Privacy Policy

Last updated: 3 September 2026

1. Who we are

Syniaps ("the Service") is an artificial intelligence assistant for businesses, published by Syniaps (website: www.syniaps.fr). Syniaps is the controller of the data described in this policy. For any question: [email protected].

This policy covers the Syniaps service. The agency's showcase website has its own privacy policy.

2. Data we process

As part of the service, we process:

  • Account data: name, professional email address, role in the workspace, authentication settings (strong authentication is mandatory).
  • Content of your workspace: the documents you import or choose to synchronize from your cloud services, as well as the knowledge base the Service builds from these documents for your company only.
  • Conversations with the assistant: your requests and the assistant's answers, kept in your history.
  • Billing data: handled by our payment provider Stripe; we do not store any card numbers.
  • Technical logs: events necessary for the security and proper operation of the service (audit of sensitive actions, errors, storage usage measurements).

3. Cloud services you connect

You can connect third-party services to the Service via the OAuth protocol, with your explicit consent for each connection: Google Drive and Gmail, Microsoft OneDrive/SharePoint and Outlook, Dropbox. Each connection serves only the features you enable:

  • Storage (Drive, OneDrive, Dropbox): synchronize the folders you select to your workspace, and send back to it the files added or updated in the Service. The Service never deletes files in your cloud.
  • Email (Gmail, Outlook): read your messages to prepare the summaries you request, and send messages on your behalf only on your instruction.

The credentials and tokens you entrust to the Service (site passwords, access tokens, API keys, session cookies) are encrypted at rest on our servers, in restricted-access files, never in a database. They are never displayed back to you and are used solely to open a connection on your behalf when you ask the Service to act. You can revoke a connection at any time from the Connections page of the Service or from the security settings of the provider concerned; we then also revoke the token with the provider where the provider allows it.

4. Data from Google APIs (Limited Use)

Syniaps' use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. In particular:

  • Google data (Drive files, Gmail messages) is used only to provide the visible features you have enabled: synchronization of the folders you choose, summaries and email actions you request;
  • it is never sold and is never used for advertising purposes;
  • no human reads it, except with your explicit consent, where necessary for security purposes (investigating abuse), to comply with the law, or as part of a support request you initiate;
  • it is never used to create, train or improve generalized artificial intelligence models, neither by us nor by our providers: it is not transmitted to any third-party AI service that would use it to train its models.

Explicit statement (in the language of the original policy): "The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements."

5. Artificial intelligence

The requests you send to the assistant, as well as the documents needed to answer them, are processed by the AI model provider connected to your account. By default this is Anthropic: via its API, under its commercial terms, your data is not used to train its models; via a personal Claude Pro or Max subscription, Anthropic may use it while the account’s “Help improve Claude” setting is on, a setting we ask you to turn off before connecting. If your company enables the advanced OCR option, the transcription of scanned documents is performed by Mistral AI, via its API, under the same conditions. If you choose to connect an alternative provider (OpenAI, Google or Moonshot AI), your requests are processed by that provider under its own terms, which the interface reminds you of when you connect and which you accept explicitly: a business account generally excludes training on your data; an individual account may, depending on the provider, allow the use of your exchanges to improve its products and models unless you turn that off in that account's settings, which we ask you to do before connecting (the interface shows you where); Moonshot AI (Kimi) offers no such setting, the refusal is requested in writing from its customer service. In all cases, no data from the Google Workspace APIs is transmitted to an AI service that would use it to create, train or improve its models.

6. Processors and transfers

We use the following providers, each for a specific function:

  • Anthropic (processing of requests by the AI model, default provider);
  • OpenAI (real-time voice conversation when you use voice; ChatGPT models only if you connect a ChatGPT account, at your choice);
  • Google (Gemini models, only if you connect a Google account, at your choice);
  • Moonshot AI (Kimi models, only if you connect a Kimi account, at your choice; established outside the European Union);
  • Mistral AI (OCR transcription, if the option is enabled);
  • Stripe (payment and billing);
  • Resend (sending of the service's transactional emails);
  • Cloudflare (delivery, protection and network access control);
  • OVHcloud (hosting of encrypted backups, on servers located in France);
  • our hosting provider, on private servers dedicated to the service, located in France.

Your data and its backups are hosted in France. Some providers may process data outside the European Union (notably in the United States, for processing by the AI model, payment or the sending of emails; and, if you connect Kimi, at Moonshot AI, outside the European Union); these transfers are governed by the mechanisms provided for by the GDPR (the "Data Privacy Framework" adequacy decision or standard contractual clauses) or, for an alternative AI provider you choose to connect, fall under your responsibility as data controller, as provided in the Terms of Use.

7. Retention

Your data is kept as long as your account is active. In the event of termination, access is cut off at the end of the paid period and the company's data is deleted within the following 30 days. Files removed by cloud synchronization are kept for 30 days in an internal recycle bin before permanent deletion. Encrypted backups, hosted in France, expire on their own by rotation within a maximum of six months after this deletion; their decryption key is never stored with them and they are only restored when genuinely needed. You can request early deletion of your account at any time.

8. Security and hosting

Your data and its backups are hosted in France. Exchanges are encrypted in transit (TLS). Each customer company has its own server, dedicated to it alone and hosted in France: no other customer company is hosted on it. Within the company, each user works in an environment isolated at system level. The secrets you entrust to us (site passwords, access tokens, API keys, session cookies) are encrypted at rest, in restricted-access files on servers that are not publicly exposed, never in a database; the decryption key is kept separately from those files. Access to the service requires strong authentication. Sensitive actions are logged.

An encrypted backup of your data is made every night and kept off the server, in France, with a French hosting provider (OVHcloud). Backups are encrypted before being sent and the decryption key is never stored with them: a backup copy, even if stolen, remains unreadable.

To speed up the setup of connections to third-party sites, Syniaps shares anonymized technical connection recipes between its instances (address of the login page and form markers); they never contain any username, password, cookie or any data that could identify a customer or a user.

For the purposes of operating the service and improving its integration catalog, the domain name of the sites you connect and the name of the third-party services you plug in are also reported, with the account identity, to our internal supervision console; never your credentials, cookies or keys, nor any secret value.

9. Your rights

In accordance with the GDPR, you have rights of access, rectification, erasure, portability, objection and restriction over your personal data. To exercise them, write to [email protected]. You may also lodge a complaint with the CNIL (www.cnil.fr).

10. Changes to this policy

We may update this policy to reflect changes in the service or in regulations. The date of the last update appears at the top of the page; in the event of a substantial change, workspace administrators are notified by email.

Privacy policy of the Syniaps service