Choose the part that applies to you.
This policy covers SYNIRIA’s main website and Customer Service Agent. The sections below explain the information used by each service and its retention periods.
Main website enquiries
This section applies to the research-interest and custom-agent forms on syniria.com.
Information we collect
Research-interest forms
We collect your work email, role and company, industry, the problem and desired outcome you describe, the research concept you select, your required data-use consent, and your optional indication of beta interest.
Custom-agent enquiry forms
We collect your name, work email, desired outcome, current workflow and systems, and required data-use consent. Company, industry, work frequency, and desired timing are optional.
How the information is used
We use submitted information to respond to enquiries, evaluate demand for future-agent research, consider optional beta interest if relevant, and prevent abuse of the forms.
Data-use consent is required so SYNIRIA can assess and respond to a submission. Beta interest is separate and optional. Selecting it does not guarantee development, a release date, an invitation, or access.
Retention and abuse prevention
- Enquiry records are retained for 12 months from receipt.
- Rate-limit hashes used for abuse prevention expire after 24 hours.
- Our enquiry database does not store raw IP addresses, anti-bot tokens, or request headers.
Services involved
The website and enquiry service run on Hetzner infrastructure. We use self-hosted n8n automation and PostgreSQL storage to process and keep enquiries, and Sender to send acknowledgement and internal notification emails containing the submission details.
Cloudflare Turnstile checks form submissions for abuse. Google Fonts supplies the typography assets loaded by your browser. These external services receive the connection information needed to provide their services, which can include your IP address and browser information.
Our database retention periods above apply to enquiry records and abuse-prevention hashes. Email copies and service-provider records are handled under the relevant service settings and retention policies. Submitting an enquiry does not add you to a marketing mailing list.
Your information requests
To request access to, correction of, or deletion of information you submitted, email info@syniria.com. Please include enough detail for us to identify the relevant enquiry.
If this notice changes materially, SYNIRIA will update the effective date and make the revised notice available on this page.
Non-essential tracking
This release does not load non-essential analytics or advertising trackers.
Customer Service Agent
This Privacy Policy explains how Syniria (“Syniria,” “we,” “us”) collects, uses, and shares information in connection with our AI customer-service agent platform (the “Service”), available at customer-service-agent.syniria.com and its dashboard.
The Service is used by businesses (“Clients”) who connect their Instagram, Facebook, and WhatsApp accounts so an AI agent can answer their customers. This policy covers two groups: our Clients, and the end customers who message a Client’s connected channels.
For personal data processed through a Client’s connected messaging channels, the Client determines the purposes and means of processing and is the data controller. Syniria processes such information solely on the Client’s documented instructions and acts as a data processor. Contact info@syniria.com to discuss any data processing agreement required for your use of the Service before submitting data that requires such an agreement.
1. Information we collect
From Clients (account & configuration). When you create an account and set up your agent, we collect:
- Account details: email address and a password, which we store using industry-standard one-way hashing (never in plain text).
- Business profile: business name, contact name, contact email/phone, time zone, and business type.
- Agent configuration: agent name, tone, business description, hours, FAQs, reactivation phrase, lead-capture field definitions, and your product/service catalog.
- Knowledge sources you upload: PDFs, spreadsheets, and website URLs you add for the agent to learn from.
- Connected-channel credentials: access tokens for the Facebook Pages, Instagram, and WhatsApp accounts you connect. These are encrypted at rest.
- Billing information, processed by our payment provider (see Sharing, below).
From end customers (via connected channels). When someone messages a Client’s connected channel, we process on the Client’s behalf:
- The content of messages exchanged with the agent: text, transcripts of voice notes, and any media the customer sends — images, video, audio files, documents, and shared locations. Media files are stored on our behalf by a third-party object-storage provider (see Sharing, below) and are automatically deleted after 90 days.
- Platform-provided identifiers (e.g. the sender’s platform-scoped ID) needed to route and reply to the conversation.
- Lead/booking details the customer provides in conversation (e.g. name, phone, email, and other fields the Client has configured), stored so the Client can follow up.
Automatically. When you use the dashboard, we automatically collect technical information such as IP address, browser type, operating system, device information, timestamps, and security logs, to operate and protect the Service.
2. Cookies and similar technologies
We use cookies and similar technologies that are strictly necessary to provide the Service:
- keeping you signed in (authentication and session cookies);
- securing the channel-connection flow (short-lived functional cookies);
- protecting against fraud and abuse, and improving security.
We do not use advertising cookies, and we do not currently use third-party analytics cookies. You can control cookies through your browser settings, though disabling strictly necessary cookies may prevent parts of the Service from working. If we introduce analytics or other non-essential cookies in the future, we will update this policy.
3. How we use information
- To operate the Service — run the AI agent, deliver replies, and capture leads.
- To let Clients configure, monitor, and manage their agent and channels.
- To authenticate accounts and send transactional emails (verification, password reset).
- To process subscriptions and payments.
- To secure the Service, prevent abuse, and comply with legal obligations.
We do not sell personal information, and we do not use end-customer message content for advertising.
4. AI processing
Agent replies are generated by third-party AI model providers. To produce a reply, we share only the information reasonably necessary to generate a response — relevant conversation content and the Client’s configured business information — with these providers, and we require them to protect that information in accordance with applicable agreements. AI-generated responses may be inaccurate or incomplete; Clients are responsible for reviewing and overseeing their agent’s behavior.
Conversation content is not limited to text. Voice notes a customer sends are transcribed by a speech-recognition provider so the agent can read them, and images a customer sends may be analysed by an AI model so the agent can respond to what is in them. In both cases the file, or a short-lived link to it, is sent to the provider only for that purpose and only at the time the reply is being produced.
5. Meta platform data
When you connect a Facebook Page, Instagram, or WhatsApp account, we receive and store an access token (encrypted) and the identifiers needed to send and receive messages on your behalf, using the permissions you grant during connection. We use this data solely to provide the messaging features you enable — never to build advertising profiles. You can disconnect a channel at any time from the dashboard, which deactivates it and deletes the stored token. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.
6. How we share information
We share information only with service providers that help us operate the Service, and as required by law. These include providers for:
- messaging on connected channels;
- object storage, for content Clients upload and for media sent by end customers in conversations (Cloudflare R2);
- payment processing (which handles your card details directly);
- AI response generation;
- transactional email delivery;
- hosting and infrastructure on which the Service runs.
We may add or replace service providers as our business evolves, and we will update this policy to reflect material changes.
7. Data retention
We retain Client account and configuration data for as long as the account is active, and end-customer conversation and lead data on the Client’s behalf for as long as the Client’s account is active or until the Client deletes it. When an account is closed, we delete or anonymize associated personal data within a reasonable period, except where retention is required by law. Deleted data may persist in encrypted backups for a limited time before being permanently removed through our normal backup-rotation schedule.
Media files have a shorter, fixed retention period. Images, video, audio files, and documents sent by end customers in a conversation are automatically and permanently deleted 90 days after they are received, regardless of whether the Client’s account remains active. The conversation record itself is kept, so the Client can still see that a file was sent, but the file is no longer retrievable.
8. Security
We use industry-standard measures to protect information, including encryption in transit, AES-256 encryption of connected-channel access tokens at rest, and one-way hashing of passwords. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing. Clients can edit or remove most of their data directly in the dashboard. End customers should direct requests to the Client they interacted with (the controller of that data); we will assist Clients in fulfilling such requests.
You can contact info@syniria.com to exercise your rights or raise a privacy concern. We may request information reasonably necessary to verify your identity or authority and locate the relevant records. We will respond within the period required by applicable law and explain any applicable exception or permitted extension. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. Depending on the law that applies to you, you may also lodge a complaint with the competent data protection authority.
10. Data deletion
To request deletion of data associated with your Meta account, you can remove the Syniria app from your Facebook/Instagram settings, which may initiate our data-deletion process, or contact us at info@syniria.com. Clients can also disconnect any channel from the dashboard at any time to immediately delete its stored access token.
End-customer media. If an end customer wants media they sent to a Client’s connected channel deleted before the automatic 90-day expiry, they should ask that Client, who can request erasure of that conversation’s files from us; we will action it and confirm. Requests can also be sent directly to info@syniria.com, though we may need the Client’s involvement to identify the correct conversation. See our data deletion page for more.
11. Third-party links
The Service and dashboard may contain links to third-party websites and platforms (such as Meta, our payment provider, and documentation). We are not responsible for the privacy practices or content of those third parties, and this policy does not apply to them.
12. Business transfers
If Syniria is involved in a merger, acquisition, financing, or sale of all or part of its assets, information covered by this policy may be transferred as part of that transaction. We will continue to protect it consistent with this policy and notify you where required.
13. Account termination
You can close your account at any time by contacting us, or through the dashboard where available. When you close your account, we stop processing your data for the Service and delete or anonymize it as described under Data Retention, except where we are required to keep it. Disconnecting a channel deletes its stored access token immediately.
14. International transfers
Syniria is a company registered in the United States, and Syniria and its service providers may process and store data in various countries. Where we transfer personal data across borders, we take steps to ensure it remains protected consistent with this policy and applicable law.
15. Children's privacy
The Service is not directed to children under 13 or the minimum age required under applicable law, and we do not knowingly collect their personal information.
16. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and by email or a prominent in-Service notice explaining the change and its effective date. Where required by applicable law, we will obtain consent before applying a change to the processing of your information.
17. Contact us
Syniria — 5830 E 2nd St, Ste 7000 #37147, Casper, WY 82609, US.
Email: info@syniria.com