Legal
Privacy Policy
1. Controller and scope
1.1. The controller of personal data relating to the use of https://syndicai.co (the “Website”) is Syndicai sp. z o.o., with its registered office in Warszawa, address: ul. Chmielna 9, 00-021 Warszawa, Poland, KRS 0000865681 (the “Controller”).
1.2. For data protection matters, the Controller may be contacted at contact@syndicai.co or its postal address. The Controller has not appointed a data protection officer.
1.3. This Policy describes the processing of data relating to Website visitors and persons contacting the Controller. References to the GDPR mean Regulation (EU) 2016/679 of the European Parliament and of the Council.
2. Contact and handling enquiries
2.1. The “Book a discovery call” form collects:
a) full name and business email address;
b) answers selected from closed lists: the area of work to be improved, the reason for the deadline and, where applicable, the quarter, the budget position, the number of people performing the work and its frequency;
c) information about the source of the enquiry described in section 4.
2.2. When contacted by email, the Controller processes the sender's address and the content of the message and attachments. If contact concerning employment or cooperation leads to recruitment, the Controller provides detailed information on data processing before recruitment begins and no later than when data are collected for that purpose.
2.3. Data are processed to respond to enquiries, arrange a call and prepare a proposal for cooperation:
a) under Article 6(1)(b) GDPR, where the contact concerns steps taken at a person's request before entering into a contract to which that person is to be a party;
b) under Article 6(1)(f) GDPR in other cases, including contact with a business representative. The Controller's legitimate interest is conducting correspondence and managing business contacts.
2.4. The enquiry is forwarded to the Controller through an email delivery service provider. The user receives a confirmation containing a copy of their answers and an explanation of the next steps. The enquiry may be recorded in an enquiry register spreadsheet held with a cloud office tools provider.
2.5. Providing data is voluntary. Without contact details and the information necessary to handle a particular enquiry, the Controller cannot respond appropriately. Submitting a form or message does not in itself constitute consent to marketing.
2.6. The Controller does not operate a newsletter or send marketing emails without separate consent. The enquiry confirmation is a transactional message.
3. Website operation and security
3.1. The hosting provider records technical logs comprising the IP address, request time and address, response code and browser information. These data support the operation and security of the Website.
3.2. The form uses a hidden field to detect bots and limits submissions from a single IP address to eight per hour. For this limit, the IP address is held in server memory for no more than one hour.
3.3. The legal basis is Article 6(1)(f) GDPR. The Controller's legitimate interest is ensuring the availability and security of the Website and preventing abuse.
4. Cookies and device storage
4.1. The Website uses neither its own nor third-party cookies and does not store information on the user's device (localStorage, sessionStorage). It does not display a cookie banner.
4.2. During a visit, the Website keeps the following in the running page's memory, until the page is closed or reloaded:
a) the entry page address, including its path and query parameters;
b) the referring page address;
c) campaign parameters utm_*, where present in the address.
4.3. This information is transmitted to the server only when the user submits the contact form. It is then attached to the enquiry.
4.4. The purpose is to establish which article or campaign led to the contact. The mechanism is not used for profiling, advertising or tracking users across websites.
4.5. To the extent that the information attached to an enquiry constitutes personal data, its further processing serves to assess the sources of enquiries, which is the Controller's legitimate interest under Article 6(1)(f) GDPR.
5. Visitor statistics
5.1. The Website uses statistics supplied by the hosting provider. The script is loaded from the Website's domain, does not use cookies and does not store information on the user's device.
5.2. The following are collected on a page view: event time, the address of the page visited, the referring address, filtered query parameters, country, region and city derived from the IP address, operating system, browser and device type. The IP address is not recorded in the statistics.
5.3. Visitors are recognised within a visit using a hash calculated from request data. The hash is automatically deleted after 24 hours. Results are presented only in aggregate form. The tool does not use identifiers for tracking across websites and is not used for profiling.
5.4. To the extent that personal data are processed, the legal basis is Article 6(1)(f) GDPR, and the Controller's legitimate interest is understanding how the Website is used and assessing its content.
6. Published data and links
6.1. The Website publishes testimonials comprising a quotation, the contributor's full name, job title and company name. These data come from the individuals concerned or their companies. Personal data are published on the basis of the data subject's consent under Article 6(1)(a) GDPR. Consent may be withdrawn at any time by contacting the Controller; the data covered by the withdrawal will be removed from the Website without undue delay and no later than 14 days after receipt of the withdrawal.
6.2. Team members' names, roles and biographies are published under Article 6(1)(f) GDPR, in the Controller's legitimate interest in presenting its team. An individual's image is published with that person's consent under Article 6(1)(a) GDPR; consent may be withdrawn at any time by contacting the Controller.
6.3. Fonts, images and scripts are served from the Website's domain. The Website contains no external embeds or social media plugins. Ordinary links lead to external websites whose operators apply their own data processing rules. Links using mailto: open the user's email application.
7. Recipients and transfers outside the EEA
7.1. Data recipients may include, to the extent necessary for their tasks:
a) the hosting and statistics provider;
b) the email delivery service provider;
c) providers of email and cloud office tools;
d) legal and accounting advisers;
e) public authorities where disclosure is required by law.
7.2. Some providers are based in the USA. Transfers outside the European Economic Area are based on:
a) Commission Implementing Decision (EU) 2023/1795 for providers covered by the relevant EU-US Data Privacy Framework certification, within the scope of that certification;
b) in other cases, the European Commission's standard contractual clauses under Article 46(2)(c) GDPR.
7.3. A copy of the safeguards used for data transfers may be obtained by contacting the Controller.
8. Retention
8.1. Data from enquiries and correspondence that do not result in a contract are retained for up to 24 months after the last contact and then deleted. Information on processing data relating to a concluded contract is provided separately.
8.2. Data necessary for the establishment, exercise or defence of legal claims may be retained until the applicable limitation periods expire. The legal basis is Article 6(1)(f) GDPR, and the Controller's legitimate interest is protecting its rights.
8.3. Technical logs are retained for no more than 30 days. The periods specified in sections 3.2, 4.2 and 5.3 apply respectively to IP addresses used to limit submissions, enquiry source information and the statistical hash.
9. Individuals' rights
9.1. Subject to the conditions laid down in the GDPR, individuals have the right of access, rectification, erasure and restriction of processing. The right to data portability applies where processing is carried out by automated means on the basis of consent or a contract.
9.2. Individuals may object to processing based on Article 6(1)(f) GDPR on grounds relating to their particular situation.
9.3. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
9.4. Requests may be sent to contact@syndicai.co. Individuals also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.
9.5. The Controller does not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect an individual within the meaning of Article 22 GDPR.