Privacy Policy

1. Who we are

DocAI ("the Service") is operated by SYNAIRO SPÓŁKA Z OGRANICZONΔ„ ODPOWIEDZIALNOŚCIΔ„, ul. ZΕ‚ota 75A/7, 00-819 Warszawa, Poland ("we", "us"). We act as the controller for the personal data we process to run the Service. Where you upload documents, you decide what they contain; we process that content to provide the Service to you. Contact: privacy@synairo.com. Full company registration details (KRS, NIP) are on our Legal Notice page.

We have not appointed a Data Protection Officer. Privacy and data-protection enquiries can be sent directly to privacy@synairo.com.

2. The data we process

We do not use web analytics, advertising, or tracking technologies, and we do not sell your personal data.

3. Legal bases (GDPR)

Where you upload documents containing special categories of personal data (Art. 9) or criminal-offence data (Art. 10), you are responsible for ensuring there is a lawful basis for that processing. See section 7.

4. Your uploaded documents

5. AI, OCR, and LLM processing

6. Workspaces, teams, and sharing

7. What to consider before uploading

DocAI can process many document types, including invoices, purchase orders, delivery notes, receipts, forms, contracts, CVs/rΓ©sumΓ©s, bank statements, and identity documents. Some of these can contain sensitive or special-category personal data. The Service is not specifically designed or certified for health, biometric, or other special-category data (GDPR Art. 9); if you process such data you remain responsible for its lawfulness. Use the field-masking and redaction tools to limit what is stored in shared results.

8. Recipients and processors

We share data with service providers strictly to operate the Service, for authentication, AI/OCR processing, hosting and storage, error monitoring, email delivery, and (for paid plans) payments. The current list, with each provider's role and location, is on our Subprocessors page. We may also disclose data to professional advisers or public authorities where required by law.

9. International transfers

Some of our providers are located outside the European Economic Area (EEA), in particular in the United States; others operate in the EU. Where personal data is transferred outside the EEA, we rely on an appropriate safeguard, an adequacy decision (such as the EU–US Data Privacy Framework, where the provider is certified) or Standard Contractual Clauses. Details for a specific provider are available on request.

10. Data retention

In short: saved analyses and any stored uploaded files are kept until you delete them. There is no time-based automatic deletion by default; your storage is instead bounded by your plan. Account data is kept until your account is deleted. Usage and billing records are kept as long as needed for billing integrity and legal obligations. Technical and security logs are short-lived. Full details are on the Data Retention page.

11. Your rights

You have the right to access, rectify, erase, restrict, or port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You can delete individual saved records, or all of your saved documents, from within the app. For account deletion or any other request, contact privacy@synairo.com. You may also lodge a complaint with your supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes UODO).

12. Cookies and similar technologies

Only strictly necessary cookies are active by default, for authentication, session security, and remembering your cookie choice. We also store your language and theme preferences. The optional "analytics" and "marketing" categories in our cookie settings are currently not active. No such technologies are deployed. You can review and change your choices at any time via Cookie settings in the menu.

13. Security

Data is encrypted in transit. The production database is encrypted at rest by our hosting provider. Stored document objects and their metadata are encrypted at rest with AES-256-GCM using keys managed by our object-storage provider. Access to stored data is restricted to your account and to workspaces you belong to; API keys and share/invitation links are stored only as cryptographic hashes. No online service can guarantee absolute security. More detail is on the Security page.

14. Children

DocAI is intended for business use by adults and is not directed to children. We do not knowingly collect personal data from children.

15. Automated decision-making

DocAI performs automated extraction and classification and presents the results for your review. It does not make automated decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22. A human (you) reviews and decides how to use the output.

16. Changes

We will post any changes to this policy on this page and update the date above. Material changes will be announced in the application.