Privacy Policy
Translation for convenience only — This is a translation provided for convenience only. In the event of any discrepancy, the French version alone is legally binding.
SYNAPTIIK attaches particular importance to the protection of personal data. This policy details the processing activities carried out, the legal bases relied upon, the associated sub-processors and the rights you may exercise, in accordance with Regulation (EU) 2016/679 (GDPR) and the amended French Data Protection Act.
1. Data controller
The data controller is Franck FROMONT (trade name SYNAPTIIK), Sole Trader (EI), 5 place des Dombes, 01140 Thoissey, France.
For data processed on behalf of professional clients (platform tenants), SYNAPTIIK acts as processor within the meaning of Article 28 GDPR under the conditions defined in the Data Processing Agreement.
DPO: dpo@synaptiik.fr.
2. Data collected and purposes
| Processing activity | Purpose | Legal basis | Retention |
|---|---|---|---|
| Professional account | Creation, authentication, platform access | Art. 6.1.b (contract) | Subscription duration + 90 days |
| Invoicing | Issuing invoices, collection, accounting | Art. 6.1.c (legal obligation) | 10 years (Art. L. 123-22 French Commercial Code) |
| Customer support | Assistance, ticket follow-up | Art. 6.1.b (contract) | Subscription + 3 years |
| Leeza Level 1 (account memory) | AI assistant — contextual memory internal to the account | Art. 6.1.f (legitimate interest) | Subscription + 90 days |
| Leeza Level 2 (anonymized learning) | Continuous improvement — anonymized output with k-anonymity ≥ 5 | Art. 6.1.a (opt-in consent) | Consent withdrawable at any time |
| Marketing (newsletter) | Product-relevance prospecting | Art. 6.1.a (consent) | Withdrawable at any time |
| Product analytics | Usage measurement, UX improvement | Art. 6.1.a (consent) | 13 months (CNIL) |
| Security logs | Incident detection, obligation under Art. 6 LCEN | Art. 6.1.f + 6.1.c | 12 months |
3. Leeza — AI assistant and transparency
The platform integrates Leeza, an AI assistant structured into two processing levels:
- Level 1 — contextual memory internal to the user account, with no external sharing for training. Legal basis: legitimate interest (Art. 6.1.f). Data is transmitted to Anthropic (Claude) for inference only, under contractual guarantee of no use for upstream training.
- Level 2 — anonymized opt-in learning: interactions are aggregated, anonymized and subject to a k-anonymity ≥ 5 rule before any use for product improvement. Explicit activation required in settings; withdrawable at any time without penalty.
Full detail on the models used, output labeling and AI governance: AI Transparency page.
4. Sub-processors
SYNAPTIIK relies on sub-processors governed by an Art. 28 GDPR agreement. The main ones as of the publication date:
| Sub-processor | Service | Region | Transfer framework |
|---|---|---|---|
| Vercel Inc. | Web hosting / edge compute | US (EU PoPs) | SCCs + DPF |
| Supabase Inc. | Database, auth, storage | EU (AWS Ireland / Paris) | EU hosting |
| Stripe Payments Europe, Ltd | Payments, invoicing, Connect | IE (processing) / US (archive) | SCCs + DPF |
| Backblaze Inc. | Media object storage | EU (Amsterdam) / US | SCCs + DPF |
| Anthropic PBC | Claude models (Leeza inference) | US | SCCs + DPF (zero retention) |
| Resend Inc. | Transactional email delivery | US | SCCs + DPF |
| PostHog Inc. | Product analytics | EU Cloud (Frankfurt) | EU hosting |
| PostHog Inc. | Error monitoring (captureException) | EU Cloud (Frankfurt) | EU hosting |
| Better Stack | Logs & uptime monitoring | EU (Frankfurt) | EU hosting |
| Yousign SAS | Electronic signature (eIDAS) | FR | EU hosting |
| Brevo (formerly Sendinblue) | Marketing emails | FR | EU hosting |
| Cloudflare Inc. | Anti-DDoS, CDN | Global (EU PoPs) | SCCs + DPF |
| Google Workspace | Internal email / productivity | US | SCCs + DPF |
| hCaptcha / reCAPTCHA | Anti-bot for public forms | US | SCCs + DPF |
Any substantial change is reflected in an update to this page and, for Agency clients, a prior notification in accordance with Article 5 of the DPA.
5. Transfers outside the European Union
Some sub-processors operate from the United States. The related transfers are governed by the European Commission's standard contractual clauses (Decision 2021/914) and, where the sub-processor is certified, by the EU-US Data Privacy Framework (Decision 2023/1795).
Systematic additional safeguards: encryption in transit (TLS 1.2 minimum) and at rest, pseudonymization of identifiers, limitation of the scope of transferred data to what is strictly necessary for the service.
6. Your rights
You have the following rights, exercisable from <code>/pro/settings/privacy</code> or on request to dpo@synaptiik.fr:
- Access (Art. 15) — full copy of the data concerning you.
- Rectification (Art. 16) — direct editing or on request.
- Erasure (Art. 17) — account deletion with a 90-day (cancellable) delay before final purge, subject to legal retention obligations (invoices).
- Restriction (Art. 18) — suspension of certain processing activities (Leeza, marketing).
- Portability (Art. 20) — structured export (ZIP containing JSON + CSV + binary media) via /api/legal/export-rgpd.
- Objection (Art. 21) — marketing opt-out, Leeza Level 2 opt-out, profiling opt-out.
- Withdrawal of consent (Art. 7.3) — at any time, with no retroactive effect.
- Post-mortem directives — in accordance with Art. 85 of the French Data Protection Act.
Response within 1 month maximum, extendable by 2 months with a reasoned notification in cases of particular complexity.
Recourse: CNIL — 3 place de Fontenoy, 75334 Paris Cedex 07, France — www.cnil.fr/fr/plaintes.
7. Security
SYNAPTIIK implements appropriate technical and organizational measures: TLS 1.2+ encryption in transit, AES-256 at rest (database, storage, backups), strong authentication (optional MFA for Solo/Studio, mandatory for Agency), role-based access control (RBAC), Row-Level Security (RLS) across all tenant-scoped tables, admin access logging, periodic penetration testing.
In the event of a data breach posing a risk to the rights and freedoms of individuals, notification to the CNIL within 72 hours (Art. 33 GDPR) and, where necessary, to the data subjects concerned (Art. 34). An internal incident register is kept up to date.
9. Changes to this policy
Any substantial change is notified by email at least 30 days before it takes effect, with the possibility of objecting via the objection-rights channels set out in paragraph 6. A versioned history is available on request.