the Client on any work-related basis who access or use the Synnect Platform in the course of their work;
- Third-party natural persons who are customers or end-users of the Client, interacting with the Client through the Synnect Platform, for example via AI-powered agents or chatbots;
- “Device”
- refers to any internet-connected device, such as a smartphone, tablet, computer, or any other technology, that can access and use the Synnect Platform or the Website.
- “Country”
- refers to the jurisdiction in which the entity operating and controlling the Synnect Platform and Website is established, in this case, the Republic of Serbia.
- “Personal Data”
- means any information relating to an identified or identifiable natural person (“Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an IP address, an email address, or any other information that can be used, alone or in combination with other data, to identify that natural person.
- “IP Address”
- means a unique string of numbers assigned to each device connected to the Internet. It can sometimes be used to approximate the geographic location of a device.
- “Cookie”
- means a small piece of data stored on your Device by your web browser while browsing a Website. Cookies are used for various purposes, including identifying your browser, performing analytics, remembering preferences (such as language or login details), and enhancing user experience.
- “Third-Party Services”
- means services, APIs, software, models, data, cloud infrastructure, AI models, payment processors, optional integrations (including email, CRM, or social media APIs), or servers provided by third parties that the Synnect Platform may integrate with or rely upon to provide certain features or functionalities.
- “Website”
- refers to the official Synnect Website, accessible at https://synnect.app.
Categories of Personal Data Processing and the Role of Synexly
For the purposes of this Privacy Policy, Synexly distinguishes between two separate categories of personal data processing:
1) Platform Processing
This processing relates to personal data handled within the Synnect Platform in connection with providing our Clients with access to and use of the Synnect Platform.
Who are the Data Subjects?
Users via the Client, as follows:
- Employees, contractors, representatives, or any other persons engaged by the Client on any work-related basis who access or use the Synnect Platform in the course of their work;
- Third-party natural persons who are customers or end-users of the Client, interacting with the Client through the Synnect Platform, for example via AI-powered agents or chatbots.
Role of Synexly: Synexly acts as a data processor and processes Personal Data solely on the documented instructions of the Client.
Role of the Client: The Client is the data controller and determines the purposes and means of processing for the Data Subjects using the Synnect Platform. How our Client uses your Personal Data will be subject to the Client’s internal policies, which outline how it processes, uses, stores, and discloses Personal Data, including any sharing with third parties. Synexly does not control or determine the purposes of such processing and acts solely as a Data Processor on the Client’s instructions.
If you are a User via the Client and no longer wish for your Personal Data to be processed in connection with the Synnect Platform or related services in accordance with this Privacy Policy, please contact the relevant Client directly. Clients are responsible for complying with applicable regulations and laws that require providing notice, disclosure, and/or obtaining consent prior to transferring Personal Data to Synexly for processing purposes. If you do not consent to the collection, use, and storage of your Personal Data, we may be unable to provide the Synnect Platform or other services to the Client.
Synexly Takes Steps to Protect Your Personal Data:
Synexly is committed to protecting the security of your Personal Data and takes all reasonable precautions to prevent unauthorized access, modification, or disclosure. We maintain a comprehensive information security program that includes administrative, technical, and physical safeguards in line with industry standards, designed to protect Personal Data processed on behalf of our Clients. We also use appropriate industry-standard security technologies to ensure that Personal Data is protected. When Personal Data is no longer required, Synexly will take all reasonable steps to de-identify or securely delete it.
2) Website Processing
This processing relates to Personal Data collected in connection with visits to and use of Synexly’s public Website, including through cookies, contact forms, and other website-related interactions.
Who are the Data Subjects?
Visitors to the Website who are natural persons and whose interactions with the Website result in the collection or processing of their Personal Data.
Role of Synexly: Synexly acts as the data controller with respect to the Personal Data collected directly from website interactions (e.g., through cookies, contact forms, newsletter sign-ups, etc).
What Data We Collect and How We Collect It
| What data do we collect | Source | Applies to | Legal Basis (GDPR) | How do we collect | Retention Period |
|---|---|---|---|---|---|
| Last name, first name, email address, message content | Website visitors | Website | Consent; pre-contractual steps (e.g., demo or contact request) | Manually, when a visitor submits a contact form, demo request, or inquiry | Until the request is resolved and no longer than 2 years, unless consent is withdrawn earlier |
| IP address, device identifiers, browser and technical data (including device type, location, browser type and version, operating system and version, internet service provider or mobile carrier, IP address or proxy server, geographic areas derived from your IP address, time and date of access, duration of access and other identifiers that help us recognize your device, etc.) | Website visitors | Website | Legitimate interest and compliance with a legal obligation (security, fraud prevention, website functionality); Consent for non-essential cookies | Automatically via server logs, cookies, and similar technologies | Server logs: up to 24 months; cookies: up to 12 months (unless deleted earlier) |
| Cookie data (preferences, analytics identifiers) (if applicable – please see the Cookies section below) | Website visitors | Website | Consent (except strictly necessary cookies) | Automatically via cookies and similar tracking technologies | Up to 12 months, depending on cookie type |
| Account and user details (last name, first name, business email, physical address, job title, position or function at the Client) – for employees, contractors, representatives, or other persons engaged by the Client who are granted an account on the Synnect Platform | Client | Platform | Consent obtained by the Client; Performance of agreement with Client (Subscription / Service Agreement) | Provided by the Client when creating and managing user accounts within the Synnect Platform | Duration of the Subscription; Deleted only upon request, within 30 days following receipt of the deletion request |
| Platform usage data (logs, interaction data, performance metrics) | Users via the Client | Platform | Consent obtained by the Client; Performance of agreement with Client (Subscription / Service Agreement); Legitimate interest and compliance with a legal obligation (ensuring Synnect Platform security, integrity, and operational stability) | Automatically generated through use of the Synnect Platform | Duration of the Subscription; Deleted only upon request, within 30 days following receipt of the deletion request |
| Communication content processed through the Synnect Platform (e.g., chatbot interactions, messages), including any personal data or other information voluntarily provided through such communications – for employees, contractors, representatives, or other persons engaged by the Client who are granted an account on the Synnect Platform; for third-party natural persons who are customers or end-users of the Client, interacting with the Client through the Synnect Platform | Client / Users via the Client | Platform | Consent obtained by the Client; Performance of agreement with Client (Subscription / Service Agreement) | Provided by users and automatically processed when users interact with AI agents or tools within the Synnect Platform | Duration of the Subscription + up to 12 months |
| Customer/end-user personal data provided by the Client (last name, first name, email, contact data) – for third-party natural persons who are customers or end-users of the Client, interacting with the Client through the Synnect Platform | Client | Platform | Consent obtained by the Client or other lawful basis determined by the Client; Performance of agreement with Client (Subscription / Service Agreement) | Provided by the Client and automatically processed when users interact with AI agents or tools within the Synnect Platform | Duration of the Subscription + up to 12 months |
| Billing and payment data (e.g., name and business contact details of the individual making the payment on behalf of the Client, billing address, subscription details, payment status, invoices) | Client / User via the Client | Website | Performance of the agreement with the Client (Subscription / Service Agreement); compliance with legal and accounting obligations | Provided during the subscription or payment process via the third-party payment processor (Paddle) | For the duration of the Subscription and thereafter as required by applicable accounting and tax laws |
Purpose of Processing and How We Will Use Your Data
We may process your Personal Data for one or more of the following purposes:
To fulfil contractual obligations with our Clients and to provide requested services
This includes, but is not limited to, managing user accounts, granting access to the Synnect Platform, processing communications between users, enabling AI-powered agents, resolving technical issues you encounter, responding to your requests for support and assistance, providing training related to the Synnect Platform, and responding to any requests submitted via the Synnect Platform or the Website. Billing and payment processing are also included, performed via third-party providers such as Paddle, while Synexly does not access full payment card details. We may also use your information when responding to a Client’s documented instructions or as may be required by applicable law.
This processing is necessary for the performance of an agreement or to take steps at the request of the Client prior to entering into a contract, and, where applicable, is based on Synexly’s legitimate interests in operating and delivering the Synnect Platform effectively, provided such interests are not overridden by your data protection rights and freedoms.
Enable security and compliance
To maintain the security, integrity, and compliance of our Synnect Platform and Website, we process data to prevent, detect, and respond to fraudulent, unauthorized, or illegal activity. This includes protecting against misuse of the Synnect Platform or Website, investigating security incidents, monitoring system access, avoiding and detecting attacks, and complying with legal and regulatory obligations.
Such processing is carried out where necessary to comply with applicable legal obligations or where it serves Synexly’s legitimate interests in ensuring the security, availability, and lawful operation of the Synnect Platform, provided those interests are not overridden by your rights.
Improve and enhance our services
To enhance the Synnect Platform, Website, and overall user experience, we may analyse aggregated, anonymized, or statistical usage data, platform performance metrics, crash information, and feedback voluntarily provided by users. This allows us to optimize system functionality, improve AI agent performance, and develop new features. No personal data that could identify individual users is used for these purposes.
This includes processing necessary to operate, maintain, and improve the Synnect Platform and Website, and is also based on Synexly’s legitimate interests in developing and enhancing its services in a secure and efficient manner (provided such interests are not overridden by your data protection rights and freedoms).
Perform sales, marketing, and events-related activities
Where users have provided consent, we may communicate information about upcoming events, new features, updates to the Synnect Platform, or other services that may be relevant. For Website visitors, this includes newsletters, promotional communications, and responding to inquiries.
You may withdraw your consent to such communications at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Legal claims, compliance, and protection of rights
Where required by law or where we believe it is necessary to protect our legal rights, interests, and the interests of others (including our Clients), we may process Personal Data in connection with legal claims, compliance, regulatory and audit functions, and disclosures related to an actual or contemplated acquisition, merger, or sale of all or part of a business.
Where possible and appropriate, and subject to applicable law, we will notify you if we are required to disclose your Personal Data to public authorities or other third parties, unless such notification is prohibited by law or would undermine the purpose of the disclosure.
Who Receives Your Personal Data?
We share Personal Data only with trusted third parties to the extent strictly necessary to operate, maintain, secure, and improve the Synnect Platform and Website, or where disclosure is required under applicable law. We do not sell Personal Data and do not disclose it to third parties for their own marketing or commercial purposes.
The categories of recipients may include:
- Service providers and processors – such as providers of cloud infrastructure, hosting, data storage, analytics, security, customer support, email delivery, and payment processing services, who process Personal Data on our behalf and under our instructions. These providers are engaged only after appropriate due diligence and may change from time to time depending on operational, technical, or legal requirements.
- Affiliates – where applicable, for internal administrative and operational purposes related to the provision of our services.
- Authorities and public bodies – where required to comply with legal obligations, court orders, or requests from competent supervisory, regulatory, or law enforcement authorities.
The categories of data shared with third-party service providers are limited to what is strictly necessary for the provision of their respective services and may include:
- limited technical and device data (such as IP address, browser type and version, operating system, and device or session identifiers);
- usage-related data, primarily in aggregated, anonymized, or pseudonymized form (such as website traffic statistics, consent status, and high-level platform usage metrics).
Synexly does not share the content of communications processed through the Synnect Platform, nor does it intentionally disclose personal data that directly identifies individuals, unless such disclosure is strictly necessary for the provision of the relevant service (e.g., hosting or infrastructure services). Where communication content is stored or transmitted via infrastructure or hosting providers, such content is processed automatically and without human access, except where access is strictly necessary for security, maintenance, or compliance purposes, or where required by law. The third parties who host our servers do not control and are not permitted to access or use your Personal Data except to the extent necessary to provide their contracted services.
All third-party service providers act as data processors on behalf of Synexly, or, where applicable, as independent data controllers for their own services. In all cases, they are bound by contractual obligations to process Personal Data in compliance with applicable data protection laws and to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
Synexly is not responsible for the independent privacy practices of third-party controllers, which are governed by their own privacy policies.
Data Storage and International Transfers
Synexly is established in the Republic of Serbia.
Personal Data is processed and stored on infrastructure provided by trusted third-party cloud and hosting service providers used for the operation, maintenance, and security of the Synnect Platform and Website.
Depending on the configuration of the infrastructure and the location of such service providers, Personal Data may be processed and stored within the Republic of Serbia, the European Union/European Economic Area, or in other jurisdictions.
In all cases, Synexly ensures that any international transfer of Personal Data is carried out in compliance with the General Data Protection Regulation (GDPR), where applicable, as well as the Law on Personal Data Protection of the Republic of Serbia. Where Personal Data is transferred outside the EU/EEA, Synexly implements appropriate safeguards to ensure an adequate level of protection, which may include:
- transfers to countries recognized as providing an adequate level of data protection by the European Commission;
- the use of Standard Contractual Clauses (SCCs) approved by the European Commission;
- other lawful transfer mechanisms recognized under applicable data protection laws, including contractual arrangements with service providers that ensure appropriate technical and organizational measures.
Synexly does not transfer Personal Data internationally for purposes unrelated to the provision, security, or maintenance of the Synnect Platform or Website. Such transfers do not affect Synexly’s role as a data processor with respect to Personal Data processed on behalf of its Clients, nor do they alter the allocation of roles and responsibilities between Synexly and the Client as defined in the applicable agreement.
European Privacy Rights
- Right of Access: You have the right to obtain confirmation of whether we process your personal data and, if so, access to the details of that processing, including how it’s used and shared.
- Right to Data Portability: You have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format. You can also request that we transfer this data to a third party, subject to certain exceptions.
- Right to Rectification: You can request corrections to any inaccuracies in your personal data held by us, ensuring that your information is up to date and accurate. You also have the right to request that we complete the information you believe is incomplete.
- Right to Erasure (Right to Be Forgotten): In specific circumstances, you have the right to request the deletion of your personal data.
- Right to Restriction of Processing: You can request that we restrict the processing of your personal data, under certain conditions (allowing us to store it but not use it for certain purposes, in certain situations).
- Right to Object: You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on our legitimate interests or those of a third party. Where your personal data is processed for direct marketing purposes, you have the right to object to such processing at any time, including any related profiling. In such cases, we will no longer process your personal data for direct marketing purposes.
- Right to Withdraw Consent: If we rely on your consent for processing your personal data, you have the right to withdraw that consent at any time.
- Right to lodge a complaint with a supervisory authority, particularly in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
Requests to exercise these rights will be responded to without undue delay and within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests, whereby we will inform you of any such extension within one month of receipt of the request. We may request the provision of additional information if it is necessary to confirm your identity.
Please be aware that some of these rights are conditional, applying only in specific situations, and their exercise may be subject to legal restrictions. For instance, if fulfilling your request would have a negative impact on the rights of others, compromise our trade secrets or intellectual property, or conflict with compelling public interests, or if legal mandates necessitate the retention of your personal information, certain rights may be limited.
Sometimes, we will need to keep processing your information for our legitimate interests or to comply with a legal obligation.
California Residents
Under the California Consumer Privacy Act (CCPA), as amended and expanded by the California Privacy Rights Act (CPRA), users have the following privacy rights:
Right to Know
You have the right to request information about the personal data collected, used, shared, sold or disclosed by us, as well as details about data practices, which includes:
- the categories of personal data collected;
- specific pieces of personal data collected;
- the categories of sources from which we collected personal data;
- the purposes for which we use the personal data;
- the categories of third parties with whom we share the personal data;
- the categories of information that we sell or disclose to third parties (if applicable).
Please note that we are not required to provide the personal information to you more than twice in a 12-month period. Answering on your request is free of charge.
Right to Correction
You have the right to request that we correct inaccurate personal data that we maintain about you.
Right to Deletion
You have the right to request that we delete your personal data collected by us about you.
Please note that we are not required to comply with user’s request to delete personal data if maintenance of personal data is necessary to:
- Complete the transaction for which the personal data was collected, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us;
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity;
- Debug to identify and repair errors that impair existing intended functionality;
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
- Comply with an existing legal obligation.
Right to Limit Use and Disclosure of Sensitive Personal Data (if applicable)
You have the right to opt-out of the use and disclosure of your sensitive personal information for anything other than supplying requested goods or services. You have the right to limit use and/or disclosure of sensitive personal information to that use/disclosure which is necessary to perform the services or provide the goods reasonably expected by an average user who requests those goods or services.
Right to Opt-Out of the Sale or Sharing of Personal Data
You have the right to opt out, which means you can request us to stop selling or sharing your personal information.
Right to Non-Discrimination
We cannot deny goods or services, charge you a different price, or provide a different level or quality of goods or services just because you exercised your rights under the CCPA/CPRA.
Authorized Agent
You can designate an Authorized Agent to act and make a request on your behalf regarding privacy rights. This makes it easier for users to exercise their privacy rights, especially when they may not have the time or expertise to navigate the process themselves. Please note that in this case, we may require more information from you, such as those for identity verification, to verify that you are the person directing the agent.
Children Less Than 16
We do not knowingly sell or share the personal information of a user less than 13 years of age. If you are under the age of 13, please do not submit any personal information through the Synnect Website, without permission of the parent or guardian. We kindly ask parent or guardian that believes the child under the age of 13 has provided personal information to us, to contact us promptly.
We refrain from selling and sharing the personal information of users under the age of 16 that we are aware of unless we obtain explicit consent, known as the “right to opt-in,” from either the user aged 13 to 16 or the parent or guardian of a user under 13 years of age.
Sensitive Personal Information
We do not collect sensitive personal information from users using the Synnect Website. For instance, sensitive information includes social security number, financial account and debit card, or credit card number, precise geolocation information, genetic data, biometric information processed to identify a user, information about racial or ethnic origin, etc. If you elect to submit such information to us, it will be subject to this Privacy Policy.
User Warning
Please do not access, browse or use the Synnect Platform, our Website, our services and features therein, or otherwise provide your information to us if you do not agree with this Privacy Policy in general or any part of it. By using the Synnect Platform, Website or our other services, you are explicitly consenting to our gathering, use, and processing of your personal data in accordance with this Privacy Policy. As we do not control the data privacy or protection policies of our Clients, we are not responsible for their privacy practices.
Compensation Claims and Jurisdiction
Where a data subject brings a claim against Synexly in connection with the processing of Personal Data, such claim shall be governed by the applicable data protection laws. To the extent permitted by applicable law, the competent courts of the Republic of Serbia shall have jurisdiction over such proceedings.
Nothing in this clause shall limit the mandatory rights of data subjects under applicable data protection laws to lodge a complaint with a competent supervisory authority or to seek judicial remedies before courts as provided by law.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. We encourage you to review this Privacy Policy regularly to stay informed about how we process Personal Data.
Material changes to this Privacy Policy will be communicated directly to affected Data Subjects - Users via the Client, prior to the change becoming effective.
Changes to this Privacy Policy are effective when they are posted on this page and continued use of the Synnect Platform or Website constitutes acceptance of such updates.
How to Contact Us
An individual who wishes to exercise their rights regarding their Personal Data should first direct their request to the relevant Client (the data controller). Alternatively, or if you have any questions about this Privacy Policy, you may submit your request to Synexly:
Email: info@synexly.com
Postal Address: 231 Jurija Gagarina Street, Apartment 329, New Belgrade, Belgrade, the Republic of Serbia