Privacy Policy
Draft — not yet in force
This is an outline of the sections this document needs. It has not been written or reviewed by a lawyer and should not be relied on. It must be completed before SimpleSynk accepts customers.
Who we are
The legal entity operating SimpleSynk, its registered address, and a contact address for privacy questions. Under GDPR this must identify the data controller.
What we collect
Account data (name, work email, role, organisation), and the content customers create: meeting agendas, notes, and action items.
Worth stating plainly: 1-on-1 notes can contain candid assessments of a person's performance. That makes this more sensitive than most B2B SaaS data and raises the bar for how clearly it is described here.
Controller and processor
For the employee data inside a workspace, the customer is the controller and SimpleSynk is the processor. This distinction determines who answers an employee's access or deletion request, and it needs a Data Processing Agreement to sit alongside it.
Legal basis for processing
The Article 6 basis relied on for each category of processing — for account data, and separately for meeting content.
Sub-processors
The third parties that process customer data on our behalf, what each one does, and where it is located. Currently: Supabase (database, EU), Vercel (hosting), Resend (transactional email), Upstash (rate limiting), and Stripe (payments).
International transfers
Whether any sub-processor moves data outside the EEA, and the transfer mechanism relied on if so.
Retention
How long data is kept, including what happens to archived users — whose meeting history is deliberately retained so the person they met with keeps their own records — and what happens after a workspace is closed.
Your rights
Access, rectification, erasure, portability, restriction, and objection; how to exercise them; and the right to complain to a supervisory authority.
Cookies
SimpleSynk currently sets only a session cookie required to keep you signed in. Strictly necessary cookies do not require consent, which is why there is no cookie banner. Adding analytics or any third-party script changes that, and a consent mechanism becomes mandatory.
Security
A plain description of the measures in place: encryption in transit, hashed passwords, per-organisation data isolation, and audit logging of administrative changes.
Contact
An email address for privacy enquiries, and a DPO if one is appointed.