Légal
Privacy Policy
1. Data controller
The data controller of personal data collected via the SynkriaOps Service is SynkriaOps SARL, hereinafter "the Publisher".
Dedicated data protection contact: [email protected]
2. Data collected
As part of the Service usage, the Publisher collects and processes the following categories of data:
2.1 User identification data
- Email, last name, first name (entered at sign-up);
- Password (bcrypt-hashed, the Publisher never has access to the password in clear text);
- Language preferences and timezone.
2.2 Usage data
- IP address, user-agent, connection date and time (legal audit trail);
- Active sessions (
active_sessionstable); - Audit logs of sensitive actions (creation/modification of vouchers, validation, closing).
2.3 Business data (Tenant)
- Legal name, NIU, CEMAC country, postal address of the Tenant;
- Counterparties (clients, suppliers, employees) entered by the User;
- Accounting data (vouchers, entries, amounts) entered or imported;
- Imported documents (PDF invoices, bank statements, Mobile Money exports).
3. Processing purposes
- Service provision (contract execution);
- Security and fraud prevention (legitimate interest);
- Compliance with legal accounting obligations (10 years SYSCOHADA art. 24);
- Service improvement via anonymized analysis (legitimate interest);
- Transactional communication (confirmation emails, notifications);
- Direct marketing only with explicit consent (opt-in newsletter).
4. Legal basis
Processing is based, depending on cases, on:
- Performance of the contract between User and Publisher (art. 6.1.b GDPR);
- Legal obligation (accounting retention, anti-money-laundering, art. 6.1.c GDPR);
- Legitimate interest of the Publisher (security, Service improvement, art. 6.1.f GDPR);
- User consent for optional uses (newsletter, non-essential analytical cookies, art. 6.1.a GDPR).
5. Retention period
- Active account data: as long as the account is active.
- Terminated account: 90 days then deletion (except legal obligations).
- Accounting data: 10 years from fiscal year closing (SYSCOHADA art. 24).
- Connection logs: 12 months.
- Backups: 35 days (PITR).
6. Subprocessors
The Publisher uses subprocessors to provide the Service. The list and their location are published below and kept up to date:
- Primary host: Hetzner GmbH (Germany, EU), application servers.
- Database: Neon Inc. (United States), EU-US standard contractual clauses.
- CDN & DNS: Cloudflare Inc. (United States), DPA in place.
- Transactional emails: Resend (United States).
- OCR (AI): Anthropic PBC (United States), for tenants having explicitly enabled AI OCR.
- Monitoring: Sentry (United States).
All transfers outside the EU are governed by Standard Contractual Clauses of the European Commission.
7. User rights
In accordance with GDPR, the User has the following rights:
- Right of access to their data;
- Right of rectification;
- Right to erasure ("right to be forgotten"), subject to legal retention obligations;
- Right to restriction of processing;
- Right to data portability (complete Tenant export in Excel + JSON format);
- Right to object to processing;
- Right to withdraw consent at any time;
- Right to lodge a complaint with a supervisory authority.
To exercise these rights: [email protected]. A response will
be provided within a maximum of 30 days.
8. Security
The Publisher implements the following measures:
- TLS 1.3 minimum encryption for all transfers;
- Hashed passwords (bcrypt 12 rounds);
- 15-minute JWT expiration + 30-day refresh token in HttpOnly cookie;
- Strict multi-tenant via PostgreSQL Row Level Security;
- Generalized audit trail on sensitive modules;
- Automated security scans (Trivy, CodeQL) on every deployment;
- Annual penetration tests (planned);
-
Responsible disclosure program:
[email protected]
9. Cookies
For details on cookies used, see the Cookie Policy.
10. Modifications
Any substantial modification of this Policy will be notified by email at least 30 days before its entry into force.