GDPR Compliance

Last updated: June 5, 2026

SyncBridge is committed to compliance with the General Data Protection Regulation (GDPR) and similar data protection laws worldwide. This page explains your rights as a data subject and how we fulfil our obligations as a data controller and, where applicable, data processor.

1. Our Role Under GDPR

Data Controller: When you create a SyncBridge account, Xoryo Technologies acts as the data controller for your account and dashboard data. We determine the purposes and means of processing your personal data.
Data Processor: When your visitors interact with the chatbot widget on your website or Facebook Page, you are the data controller and SyncBridge processes that visitor data on your behalf. You should ensure your own privacy policy covers this processing.

2. Lawful Basis for Processing

We process personal data under the following lawful bases:

Contract Performance: Processing necessary to provide the services you have subscribed to: running your chatbot, storing conversations, billing.
Legitimate Interests: Analytics, fraud prevention, and security monitoring where our interests do not override your rights.
Legal Obligation: Retaining financial records and responding to lawful requests from authorities.
Consent: Marketing communications and optional analytics. You may withdraw consent at any time.

3. Your Data Subject Rights

Under GDPR you have the following rights regarding your personal data:

Right of Access (Art. 15): Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data. Most data can be updated directly in Account Settings.
Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"). We will delete your data within 30 days of a verified request, subject to legal retention requirements.
Right to Restriction (Art. 18): Ask us to restrict processing of your data while a complaint is being investigated.
Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON/CSV) for transfer to another service.
Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email info@xoryotech.com with the subject "Data Subject Request". We will verify your identity and respond within 30 days (extendable to 90 days for complex requests with notice).

4. Data Processing Agreements

If you use SyncBridge to process personal data of EU/UK residents on your behalf (e.g., chatbot visitor data), you may require a Data Processing Agreement (DPA). We provide a standard DPA upon request.

Email info@xoryotech.com with the subject "DPA Request" and we will send it within 5 business days.

5. International Data Transfers

SyncBridge infrastructure is hosted primarily in the US. Where we transfer data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and sub-processors certified under applicable adequacy frameworks.

Our key sub-processors include: Supabase (database and auth), OpenAI (AI responses), Stripe, PayPal, Lemon Squeezy (payments), Resend (email delivery), Meta (Facebook/Instagram/WhatsApp messaging), Google (Calendar/Meet), Zoom, Calendly, Slack, Microsoft (Teams), Salesforce, Zapier, and WooCommerce; each governed by their own data transfer mechanisms. A full sub-processor list is available on request at info@xoryotech.com.

6. Data Retention

  • Account data: retained for the duration of your subscription plus 30 days after deletion.
  • Conversation data: retained during your active subscription. Deleted within 30 days of account closure.
  • Billing records: retained for 7 years as required by financial regulations.
  • Audit logs: retained for 12 months.

7. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where feasible. We will notify affected users without undue delay if the breach is likely to result in a high risk to their rights.

8. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, contact the supervisory authority in your country of residence.

9. Contact & Data Protection

For all GDPR-related enquiries contact our data protection contact:

SyncBridge — Xoryo Technologies

info@xoryotech.com

https://www.sync-bridge.app