Legal
Privacy Policy
Effective Date: April 9, 2026
At SyncU (“SyncU”, “we”, “us”, or “our”) we consider the privacy and security of personal data to be extremely important. This Privacy Policy describes how we collect, use, share, and protect information in connection with our platform and services (the “Service”).
We process personal data for (1) our own purposes and (2) under the instructions of our customers who use the Service. In the second case, we strictly follow customers' instructions and do not use data for any other purpose than providing the Service.
Questions? Email us at privacy@syncu.app.
1. How We Collect Personal Data
What personal data we collect depends largely on the interaction that takes place between you and SyncU:
- •When you use the Service. We store all content you provide, including information related to you as a customer or end-user of the Service. We gather this information directly from you or from integrations you linked (WhatsApp, Instagram, Telegram, etc.).
- •When you send us emails or messages. We may store the content of such communications, attachments, and your contact details.
- •When you submit forms or register. We collect contact details and information you complete in registration, demo request, or contact forms.
- •When you use our website. We collect certain technical data (IP address, browser, device) that may constitute personal data.
- •From third-party integrations. For example, from payment service providers confirming whether your payment was successful.
2. What Types of Personal Data We Process
- •Account details. Name, email address, password hash, business name, linked channel pages and accounts, subscription plan, location.
- •Financial information. Last four digits of card number, billing address, and payment transaction records (processed via our payment provider; we do not store raw card data).
- •Contact & business data. Full name, job title, company name, email, phone number collected for communication and cooperation purposes.
- •Messages and conversation data. Content of messages, media, and automated flow interactions processed on your behalf via connected channels.
- •Usage data & logs. IP address, browser type, device identifiers, pages visited, timestamps, feature usage frequency.
- •Cookies and similar technologies. See Section 9 for details.
- •Customer Content (Subscriber data). Personal data you import about your own customers or subscribers. We process this only on your behalf. You are responsible for ensuring you have appropriate permission and legal basis to share this data with us.
Please do not send us sensitive personal data (e.g. health data, racial/ethnic origin, political opinions, biometric data, criminal background) on or through the Service.
3. For Which Purposes We Use Personal Data
- •To operate the Service. Create and maintain your account, authenticate users, process billing, send security alerts and administrative notices.
- •To provide the Service. Route messages across connected channels, execute automation flows, AI responses, and broadcast campaigns on your behalf.
- •To communicate with you. Send product updates, feature announcements, and marketing communications (with opt-out provided in every email).
- •To comply with law. Meet applicable legal obligations, accounting and tax requirements, and respond to valid government requests.
- •For compliance and safety. Enforce our Terms of Service, protect rights and safety of SyncU and its users, and deter fraudulent or illegal activity.
- •To improve the Service. Analyse anonymised usage data to improve platform features and performance. We do not use your message content to train AI models without your explicit consent.
5. Your Data Protection Rights & Choices
Depending on your location, you may have the following rights:
- •Access. Request a copy of the personal data we hold about you.
- •Correction. Request correction of inaccurate or incomplete data.
- •Deletion. Request deletion of your personal data.
- •Portability. Receive your data in a structured, machine-readable format.
- •Objection. Object to certain processing activities.
- •Restriction. Request restriction of processing in certain circumstances.
- •Opt-out of marketing. Unsubscribe from marketing emails at any time via the link in any email or by contacting us.
To exercise any right, email privacy@syncu.app. We will respond within 30 days.
6. For How Long We Retain Personal Data
We retain personal data for as long as your account is active or as needed to provide the Service:
- •Account and contact data is deleted within 30 days of account deletion.
- •Message and conversation history is deleted within 30 days of account deletion.
- •Billing records are retained for 7 years as required by UAE commercial law.
- •Anonymised analytics data may be retained indefinitely.
You may request data deletion at any time by emailing privacy@syncu.app.
7. International Data Transfers
SyncU is based in Dubai, United Arab Emirates. If you access the Service from outside the UAE, your data may be transferred to and stored on servers in the UAE or other jurisdictions where our infrastructure providers operate.
For users in the European Economic Area (EEA) or United Kingdom, we ensure appropriate safeguards are in place for cross-border data transfers in compliance with applicable data protection law (e.g. Standard Contractual Clauses).
8. Children's Information
The Service is intended for business users aged 18 and older. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@syncu.app and we will delete it promptly.
9. Security
We implement industry-standard technical and organisational security measures:
- •All data encrypted in transit using TLS 1.2+
- •Passwords hashed using bcrypt with a high work factor — never stored in plaintext
- •JWT access tokens expire after 15 minutes; refresh tokens expire after 7 days
- •Strict multi-tenant data isolation enforced at the database level — tenant data never crosses accounts
- •Regular dependency updates and security reviews
No method of transmission or storage is 100% secure. If you suspect a security incident, contact us immediately at privacy@syncu.app.
10. Legal Basis for Processing (EEA / UK)
For users in the EEA or UK, our legal bases for processing personal data are:
- •Contract performance — processing necessary to provide the Service you signed up for.
- •Legitimate interests — improving our platform, preventing fraud, and direct marketing to existing customers.
- •Legal obligation — complying with applicable laws and regulations.
- •Consent — where you have given explicit consent (e.g. marketing emails for new prospects).
11. Changes to Our Privacy Policy
We may update this Privacy Policy periodically. When we make material changes, we will update the Effective Date and notify you via email or an in-app notice. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
12. How to Contact Us
For questions, requests, or concerns regarding this Privacy Policy:
Also see our Terms of Service
View Terms of Service →