Privacy Policy

Last Updated: August 5, 2025

Introduction and Scope

Synesai Pty Ltd (ABN 79 692 335 050) ("Synesai", "we", "us" or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose data when you use our cloud-based workflow automation platform and related services ("Services"). It applies to business customers globally and covers data collected through our websites, applications, and integrations with third-party systems.

Our Services: Synesai helps businesses define complex workflows using business requirements, process documents, and system context, connect systems, and run inspectable workflow programs with auditable traces.

What this Policy Covers: This Policy covers personal information and business data you or your organization provide to us, or that we generate or receive when delivering the Services. Personal information in this context mainly refers to business contact details (such as names, work emails, phone numbers) and any personal data contained within the business documents you upload. We do not intentionally collect sensitive personal data (e.g. government ID numbers, financial account passwords, health or biometric data) beyond basic contact information. Our Services are intended for use by businesses, and any personal data about individuals (such as your employees or customers) that you input is considered business-related information.

Controller vs Processor: For personal data that you provide about third parties (for example, information about your customers or employees in financial records, contracts, or communications), you are the "data controller" (or equivalent term under applicable law), and Synesai acts as a "data processor" or service provider on your behalf. This means we will only process that data to provide the Services according to your instructions and our Terms of Service or data processing agreement. This Privacy Policy primarily addresses how we handle personal data when we act as a data controller (for example, information about our direct customers and website users). If you have questions about personal data that may be contained in your business data on our platform, you should direct those questions to the relevant business (the data controller).

Legal Frameworks: This Privacy Policy takes into account the requirements of:

  • The Privacy Act 1988 (Cth) and Australian Privacy Principles
  • The New Zealand Privacy Act 2020 and Information Privacy Principles
  • The General Data Protection Regulation (EU) 2016/679 and UK GDPR
  • The California Consumer Privacy Act (CCPA) as amended by CPRA
  • Singapore's Personal Data Protection Act (PDPA)

Appendix 1 outlines additional rights for individuals located in the EU and UK under the GDPR.


Information We Collect

We collect business-related data in order to provide our Services. This includes:

Account and Contact Information

When you sign up or communicate with us, we collect your name, business email, phone number, job title/role, company name, billing address, and similar contact details. This allows us to create and manage your account and reach you when needed.

Business and Workflow Data

Our workflow automation platform processes data such as operational events, API payloads, database records, contractual documents, analytical queries, and other business data that you choose to upload or input. This data typically relates to your company's operations. Any personal information within this business data (for example, a customer's name on a record) is incidental and handled as part of providing the Service to you. We process this data as a data processor on your behalf.

Usage and Technical Data

We automatically collect certain information about how you and your users interact with our Services. This includes:

  • Log data (IP address, browser type, device identifiers)
  • Timestamps of access
  • Features used and queries submitted
  • Pages or reports viewed
  • Error logs and performance data

We may also use cookies or similar technologies on our website or app to remember your preferences and improve user experience. This usage data does not normally identify you as an individual, but it may be linked with your account for service analytics and security purposes.

Payment Data

We collect billing information to process payments for our Services. Payment card details are processed through our third-party payment processor. We do not directly store or have access to your full payment card numbers.

Integration Data

If you integrate our Service with third-party systems (such as Excel, Xero, QuickBooks, Slack, Microsoft Teams, or other tools), we may collect data from those sources. For example, this could include:

  • Records retrieved from connected business systems
  • Events or commands sent via Slack/Teams to our application
  • Documents from connected storage services

We only access and use such data to the extent needed to perform the integration or provide the requested functionality.

Support and Feedback

If you contact us for support or provide feedback, we will collect the information you provide (such as the details of your query or problem, and any screenshots or attachments). We keep records of support tickets and communications to help resolve issues and improve our Services.

No Collection of Sensitive Personal Data

We do not knowingly collect any sensitive personal information such as racial or ethnic origin, political opinions, health information, or financial account passwords. We ask that you do not include such data in the materials you upload to our Service. In the event we encounter sensitive data incidental to the permitted use of our Services, we will treat it securely and in accordance with this Policy.


How We Use Your Information

We use the collected information for the following business purposes:

Providing and Improving the Services

We process your business data, documents, and inputs to deliver our workflow automation platform functionality - for example, to synthesize workflows, run programs, analyse documents, and provide transparent audit trails. We use contact and account data to maintain your user account, authenticate logins, and provide customer support.

We may analyse aggregate usage patterns and feedback to improve existing features and develop new ones. The Services process your workflow descriptions, queries, and data to provide structured outputs, always showing the full process and sources so you can verify accuracy.

AI Processing and Zero Training Commitment: We utilize AI tools and machine learning to assist with workflow synthesis and data processing. We have zero-retention agreements with our AI providers - your data is never used to train AI models. Any AI processing is done with safeguards to maintain confidentiality and accuracy, and not for unrelated purposes.

Communication

We use your contact information to send necessary communications about the Service, including:

  • Transactional emails (billing notices, security alerts, system updates)
  • Changes to our Services or policies
  • Responses to support requests

We may also send product announcements, training materials, or marketing communications about new features or offers, but you can opt out of marketing emails at any time. We will ensure that any marketing complies with applicable laws.

Third-Party Integration

When you choose to integrate our Service with third-party platforms, we use the relevant data from those integrations strictly to perform the integration. For example, if you connect Xero, we retrieve financial data to analyse. If you connect Slack, we may send notifications or receive commands via Slack as directed by you. We do not use data from third-party integrations for any purpose other than providing the intended functionality to you.

Compliance and Legal

We may process and retain data as needed to comply with legal obligations, such as financial reporting regulations, tax requirements, or responding to lawful requests by authorities. We also use data to enforce our Terms of Service and to detect or prevent fraud, security incidents, or other malicious activity.

Aggregated and Anonymized Insights

We may combine and anonymize data from many users to generate statistical insights that help us understand how our Services are used (for example, average usage trends or benchmark metrics). These aggregated insights contain no personal data and cannot be linked back to any individual or company. We may use such insights internally or share them publicly in a manner that does not compromise confidentiality.

If we ever need to use your personal information for a new purpose that is not compatible with the original purposes above, we will obtain your consent or provide you with appropriate notice, as required by law.


Disclosure of Data to Third Parties

We do not sell your personal information to third parties. However, we do share certain data with trusted third-party service providers and partners in order to run our business and deliver the Services to you:

Cloud Hosting and Infrastructure

Synesai relies on reputable third-party cloud providers such as Amazon Web Services (AWS), Google Cloud Platform, and DigitalOcean to host our application and store data. Your data (including backups) may be stored on secure servers operated by these providers. We use industry-standard safeguards (encryption, access controls, etc.) to protect data in the cloud. These providers act as our data processors and are bound by strict security and confidentiality obligations.

AI Service Providers

We use third-party AI providers to assist with workflow synthesis and data processing. We have zero-retention agreements with these providers - your data is processed only to provide the requested functionality and is not retained or used for training. Any data sent to AI providers is limited to what's required for the specific request and is subject to strict confidentiality.

Integration Partners

If you enable integrations with tools like Microsoft (Teams, Excel, OneDrive), Slack, Xero, QuickBooks, or other services, we will share or transmit data to those services as necessary for the integration to function. Each third-party service you connect may also collect or receive data under their own terms and privacy policies, which we encourage you to review.

Service Providers and Sub-Processors

We employ other companies and individuals to perform functions on our behalf. Examples include:

  • Payment processors
  • Email/SMS delivery services
  • Analytics services
  • Customer support software

These providers may process personal data solely for our business purposes. We contractually require all sub-processors to protect personal information with at least the same level of care as we do, and to use it only for the services they provide to us.

Business Transfers

If Synesai is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, or sale of company assets, your data may be disclosed to our advisors and any prospective or actual acquiring entity, to be used solely for the purpose of evaluating or completing the transaction and operating the Services thereafter. In such cases, we will ensure the recipient commits to respect this Privacy Policy or provides you notice and choices regarding your personal data.

Legal Compliance and Protection

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g. a court order, subpoena, or government inquiry). We may also disclose data if we believe in good faith that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights, property, or safety of Synesai, our customers, or others
  • Investigate or assist in preventing any violation of law or our Terms of Service
  • Protect against legal liability

We will endeavor to notify you of any such disclosure, to the extent permitted by law.

In all cases where we share your data with third parties, we only share the minimum necessary information and we take steps to ensure the third party will safeguard it. We never share your business financial records or personal contact details with advertisers or unrelated third parties for their own marketing.


Data Storage and International Transfers

Australian Data Residency

Synesai is an Australian company and your data is primarily stored in Australia on secure servers located in Australian data centers. This provides our customers with the benefit of Australian data residency, subject to the strong privacy protections of Australian law.

While your primary data resides in Australia, certain processing activities require transfers to service providers located overseas:

  • AI Processing: Our AI service providers are located in the United States. When you use AI-assisted workflow features, your queries and relevant data are processed by these providers under zero-retention agreements.
  • Payment Processing: Payment transactions are processed by Stripe, which operates globally including in the United States.

We understand that different countries may have different data protection laws, so we take appropriate measures to ensure your personal data remains protected whenever it is transferred across borders.

Transfers from the EU/UK

If you are located in the European Economic Area (EEA) or the UK, and your personal data is transferred outside of Europe (including to Australia or the United States), we will only transfer such data where we have a legal basis and adequate safeguards in place. This means we will use Standard Contractual Clauses (SCCs) or equivalent data transfer agreements approved by regulators to protect your information.

Transfers from Australia, New Zealand, and Singapore

For transfers from Australia, Singapore, or New Zealand to other countries (such as the United States for AI processing), we comply with local requirements (such as Australia's Privacy Principle 8 and Singapore's PDPA provisions on cross-border data sharing) by ensuring the overseas recipients uphold commitments to protect your data.

Data Storage and Retention

Your data is primarily stored on secure servers in Australia with robust backup and recovery systems. Your data is encrypted at rest and in transit for protection.

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy or as required by law. In practice, this means:

  • We keep your account information and business records while you have an active subscription
  • After termination, we retain data for 30 days to allow you to retrieve your information
  • When personal data is no longer needed, we will securely delete it or anonymize it

For data that we process on your behalf (where you are the controller), our data processing terms govern deletion or return of data upon termination of services, subject to applicable law.


Security Measures

We take the security of your data very seriously. Synesai implements a range of administrative, technical, and physical security measures to safeguard your information from unauthorized access, disclosure, or alteration:

Encryption

  • At Rest: Per-customer AES-256 encryption for data stored on our servers
  • In Transit: TLS 1.3 encryption for all data transmitted between your device and our Services
  • Enterprise: Bring Your Own Key (BYOK) encryption available for enterprise customers

Access Controls

We employ strict access controls on our systems. Only a limited number of authorized personnel at Synesai have access to customer data, and only to the extent necessary for their job roles. Access to production systems is secured via multi-factor authentication and VPN, and all access is logged and monitored. We enforce the principle of least privilege and regularly review permissions.

Role-Based Access

Our platform provides role-based access controls to ensure only authorized users within your organization can view sensitive information.

Authentication and Account Security

We strongly encourage all users to enable two-factor authentication (2FA) to add an extra layer of security to their accounts. We require strong passwords and employ measures to prevent brute-force login attempts.

Zero Data Retention with AI Providers

We have zero-retention agreements with our AI providers. Your data is never used to train AI models and is not retained after processing your queries.

Certifications and Standards

Synesai follows industry best practices for information security. Our infrastructure and processes are built on SOC 2 and DPA standards. Our security practices are designed to meet the standards required of financial services providers.

Data Residency and Tenant Isolation

We offer data residency options and maintain strict tenant isolation to ensure your data is separated from other customers' data.

Employee Training and Policies

Every Synesai employee undergoes background checks and is trained on confidentiality, data protection, and security best practices. We have documented incident response procedures and will notify you and any applicable regulators of data breaches as required by law.

While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We continuously work to update and improve our safeguards. You also play a role in security: please use a strong password, keep your login credentials confidential, enable 2FA, and notify us immediately if you suspect any unauthorized access to your account.


Your Rights and Choices

We respect your rights to control your personal information. Depending on the laws that apply to you, you may have some or all of the following rights:

Right to Access

You can request confirmation of whether we are processing your personal information and access to the personal data we hold about you. We will provide you with a copy of your information in a commonly used format, subject to some exceptions.

Right to Correction

If any of your personal data is inaccurate or incomplete, you have the right to ask us to correct or update it. You can update your contact details in your account settings, or contact us to request correction.

Right to Deletion

You can request that we delete your personal information. We will honor such requests to the extent required by applicable law. Note that we might retain certain minimal information as required for legal compliance or legitimate business purposes.

Right to Restrict Processing

You have the right to ask us to restrict or suspend the processing of your personal data in certain circumstances.

Right to Data Portability

For data you provided to us, you can request to receive it in a structured, commonly used, and machine-readable format. You can export your data from our platform at any time during your subscription.

Right to Object

If we are processing your data based on our legitimate interests, you can object to that processing if you feel it impacts your fundamental rights. You also have an unconditional right to object to your personal data being used for direct marketing purposes.

Right to Withdraw Consent

In cases where we rely on your consent to process personal data, you have the right to withdraw your consent at any time.

Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request as soon as possible and within any timeframe required by law (typically within 30 days). We may need to verify your identity before executing your request.

Your Choices (Opt-Out)

  • Marketing: Opt out of marketing emails by clicking "unsubscribe" in any such email or by contacting us
  • Cookies: Manage your cookie preferences through our cookie consent banner or the cookie settings link in our website footer. Note that strictly necessary cookies (including authentication) cannot be disabled while using the Services.
  • Integrations: Disconnect any integration at any time from your account settings

We want to emphasize that you own your business data. If you decide to stop using Synesai, you can export your data from our platform at any time during your subscription.


Cookies

We use cookies and similar technologies on our website and platform. Cookies are text files placed in your computer's browser to store information and enable functionality.

Cookie Consent

When you first visit our website, we will ask for your consent to use non-essential cookies through our cookie consent banner. You can manage your cookie preferences at any time through the cookie settings link in the footer of our website.

Important: Strictly necessary cookies (including authentication cookies) are essential for the operation of our Services and cannot be disabled. If you block these cookies, you will not be able to use our platform.

Types of Cookies We Use

Strictly Necessary Cookies: Required for the operation of our Services. These include cookies that enable you to log into secure areas, maintain your session, and use core platform features. These cookies are essential and cannot be refused while using our Services.

Analytical/Performance Cookies: Allow us to recognise and count visitors and see how visitors move around our Services. This helps us improve how our Services work. We use Google Analytics for this purpose. These cookies require your consent.

Functionality Cookies: Used to recognise you when you return to our Services, enabling us to personalise content and remember your preferences. These cookies require your consent.

Targeting and Advertising Cookies: Record your visit to our website, the pages you have visited and the links you have followed. We use this information to make our website and advertising more relevant to your interests. These cookies require your consent.

Google Analytics

We use Google Analytics to understand how visitors interact with our website. These cookies may collect Technical and Usage Data about you. You can opt-out of Google Analytics using the Google Analytics Opt-out Browser add-on available at https://tools.google.com/dlpage/gaoptout, or by adjusting your preferences in our cookie consent banner.

Managing Your Cookie Preferences

You can manage your cookie preferences at any time by:

  • Using our cookie consent banner when you first visit the site
  • Clicking the cookie settings link in the footer of our website
  • Adjusting your browser settings to block or delete cookies

Please note that if you disable strictly necessary cookies through your browser settings, you will not be able to use our Services as these cookies are required for authentication and core functionality.


Links to Other Websites

Our website may contain links to other parties' websites. We do not have any control over those websites and we are not responsible for the protection and privacy of any personal information which you provide whilst visiting those websites. Those websites are not governed by this Privacy Policy.


Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal obligations, or data handling practices. If we make a material change, we will provide you with advance notice and the opportunity to review the revised Policy before it takes effect. We may notify you by email or by posting a prominent notice within our application or on our website.

Minor updates may be posted without specific notice, but you can always see the "Last Updated" date at the top to track changes. We encourage you to periodically review this Privacy Policy. If you continue to use the Services after a Privacy Policy update takes effect, it will constitute your acceptance of the changes.


Contact Us and Complaints

If you have any questions, concerns, or requests regarding this Privacy Policy or how Synesai handles your data, please contact us:

Privacy Officer - Synesai Pty Ltd

  • Email: [email protected]
  • Address: 81-83 Campbell Street, Surry Hills, NSW, Australia 2010

We will address your inquiry as promptly as possible. If you have a complaint about our privacy practices, please let us know and we will do our best to resolve it. We aim to respond to complaints within 30 days.

If you are not satisfied with our response, you have the right to escalate your complaint to the data protection authority in your jurisdiction:

  • Australia: Office of the Australian Information Commissioner (OAIC)
  • New Zealand: Office of the Privacy Commissioner
  • United Kingdom: Information Commissioner's Office (ICO)
  • European Union: Your local Data Protection Authority
  • Singapore: Personal Data Protection Commission (PDPC)
  • United States: Your state Attorney General's office or the Federal Trade Commission

Appendix 1: Additional Rights and Information for Individuals Located in the EU or UK

Under the GDPR, individuals located in the EU and the UK have extra rights which apply to their personal information. This Appendix sets out the additional rights and information on how we process personal information of individuals located in the EU and UK.

Legal Bases for Processing

We collect and process personal information about you only where we have legal bases for doing so under applicable laws:

To enable you to access and use our Services

  • Data: Identity Data, Contact Data
  • Legal Basis: Performance of a contract with you

To do business with you and provide our Services

  • Data: Identity Data, Contact Data
  • Legal Basis: Performance of a contract with you

To contact and communicate with you about our business

  • Data: Identity Data, Contact Data, Profile Data
  • Legal Basis: Performance of a contract; Legitimate interests (providing support)

For internal record keeping, invoicing and billing

  • Data: Identity Data, Contact Data, Financial Data, Transaction Data
  • Legal Basis: Performance of a contract; Legal obligation; Legitimate interests (debt recovery)

For analytics, market research and business development

  • Data: Profile Data, Technical and Usage Data
  • Legal Basis: Legitimate interests (improving our Services, informing strategy)

For advertising and marketing

  • Data: Identity Data, Contact Data, Technical and Usage Data, Marketing Preferences
  • Legal Basis: Legitimate interests (growing our business); Consent (where required)

To comply with legal obligations

  • Data: Any relevant Personal Information
  • Legal Basis: Legal obligation

Your Additional Rights

In addition to the rights outlined in the main Privacy Policy, EU and UK individuals may also:

  • Request details of how we are processing your personal information (a "data subject request")
  • Object to decisions being made based on automated processing where the decision produces a legal or similarly significant effect
  • Stop unauthorised transfers of your personal information to a third party
  • Lodge a complaint with your local Data Protection Authority

Data Transfers

Where we transfer your personal information outside of the EEA or UK, we use appropriate safeguards including:

  • Transferring to countries deemed to provide adequate protection
  • Using Standard Contractual Clauses approved by the European Commission or UK ICO

Data Retention

We retain your personal information only for as long as reasonably necessary to fulfil the purposes we collected it for, including for legal, regulatory, tax, accounting or reporting requirements. We consider the amount, nature and sensitivity of the data, the potential risk of harm, and applicable legal requirements when determining retention periods.

Contact for EU/UK Individuals

For any questions or to exercise your rights under the GDPR, please contact:

Email: [email protected]

If you are not happy with how we are processing your personal information, you have the right to make a complaint to the relevant Data Protection Authority. We would appreciate the chance to address your concerns first, so please contact us in the first instance.