1. Data controller
The controller is Synapsis Technologies s.r.o., registered office Plzeňská 134, 261 01 Příbram, Company ID 298 83 041. Registered in the Commercial Register maintained by the Municipal Court in Prague, File No. C 453896.
Managing director: Matěj Melichar. Contact email: support@synapsisapp.com.
2. Purposes and retention
We process only the data needed to provide the service, meet legal duties, and — where the law requires it — on the basis of your consent.
- Account: email, login credentials, and subscription status are processed to perform the contract. After account closure we keep necessary records for 1 additional year (complaints, accounting and security traces), unless a longer period is required by law.
- Platform data: trading journal, watchlists, saved views, and similar content you create in Synapsis are processed to provide the service for as long as the account exists or until you delete the data.
- Communications: support messages and related correspondence are kept for up to 3 years after the request is closed.
- Analytics: traffic and technical measurement (for example Vercel Analytics) are processed only with your consent, for a maximum of 26 months.
- Newsletter: your email for news is processed on the basis of consent until withdrawn. You can unsubscribe via the link in every email or by contacting support.
3. Processors and recipients
We do not sell personal data. We use vetted processors without whom the service cannot run:
- Supabase — database hosting, authentication, and storage.
- Stripe — subscription payments; we do not store card numbers.
- Vercel — website hosting and optional analytics after consent.
- OpenRouter and third-party AI model APIs — processing Sensei assistant prompts and related analytical output.
- Google and Microsoft — OAuth sign-in if you choose that method.
- Market-data providers (for example Polygon, Finnhub) — market feeds, not your billing details.
4. Transfers outside the EU
Some processors (especially cloud and AI APIs) may transfer data to the United States or other third countries. Where there is no adequacy decision we rely on Standard Contractual Clauses and other GDPR safeguards.
5. Data-subject rights
You have the right of access, rectification, erasure, restriction, portability, and to object. You may withdraw consent (analytics, newsletter, marketing) at any time without affecting the lawfulness of processing before withdrawal.
You may lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ), https://uoou.gov.cz. Send rights requests to support@synapsisapp.com. ÚOOÚ
6. Security
We use transport encryption (HTTPS), access control, environment separation, and other technical and organisational measures appropriate to the risk. No internet transmission is absolutely secure. We notify personal-data breaches in line with the GDPR.