Legal
Privacy policy
This policy explains how personal data is processed when you visit Synbuild, contact us, use an account, place an order or use a Synbuild product.
Last updated: 23 August 2026
Article 1 – Who is responsible
Synbuild is a product platform owned and operated by Goldflux Technologies OÜ, registry code 17479596, with its registered address at Harju maakond, Kesklinna linnaosa, Pärnu mnt 139b, 11317 Tallinn, Estonia. Goldflux Technologies OÜ is the legal entity that provides all Synbuild products and services. In this policy, “Synbuild”, “we”, “us” and “our” refer to Goldflux Technologies OÜ.
For more information about Synbuild's legal entity and its relationship with Goldflux, see Legal and ownership.
Goldflux Technologies OÜ is the controller for personal data used to operate Synbuild, manage business relationships, accounts, orders, transactions, security and support. Privacy questions and data-subject requests can be sent to hello@syn.build.
Article 2 – Who this policy covers
- Visitors to syn.build and related Synbuild pages.
- Business customers, prospective customers and their representatives.
- Users of Synbuild accounts, products, scans, workflows, automations or future platform functionality.
- People who contact Synbuild or whose business contact details are provided in connection with a customer engagement.
Article 3 – Personal data, purposes and sources
3.1 Website and technical operation
When the site is used, Synbuild may process device and browser information, requested URLs and routes, request methods, response status and duration, timestamps, security events, error information and session identifiers.
These data are used to deliver and secure the website, maintain sessions, prevent misuse, diagnose faults, measure service reliability and protect Synbuild and its users. The existing session identifier may be used to relate requests within that session only. Website telemetry does not include request bodies, IP addresses or identifiers derived from IP addresses.
3.2 Accounts and authentication
Where accounts are available, Synbuild processes name, business email address, password hash, email-verification status, account timestamps, login and session information, password-reset data and any remember-me token selected by the user.
These data are used to create and administer accounts, authenticate users, recover access, maintain security and provide account functionality.
3.3 Enquiries and support
When you contact us, Synbuild may process your name, business contact details, company, message, correspondence and information needed to respond or provide support.
3.4 Orders, contracts and administration
For quotations, orders and delivery, Synbuild may process business contact details, company and billing information, selected product, order status, contractual correspondence, invoices, payment status and records required for accounting and dispute handling.
3.5 Products, scans and workflows
Synbuild may process project information, business-process details, files, instructions, system information and other data supplied by or for the customer to deliver an agreed product.
Customers should provide only data that is relevant and lawful for the engagement and should avoid special-category or highly sensitive personal data unless expressly agreed and appropriately protected.
3.6 Online payments
Where online payment is available, Stripe may process payer identity, billing details, payment-method information, transaction identifiers, fraud-prevention signals and payment status. Synbuild generally receives transaction and status information rather than complete card details.
Until online payment is activated, Synbuild's checkout may operate only as a non-payment validation or ordering flow.
Article 4 – Legal bases
- Taking steps at a business customer's request and performing an agreement.
- Compliance with legal obligations, including tax, accounting and lawful requests.
- Legitimate interests in operating and securing Synbuild, communicating with business contacts, preventing misuse, improving reliability and establishing or defending legal claims.
- Consent where it is specifically requested and is the appropriate legal basis.
Where processing relies on consent, consent can be withdrawn at any time without affecting earlier lawful processing.
Article 5 – Controller and processor roles
Goldflux Technologies OÜ acts as controller for Synbuild website, account, business-contact, order, transaction, security and support data.
When a business customer supplies personal data for processing within a scan, workflow, automation or hosted product and determines its purposes and means, Goldflux Technologies OÜ may act as processor on that customer's behalf. In that case, the customer is normally the controller and remains responsible for the lawfulness of its instructions, transparency to data subjects and a valid basis for the processing.
Where required, the parties will enter into a data-processing agreement describing the subject matter, duration, security and instructions.
Article 6 – Recipients and service providers
Personal data may be shared only where reasonably necessary with authorised personnel, professional advisers, public authorities where legally required, and providers supporting hosting, infrastructure, security, email, customer support, software and AI functionality.
Postmark may be used to deliver operational messages such as account verification, password resets, order or service communications.
Where online payment is available, Stripe may process payment and fraud-prevention data in accordance with its own responsibilities and privacy information.
Synbuild does not sell personal data.
Article 7 – International transfers
Synbuild aims to process personal data within the European Economic Area where reasonably possible. Some service providers may process data in other countries.
Where the GDPR requires safeguards for an international transfer, Synbuild uses an applicable adequacy decision, standard contractual clauses or another lawful transfer mechanism and applies supplementary measures where appropriate.
Article 8 – Retention
Personal data is retained only for as long as reasonably necessary for the relevant purpose, including service delivery, account administration, security, support, accounting and legal claims.
- Session records expire according to the configured session lifetime and may be removed through routine system maintenance.
- Raw website telemetry is retained no longer than necessary for reliability, security and fault diagnosis.
- Password-reset records are short-lived and replaced or deleted when no longer valid.
- Account data is retained while the account is active and afterwards only as needed for security, legal claims or statutory obligations.
- Order, invoice and accounting records are retained for the period required by applicable tax and accounting law.
- Customer data processed on behalf of a customer is retained and deleted according to the agreement, documented instructions and applicable legal requirements.
Article 9 – Security
Synbuild uses technical and organisational measures appropriate to the nature and risk of the processing. These may include access controls, password hashing, encrypted transport, restricted administration, secure session settings, logging, backups and supplier controls.
No online service can guarantee absolute security. Users should protect their credentials and promptly report suspected unauthorised access.
Article 10 – Your rights
Subject to the GDPR and applicable conditions, you may request access, correction, deletion, restriction, portability or object to processing. You may also withdraw consent where processing is based on consent.
Requests can be sent to hello@syn.build. We may request information needed to verify identity and will respond within the applicable legal period.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate or the competent supervisory authority in the EU or EEA country where you live or work or where an alleged infringement occurred.
Article 11 – Automated decisions
Synbuild does not use the personal data described in this policy to make decisions based solely on automated processing that produce legal or similarly significant effects, unless this is expressly introduced with the information and safeguards required by law.
Article 12 – Changes and contact
This policy may be updated when Synbuild's products, suppliers or legal obligations change. The current version and its last-updated date are published on this page.
Questions about this policy can be sent to hello@syn.build.