Legal
Privacy Policy
Last updated: July 29, 2026
1. Introduction
SYNCORS NEXUS (PRIVATE) LIMITED ("Syncors", "we", "us", or "our") operates a white-label CRM platform for marketing agencies. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our platform ("the Service"). We are committed to protecting your privacy and complying with applicable data-protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Data Controller & Processor
Syncors acts as a data processor for personal data stored within client workspaces (e.g. your contacts, leads, and customer communications). You, as the agency using the Service, act as the data controller for that data. Syncors acts as a data controller for the personal data we collect directly from you (e.g. account information and billing data).
3. Information We Collect
We collect the following types of information:
- Account data: Name, email address, phone number, company name, and industry — provided during registration.
- Billing data: Payment details processed by our payment processor (Paddle). We do not store full card numbers on our servers.
- Usage data: IP address, approximate location (country), browser type, device information, and interaction logs.
- Workspace data: Contacts, leads, messages, pipelines, and other data you and your team enter into client workspaces.
4. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service;
- Process subscription payments and manage billing;
- Display pricing in your local currency based on your approximate location;
- Communicate with you about your account, updates, and support;
- Provide AI-assisted features (text and analytics only) that you invoke;
- Monitor usage to detect and prevent fraud or abuse;
- Comply with legal obligations.
5. Legal Basis for Processing (GDPR)
Under the GDPR, we process personal data on the following legal bases:
- Performance of a contract: Processing necessary to deliver the Service under our Terms.
- Legitimate interests: Service improvement, security, and fraud prevention.
- Legal obligation: Compliance with applicable laws.
- Consent: Where you have provided explicit consent for specific activities.
6. Data Sharing & Sub-Processors
We do not sell your personal data. We share data with the following categories of service providers who help us operate the Service:
- Payment processing: Paddle — our Merchant of Record for billing and tax.
- Messaging & social platforms: Meta (WhatsApp Business, Instagram, Messenger, Threads, and Ads), and email/SMS gateways used to deliver messages you send through the Service.
- AI model providers: OpenAI — used to generate the text and analytics outputs of our AI features. Your data is not used to train their models.
- Cloud infrastructure: Hosting providers that store and process your data.
- Analytics: Tools that help us understand platform usage and improve the Service.
All sub-processors are bound by data-processing agreements requiring them to protect your data in accordance with applicable law.
7. Data Retention
We retain your data while your account is active. After account termination, we retain workspace data for 30 days to allow recovery, after which it is permanently deleted. Account and billing records may be retained longer where required by law (e.g. tax compliance). You can request deletion at any time via our Data Deletion page.
8. Data Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, regular reviews, and monitoring. No system is 100% secure; we will notify you of any breach affecting your personal data as required by law.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (subject to legal exceptions).
- Restriction: Request that we limit processing of your data.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdrawal of consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@syncors.com.
10. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) where required.
11. Cookies
We use essential cookies for authentication and security, and may use analytics cookies to understand usage. For full details and how to control them, see our Cookie Policy.
12. Children’s Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days before they take effect. The "Last updated" date above reflects the most recent revision.
14. Contact
Questions about this Privacy Policy or your data? Contact SYNCORS NEXUS (PRIVATE) LIMITED at privacy@syncors.com.