Privacy policy
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) is Khondakar Readul Islam (SYNAC.IO), Darmstadt, Germany. Write to privacy@synac.io. We have not appointed a data protection officer, because the law does not require one for us.
2. What this policy covers
This policy covers the website synacflow.com, the SYNAC FLOW connect service at connect.synacflow.com, and how the SYNAC FLOW software handles data from accounts you connect to it.
SYNAC FLOW is software that an organisation installs and runs on its own server. Everything inside an installation, such as people, workflows, runs and connected accounts, stays there. The organisation that runs the installation decides about that data and is its controller. We have no access to installations.
3. This website
When you open this website, your browser sends technical data to our server: your IP address, the date and time, the page you asked for, and your browser's name and version. The server needs this to deliver the page and does not keep it in a log. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in delivering the website.
The website runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, which processes data for us under a data processing agreement (Art. 28 GDPR).
The website sets no cookies, uses no tracking or analytics, and loads nothing from other servers. Its fonts are served from this website.
If you write to us by email, we use your address and your message only to answer you, and delete them once the matter is settled, unless the law requires us to keep them. Legal basis: Art. 6(1)(b) and (f) GDPR.
4. The SYNAC FLOW connect service
The connect service lets a SYNAC FLOW installation connect your account at Google, Meta, X, LinkedIn, Atlassian, Canva or TikTok through one app registered for SYNAC FLOW, so that nobody has to register an app of their own. When you connect an account, it processes:
- the address of the installation that started the sign-in, a one-time sign-in value, a one-time key and your language, to show you which installation asked and to send the result only to it;
- the one-time code the provider returns and the tokens it issues, to complete the sign-in;
- when an installation renews a connection, the renewal token and the new access token;
- your IP address, to limit how many sign-ins one address can start.
The service encrypts the tokens straight away for the installation that asked, sends them back through your browser and forgets them when the request ends. It never writes them to disk or to a log, and it never sees your emails, videos, posts or files. Your IP address stays only in the service's working memory for the sign-in limit. It is never written to disk or to a log, and it is gone when the service restarts.
Legal basis: Art. 6(1)(b) GDPR, because you ask to connect your account, and Art. 6(1)(f) GDPR for the sign-in limit, our legitimate interest in preventing misuse. Recipients: the provider you sign in to, as part of the sign-in. Hosting: Hetzner Online GmbH, Germany.
5. Connected accounts
A person in an installation connects an account once. The installation keeps the access encrypted until someone deletes the connection, and uses it only when a workflow step needs it. Depending on the service, SYNAC FLOW asks for:
- Google (Gmail, YouTube): your name, email address and profile picture to label the connection; reading and sending email, for the Gmail steps search, read, reply and send; uploading videos and reading your channel details.
- Meta (Facebook Pages, Instagram): the Facebook Pages you manage, publishing to them and reading their engagement; publishing photos and reels to an Instagram business or creator account.
- X: reading your profile and posts, and posting.
- LinkedIn: your name, email address and profile picture, and sharing posts as you.
- Atlassian (Jira): reading and writing Jira issues and reading your Jira profile.
- Canva: reading your profile, reading and creating designs, and reading and uploading media.
- TikTok: your basic profile, and uploading and publishing videos.
Each connection also keeps a renewal token, so that workflows can still run later. The installation uses this data only to carry out the workflow steps that you or your organisation set up and run, for example "read new email, summarise it with AI, reply". When a step sends data to another service, such as an AI provider your organisation chose, that happens on your organisation's instruction and under that service's terms. SYNAC FLOW does not sell this data, does not use it for advertising and does not use it to train AI models. The organisation that runs the installation is the controller for this data; ask its administrator about anything stored there.
6. Google user data
SYNAC FLOW's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Gmail and YouTube data is used only to provide the workflow steps a person sets up and runs.
- It is passed on only when such a step needs it, when the law requires it, or with the person's consent.
- It is not used for advertising, and not used to develop, improve or train generalised AI or machine learning models.
- Nobody at SYNAC FLOW reads it. We have no access to installations.
SYNAC FLOW uses YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service. How Google handles data is described in the Google Privacy Policy.
7. Disconnecting and deleting data
- In SYNAC FLOW, open Workflows → Credentials and delete the connection. The stored access is deleted at once.
- Remove SYNAC FLOW's access at the provider too: for Google at myaccount.google.com/permissions, for Facebook and Instagram in your Facebook settings under Business integrations or Apps and websites.
- For anything else in your organisation's installation, such as results of earlier runs, ask its administrator.
The connect service stores nothing, so there is nothing to delete there. For any question, write to privacy@synac.io.
8. Security
All connections use https. Tokens travel encrypted for one installation only, and the installation stores them encrypted for each organisation. Please report a security problem to security@synac.io.
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and you can object to processing based on legitimate interests (Art. 21). Write to privacy@synac.io; we answer within one month. You can also complain to a data protection supervisory authority (Art. 77 GDPR). Ours is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)Postfach 3163, 65021 Wiesbaden
Germany
datenschutz.hessen.de
The website and the connect service are not directed at children under 16.
10. Changes
We update this policy when SYNAC FLOW or the law changes. The date at the top shows the current version.