Syntra Logic Get your free reviewFree review
← Syntra Logic

How we handle your client data

Automating a process usually means touching a spreadsheet full of real people. This is what happens to it, written before you ask, because you should not have to.

If you are looking for what this website collects, that is on the privacy page. This page is about the data you hand us when we work together, which is a different question with a different answer.

The short version

Four things that decide most of the risk

Why we ask for fake data

A column called customer_email full of a@example.com builds and tests exactly the same automation as one full of real addresses. The logic does not know the difference. So the default request is structure and a handful of invented rows, and for most projects, that is where it ends.

Synthetic data is often better for building than the real thing, because the awkward cases can be written deliberately rather than waited for: the empty field, the name with an apostrophe, the date in the wrong format, the duplicate that should not exist.

First askColumn headers, data types, and a dozen fabricated rows. Enough to build against.
If that will not doA generated file matching the real shape: row counts, value ranges, the messy formats that break parsers.
ThenA real extract with names, emails and account numbers replaced.
Only if necessaryReal records, accessed inside your environment, limited to the fields the job needs, for as long as the job takes.

We move down that list one step at a time, only when the step above genuinely will not work, and we tell you why.

Where the work happens

Builds run on your own accounts and infrastructure. That is our standard position for reasons that have nothing to do with data protection: you own what you paid for, and there is nothing to migrate if you stop working with us. But it happens to be the strongest privacy control available: data that never leaves your environment is not exposed by ours.

It also keeps the supplier list below short. When an automation calls a service under your own key, that service is your supplier, not ours. It never enters our contract chain.

AI services, specifically

We sell AI automation, so this deserves saying plainly rather than leaving you to wonder.

Our rules for anything involving a language model

Who else could see it

These are the suppliers involved in running the practice itself. Anything specific to your project is named in your agreement before it is used, and you get notice and a right to object before we add anything.

CloudflareHosts and serves this website. Processes IP and request data to deliver pages and block abuse.
Proton MailThe inbox your correspondence arrives in and is stored in. Switzerland.
Web3FormsRelays contact-form submissions to that inbox.
FrankfurterExchange rates for the currency switcher, and only if you pick a non-dollar currency. No personal data is sent.

The typefaces on this site are served from our own domain rather than a font CDN, so loading a page does not disclose your IP address to a third party.

Roles, in the legal sense

When you engage us and we handle data about your customers or staff, you are the controller and we are the processor. You decide what happens to that data; we act on your instructions. GDPR Article 28 requires a written agreement between us, and we will send you one rather than wait to be asked.

It covers what the regulation requires: processing only on your instructions, confidentiality, security measures, sub-processor rules, help with data subject requests, breach notification, and deletion or return of everything at the end, confirmed in writing.

We are a United States company. Where you are in the EEA or the UK, the agreement includes the European Commission's standard contractual clauses, with the UK addendum where that applies.

What we will not take

Some data raises the bar past what is proportionate for work of this size. We will say no, or ask for specific terms first, rather than accept it and hope:

If something goes wrong

If we become aware of a breach affecting your data, we tell you without undue delay and within 24 hours, before we have the full picture, not after. Your own 72-hour deadline to notify a regulator starts when you find out, so waiting until the investigation is tidy would be spending your time, not ours.

Want the paperwork before you talk to us? Ask and we will send the data processing agreement and our technical and organisational measures document. No call required, and no obligation to have one.

Get in touch