Privacy Policy
Effective: August 20, 2026
Synk AI (the Controller) is committed to protecting personal data. This policy explains, in line with Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on informational self-determination, what personal data we process when you use the synkai.hu website and the related services, for what purpose, on what legal basis and for how long, and what rights you have. Section 4 describes in detail how we handle Google user data obtained through Google APIs.
1. The Controller
- Company
- Orosz Enterprises FZE LLC (trading as Synk AI)
- Registered office
- Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates
- Registration number
- 4428075.01 (incorporation number: 4428075)
- Representative
- Peter Orosz, Managing Director
- Email for privacy requests
- info@synkaisolutions.com
- Website
- synkai.hu
- EU representative (GDPR Art. 27)
- Appointment in progress. Until appointed, privacy requests are handled directly by the Controller at info@synkaisolutions.com
The Controller is not required to appoint a Data Protection Officer under Art. 37 GDPR. For any privacy matter, please contact us at the email address above.
2. What data we process, why, and for how long
2.1. Contact and quote request forms
When you fill in a form on the website we process the following data: last name, first name, company name, email address, phone number, the text of your message, the time of submission and the source page of the form.
- Purpose: to contact you, to provide a quote, to answer your enquiry.
- Legal basis: your consent (Art. 6(1)(a) GDPR) and steps taken prior to entering into a contract (Art. 6(1)(b) GDPR).
- Retention: until consent is withdrawn, and at most 2 years from the last contact. If a contract is concluded, the contractual retention rules apply.
- Recipients: our own client management system (Synk CRM, app.synkai.hu, stored on Supabase, EU / Paris) and the GoHighLevel CRM (HighLevel Inc., USA).
2.2. Contracts, client relationship, client portal
When a contract is concluded we process the name, job title, email address and phone number of the contact persons, the company data, the image of the electronic signature, the time of signing and the related technical log data, as well as the account data required to use the client portal.
- Purpose: conclusion and performance of the contract, communication, providing portal access.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR); for contact person data, the legitimate interest of the Controller and of the client (Art. 6(1)(f) GDPR).
- Retention: 5 years from the termination of the contract (general limitation period under Hungarian civil law).
2.3. Invoicing
- Data processed: billing name, address, tax number, invoice data, payment data.
- Purpose and legal basis: compliance with accounting and tax record keeping obligations (Art. 6(1)(c) GDPR).
- Retention: 8 years under Section 169 of Hungarian Act C of 2000 on Accounting.
- Recipients: for online payments, Stripe (Stripe, Inc. / Stripe Payments Europe Ltd.). Card data is processed exclusively by Stripe; the Controller has no access to it.
2.4. Job applications
- Data processed: name, contact details, CV and any other data provided by the applicant.
- Purpose and legal basis: running the selection process, based on the consent of the applicant (Art. 6(1)(a) GDPR).
- Retention: until the position is filled; with the separate consent of the applicant, at most 1 year from submission.
2.5. Website visits, logging
While serving the website our hosting provider (Vercel) may record technical log data (IP address, time of the request, browser data) in order to operate the service securely. Legal basis: the legitimate interest of the Controller in the secure operation of the website (Art. 6(1)(f) GDPR).
3. Cookies and similar technologies
Besides the cookies strictly necessary for its operation, the website uses analytics and marketing cookies and similar technologies only with your prior consent. Consent is given in the cookie banner, can be tailored by category, and can be changed or withdrawn at any time by clicking the cookie icon in the lower left corner. Your choice is stored in the local storage of your browser (localStorage, key synk_cookie_consent_v1). The loading of measurement and advertising tags is governed by Google Consent Mode: without consent, marketing and analytics tags receive no data.
| Category | Service | Purpose | Lifetime |
|---|---|---|---|
| Necessary | synk_cookie_consent_v1 (localStorage) | Storing the cookie consent | Until deleted |
| Analytics | Google Analytics 4 (_ga, _ga_*) | Traffic statistics, improvement of the website | Up to 2 years |
| Analytics | Microsoft Clarity (_clck, _clsk) | Session recording and heatmaps to improve the user experience | _clck: 1 year, _clsk: 1 day |
| Marketing | Google Ads | Ad measurement, conversion tracking, remarketing | Up to 2 years |
| Marketing | Meta Pixel (_fbp) | Measurement of Facebook and Instagram ads, remarketing | 3 months |
The legal basis for cookie related processing is your consent (Art. 6(1)(a) GDPR and Section 155(4) of Hungarian Act C of 2003 on electronic communications). The legal basis for necessary cookies is our legitimate interest in operating the website.
4. Google user data: connecting a Google Account (Calendar and sending email)
The Synk AI client portal (app.synkai.hu) allows a user to connect their own Google Account to Synk AI. Connecting is entirely voluntary, it is never a condition of using the portal, and it can be revoked at any time. The table below lists exactly which Google permissions we request, what each one gives access to, and what we use it for.
4.1. What Google user data we access and how we use it
| Google OAuth scope | What it gives access to | How Synk AI uses it |
|---|---|---|
| Calendar events .../auth/calendar.events | Reading and writing events in the calendar of the connected user | Reading the start and end times of existing events so the booking page offers only genuinely free time slots; writing a confirmed booking into the calendar as an event and inviting the other party; updating or cancelling that event when the booking changes |
| Sending email .../auth/gmail.send | Sending email on behalf of the connected user. It grants no read access of any kind. | Sending the booking confirmation and the booking reminders from the address of the user, so that the recipient can reply to a real person |
| Email address .../auth/userinfo.email | The email address of the connected account | Displaying the connected address in the portal settings so the user can verify which account is linked |
We request the narrowest scopes that make these features work. We do not request the full Google Calendar scope (.../auth/calendar), because we never need to manage or share calendars, and we request no Gmail read, modify or compose scope of any kind.
4.2. What we explicitly do not do
- We do not read, search, modify or delete the incoming or sent email of the user. The gmail.send scope, as defined by Google, grants no read access whatsoever.
- We do not manage the calendar sharing settings of the user, and we do not create, delete or share calendars.
- We do not analyse or store the content, the description or the attendees of calendar events. Only the start and end times of events are used, in order to compute free time slots.
- We do not use Google user data for advertising, we do not sell it, and we do not use it to train artificial intelligence or machine learning models.
4.3. With whom Google user data is shared
Google user data obtained through the Google APIs is not shared, transferred or disclosed to any third party, with the following two narrow exceptions:
- Our own infrastructure providers acting as processors, strictly in order to operate the service: Supabase Inc. (database hosting, EU, AWS eu-west-3, Paris) and Vercel Inc. (application hosting). They act on our documented instructions under a data processing agreement and never use the data for their own purposes.
- Disclosure required by law, for example a binding request from a competent authority.
Google user data is never sold, never used for advertising or ad targeting, never shared with data brokers, and never used for artificial intelligence or machine learning model training.
4.4. How we protect Google user data
- The access and refresh tokens issued by Google are stored encrypted at rest in the client portal database (Supabase, EU, Paris).
- All data in transit is protected by HTTPS / TLS.
- Database access is restricted by role based access control and row level security, so a portal user can only reach the integrations of their own organisation.
- Tokens are used exclusively for the operations listed in section 4.1, by the server side of the application. They are never exposed to the browser and never written into logs.
- Access to production systems is limited to a small number of named staff members, is authenticated, and is logged.
4.5. Legal basis, retention and deletion
- Legal basis: the explicit consent of the user (Art. 6(1)(a) GDPR), given on the consent screen of Google.
- Retention: Google tokens are retained only while the connection is active. We do not retain copies of calendar events or of any sent email.
- Deletion: when the user disconnects, the stored access and refresh tokens are deleted from our database immediately and the refresh token is revoked at Google. All Google user data associated with the connection is deleted at that point.
- How to disconnect: in the portal, under the Calendar menu, on the Settings tab, using the Disconnect button, or at any time in the security settings of the Google Account at myaccount.google.com/permissions.
- Deletion on request: a user may also request deletion by writing to info@synkaisolutions.com. We action such requests without undue delay and within 30 days at the latest.
4.6. Limited Use
Synk AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Processors and recipients
The Controller uses the following main processors and service providers:
| Provider | Activity | Location of the data |
|---|---|---|
| Vercel Inc. (USA) | Website hosting and delivery | USA / EU (EU-US Data Privacy Framework) |
| Supabase Inc. | Client portal and CRM database | EU (AWS eu-west-3, Paris) |
| Google Ireland Ltd. | Analytics (GA4), advertising (Google Ads), tag management (GTM) | EU / USA (DPF) |
| Meta Platforms Ireland Ltd. | Ad measurement, remarketing (Meta Pixel) | EU / USA (DPF) |
| HighLevel Inc. (USA) | CRM and marketing automation (GoHighLevel) | USA (standard contractual clauses) |
| Stripe Payments Europe Ltd. / Stripe Inc. | Online payments | EU / USA (DPF) |
| Resend / email infrastructure | Sending transactional email | USA (SCC) |
The providers listed in this section receive the data described in section 2. Google user data as described in section 4 is only ever processed by Supabase and Vercel, as set out in section 4.3. The complete and current list of processors is available on request at info@synkaisolutions.com.
6. International transfers
Some of our providers process data outside the European Economic Area, primarily in the United States and, in the case of the registered office of the Controller, in the United Arab Emirates. Such transfers take place under the safeguards of Chapter V of the GDPR: the EU-US Data Privacy Framework where the provider is certified, otherwise the standard contractual clauses of the European Commission, supplemented where necessary by additional technical measures.
7. Data security
The Controller protects personal data with appropriate technical and organisational measures, in particular: encrypted transmission (HTTPS / TLS), encryption at rest for sensitive credentials such as OAuth tokens, role based restriction of access rights, row level security in the database, regular backups, and protection of electronic signatures with a document checksum (hash).
8. Your rights
Under the GDPR you have the right at any time to request:
- access to the personal data we process about you (Art. 15),
- rectification of your data (Art. 16),
- erasure (the right to be forgotten, Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- to object to processing based on legitimate interest (Art. 21),
- to withdraw your consent at any time, which does not affect the lawfulness of processing carried out before the withdrawal (Art. 7(3)).
Send your request to info@synkaisolutions.com. We will fulfil or answer it without undue delay and at the latest within 1 month of receipt; this deadline may be extended by 2 months where necessary, of which we will inform you.
9. Remedies
If you consider that the processing infringes the law, you may lodge a complaint with the supervisory authority:
- Authority
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- Phone
- +36 (1) 391-1400
- ugyfelszolgalat@naih.hu
- Web
- naih.hu
You may also bring the matter before a court under Art. 79 GDPR; the action may, at your choice, be brought before the court of your place of residence or stay.
10. Automated decision making, profiling
The Controller does not carry out decision making based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Advertising systems (Google, Meta) may form interest based audiences on the basis of your consent, in accordance with their own policies.
11. Changes to this policy
The Controller may amend this policy unilaterally; the version in force at any given time is available on the website. We announce material changes prominently on the website and, for existing clients, by email.