This Privacy Policy sets out the basis on which Synapflo Pte. Ltd., a company incorporated in Singapore (UEN: 202548336W) ("Synapflo", "we", "us", or "our"), collects, uses, discloses, and processes personal data in connection with our websites and the provision of our software platforms and related services, including Synapflo CRM, Synapflo Business Operating System, Synapflo ERP, AI Agents, and Customised ERP solutions. This Policy has been developed in accordance with the Personal Data Protection Act 2012 of Singapore (PDPA) and should be read together with our Terms of Service.
When clients subscribe to or use the Platform, Synapflo may process personal data submitted by or on behalf of the client. This may include personal data relating to the client's customers, staff, contractors, or authorised users. Such data may include names, addresses, contact details, company information, job titles, communications content, and other information uploaded or transmitted through the Platform or through correspondence with Synapflo. Synapflo processes such data solely on the documented instructions of the client and does not determine the purposes or lawful bases of processing.
When users access or interact with the Platform, our website, or our clients' websites (through the chatbot SDK), Synapflo may automatically collect limited technical and usage information including Internet Protocol (IP) address, device identifiers and browser type, time zone and approximate location derived from IP, access timestamps and system logs, and interaction and usage metadata necessary for platform operation. This information is used for system security, system administration, and improving platform performance.
Depending on the client's subscription plan, configuration, and enabled features, the Platform may process Synapflo CRM, Synapflo Business Operating System, and Synapflo ERP data — including business contact records, interaction history, communications via integrated channels such as WhatsApp, SMS, email, X, and LinkedIn, profile data relating to communications, message timestamps and delivery or read status, operational and administrative records, workflow records created or uploaded by the client, calendar data, knowledge base data, inventory data, campaign and template data, and billing information and wallet credit data; AI Agent data, including prompts and contextual inputs, knowledge base information, AI-generated outputs, and LLM token usage; and Customised ERP data, meaning data structures and records defined by the client's operational requirements and contractual scope. Synapflo does not access such data except where necessary to provide and support the Platform and related services. Where the Platform processes sensitive personal data, children's data, or other regulated categories of data, such processing occurs solely as determined and controlled by the client.
When individuals visit our websites or submit information through contact forms, Synapflo may collect names, email addresses, IP addresses, cookie identifiers, and usage or analytics information. Synapflo processes such information as a data controller for purposes including responding to enquiries, operating our websites, improving services, analytics, and security.
Synapflo may use cookies and similar technologies to operate and enhance the website, analyse usage patterns, maintain security, and enhance user experience. Users may adjust browser settings to refuse cookies. However, some features of the website or Platform may not function properly if cookies are disabled.
The Platform is a business service and is not intended for use by individuals under the age of 18. Synapflo does not knowingly permit individuals under 18 to register for or directly use the Platform, and clients are responsible for ensuring that their authorised users are at least 18 years of age. Separately, a client may configure the Platform to process personal data relating to that client's own customers or contacts, who may in some cases include minors. Where this occurs, the client acts as data controller and is solely responsible for establishing a lawful basis for that processing, including obtaining parental or guardian consent where required. Synapflo processes such data only on the client's documented instructions and does not itself knowingly collect personal data from children.
Clients are responsible for ensuring that all personal data uploaded to or processed through the Platform has been lawfully collected and that all necessary notices, permissions, and consents have been obtained where required under applicable law. Where clients process personal data relating to their customers, employees, or other individuals through the Platform, the client acts as the data controller and Synapflo acts as a data processor. Synapflo does not independently verify the legality of data uploaded by clients and shall not be responsible for unlawful or unauthorised data processing conducted by clients through the Platform.
Synapflo processes personal data for purposes including providing, operating, and maintaining the Platform and related services; administering client accounts and subscriptions; enabling configured workflows, automation, and integrations; providing technical support and responding to enquiries; communicating with clients and responding to support requests; monitoring system performance, security, and reliability; complying with applicable legal and regulatory obligations; responding to legal proceedings or lawful requests; creating, sending, and editing templates and receiving template responses; and presenting context, insight, and updates.
Where AI features are enabled, personal data may be processed to generate outputs, summaries, suggested responses, or insights within the client's Platform environment and for the client's internal use. Where permitted under the applicable data processing agreement, Synapflo may create aggregated and de-identified data from Platform usage and use it solely to operate, secure, and improve the Platform; such data does not identify any client or individual. Synapflo does not use identifiable client data to train general-purpose artificial intelligence or machine learning models. AI-generated outputs are produced automatically based on available inputs and contextual information and may not always be accurate, complete, or appropriate for all circumstances. Clients are responsible for reviewing and validating AI-generated outputs before relying on them, and Synapflo does not guarantee the accuracy or reliability of any AI-generated outputs produced by the Platform.
Where Synapflo acts as a data controller, personal data is processed only where a lawful basis exists, including where processing is necessary to provide services requested by the user or to perform a contract with the client, where processing is necessary for Synapflo's legitimate interests in operating, maintaining, and improving the Platform, where processing is necessary to comply with legal or regulatory obligations, or where the individual has provided consent where required under applicable law.
The Platform may rely on trusted third-party providers to operate and deliver services, including cloud infrastructure providers, messaging platforms, artificial intelligence service providers, payment processors, and other technical service providers supporting the Platform. These third parties operate under their own terms and privacy policies, and Synapflo does not control their independent data practices. Clients are responsible for ensuring they have appropriate permissions to enable integrations with third-party platforms.
Synapflo treats personal data as confidential. Personal data may be disclosed on a limited, need-to-know basis to Synapflo employees and authorised contractors subject to confidentiality obligations; cloud infrastructure, messaging, and AI service providers supporting the Platform; professional advisers such as auditors, accountants, or legal advisers; regulatory or governmental authorities where required by law; and parties involved in corporate transactions such as mergers or acquisitions. Synapflo does not sell personal data or disclose personal data for advertising purposes, and no Google Workspace data is ever used to train general-purpose AI or ML models. Synapflo requires third-party service providers to process personal data only in accordance with contractual obligations and applicable data protection laws.
Personal data processed through the Platform may be transferred to and processed in jurisdictions outside the country where the data originated, including where Synapflo's infrastructure or service providers operate. Synapflo takes reasonable steps to ensure such transfers are conducted in accordance with applicable data protection laws.
Synapflo retains personal data only for as long as necessary to provide the Platform and comply with applicable legal obligations. Unless otherwise agreed in writing, WhatsApp message content and related metadata may be retained for up to six (6) months, thereafter only summaries or limited metadata may be retained. Upon termination of a subscription or expiration of a free trial, Synapflo may delete client data following the end of the applicable subscription or trial period, subject to any legal retention obligations. API data is retained only for as long as required to provide the requested functionality, and when no longer required, data is securely deleted or anonymised. Clients may request deletion of their data by contacting contact@synapflo.com, and Synapflo will respond and process such requests within 30 days. Following termination or expiry, client data remains available for export for thirty (30) days as set out in the Terms of Service, after which it is deleted, subject to legal retention obligations and routine backup cycles.
Synapflo implements administrative, technical, and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration. Security safeguards include restricted access to authorised personnel under confidentiality obligations, secure cloud infrastructure operated by trusted service providers (which may be located worldwide), and periodic operational and security reviews. While Synapflo implements reasonable safeguards, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure, and absolute security cannot be guaranteed.
Synapflo maintains procedures for identifying, assessing, containing, and responding to data breaches. Where Synapflo acts as a data intermediary (processor) and a breach affects personal data it processes on behalf of a client, Synapflo will notify the affected client without undue delay, and in any event within 48 hours of becoming aware of the breach, including — to the extent then known — the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed to mitigate its effects; where full information is not available within that period, Synapflo will provide information in stages as it becomes available. As data controller, the client is responsible for assessing whether the breach is notifiable under applicable law and for making any required notifications to the Personal Data Protection Commission, other regulators, or affected individuals, and Synapflo will provide reasonable assistance in doing so. Where Synapflo acts as a data controller — in respect of website, enquiry, and client account data — Synapflo will assess any breach expeditiously and, where notifiable under Part 6A of the PDPA, notify the Personal Data Protection Commission as soon as practicable and no later than three (3) calendar days after completing that assessment, and notify affected individuals where required. If you believe a data breach or security vulnerability affecting the Platform has occurred, please contact contact@synapflo.com without delay. Notification of a breach under this section is not, and shall not be construed as, an acknowledgement of fault or liability on the part of Synapflo.
Where paid services are offered in connection with the Platform, payment processing is handled by third-party payment service providers such as Stripe. Synapflo does not store payment card details. Payment information is processed directly by the payment provider in accordance with its privacy policies and security standards, including the Payment Card Industry Data Security Standard (PCI DSS).
Where Synapflo acts as a data processor, clients are responsible for responding to data subject requests including requests for access, correction, or deletion, and Synapflo will provide reasonable assistance to clients in fulfilling such requests where required under applicable law. Where Synapflo acts as a data controller for personal data it controls — website visitors, enquiries, and client account contacts — you may request access to your personal data and information about how it was used or disclosed in the past year, request correction of an error or omission, or withdraw your consent on reasonable notice by emailing contact@synapflo.com. Synapflo will respond as soon as reasonably possible and will tell you when to expect a response if it cannot reply within 30 days. A reasonable fee may apply to access requests, and Synapflo may decline a request where a PDPA exception applies, and will tell you if it does.
Synapflo may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. Continued use of the Platform following any updates constitutes acceptance of the revised Privacy Policy.
For questions regarding this Privacy Policy or Synapflo's data processing practices, please contact our Data Protection Officer, Synapflo Pte. Ltd., at contact@synapflo.com.
Questions about this policy?
contact@synapflo.com