Privacy Policy
This Draft Privacy Policy explains how [Syntropy AI Global LLC] ("Syntropy AI Global", "we", "us", or "our") collects, uses, processes, and protects personal data when you visit our website, use our B2B software accounts, or when our retail and enterprise customers process data inside our software products.
1. Who We Are, Contact Details & Controller vs. Processor Roles
We are [Syntropy AI Global LLC]. When you browse our website or manage your billing account with us, we act as a "data controller" (we decide how that data is used). When our business customers use our Lottery, POS, or CRM software to manage their own store employees or leads, our customer is the "controller" and we act strictly as a "data processor" following their instructions.
[Syntropy AI Global LLC] is a business-to-business (B2B) software company with registered offices at [100 Enterprise Way, Suite 400, City, State, ZIP, Country]. For all privacy-related inquiries, data subject requests, or Data Protection Officer (DPO) communications, please contact us at privacy@[yourdomain.com].
Under the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and comparable global privacy laws, our legal role depends on the context of the interaction:
- Syntropy AI Global as Data Controller ("Business"): We act as the data controller for personal information collected from visitors to [yourdomain.com], individuals who submit our "Book a demo" or contact forms, job applicants, and administrative/billing contacts of our B2B customers.
- Syntropy AI Global as Data Processor ("Service Provider"): When an enterprise or licensed retail customer deploys our Lottery Sales & Inventory Management, Enterprise CRM, POS Systems, or Custom Software, any personal data uploaded or ingested into their workspace ("Customer Data") is controlled by that customer. We process Customer Data solely on the customer’s documented instructions pursuant to our Data Processing Agreement (DPA).
2. Data We Collect (Website Visitors, Account Users & Customer Data)
We collect three distinct buckets of data: (1) basic contact and browsing info when you visit our marketing site or book a demo, (2) login and audit logs when you sign into our software, and (3) operational retail/CRM records that our customers process inside their own workspaces.
We practice data minimization and separate the information we collect into three clear operational categories:
- A. Website Visitors & Marketing Prospects: When you submit a form on [yourdomain.com], we collect your full name, work email address, company name, company size, product interests, country, and message content. With your explicit cookie consent, we also collect aggregate analytics data (IP address, browser type, device OS, referring URL, and pages viewed).
- B. Account Users & Store Personnel: When authorized users sign into our Web, iOS, Android, Windows, or macOS applications at [https://app.yourdomain.com], we collect authentication credentials, Single Sign-On (SSO) identifiers, role permissions, store assignments, device telemetry, and security audit logs (such as login timestamps and IP addresses).
- C. Customer Data Processed in Our Products: On behalf of our customers, our products process operational data including cashier shift scan logs, POS register transaction histories (excluding raw cardholder PAN/CVV data, which is handled by certified payment processors), and CRM contact/lead records captured from Meta Lead Ads, TikTok Lead Generation forms, or customer web forms.
3. Purposes of Processing & GDPR Legal Bases
We only process personal data when we have a valid legal reason—such as fulfilling a software contract with your company, securing our platform against fraud, obeying tax/accounting laws, or acting on your explicit consent for optional marketing.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process personal data where we act as a Data Controller under the following legal bases defined in Article 6 of the GDPR:
| Purpose of Processing | Categories of Data | GDPR Legal Basis (Art. 6) |
|---|---|---|
| Provisioning SaaS accounts, authenticating users, and delivering support | Account User Data, Contact Data, Support Tickets | Performance of a Contract (Art. 6(1)(b)) & Legitimate Interests (Art. 6(1)(f)) |
| Responding to "Book a demo" and sales inquiries | Website Prospect Contact & Company Data | Legitimate Interests in B2B communications (Art. 6(1)(f)) or Pre-contractual steps (Art. 6(1)(b)) |
| Platform security, fraud prevention, and immutable audit logging | IP Addresses, Device Identifiers, Access & Shift Audit Logs | Legitimate Interests in securing multi-tenant systems (Art. 6(1)(f)) & Legal Obligation (Art. 6(1)(c)) |
| Optional website analytics and B2B campaign attribution cookies | Cookie Identifiers, Page View Events, UTM Parameters | Consent (Art. 6(1)(a)) — strictly gated until opted in |
| Billing, tax compliance, and corporate accounting | Billing Contact Data, Invoice History, Order Forms | Legal Obligation (Art. 6(1)(c)) & Performance of a Contract (Art. 6(1)(b)) |
4. AI, Machine Learning & Automated Processing (No Training Without Opt-In)
Our AI features forecast sales, suggest inventory reorders, flag shift anomalies, score CRM leads, and answer SOP questions. We NEVER use your confidential customer data to train shared AI models without your explicit written opt-in, and we never let AI make autonomous legal or employment decisions without a human in the loop.
Syntropy AI Global incorporates applied machine learning features across our product suite, including store-level sales forecasting, smart reorder suggestions, lottery/POS anomaly detection, explainable CRM lead scoring, and an SOP-grounded support assistant.
No Training on Customer Data Without Explicit Opt-In: [Syntropy AI Global LLC] does NOT use Customer Data, CRM contact records, POS transaction logs, or private SOP documents to train foundational or shared multi-tenant machine learning models unless the Customer has executed an explicit, written opt-in addendum.
Human Oversight & No Solely Automated Legal Effects (GDPR Art. 22): Our AI features are decision-support tools designed for human review. Anomaly detection alerts and lead scores always display their underlying factors for human manager verification and are never used to make solely automated decisions producing legal or similarly significant effects on individuals.
6. International Data Transfers & Standard Contractual Clauses (SCCs)
If personal data is transferred across international borders (such as from the EU/UK to the United States), we protect it using legally approved Standard Contractual Clauses (SCCs) and strong encryption.
[Syntropy AI Global LLC] is headquartered in [United States / Country Placeholder] and utilizes cloud infrastructure located in [United States / EU Region Placeholders].
Whenever personal data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred to a country that has not received a formal adequacy decision, we safeguard the transfer using the European Commission’s Standard Contractual Clauses (SCCs — Module Two for Controller-to-Processor and Module Three for Processor-to-Processor), the UK International Data Transfer Addendum, and supplementary technical safeguards including TLS 1.3 encryption in transit and AES-256 encryption at rest.
7. Data Retention Schedules
We keep personal data only as long as needed to provide our software, fulfill customer contracts, or satisfy tax and audit laws, after which it is securely deleted or anonymized.
We retain personal data in accordance with the following lifecycle rules:
- Active Customer Workspace Data: Retained for the duration of the Customer’s active subscription agreement. Upon contract termination or non-renewal, Customer may export their data during a [30-day] transition window, after which production records are deleted within [60 days] and encrypted backups rotate out within [90 days].
- B2B Marketing & Demo Inquiries: Retained for up to [24 months] from the last meaningful interaction, or until you request deletion or opt out.
- Financial, Tax & Security Audit Records: Retained for [7 years] (or the period mandated by applicable tax and corporate accounting laws).
8. Security Controls & Data Protection
We protect your data with TLS 1.2/1.3 encryption in transit, AES-256 encryption at rest (both in the cloud and on offline POS devices), role-based access control, and continuous security monitoring.
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include TLS 1.2/1.3 encryption in transit, AES-256 encryption at rest across cloud databases and local offline caches, Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), SAML 2.0 Single Sign-On, and immutable audit logging. Visit our Security & Trust Center (/security) for full architectural details.
9. Your Privacy Rights (GDPR & CCPA/CPRA) & How to Submit Requests
Depending on where you live, you have the right to access, correct, delete, or export your personal data, or opt out of marketing/analytics sharing. You can exercise any of these rights by emailing privacy@[yourdomain.com] or using our online request form.
We honor applicable data protection rights for individuals under the GDPR, UK GDPR, CCPA/CPRA, and other state or national privacy statutes:
- Right of Access & Know: Request confirmation of whether we process your personal data and receive a copy of the categories and specific pieces of personal information we hold.
- Right to Deletion (Erasure): Request that we delete personal data we have collected from you, subject to statutory legal or accounting retention exceptions.
- Right to Correction (Rectification): Request that we correct inaccurate or incomplete personal information.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON).
- Right to Restrict or Object to Processing: Object to processing based on legitimate interests or direct marketing.
- Right to Opt Out of "Sale" or "Sharing" (CCPA/CPRA): While we never sell personal data for money, you may opt out of optional analytics/marketing cookies at any time via our "Do Not Sell or Share My Personal Information" page (/legal/do-not-sell).
- Non-Discrimination: We will never discriminate against you or degrade software service quality for exercising your privacy rights.
10. How to Submit a Privacy Request & Verification Process
Email privacy@[yourdomain.com] or submit our form on the "Do Not Sell or Share" page. If your data is inside one of our customer’s workspaces, we will forward your request to that customer (the data controller).
To exercise your privacy rights where [Syntropy AI Global LLC] acts as Data Controller, please email privacy@[yourdomain.com] with the subject line "Privacy Rights Request" or complete the interactive form on our Do Not Sell or Share My Personal Information page (/legal/do-not-sell). We will verify your identity using your work email address and respond within [30 days] (under GDPR) or [45 days] (under CCPA/CPRA).
Note for End-Users or Employees of Our Customers: If your personal data was entered into a Syntropy AI Global product by one of our retail or enterprise customers (for example, as a store employee or CRM lead), that customer is the Data Controller. Please direct your request to that organization first, or let us know the organization name so we can promptly forward your request to their administrator.
12. Changes to This Privacy Policy
If we make important updates to this policy, we will update the "Last Updated" date at the top of this page and notify account administrators by email or in-app banner.
We may update this Privacy Policy periodically to reflect new software capabilities, sub-processors, or regulatory requirements. When we make material changes, we will update the Effective Date at the top of this page and notify active customer administrators via email from privacy@[yourdomain.com] or an in-application notice.