Privacy Policy

Last updated: January 1, 2025

1. Introduction

MYG Media SRL, operating as Synthesis AI ("we," "our," or "us"), is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our AI-powered business automation platform and services.

By using Synthesis AI, including our Harv3y AI Operator service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

2.1 Information You Provide

2.2 Information Collected Automatically

2.3 Information from Third Parties

3. API Key Processing (BYOK Model)

🔒 Your API Keys Are Secure

When you use your own API keys (Bring Your Own Key model):

  • We act as a data processor, not a data controller
  • API keys are stored encrypted locally in your browser only
  • We NEVER store API keys on our servers
  • Data flows directly between you and AI providers
  • You maintain the data controller relationship with AI providers
  • API responses may be temporarily cached (max 24 hours)

3.1 How We Handle API Keys

Your API keys are encrypted using AES-256 encryption and stored exclusively in your browser's local storage. We implement:

3.2 Data Flow with API Keys

When you use your API keys:

4. How We Use Your Information

We use the collected information for the following purposes:

5. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

For API key processing, you provide explicit consent when connecting your keys, which you can withdraw at any time.

6. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share your data in these circumstances:

6.1 Service Providers

6.2 Legal Requirements

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

6.4 Consent

With your explicit consent for purposes not covered in this policy.

7. Data Security

We implement industry-standard security measures to protect your data:

Security Notice: While we use advanced security measures, no system is 100% secure. We continuously work to protect your data but cannot guarantee absolute security.

8. Your Rights Under GDPR

Depending on your location, you have specific rights regarding your personal data:

8.1 Right to Access (Article 15)

8.2 Right to Rectification and Erasure (Articles 16-17)

8.3 Right to Restrict Processing and Object (Articles 18, 21)

8.4 Right to Data Portability (Article 20)

8.5 Rights Related to Automated Decision-Making (Article 22)

How to Exercise Your Rights

To exercise any of these rights:

  • Email us at: privacy@synthesis-ai.com
  • Use the data management tools in your dashboard
  • We will respond within 30 days
  • No fee unless requests are manifestly unfounded or excessive

9. Data Subject Rights Dashboard

We provide a comprehensive dashboard for managing your data rights:

10. International Data Transfers

Your data may be transferred to and processed in countries other than your residence. We ensure appropriate safeguards:

11. Data Retention

We retain your data only as long as necessary:

12. Cookies and Storage Consent

We use local storage for API keys only with your explicit consent:

Local Storage Notice: We store API keys locally in your browser for functionality. No server storage occurs. You can clear this data anytime through browser settings or our dashboard.

13. Children's Privacy

Synthesis AI is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we discover we have collected data from a child, we will promptly delete it.

14. Data Breach Notification

In the event of a data breach, we will:

15. Regional Privacy Rights

15.1 European Union (GDPR)

15.2 California (CCPA/CPRA)

15.3 Other Jurisdictions

If you reside in other jurisdictions with privacy laws, you may have additional rights. Contact us to exercise your rights under applicable law.

16. API Provider Relationships

When using your own API keys:

Important: You maintain a direct relationship with AI providers. We only facilitate the technical connection. Ensure you comply with their terms of service.

17. AI-Specific Considerations

17.1 AI Processing

17.2 AI Data Isolation

17.3 AI Transparency

18. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

18.1 Essential Cookies

18.2 Functional Cookies

18.3 Analytics Cookies

Cookie Control: You can manage cookie preferences through your browser settings. Note that disabling certain cookies may impact functionality.

19. Third-Party Links

Our service may contain links to third-party websites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing any personal information.

20. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes through:

Continued use of our services after changes constitutes acceptance of the updated policy.

21. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with privacy laws. You can contact our DPO for any privacy-related concerns.

Contact Us

If you have questions about this Privacy Policy or want to exercise your privacy rights, please contact us:

Email: privacy@synthesis-ai.com

Data Protection Officer: dpo@synthesis-ai.com

Address: MYG Media SRL, Privacy Department
Bulevardul GEORGE ENESCU, Nr. 23
Bloc G45, Scara B, Ap. 6
Judet Suceava, Romania

Response Time: We aim to respond to all privacy requests within 30 days.

22. Supervisory Authority

For EU residents, you have the right to lodge a complaint with your local supervisory authority:

You may also contact the supervisory authority in your country of residence.

If you are located in the European Economic Area and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority.