Trust & Transparency
At Synaptiik, the sovereignty of your data is a sacred asset — not a marketing promise. Here are our concrete, verifiable and contractually enforceable commitments.
GDPR by design
From the ground up
ISO 27001
Hosting provider (Supabase/AWS EU)
Electronic signature (SES)
SHA-256; server timestamp in the audit ledger
PCI DSS Level 1
Stripe payments
TLS 1.3 + AES-256
Encryption in transit & at rest
Anthropic zero-retention
AI with no third-party training
Data protection
GDPR is not a checkbox. It is wired into the architecture from the very first commit.
Artificial intelligence
Leeza runs exclusively on Anthropic models — with a zero-retention policy.
Infrastructure
Encryption in transit (TLS 1.3) and at rest (AES-256), multi-factor authentication, zero-trust architecture.
Sovereignty
Production infrastructure and data hosted in Europe, with ISO 27001 certified providers. AI processing via Anthropic (US) governed by DPA/SCC, zero retention.
Legal value
Signatures admissible as evidence (art. 1366 C. civ. / eIDAS art. 25.1), reinforced by SHA-256 integrity proof and a server timestamp.
Tax compliance
The French reform makes electronic invoicing mandatory for every VAT-liable business: receiving from September 1, 2026, issuing from September 1, 2027. Synaptiik is ready.
Product commitment
No dark patterns. No paid rankings. No algorithmic manipulation.
Service agreement
Contractual commitments, not marketing promises.
Disambiguation
Your photos, videos, contracts, client data and organizational memory belong exclusively to your studio. Synaptiik is a service operator, not a data owner. You can export everything at any time and request full deletion — without justification and without delay (72h maximum).
In the event of cancellation, your data remains exportable for 90 days. After that period, it is irreversibly and verifiably deleted.
Row Level Security (RLS) enabled on every table. Your data is never accessible to another Synaptiik subscriber. Strict per-organization isolation via Row-Level Security.
What this actually means
"Secure" means nothing until you say against what, at what level, and what remains verifiable afterwards. The commitments listed above describe measures that are actually implemented — not intentions, and not labels we don't hold.
When a guarantee relies on a third party, it is named as such: PCI DSS compliance for payments is Stripe's, ISO 27001 certification is our infrastructure host's. What falls under Synaptiik is described below in technical terms.

Photo : Felix Moeller · Pexels
Technical measures
Each measure is described by what it does and by the risk it covers — because a mechanism whose purpose is unknown reassures no one.
Studio practices
Most incidents at a studio don't come from an attack, but from a convenient habit: a public link, a shared password, a local folder.
Disambiguation
The name invites confusion, and the photo-software market is crowded with vague promises. Here is, plainly, what Synaptiik does not do.
Money & billing
A sensitive topic, explained without jargon: who gets paid, when, and under what conditions you can change your mind.
FAQ
In the European Union, with our infrastructure host. Application processing and file storage fall within the same geographic perimeter, which avoids a transfer outside the EU in normal operation.
No, unless you decide otherwise. Access is granted per person and per scope: a second shooter or a service provider only sees the assignments they are attached to. Filtering is applied at the source, in the database, not just hidden on screen.
You do. Synaptiik is a technical service provider: it hosts and transmits your files on your behalf. No usage rights are acquired over your images, and they are never resold or used for third-party commercial purposes.
The request is processed within the timeframe set by GDPR. Because data is attached to an organization and a project, it can be located and then deleted, subject to legal retention obligations — invoices, in particular, must be kept for the duration required by law.
No. Every recommendation is presented with its reason and its alternative, no commercial decision is executed without explicit validation, and the assistant can be switched off per account and per portal.
It remains accessible for thirty days after cancellation, giving you time to export your projects, documents, and files. After that period, it is purged according to the retention policy applicable to your account.
Payments are processed by Stripe, our licensed payment provider. Synaptiik never holds funds in an escrow account: they are settled directly to the professional or contractor concerned. A flat 5% service fee applies identically across all relevant services — never presented as a variable commission.
Yes, on the Solo and Studio plans: commercial refund within 14 days monthly, 30 days annually. The Prestataire plan (€29/month) gets 14 days. Agence and Agence Scale, evaluated via demo and pilot before subscribing, are not covered by this window.
Synaptiik has no commitment: cancellation happens from your billing space, with no contractual notice or exit fees. Your data stays accessible for thirty days after cancellation so you can export your projects.
Yes. The Synaptiik blog shows the publish date of every article, updated as the product and regulatory framework evolve — you can check the freshness of the content yourself on /blog. The business guides (/ressources) are also revised when the legal framework changes.
Our team answers any DPO request, security audit, or contractual question. Guaranteed response time: 48 business hours.