Legal
Privacy Policy
What personal data we handle, why we are allowed to, how long we keep it and the rights you can exercise at any time.
Effective date: 1 August 2026 · Sintoralabs OÜ · Registry code 17456201
Draft — pending legal review
This document is a working draft prepared for review. It is not yet in force and does not create obligations for Sintoralabs OÜ or its customers. Sections marked “to be confirmed” still need company-specific detail before publication.
1. Who we are
Sintoralabs OÜ ("Sintora", "we", "us") is a company registered in Estonia under registry code 17456201, with its registered office at Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.
We build Sintora, an AI business platform covering operations, marketing and product delivery, together with industry solutions for real estate, hospitality and service businesses.
This policy explains how we handle personal data. It applies to the sintora.ai website, to enquiries and demo requests, and to the accounts of people who administer or use the Sintora platform.
2. When we are a controller and when we are a processor
This distinction matters, because it determines who decides what happens to your data and who you should contact about it.
We act as a controller for the personal data we decide about ourselves: website visitors, people who contact us or request a demo, prospects we approach, our customers’ administrative contacts, applicants and suppliers. This policy governs that processing.
We act as a processor when our customers use the platform and load their own data into it — their clients, tenants, guests, bookings, invoices, conversations. In that case the customer is the controller, decides the purposes, and its own privacy notice applies. We process such data only on the customer’s documented instructions under a data processing agreement. If you are a customer’s client and want to exercise your rights, contact that customer; we will support them in responding.
3. Personal data we collect
As a controller, we collect the following categories of personal data.
| Category | Examples | Where it comes from |
|---|---|---|
| Contact and enquiry data | Name, business email, phone, company, role, the content of your message or demo request | You, when you fill in a form or write to us |
| Account data | Account identifiers, authentication data, role and permissions, product settings | You or your organisation, when an account is created |
| Usage and technical data | IP address, device and browser type, pages viewed, timestamps, security and error logs | Automatically, when you use the website or the platform |
| Commercial relationship data | Contract and billing details, correspondence, support tickets | You, your organisation, and our records of the relationship |
| Prospect data | Business contact details and publicly available professional information | You, public sources, and business data providers |
We do not ask for special categories of personal data (such as health or biometric data) for our own purposes, and we ask you not to include them in free-text fields.
4. Why we use it, and on what legal basis
Under the GDPR every use of personal data needs a legal basis. Ours are set out below.
| Purpose | Legal basis |
|---|---|
| Responding to enquiries, arranging and running demos | Steps taken at your request before entering a contract (Art. 6(1)(b)), or our legitimate interest in answering business enquiries (Art. 6(1)(f)) |
| Providing the platform, managing accounts, support and billing | Performance of a contract (Art. 6(1)(b)); where you act for an organisation, our legitimate interest in serving that customer (Art. 6(1)(f)) |
| Keeping the service secure — abuse prevention, bot protection, logging, incident investigation | Legitimate interest in the security and integrity of our service (Art. 6(1)(f)); legal obligation where security incidents must be reported (Art. 6(1)(c)) |
| Improving the product and understanding how the service is used | Legitimate interest in developing our service (Art. 6(1)(f)) |
| Marketing to businesses — newsletters, product updates, outreach | Consent where required (Art. 6(1)(a)), otherwise legitimate interest in business-to-business marketing (Art. 6(1)(f)). You can opt out at any time |
| Complying with accounting, tax and other legal duties | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims | Legitimate interest in protecting our rights (Art. 6(1)(f)) |
Where we rely on legitimate interests, we weigh those interests against your rights and freedoms, and we can share the outcome of that assessment on request.
7. International transfers
We are established in the European Union and prefer to keep personal data within the European Economic Area. Where a provider processes data outside the EEA, we rely on a transfer mechanism recognised under Chapter V of the GDPR — an adequacy decision, or the European Commission’s Standard Contractual Clauses combined with an assessment of the destination country and any additional technical measures needed.
To be confirmed before publication: the specific destinations and mechanisms that apply to our current providers.
8. How long we keep it
We keep personal data only as long as it serves the purpose it was collected for, and then delete or anonymise it. In practice that means:
- Enquiries and demo requests — for the duration of the conversation and a reasonable follow-up period afterwards.
- Customer account and contract data — for the life of the contract, and afterwards for as long as claims can still be brought.
- Accounting records — for the retention period required by Estonian accounting and tax law.
- Security and system logs — for a short, defined period appropriate to investigating incidents.
- Marketing contacts — until you opt out or we conclude the contact is no longer relevant.
To be confirmed before publication: exact retention periods per category, aligned with the internal retention schedule.
9. How we protect it
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege administration, logging and monitoring, secure development practices and supplier due diligence. Our Security Summary describes these measures in more detail.
10. AI features and automated decisions
Sintora includes AI features that summarise conversations, draft content, suggest tasks and highlight risks. These produce suggestions for people to act on; they are assistive and remain under human control.
We do not make decisions producing legal or similarly significant effects about you by purely automated means without human involvement. If that ever changes, we will tell you and explain the logic involved, the significance and the consequences, and provide the safeguards the GDPR requires.
To be confirmed before publication: our position on whether customer content is used to train or improve models, which sub-processors provide model inference, and any customer-configurable controls over AI features.
11. Your rights
Where we are the controller, you have the following rights under the GDPR.
- Access — obtain confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where one of the grounds in Art. 17 applies.
- Restriction — have processing limited while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format, or have it sent to another controller.
- Objection — object at any time to processing based on legitimate interests, and absolutely to direct marketing.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting processing already carried out.
To exercise a right, write to info@sintora.ai. We respond within one month, which can be extended by two further months for complex requests — we will tell you if that happens. We may need to verify your identity first.
12. Complaints
If you believe we have handled your personal data unlawfully, please raise it with us first — we would rather fix it directly. You also have the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work.
Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia.
13. Children
Sintora is a business product and is not directed at children. We do not knowingly collect personal data from children for our own purposes. If you believe a child has provided us with personal data, contact us and we will remove it.
14. Changes to this policy
We review this policy regularly and update it when our processing changes. The effective date at the top shows when the current version took effect. Where a change materially affects you, we will notify you — by email or a notice in the product — before it takes effect.
15. Contact
For any privacy question, or to exercise your rights, contact us at info@sintora.ai, or by post at Sintoralabs OÜ, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.
To be confirmed before publication: whether a Data Protection Officer has been appointed and, if so, their contact details; and whether an EU representative is required for any group entity established outside the EEA.