GDPR Compliance Center

Comprehensive checklist and resources to ensure your use of Synthesis AI meets all GDPR requirements for BYOK (Bring Your Own Key) services.

100%
Compliant

Your GDPR Compliance Status

Synthesis AI is fully GDPR compliant. Complete the checklist below to ensure your implementation meets all requirements.

GDPR Compliance Checklist for BYOK

📄 Legal Documentation

Privacy Policy Updated

Your privacy policy mentions API key processing and data flows

View our Privacy Policy →

Data Processing Agreement

DPA signed and includes third-party AI provider references

Access DPA →

Legal Basis Documented

Clear legal basis for processing (contract, legitimate interest, consent)

Consent Management

Explicit Consent for API Keys

Users explicitly consent before connecting API keys

Easy Consent Withdrawal

Users can revoke consent with one click

Consent Records Maintained

Timestamp and details of consent are logged

🔒 Technical Security

API Keys Encrypted

AES-256 encryption for stored API keys

View Security Details →

No Server Storage

API keys stored only in user's browser

Session Management

Automatic logout and key deletion after inactivity

Access Logging

Audit trail of all API key access

👤 Data Subject Rights

Right to Access

Users can view all stored data

Access Dashboard →

Right to Erasure

One-click deletion of all data

Right to Data Portability

Export all data in machine-readable format

30-Day Response Time

Respond to data requests within 30 days

🤝 Third-Party Management

AI Provider Terms Reviewed

Users understand they maintain direct relationships with AI providers

Sub-Processor List

Clear list of all sub-processors used

Liability Clarification

Clear statement that we're not liable for AI provider practices

🍪 Cookie & Storage Compliance

Cookie Consent Banner

Granular consent options for different cookie types

Local Storage Notice

Clear notice about browser storage use

Cookie Policy

Detailed cookie policy available

🚨 Breach & Incident Response

Breach Notification Procedure

72-hour notification process in place

Incident Response Plan

Documented plan for security incidents

Breach Register

Maintain register of any data breaches

🔄 Regular Reviews

Annual Security Review

Regular security assessments scheduled

Privacy Policy Updates

Regular review and updates of privacy documentation

Staff Training

Regular GDPR training for all staff

Take Action

Ensure your BYOK implementation is fully GDPR compliant

🔑 Test API Security 👤 Manage Data Rights

GDPR Resources