Your data rights are our priority. Learn how Synthesis AI complies with the General Data Protection Regulation and protects your personal information.
Industry-standard encryption and security measures protect your data at rest and in transit.
Your data is stored in EU-based data centers with full compliance to data localization requirements.
We commit to notifying authorities and affected users within 72 hours of any data breach.
Synthesis AI acts as the data controller for personal data collected through our services.
Entity | Details |
---|---|
Company Name | MYG Media SRL (operating as Synthesis AI) |
Registration Number | RO50059004 |
Registered Address | Bulevardul GEORGE ENESCU, Nr. 23, Bloc G45, Scara B, Ap. 6, Judet Suceava, Romania |
Data Protection Officer | dpo@synthesis-ai.com |
Representative in EU | Not required (established in EU - Romania) |
Under the GDPR, you have the following rights regarding your personal data:
Request a copy of your personal data we hold
Correct any inaccurate or incomplete data
Request deletion of your personal data
Limit how we process your data
Receive your data in a machine-readable format
Object to certain types of processing
How to Exercise Your Rights: You can exercise any of these rights by contacting our Data Protection Officer at dpo@synthesis-ai.com or through your account dashboard.
We process your personal data under the following legal bases:
Data Category | Purpose | Legal Basis | Retention Period |
---|---|---|---|
Account Information | Service provision | Contract | Account lifetime + 1 year |
Payment Data | Billing | Contract | 7 years (tax requirements) |
Usage Data | Service improvement | Legitimate interest | 2 years |
AI Interactions | Service delivery | Contract | 90 days |
Support Tickets | Customer service | Contract | 3 years |
Marketing Preferences | Communications | Consent | Until withdrawn |
When we transfer your data outside the EEA, we ensure appropriate safeguards:
Note: Some of our sub-processors (OpenAI, Anthropic) may process data in the United States. We ensure all transfers are covered by appropriate safeguards.
AES-256 encryption at rest
TLS 1.3 in transit
End-to-end encryption for sensitive data
Role-based access control
Multi-factor authentication
Regular access reviews
24/7 security monitoring
Intrusion detection systems
Regular security audits
Daily encrypted backups
Disaster recovery plan
Regular recovery testing
Annual GDPR training
Security awareness programs
Incident response drills
Annual security assessments
Penetration testing
Compliance audits
We've streamlined the process for exercising your GDPR rights:
Contact us via email, dashboard, or web form with your request
We verify your identity to protect your data (within 48 hours)
We process your request and gather relevant data (within 30 days)
We provide the requested information or action confirmation
No Fees: We do not charge fees for data subject requests unless they are manifestly unfounded or excessive.
We use cookies in compliance with GDPR requirements:
You can manage your cookie preferences:
We share data with third parties only when necessary and with appropriate safeguards:
Category | Purpose | Data Shared | Location |
---|---|---|---|
Payment Processor (Stripe) | Payment processing | Payment details | EU/US |
AI Providers | AI processing | User queries (anonymized) | US |
Cloud Infrastructure | Data storage | All user data | EU |
Analytics | Service improvement | Usage data | EU |
In the unlikely event of a data breach, we follow a strict response protocol:
Breach History: We maintain full transparency about any data breaches. To date, we have had zero reportable data breaches.
For any GDPR-related queries, concerns, or to exercise your rights:
Data Protection Officer
MYG Media SRL
Bulevardul GEORGE ENESCU, Nr. 23
Bloc G45, Scara B, Ap. 6
Judet Suceava, Romania
Response Time: We aim to respond to all GDPR requests within 72 hours and complete them within 30 days as required by law.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
You can find your local authority at: European Data Protection Board Members
Our lead supervisory authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1
București, 010336, Romania
Phone: +40 318 059 211
Email: anspdcp@dataprotection.ro
This GDPR compliance page was last updated on June 28, 2025.
We regularly review and update our GDPR compliance measures. Any material changes will be communicated through: