Who does what
Your business is the controller of your users’ personal data. Aerosol is your processor: we handle that data only on your instructions, which are your configuration of Synq and your calls to its API, and only to run Synq for you.
What we process
- Identifiers: email addresses, names, usernames, profile details and the metadata you add.
- Credentials: password hashes, and the accounts and wallet addresses people sign in with.
- Activity: sessions, sign-in history, and audit records with IP addresses and browser details.
We process it to sign your users in, keep their accounts secure, and give you the features you use.
What we commit to
- Only the people who run Synq can reach your data, and they are bound to keep it confidential.
- We protect it with the measures on our security page.
- We use only the subprocessors we list, and we tell you before we add one that handles personal data.
- We help you answer your users’ requests to see, correct, export or delete their data.
- We tell you without undue delay if we learn of a breach affecting your data.
- When you leave, we delete your data, 30 days after you delete your org.
A signed agreement
We sign a data processing agreement with every business before its users’ personal data reaches Synq. Ask for ours at support@synq.build. The signed agreement is the binding text; this page summarises it.