Privacy Policy

December 2nd, 2024

Synthesio is made up of different legal entities, details of which can be found here. This privacy policy is issued on behalf of the Synthesio Group so when we mention “Synthesio”, “we”, “us” or “our” in this privacy policy, we are referring to the relevant company in the Synthesio Group responsible for processing your data. If you are based in the European Union, we will let you know which entity will be the point of contact for your data when you purchase a service with us.


Purpose of the privacy policy
This privacy policy aims to give you information on how Synthesio collects and processes your data. Any capitalized but undefined term in this Privacy Policy shall have the meaning given to it in the Contract between us (“Terms”).


a) Customer Data
Customer Data, meaning personal data that we collect, process and manage on behalf of our business customers (“Customers”), submitted to the Synthesio cloud-based services, including our platforms, products, applications, application programming interface (“API”), tools, and any ancillary or supplementary Synthesio products and services (as defined in your Contract with us) offered online (collectively, “Platform”).

We process such Customer Data on behalf and under the instruction of the respective Customer in our capacity as a “data processor”, in accordance with our commercial agreements with them. For more information, please refer to Section 9 below.


Accordingly, this Privacy Policy – which describes Synthesio’s independent privacy and data processing practices as a “data controller” – with respect to the Platform, Sites (as defined below) and any other services provided to Customer by Synthesio (“Services”), and does not apply to the processing of Customer Data. If you have any questions or requests regarding Customer Data, please contact your account administrator(s) (“Account Admin”) directly.


b) User Data
User data means personal data concerning our Customers’ internal focal persons who directly engage with Synthesio concerning their Synthesio account (e.g. billing contacts and authorized signatories), Customers’ Account Admins, and authorized users of the Platform (collectively, “Users”).


c) Prospect Data
Prospect data means any data relating to visitors of our websites (including but not limited to https://www.synthesio.com/), participants at events, and any other prospective customer, user or partner (collectively, “Prospects”) who visit or otherwise interact with our programs, marketing and social activities and our websites, digital ads and content, emails, integrations or communications under our control (“Sites”).

Data Collection & Processing. When we use the term “personal data” in this Privacy Policy, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual. It does not include aggregated or anonymized information that is maintained in a form that is notreasonably capable of being associated with or linked to an individual. We collect or generate the following categories of personal data in relation to the Services:

  • Usage and device information concerning our Users, Prospects:
    Connectivity, technical and usage data, such as IP addresses and approximate general locations derived from such IP addresses, device and application data (like type, operating system, mobile device or app id, browser version, location and language settings used), activity logs, the relevant cookies and pixels installed or utilized on your device, and the recorded activity
    (sessions, clicks, use of features, logged activities and other interactions) of Prospects and
    Users in connection with our Services. We collect and generate this information
    automatically, including through the use of analytics tools (including cookies and pixels) – which
    collect data such as: how often Prospects or Users visit or use the Sites, which pages they visit
    and when, which website, ad or email message brought them there, and how Users interact with
    and use the Platform and its various features.
  • Contact and profile information concerning our Customers, Users, Prospects:
    Name, email, phone number, position, workplace, profile picture, login credentials, contractual
    and billing details, and any other information submitted by Account Admins and Users or
    otherwise available to us when they sign up or log in to the Platform, when creating their
    individual profile (“User Profile”), or by updating their account. We collect this information
    directly from you, or from other sources and third parties such as our Customer (your employer),
    Users and colleagues related to your organizational Synthesio account, organizers of events or
    promotions that both you and us were involved in, and through the use of tools and channels
    commonly used for connecting between companies and individual professionals in order to
    explore potential business and employment opportunities.
  • Communications with our Customers, Users, Prospects:
    Personal data contained in any forms and inquiries that you may submit to us, including support
    requests, interactions through social media channels and instant messaging apps, registrations
    to events that we host, organize or sponsor, and participation in our online and offline
    communities and activities); surveys, feedback and testimonials received; expressed, presumed
    or identified needs, preferences, attributes and insights relevant to our potential or existing
    engagement; and sensory information including phone call and video conference recordings
    (e.g., with our customer experience or product consultants), as well as written correspondences,
    screen recordings, screenshots, documentation and related information that may be
    automatically recorded, tracked, transcribed and analyzed, for purposes including analytics,
    quality control and improvements, training, and record- keeping purposes.

Data Uses & Legal Bases
We use personal data as necessary for the performance of our Services (“Performance of Contract”); to comply with our legal and contractual obligations (“Legal Obligations”); and to support our legitimate interests in maintaining and improving our Services, e.g. in understanding how our Services are used and gaining insights which help us dedicate our resources and efforts more efficiently; in marketing, advertising and selling our Services to you and others; providing customer services and technical support; and protecting and securing our Users, Customers, Prospects, ourselves and our Services (“Legitimate Interests”). If you reside or are using the Services in a territory governed by privacy laws under which “consent” is the only or most appropriate legal basis for processing personal data as described in this Privacy Policy (either in general, based on the types of personal data you expect or elect to process or have processed by us or via the Services, or due to the nature of such processing) (“Consent”), your acceptance of our Contract and of this Privacy Policy will be deemed as your consent to the processing of your personal data for all purposes detailed in this Privacy Policy, unless applicable law requires a different form of consent. If you wish to revoke such consent, please contact us (see below). Specifically, we use personal data for the following purposes (and in reliance on the legal bases for processing noted next to them, as appropriate):

Customer and User personal data

  • To facilitate, operate, enhance, secure and provide our Services; (Performance of Contract;
    Legitimate Interests)
  • To invoice and process payments (Performance of Contract; Legitimate Interests); and
  • To personalize our Services, including by recognizing an individual and remembering their
    information when they return to our Services, and to provide further localization and
    personalization capabilities (Performance of Contract; Legitimate Interests).
  • To provide our Users, and Customers with assistance and support, to test and monitor the
    Services, diagnose or fix technical issues, and to train our Customers’ and Customer-facing staff
    (Performance ofContract; Legitimate Interests);
  • To gain a better understanding of how Users evaluate, use, and interact with our Services, to
    utilize such information to continuously improve our Services, the overall performance, user experience and valuegenerated therefrom. We collect such information automatically through
    their usage of the Services, including through User’s utilization of artificial intelligence
    capabilities in the Platform (Legitimate Interests);
  • To create aggregated statistical data, inferred non-personal data or anonymized or
    pseudonymized data (rendered non-personal), which we or others may use to provide and
    improve our respective Services, or for any other business purpose such as business
    intelligence (Legitimate Interests);
  • To contact our Customers, Users and Prospects and with general or personalized Services related messages, as well as promotional messages that may be of specific interest to them
    (Performance of Contract; Legitimate Interests; Consent);
  • To support and enhance our data security measures, including for the purposes of preventing
    and mitigating the risks of fraud, error or any illegal or prohibited activity (Performance of
    Contact; Legitimate Interests; Legal Obligation);
  • To comply with our contractual and legal obligations and requirements, and maintain our
    compliance with applicable laws, regulations and standards (Performance of Contract;
    Legitimate Interests; Legal Obligation); and
  • For any other lawful purpose, or other purpose that you consent to in connection with
    provisioning our Services. (Legal Obligation; Consent).

Data Disclosure
We may disclose personal data in the following instances:
Service Providers: We engage selected third-party companies and individuals as “Service Providers”,
to performservices on our behalf or complementary to our own. These include providers of Third Party
Services (as defined below), such as: hosting and server co-location services, communications and
content delivery networks (CDNs), data and cyber security services, billing and payment processing
services, fraud detection, investigation and prevention services, web and mobile analytics, email and
communication distribution and monitoring services, session or activity recording services, call
recording, analytics and transcription services, event production and hosting services, remote access
services, performance measurement, data optimization and marketing services,social and advertising
networks, content, lead generating and data enrichment providers, email, voicemails, video
conferencing solutions, support and customer relation management systems, third-party customer
support providers, and our legal, compliance and financial advisors and auditors.
Our Service Providers may have access to personal data, depending on each of their specific roles and purposes in facilitating and enhancing our Services or other activities, and may only use the data as determined in our agreements with them.
Third Party Websites and Services: Our Services includes links to third party websites and services,
and integrations with Third Party Services (as defined in our commercial agreements). Such websites,
services and Third Party Services, and any information you process, submit, transmit or otherwise use
with or to such websites, services and Third Party Services, are governed by such third party’s terms
and privacy practices and policies, and not by this Privacy Policy. We encourage you to carefully read
the terms and privacy policies of such websites, services and Third Party Services.
In particular, in order to provide our Services to you, we use Third Party API Services, notably Google API Services, YouTube API Services, X (Twitter) API Services, Meta API Services and Reddit API Services. We may disclose yourpersonal data (such as your User Profile and contact details, as well as relevant usage data) to these provider(s) in order to enable your access to the Services. These third parties will process this data in accordance with theirown terms and privacy policies. You can access the terms and privacy policies of these providers using the links below.

Data Location & Retention
Data Location: We and our authorized Service Providers (defined below) maintain, store and process personal data in the United States (US), Europe, Singapore, the United Kingdom (UK), and other locations as reasonably necessary for the proper performance and delivery of our Services, or as may be required by applicable law. While privacy laws vary between jurisdictions, Synthesio, its affiliates and Service Providers are each committed to protect personal data in accordance with this Privacy Policy, customary and reasonable industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction to which such data is transferred.
For data transfers from the EEA, the UK and Switzerland to countries which are not considered to be offering anadequate level of data protection, we and the relevant data exporters and importers have entered into Standard Contractual Clauses as approved by the European Commission, the UK Information Commissioner’s Office (ICO), and the Swiss FDPIC, as applicable.

Please note that where Synthesio processes personal data on behalf of a Customer, such personal data (included in their Customer Data) may only be processed in accordance with, and in the locations as agreed in our commercial agreements with such Customer (as further described in Section 9 below).

Data Retention: We may retain your personal data for as long as it is reasonably needed to maintain and expand our relationship and provide you with our Services and offerings; in order to comply with our legal and contractual obligations; or to protect ourselves from any potential disputes (e.g. as required by laws applicable to log-keeping, records and bookkeeping, and in order to have proof and evidence concerning our relationship, should any legal issues arise following your discontinuance of use), all in accordance with our data retention policy and at our reasonable discretion. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of such data, the potential risk of harm from unauthorized use or disclosure of such data, the purposes for which we process it, and the applicable legal requirements. If you have any questions about our data retention policy, please contact us by email, see contact details below.

SourceSource Terms of ServicePrivacy Policy
GoogleGoogle Terms of Service – Privacy & Terms – Googlehttp://www.google.com/policies/privacy
YouTubehttps://www.youtube.com/t/termshttp://www.google.com/policies/privacy
X (Twitter)https://twitter.com/en/toshttps://twitter.com/fr/privacy
Reddithttps://www.redditinc.com/policies/user-agreementhttps://www.reddit.com/policies/privacy-policy
Metahttps://www.facebook.com/legal/termshttps://www.facebook.com/privacy/policy

Application Providers: If so instructed or permitted by you or your Account Admin, we may disclose your personal data (such as your User Profile and contact details, as well as relevant usage data) to the provider(s) of any third- party applications, services or integrations added to your Account. Customers and other Users: Your personal data may be disclosed to the Customer owning the Account to which you are subscribed as a User (including data and communications concerning your User Profile), as well as other Users of that Account. Your personal data and activity within the Services may also be monitored, processed and analyzed by the Account Admin. This includes instances where you contact us for help in resolving an issue specific to a team of which you are a member (and which is managed by the same Customer).
Also, in cases where your personal data appears in boards within that Account that are set as “private” or with limited view privileges, the Account Admin(s) may still access it on behalf of the Customer.
Any content submitted by you may still be accessed, copied and processed by the Account Admin(s). Your User Profile and personal data will also be made available to all the authorized Users who can view the same board(s) as you. Please note that Synthesio is not responsible for and does not control any further disclosure, use or monitoring by or on behalf of the Customer (including sharing of boards or use of broadcast features within the Services), that itself acts as the “Data Controller” of such data (as further described in Section 9 below).
If you register or access the Services using an email address at a domain that is owned by your employer or organization (our Customer), and another team within such Customer’s organization wishes to establish an account on the Services, certain information about you including your name, profile picture, contact info and general use of your Account will become accessible to the Account Admin and Users.
Services integrations: You or your Account Admin may choose to integrate your Account on the Services with third-party Services (provided that such integration is supported by our Services). The provider of such integrated third-party Services may receive certain relevant data about or from your Account on the Services, or disclose certain relevant data from the account on the third-party provider’s Services with our Services, depending on the nature and purpose of such integration. Note that we do not receive or store your passwords for any of these third-party Services (but do typically require your API key in order to integrate with them). If you do not wish your data to be disclosed to such third-party Services(s), please contact your Account Admin.
Legal Compliance: In exceptional circumstances, we may disclose or allow government and law enforcement officials access to your personal data, in response to a subpoena, search warrant or court order (or similar requirement), or in compliance with applicable laws and regulations. Such disclosure or access may occur if we believe in good faith that: (a) we are legally compelled to do so; (b) disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing; or (c) such disclosure is required to protect the security or integrity of our products and Services.
Protecting Rights and Safety: We may disclose your personal data to others if we believe in good faith that this will help protect the rights, property or safety of Synthesio, any of our Users or Customers, or any members of the general public.
Synthesio Subsidiaries: We disclose personal data internally within our group of companies, for the purposes described in this Privacy Policy. In addition, should Synthesio or any of its subsidiaries undergo any change in control, including by means of merger, acquisition or purchase of substantially all of its assets, your personal data may be disclosed with the parties involved in such an event. If we believe that such change in control might materially affect your personal data then stored with us, we will notify you of this event and the choices you may have via email or prominent notice on our Services.
For the avoidance of doubt, Synthesio may disclose your personal data in additional manners, pursuant to your explicit approval, if we are legally obligated to do so, or if we have successfully rendered such data non-personal and anonymous.

Cookies and Tracking Technologies
Our Sites and Services (including some of our Services Providers) utilize “cookies”, anonymous identifiers, pixels, container tags and other technologies in order for us to provide and monitor our Services and Sites, to ensure that they perform properly, to analyze our performance and marketing activities, and to personalize your experience. Such cookies and similar files or tags may also be temporarily placed on your device. Certain cookies and other technologies serve to recall personal data, such as an IP address, as indicated by a Prospect or User. You may also use the “Cookie settings” feature available in our Services or your browser depending on your location and activity on our Services, as applicable.

Communications
We engage in Services and promotional communications, through email, phone, SMS and notifications. Services Communications: We may contact you with important information regarding our Services. For example, we may send you notifications (through any of the means available to us) of changes or updates to our Services, billing issues, log-in attempts or password reset notices, etc. Our Customers, and other Users on the same Account, may also send you notifications, messages and other updates regarding their or your use of the Services. You can control your communications in accordance with the instructions that may be included in the communications sent to you. However, please note that you will not be able to opt-out of receiving certain Services communications which are integral to your use (like password resets or billing notices).
Promotional Communications: We may also notify you about new features, additional offerings, events and special opportunities or any other information we think you will find valuable, as our Customer or User. We may provide such notices through any of the contact means available to us (e.g. phone, mobile or email), through the Services, or through our marketing campaigns on any other sites or platforms. If you do not wish to receive such promotional communications, you may notify Synthesio at any time by sending an email, please see contact details below.

Data Security
Synthesio places great importance on the security of all personal data. We have appropriate security measures in place to protect against the loss, misuse, and alteration of personal information under our control. Our security and privacy policies are periodically reviewed and enhanced as necessary and only authorized personnel have access to personal information. Whilst we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use all reasonable efforts to prevent it.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our Platform; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.
We have also put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
However, please be aware that regardless of any security measures used, we cannot and do not guarantee the absolute protection and security of any personal data stored with us or with any third parties as described in Section 4 above.

Data Subject Rights
If you wish to exercise your privacy rights under applicable law (including the EU or UK GDPR, Swiss Federal Data Protection Act, or the CCPA), such as (each to the extent applicable to you under the laws which apply to you) – the right to know/request access to (specific pieces of personal data collected; categories of personal data collected; categories of sources from whom the personal data was collected; purpose of collecting personal data; categories of third parties with whom we have disclosed personal data), to request rectification or erasure of your personal data held with Synthesio, or to restrict or object to such personal data’s processing (including the right to direct us not to sell your personal data to third parties now or in the future), or to obtain a copy or port such personal data, or the right to equal Services and prices (e.g. freedom from discrimination) – please contact us by email, see contact details below. If you are a GDPR-protected individual, you also have the right to lodge a complaint with the relevant supervisory authority in the EEA or the UK, as applicable.
You may designate an authorized agent, in writing or through a power of attorney, to request to exercise your privacy rights on your behalf. The authorized agent may submit a request to exercise these rights by emailing us. In such cases, we may request further information to verify such power of attorney and authorization.
Please note that our data deletion process applies globally across all regions, ensuring that data is removed uniformly from all locations, regardless of geographic boundaries. When you ask us to exercise any of your rights under this Privacy Policy or applicable law, we may instruct you on how to fulfill your request independently through your User Profile settings; refer you to your Account Admin; or require additional information and documents, including certain personal data and credentials in order to process your request in a proper manner (e.g. in order to authenticate and validate your identity so that we know which data in our systems relates to you, and where necessary, to better understand the nature and scope of your request). Such additional information will be then retained by us for legal purposes (e.g. as proof of the identity of the person submitting the request, and of how each request was handled), in accordance with Section 3 above.
We may redact from the data which we make available to you, any personal or confidential data related to others.

Data Controller/Processor
Certain data protection laws and regulations, such as the GDPR or the CCPA, typically distinguish between two main roles for parties processing personal data: the “data controller” (or under the CCPA, “business”), who determines the purposes and means of processing; and the “data processor” (or under the CCPA, “service provider”), who processes such data on behalf of the data controller (or business). Below we explain how these roles apply to our Services, to the extent that such laws and regulations apply.
Synthesio is the “data controller” of its Prospects’, Users’ and Customers’ personal data, as detailed in Section 1 above. Accordingly, we assume the responsibilities of a data controller (solely to the extent applicable under law), as set forth in this Privacy Policy.
Synthesio is the “data processor” of personal data contained in Customer Data, as submitted by our Customers and their Users to. We process such data on behalf of our Customer (who is the “data controller” of such data) and in accordance with its reasonable instructions, subject to our Terms (to the extent applicable) and other commercial agreements with such Customer.
Our Customers are solely responsible for determining whether and how they wish to use our Services, and for ensuring that all individuals using the Services on the Customer’s behalf or at their request, as well as all individuals whose personal data may be included in Customer Data processed through the Services, have been provided with adequate notice and given informed consent to the processing of their personal data, where such consent is necessary or advised, and that all legal requirements applicable to the collection, use or other processing of data through our Services are fully met by the Customer. Our Customers are also responsible for handling data subject rights requests under applicable law, by their Users and other individuals whose data they process through the Services.
If you would like to make any requests or queries regarding personal data we process as a data processor on our Customer’s behalf, including accessing, correcting or deleting your data, please contact the Customer’s Account Admin directly.

Additional Notices
Updates and Amendments: We may update and amend this Privacy Policy from time to time by posting an amended version on our Services. The amended version will be effective as of the date it is published. When we make material changes to this Privacy Policy, we will give notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Services or by sending an email. Your continued use of the Services after the changes have been implemented will constitute your acceptance of the changes.

Contact Details
Please submit any questions, concerns or comments you have about this privacy policy or any requests concerning your personal data by email.
Our full details are:
Data privacy and information security
Team Email address: privacy@synthesio.com
Postal address: 35 Rue du Val de Marne, 75013 Paris,
FRANCE Telephone number: +33 1 44 77 89 10
If you are based in the European Union you have the right to make a complaint at any time to your local supervisory authority for data protection issues. The information about your supervisory authority can be found below:
If you are based in the UK: the Information Commissioner’s Office (ICO) at www.ico.org.uk
If you are based in France: the Commission Nationale de l’Informatique et des Libertés (CNIL) at https://www.cnil.fr/en/contact-cnil
If you are based in Belgium: the Belgian Data Protection Authority at commission@privacycommission.be
We would, however, appreciate the chance to deal with your concerns before you approach your local supervisory authority, so please contact us first.

Contact

We would love to get in touch

Tell us how we can help you!

  • Request a demo
  • Learn which plan is right for your team
  • Get onboarding help
  •  Anything else?
Contact
Nearly there!

Just a few more details..

  • Request a demo
  • Learn which plan is right for your team
  • Get onboarding help
Tell us how we can help
Download the report

Learn more!

Reach out and discover actionnable insights, unlock exclusive data and trends and many more. Complete the form and let’s start talking.

Your privacy is important to us.