Privacy Policy
Last Updated: January 2025
Introduction
Synthos is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, store, and protect information when you interact with our services, website, or team members.
This policy applies to all data processing activities carried out by Synthos in the course of providing AI development services, consulting, and related offerings to organizations in Singapore and the broader region.
What Personal Data We Collect
Personal data refers to information that can identify you as an individual. We collect the following categories of personal data:
Contact Information
- Name and job title
- Email address
- Phone number
- Business address
- Company name and role
Usage Data
- Website browsing patterns and preferences
- Technical information including IP address and browser type
- Interaction with our communications and content
- Time and date of website visits
Project and Communication Data
- Information you provide in inquiries or project discussions
- Details about your organization's needs and challenges
- Feedback and evaluation responses
- Meeting notes and correspondence
How We Collect Personal Data
Directly from you: When you submit contact forms, request information, engage our services, or communicate with us via email or phone.
Automatically: Through cookies and similar technologies when you visit our website. These collect technical and usage information.
From third parties: Occasionally from business referral sources or professional networks, always with appropriate consent.
During service delivery: As part of our AI development work, we may process data you provide for project purposes, though this is typically handled under separate data processing agreements.
Legal Basis for Processing
We process personal data on the following legal grounds under Singapore's Personal Data Protection Act (PDPA):
Consent: You have given clear consent for us to process your personal data for specific purposes.
Contract fulfillment: Processing is necessary to fulfill our contractual obligations when providing services to you.
Legitimate interests: Processing is necessary for legitimate business purposes, such as improving our services, provided this does not override your data protection rights.
Legal obligations: Processing is required to comply with legal or regulatory requirements.
How We Use Personal Data
We use collected data for the following purposes:
- Responding to inquiries and providing information about our services
- Delivering contracted AI development and consulting services
- Communicating project updates, deliverables, and support
- Improving our website functionality and user experience
- Conducting internal analysis to enhance service quality
- Meeting legal and regulatory compliance requirements
- Protecting security and preventing fraud
- With your consent, sending relevant information about our services
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or as required by law:
Active client data: Maintained throughout our business relationship and for six years thereafter for contractual and legal purposes.
Inquiry data: Retained for two years to track communication history and support potential future engagement.
Marketing data: Kept until you withdraw consent or we determine the data is no longer relevant.
Website usage data: Typically retained for up to two years for analytical purposes.
When data is no longer needed, we securely delete or anonymize it to prevent identification.
Data Protection and Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit and at rest
- Access controls limiting data access to authorized personnel only
- Regular security assessments and updates to protection measures
- Secure backup procedures to prevent data loss
- Staff training on data protection responsibilities
- Incident response procedures for potential data breaches
While we take security seriously, no method of transmission or storage is completely secure. We cannot guarantee absolute security but continuously work to maintain strong protection standards.
Your Data Protection Rights
Under Singapore's PDPA and applicable data protection laws, you have the following rights:
Right to access: Request copies of your personal data we hold.
Right to rectification: Request correction of inaccurate or incomplete data.
Right to erasure: Request deletion of your personal data under certain circumstances.
Right to restrict processing: Request limitation of how we use your data.
Right to data portability: Request transfer of your data to another organization.
Right to object: Object to processing based on legitimate interests.
Right to withdraw consent: Withdraw previously given consent at any time.
To exercise any of these rights, contact us at [email protected]. We will respond to requests within one month.
Third-Party Services
We may share data with third-party service providers who assist in operating our business:
Analytics providers: Google Analytics helps us understand website usage patterns. See their privacy policy at https://policies.google.com/privacy
Communication tools: Email and communication platforms for correspondence management.
Hosting services: Website and data hosting infrastructure providers.
Professional service providers: Legal, accounting, and business consulting firms as needed.
All third parties are required to maintain appropriate data protection standards and use data only for specified purposes.
International Data Transfers
Your data is primarily stored and processed in Singapore. If data must be transferred outside Singapore, we ensure adequate safeguards are in place:
- Transfers to countries with adequate data protection standards as recognized by Singapore authorities
- Implementation of standard contractual clauses or other approved transfer mechanisms
- Obtaining your explicit consent where required
- Ensuring recipient organizations maintain appropriate security measures
Cookies and Tracking
Our website uses cookies and similar technologies to enhance functionality and analyze usage. For detailed information about cookies we use and how to manage them, please see our Cookie Policy.
Changes to This Policy
We may update this privacy policy periodically to reflect changes in our practices or legal requirements. When significant changes occur, we will notify you by email or through a notice on our website. The "Last Updated" date at the top indicates when the policy was most recently revised. We encourage you to review this policy regularly to stay informed about how we protect your data.
Contact Information
For questions about this privacy policy or our data practices, or to exercise your data protection rights, please contact:
Email: [email protected]
Phone: +65 6471 3852
Address: 1 Raffles Place, #44-01, One Raffles Place Tower 2, Singapore 048616