Legal

Privacy Policy

A clear account of the personal data Synconix uses to provide, secure and support its website, client area and SHM, SDM and SBM products.

Effective
Last updated

1.Scope and controller

This Privacy Policy explains how SYNCONIX SOFT SRL (“Synconix”, “we”, “us” or “our”) processes personal data when you visit our website, use the client area, obtain or operate SHM Hosting Manager, SDM DNS Manager or SBM Backup Manager, contact support, make a payment, or participate in the Synconix blog or forum.

For those activities, the controller is SYNCONIX SOFT SRL, VAT number RO43512578, registered under J2021000005127, with its registered office at Popești 174M, Baciu, Cluj 407058, Romania.

This Policy does not govern an independent third-party service that a customer chooses to connect to a Synconix product. That provider’s privacy terms apply to its own processing. It also does not make Synconix the controller of all data stored on customer-managed servers merely because a locally installed product can administer those systems.

Privacy requests can be sent to support@synconix.com. We have not designated this address as a statutory data protection officer; it is the monitored contact for privacy and security requests.

2.Personal data we process

The data depends on how you interact with Synconix. We collect information directly from you, from an organisation that invites you to its team, from a licensed installation, from your browser or device, and from payment or operational providers involved in a request you initiate.

  • Identity and contact data: name, email address, public forum nickname, company, role, telephone number where provided, address, country and team membership.
  • Account and security data: password-derived authentication records, email verification, two-factor configuration, recovery events, permissions, trusted-device identifier, browser and platform details, login IP address, last-login data and security audit events.
  • Commercial data: product and licence selections, orders, billing cycle, company and Tax ID details, invoices, VAT, payment status, provider transaction references, refunds and Enterprise contract or usage details.
  • Contract evidence: the legal-document version and cryptographic hash presented, the declarations accepted at registration and checkout, server-recorded date and time, minimised IP and browser hashes, order linkage, and online withdrawal statements and receipt-delivery status.
  • Licence and operational data: licence and product identifiers, machine or server identity, registered and observed IP addresses, operating system, product version and release channel, activation, heartbeat, validation, binding and attestation state, and the capacity or usage counters described below.
  • Support and remote-management data: tickets, replies, attachments, selected licence context, diagnostics, logs, actions and temporary access information that you choose to provide through an approved workflow.
  • Community and editorial data: blog submissions, topics, replies, reactions, attachments, moderation status, publishing and approval details, and reports about content.
  • Website and communications data: pages or endpoints requested, timestamps, technical error and security logs, messages sent through our forms, and records of service, legal and transactional communications.
Please do not place passwords, private keys, unrestricted root credentials, payment card details or unrelated sensitive personal data in tickets, forum posts or free-text forms.

3.SHM, SDM and SBM licence telemetry

A licensed installation sends limited operational information to activate, validate and secure the licence, display its status in the client area, investigate binding changes and calculate contracted usage. This is not intended to copy website content, DNS record content or backup payloads from customer infrastructure.

Licence telemetry by product
Applies toOperational dataWhy it is needed
All productsLicence, product and machine/server identifiers; public IP; operating system; version and channel; activation and heartbeat time; validation, binding, attestation and security state.Provisioning, licence enforcement, fraud prevention, compatibility, troubleshooting and account visibility.
SHM Hosting ManagerAggregate hosting-account capacity or usage associated with the licensed installation.Apply the purchased account option and calculate Enterprise usage where contracted.
SDM DNS ManagerAggregate user and DNS-zone capacity or usage associated with the licensed installation.Apply the purchased account option and calculate Enterprise usage where contracted.
SBM Backup ManagerAggregate managed-server, storage-server, job or capacity usage associated with the licensed installation.Apply the purchased account option and calculate Enterprise usage where contracted.

4.Purposes and legal bases

Under the GDPR, we rely on the legal basis appropriate to each purpose. Where more than one basis is shown, the basis used depends on the circumstances and your relationship with Synconix.

Purposes and legal bases for personal data processing
ActivityPurposeGDPR legal basis
Account, team and authenticationCreate and administer accounts, verify identity and email, provide permissions, maintain sessions, trusted devices and account recovery.Performance of a contract; legitimate interests in secure account administration.
Orders, licences and productsQuote, provision and operate SHM, SDM and SBM; validate licences; provide product status and enforce purchased capacity.Performance of a contract; legitimate interests in preventing misuse and protecting the licensing service.
Billing, payment and taxGenerate invoices, collect and reconcile payments, calculate VAT, prevent fraud, process refunds and maintain accounting records.Performance of a contract; compliance with legal obligations; legitimate interests in financial control and fraud prevention.
Enterprise daily usageMeasure contracted daily usage, present usage history, calculate monthly charges and resolve disputes.Performance of a contract; legitimate interests in accurate and auditable billing.
Support and authorised remote managementRespond to requests, diagnose incidents and perform specifically authorised actions.Performance of a contract; legitimate interests in support and service security; customer instructions where Synconix acts as processor.
Website, security and service logsDeliver pages and APIs, detect abuse, investigate errors, protect users and preserve evidence of security events.Legitimate interests in availability, security and defence of legal claims; compliance with legal obligations where applicable.
Blog, forum and moderationPublish requested content, operate community features, enforce rules, handle reports and protect the community.Performance of the service requested; legitimate interests in editorial and community administration; legal obligations for valid notices.
Service, legal and transactional messagesSend verification codes, security alerts, invoices, support replies, material service notices and required legal communications.Performance of a contract; compliance with legal obligations; legitimate interests in operating and securing the Services.
We do not currently use website data for behavioural advertising. If optional marketing communications are introduced, the message and account settings will provide the legally required choice and unsubscribe method.

5.When providing data is required

Identity, verified email, authentication information and the technical data necessary to create a secure account are required to provide the client area. Product, server identity and validation data are required to issue and maintain a licence. Billing identity, address, country and Tax ID information are required where applicable to invoice an order lawfully.

If required information is not provided or cannot be verified, we may be unable to create the account, accept the order, activate the licence, process the payment or respond to a rights request. Optional profile fields and public community participation are not required to buy a licence.

6.Controller and processor roles

Synconix is a controller for its website, customer accounts, licensing, security, billing, support administration, blog and forum. The customer is generally the controller of personal data in the hosting accounts, DNS systems, backups and other infrastructure it manages.

A Synconix product running on customer infrastructure does not by itself transfer the content of that infrastructure to Synconix. If a customer expressly authorises remote management or sends logs or data for support, Synconix may process that material on the customer’s documented instructions. The applicable order or data processing terms must define the subject, duration, data, security and deletion obligations where the GDPR requires a processor agreement.

Customers must give their own users and end customers appropriate privacy notices and must not instruct Synconix to process personal data unlawfully. Synconix may process limited account, security and billing data as an independent controller even when it also performs a customer instruction as processor.

7.Payments and wallets

Payment methods are delivered through the configured Revolut payment integration. When you initiate card payment, Revolut Pay, Apple Pay or Google Pay, the selected provider receives the information needed to authenticate and complete the transaction. Wallet availability depends on the browser, device, region and wallet account.

Full card numbers and card security codes are entered in provider-controlled payment fields. The Synconix application uses order, amount, currency, payer contact, payment status and transaction references returned for reconciliation; it is not designed to store the full card number or security code.

The payment provider may process device, fraud-prevention, wallet and transaction data as an independent controller under its own policy. We load a payment provider only in connection with a payment flow you request, not for advertising measurement.

8.Recipients and disclosures

We disclose personal data only where necessary for the purposes above, under appropriate contractual, confidentiality and security controls. Categories of recipients may include infrastructure and hosting providers, transactional email providers, payment providers, professional advisers, auditors and public authorities with lawful authority.

Authorised team members can see customer information according to their permissions. Public blog and forum content can be seen by other users and may be indexed by search engines. Moderators can access content and reports needed to administer those features.

We may disclose data during a merger, financing, reorganisation or sale of relevant assets, subject to confidentiality and notice where required. We may also preserve or disclose data to comply with law, protect rights and security, investigate abuse or establish, exercise or defend legal claims.

Synconix does not sell personal data and does not share website visitors’ data for cross-site behavioural advertising. A customer-selected integration is not automatically a Synconix subprocesser merely because the product can connect to it.

9.International transfers

We aim to use European Economic Area processing where appropriate. A payment, email, infrastructure or support provider may nevertheless process data in another country. Where GDPR Chapter V applies, Synconix will use an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism, together with supplementary safeguards where needed.

The country and legal role of a customer-selected third-party service are controlled by that customer. Contact us if you need information about the safeguards relevant to a specific Synconix processing activity.

10.Retention

We retain personal data only for as long as reasonably necessary for the purpose collected. Because the relevant period depends on the record and legal context, we use the criteria below rather than claiming one period for every category.

Personal data retention criteria
DataRetention criteria
Account and team recordsFor the active account and a limited period afterwards needed for closure, recovery, disputes, security and legal claims.
Orders, invoices, VAT and paymentsFor the statutory accounting, tax, anti-fraud and limitation periods that apply to the transaction.
Licence, validation and Enterprise usageFor the licence term and afterwards as needed to verify entitlement, prevent repeat trial abuse, reconcile billing, resolve binding history and defend claims.
Authentication and security logsFor a proportionate period based on security risk, investigation needs and account state; longer where an incident or legal hold requires it.
Support and remote-management recordsFor the request lifecycle and a period afterwards needed for service history, accountability, disputes and security. Temporary access should be revoked when the task ends.
Blog and forum contentWhile published or needed for moderation and community integrity; deletion may be restricted where preservation is legally required or replies would otherwise lose necessary context.
Deletion from an active system may not immediately remove data from encrypted, access-controlled backups. Backup copies are isolated from ordinary use and expire through the applicable backup cycle unless preservation is legally required.

11.Security

We use technical and organisational measures proportionate to the data and risk, including access controls, role permissions, email verification, optional multi-factor authentication, trusted-device management, secure cookie attributes, encryption in transit, logging, monitoring and controlled administrative access.

No internet service can guarantee absolute security. Protect your credentials, enable an appropriate second factor, review trusted devices and team access, secure customer-managed servers and report suspected compromise promptly. Do not send secrets through public or ordinary free-text channels.

If a personal data breach creates a notification duty, we will notify the competent authority and affected persons within the periods and with the information required by applicable law.

12.Your data protection rights

Subject to the conditions in applicable law, you may request access, correction, erasure, restriction, portability or a copy of your personal data; object to processing based on legitimate interests or direct marketing; and withdraw consent without affecting earlier lawful processing. You may also request human review of a significant decision made solely by automated means where that right applies.

Send a request from your account email where possible and describe the account or activity concerned. We may request proportionate identity verification and may need to preserve information that remains subject to a legal obligation or overriding lawful ground. We normally respond within one month, with a permitted extension for a complex or numerous request and notice of the reason.

You may complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), through its complaint form, or to another competent supervisory authority. We encourage you to contact us first so we can investigate, but doing so is not required.

13.Automated controls and assisted features

Automated controls may validate licences, detect unusual authentication or payment activity, calculate contracted Enterprise usage, enforce a purchased capacity or temporarily restrict a request presenting a security risk. These controls use the operational data described above. Contact support if you believe a result is incorrect and want it reviewed.

An assisted feature may process a prompt, selected diagnostic context or configuration information only when the feature is invoked. Review any generated suggestion before applying it. Do not submit secrets or unrelated personal data, and consult the feature-specific notice or order if an external model provider is used.

14.Cookies, local storage and children

Our current use of cookies and browser storage—including authentication, trusted devices, theme, documentation layout and Enterprise request drafts—is documented in Cookie Settings. We do not currently use analytics or advertising cookies on the website.

The Services are intended for people who can lawfully enter into an account or act for a customer and are not directed to children. Do not create an account or submit personal data if you are under 18 unless a parent or legal guardian has authorised the activity and applicable law permits it. Contact us if you believe a child has provided data improperly.

15.Changes and contact

We may update this Policy to reflect legal, technical or service changes. The effective date and last-updated date appear at the top. We will provide additional notice through the website, client area or account email where a change materially affects how we process existing personal data or where law requires it.

For a privacy request or question, contact support@synconix.com and include enough information to identify the relevant account or interaction without sending passwords or sensitive credentials.

Contract-acceptance and withdrawal evidence is used to form and administer the contract, meet consumer and e-commerce duties, establish or defend legal claims, prevent abuse and demonstrate that required information and confirmations were delivered. Access is limited to personnel who need it for legal, billing, support or security work.

SYNCONIX SOFT SRL
Registered office: Popești 174M, Baciu, Cluj 407058, Romania
Trade Register: J2021000005127
EUID: ROONRC.J2021000005127
VAT number: RO43512578