syniria

Legal

Privacy Policy

Last updated: July 20, 2026

This Privacy Policy explains how Syniria (“Syniria,” “we,” “us”) collects, uses, and shares information in connection with our AI customer-service agent platform (the “Service”), available at syniria.com and its dashboard.

The Service is used by businesses (“Clients”) who connect their Instagram, Facebook, and WhatsApp accounts so an AI agent can answer their customers. This policy covers two groups: our Clients, and the end customerswho message a Client’s connected channels.

For personal data processed through a Client’s connected messaging channels, the Client determines the purposes and means of processing and is the data controller. Syniria processes such information solely on the Client’s documented instructions and acts as a data processor. Where required by applicable law, we make a data processing agreement available to Clients.

1. Information we collect

From Clients (account & configuration). When you create an account and set up your agent, we collect:

  • Account details: email address and a password, which we store using industry-standard one-way hashing (never in plain text).
  • Business profile: business name, contact name, contact email/phone, time zone, and business type.
  • Agent configuration: agent name, tone, business description, hours, FAQs, reactivation phrase, lead-capture field definitions, and your product/service catalog.
  • Knowledge sources you upload: PDFs, spreadsheets, and website URLs you add for the agent to learn from.
  • Connected-channel credentials: access tokens for the Facebook Pages, Instagram, and WhatsApp accounts you connect. These are encrypted at rest.
  • Billing information, processed by our payment provider (see Sharing, below).

From end customers (via connected channels).When someone messages a Client’s connected channel, we process on the Client’s behalf:

  • The content of messages exchanged with the agent (text, and transcripts of voice notes).
  • Platform-provided identifiers (e.g. the sender’s platform-scoped ID) needed to route and reply to the conversation.
  • Lead/booking details the customer provides in conversation (e.g. name, phone, email, and other fields the Client has configured), stored so the Client can follow up.

Automatically. When you use the dashboard, we automatically collect technical information such as IP address, browser type, operating system, device information, timestamps, and security logs, to operate and protect the Service.

2. Cookies and similar technologies

We use cookies and similar technologies that are strictly necessary to provide the Service:

  • keeping you signed in (authentication and session cookies);
  • securing the channel-connection flow (short-lived functional cookies);
  • protecting against fraud and abuse, and improving security.

We do not use advertising cookies, and we do not currently use third-party analytics cookies. You can control cookies through your browser settings, though disabling strictly necessary cookies may prevent parts of the Service from working. If we introduce analytics or other non-essential cookies in the future, we will update this policy.

3. How we use information

  • To operate the Service — run the AI agent, deliver replies, and capture leads.
  • To let Clients configure, monitor, and manage their agent and channels.
  • To authenticate accounts and send transactional emails (verification, password reset).
  • To process subscriptions and payments.
  • To secure the Service, prevent abuse, and comply with legal obligations.

We do not sell personal information, and we do not use end-customer message content for advertising.

4. AI processing

Agent replies are generated by third-party AI language-model providers. To produce a reply, we share only the information reasonably necessary to generate a response — relevant conversation content and the Client’s configured business information — with these providers, and we require them to protect that information in accordance with applicable agreements. AI-generated responses may be inaccurate or incomplete; Clients are responsible for reviewing and overseeing their agent’s behavior.

5. Meta platform data

When you connect a Facebook Page, Instagram, or WhatsApp account, we receive and store an access token (encrypted) and the identifiers needed to send and receive messages on your behalf, using the permissions you grant during connection. We use this data solely to provide the messaging features you enable — never to build advertising profiles. You can disconnect a channel at any time from the dashboard, which deactivates it and deletes the stored token. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.

6. How we share information

We share information only with service providers that help us operate the Service, and as required by law. These include providers for:

  • messaging on connected channels;
  • file storage for content you upload;
  • payment processing (which handles your card details directly);
  • AI response generation;
  • transactional email delivery;
  • hosting and infrastructure on which the Service runs.

We may add or replace service providers as our business evolves, and we will update this policy to reflect material changes.

7. Data retention

We retain Client account and configuration data for as long as the account is active, and end-customer conversation and lead data on the Client’s behalf for as long as the Client’s account is active or until the Client deletes it. When an account is closed, we delete or anonymize associated personal data within a reasonable period, except where retention is required by law. Deleted data may persist in encrypted backups for a limited time before being permanently removed through our normal backup-rotation schedule.

8. Security

We use industry-standard measures to protect information, including encryption in transit, AES-256 encryption of connected-channel access tokens at rest, and one-way hashing of passwords. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing. Clients can edit or remove most of their data directly in the dashboard. End customers should direct requests to the Client they interacted with (the controller of that data); we will assist Clients in fulfilling such requests.

10. Data deletion

To request deletion of data associated with your Meta account, you can remove the Syniria app from your Facebook/Instagram settings, which may initiate our data-deletion process, or contact us at info@syniria.com. Clients can also disconnect any channel from the dashboard at any time to immediately delete its stored access token. See our data deletion page for more.

11. Third-party links

The Service and dashboard may contain links to third-party websites and platforms (such as Meta, our payment provider, and documentation). We are not responsible for the privacy practices or content of those third parties, and this policy does not apply to them.

12. Business transfers

If Syniria is involved in a merger, acquisition, financing, or sale of all or part of its assets, information covered by this policy may be transferred as part of that transaction. We will continue to protect it consistent with this policy and notify you where required.

13. Account termination

You can close your account at any time by contacting us, or through the dashboard where available. When you close your account, we stop processing your data for the Service and delete or anonymize it as described under Data Retention, except where we are required to keep it. Disconnecting a channel deletes its stored access token immediately.

14. International transfers

Syniria is a company registered in the United States, and Syniria and its service providers may process and store data in various countries. Where we transfer personal data across borders, we take steps to ensure it remains protected consistent with this policy and applicable law.

15. Children's privacy

The Service is not directed to children under 13 or the minimum age required under applicable law, and we do not knowingly collect their personal information.

16. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.

17. Contact us

Syniria — 5830 E 2nd St, Ste 7000 #37147, Casper, WY 82609, US.
Email: info@syniria.com