Skip to content
addsynapse

Draft — this document is a placeholder and will be finalised before launch.

Privacy Policy

We process as little personal data as possible, and never sell it. This policy explains what we process and your rights under the GDPR.

1. Who we are

addsynapse is the data controller for account data and a data processor for the content of your site that you ask our AI to work with. Contact: through the contact form on this site.

2. Data we process

  • Account data: name, email, password hash, two-factor settings, team memberships, sign-in provider identifiers.
  • Site data: site address, keys (secrets encrypted), module and plan status, usage counters.
  • Content you ask the AI to work with: product and page data needed for a request, and the conversation itself. Customer personal data (names, emails, phones, addresses) of your shop is not sent to us.
  • Billing data: handled by Stripe; we keep the customer id, subscription status and invoices metadata.
  • Contact form messages and essential technical logs (with IP addresses stored only as hashes where possible).

3. Why and on what legal basis

To provide the service you subscribed to (contract), to secure it and prevent abuse (legitimate interest), and to meet tax and accounting obligations (legal obligation).

4. Subprocessors

  • Anthropic (AI model provider, USA) — processes request content to generate answers; not used to train models; EU Standard Contractual Clauses.
  • Stripe (payments) — card and billing data, invoices and tax.
  • Our hosting provider in the EU (servers and backups) and our email delivery provider.

5. Retention

Account data for as long as your account exists; conversations and usage records for the period needed to provide and bill the service; invoices as required by law.

6. Your rights

You can access, correct, export or delete your data, object to or restrict processing, and complain to the Hellenic Data Protection Authority (dpa.gr).

7. Security

Encryption in transit and at rest for secrets, two-factor authentication, signed requests, least-privilege access and audit logs. See our security page for details.