Sintora Give Your Company One Brain

Legal

Privacy Policy

What personal data we handle, why we are allowed to, how long we keep it and the rights you can exercise at any time.

Effective date: 1 August 2026 · Sintoralabs OÜ · Registry code 17456201

Draft — pending legal review

This document is a working draft prepared for review. It is not yet in force and does not create obligations for Sintoralabs OÜ or its customers. Sections marked “to be confirmed” still need company-specific detail before publication.

1. Who we are

Sintoralabs OÜ ("Sintora", "we", "us") is a company registered in Estonia under registry code 17456201, with its registered office at Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.

We build Sintora, an AI business platform covering operations, marketing and product delivery, together with industry solutions for real estate, hospitality and service businesses.

This policy explains how we handle personal data. It applies to the sintora.ai website, to enquiries and demo requests, and to the accounts of people who administer or use the Sintora platform.

2. When we are a controller and when we are a processor

This distinction matters, because it determines who decides what happens to your data and who you should contact about it.

We act as a controller for the personal data we decide about ourselves: website visitors, people who contact us or request a demo, prospects we approach, our customers’ administrative contacts, applicants and suppliers. This policy governs that processing.

We act as a processor when our customers use the platform and load their own data into it — their clients, tenants, guests, bookings, invoices, conversations. In that case the customer is the controller, decides the purposes, and its own privacy notice applies. We process such data only on the customer’s documented instructions under a data processing agreement. If you are a customer’s client and want to exercise your rights, contact that customer; we will support them in responding.

3. Personal data we collect

As a controller, we collect the following categories of personal data.

CategoryExamplesWhere it comes from
Contact and enquiry dataName, business email, phone, company, role, the content of your message or demo requestYou, when you fill in a form or write to us
Account dataAccount identifiers, authentication data, role and permissions, product settingsYou or your organisation, when an account is created
Usage and technical dataIP address, device and browser type, pages viewed, timestamps, security and error logsAutomatically, when you use the website or the platform
Commercial relationship dataContract and billing details, correspondence, support ticketsYou, your organisation, and our records of the relationship
Prospect dataBusiness contact details and publicly available professional informationYou, public sources, and business data providers

We do not ask for special categories of personal data (such as health or biometric data) for our own purposes, and we ask you not to include them in free-text fields.

4. Why we use it, and on what legal basis

Under the GDPR every use of personal data needs a legal basis. Ours are set out below.

PurposeLegal basis
Responding to enquiries, arranging and running demosSteps taken at your request before entering a contract (Art. 6(1)(b)), or our legitimate interest in answering business enquiries (Art. 6(1)(f))
Providing the platform, managing accounts, support and billingPerformance of a contract (Art. 6(1)(b)); where you act for an organisation, our legitimate interest in serving that customer (Art. 6(1)(f))
Keeping the service secure — abuse prevention, bot protection, logging, incident investigationLegitimate interest in the security and integrity of our service (Art. 6(1)(f)); legal obligation where security incidents must be reported (Art. 6(1)(c))
Improving the product and understanding how the service is usedLegitimate interest in developing our service (Art. 6(1)(f))
Marketing to businesses — newsletters, product updates, outreachConsent where required (Art. 6(1)(a)), otherwise legitimate interest in business-to-business marketing (Art. 6(1)(f)). You can opt out at any time
Complying with accounting, tax and other legal dutiesLegal obligation (Art. 6(1)(c))
Establishing, exercising or defending legal claimsLegitimate interest in protecting our rights (Art. 6(1)(f))

Where we rely on legitimate interests, we weigh those interests against your rights and freedoms, and we can share the outcome of that assessment on request.

5. Cookies and similar technologies

Our website currently uses only strictly necessary cookies — for security, delivery and protecting our forms from automated abuse. The full inventory, the categories we use and how consent works are described in our Cookies Policy.

6. Who we share personal data with

We do not sell personal data. We share it only where necessary, with the following types of recipient.

  • Service providers acting as our processors — hosting and infrastructure, security and content delivery, communication and support tooling, analytics where enabled, payment and accounting providers. Each is bound by a data processing agreement.
  • Professional advisers such as lawyers, auditors and accountants, where they need the data to advise us.
  • Public authorities and courts, where we are legally required to disclose data or need to defend a legal claim.
  • An acquirer or investor, in the context of a merger, acquisition or restructuring, subject to appropriate confidentiality safeguards.

To be confirmed before publication: the current list of sub-processors used to deliver the platform, which we intend to publish here and keep up to date, together with a mechanism for customers to be notified of changes.

7. International transfers

We are established in the European Union and prefer to keep personal data within the European Economic Area. Where a provider processes data outside the EEA, we rely on a transfer mechanism recognised under Chapter V of the GDPR — an adequacy decision, or the European Commission’s Standard Contractual Clauses combined with an assessment of the destination country and any additional technical measures needed.

To be confirmed before publication: the specific destinations and mechanisms that apply to our current providers.

8. How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, and then delete or anonymise it. In practice that means:

  • Enquiries and demo requests — for the duration of the conversation and a reasonable follow-up period afterwards.
  • Customer account and contract data — for the life of the contract, and afterwards for as long as claims can still be brought.
  • Accounting records — for the retention period required by Estonian accounting and tax law.
  • Security and system logs — for a short, defined period appropriate to investigating incidents.
  • Marketing contacts — until you opt out or we conclude the contact is no longer relevant.

To be confirmed before publication: exact retention periods per category, aligned with the internal retention schedule.

9. How we protect it

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege administration, logging and monitoring, secure development practices and supplier due diligence. Our Security Summary describes these measures in more detail.

10. AI features and automated decisions

Sintora includes AI features that summarise conversations, draft content, suggest tasks and highlight risks. These produce suggestions for people to act on; they are assistive and remain under human control.

We do not make decisions producing legal or similarly significant effects about you by purely automated means without human involvement. If that ever changes, we will tell you and explain the logic involved, the significance and the consequences, and provide the safeguards the GDPR requires.

To be confirmed before publication: our position on whether customer content is used to train or improve models, which sub-processors provide model inference, and any customer-configurable controls over AI features.

11. Your rights

Where we are the controller, you have the following rights under the GDPR.

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where one of the grounds in Art. 17 applies.
  • Restriction — have processing limited while a dispute about accuracy or legitimate interests is resolved.
  • Portability — receive data you provided to us in a structured, commonly used, machine-readable format, or have it sent to another controller.
  • Objection — object at any time to processing based on legitimate interests, and absolutely to direct marketing.
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting processing already carried out.

To exercise a right, write to info@sintora.ai. We respond within one month, which can be extended by two further months for complex requests — we will tell you if that happens. We may need to verify your identity first.

12. Complaints

If you believe we have handled your personal data unlawfully, please raise it with us first — we would rather fix it directly. You also have the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work.

Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia.

13. Children

Sintora is a business product and is not directed at children. We do not knowingly collect personal data from children for our own purposes. If you believe a child has provided us with personal data, contact us and we will remove it.

14. Changes to this policy

We review this policy regularly and update it when our processing changes. The effective date at the top shows when the current version took effect. Where a change materially affects you, we will notify you — by email or a notice in the product — before it takes effect.

15. Contact

For any privacy question, or to exercise your rights, contact us at info@sintora.ai, or by post at Sintoralabs OÜ, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.

To be confirmed before publication: whether a Data Protection Officer has been appointed and, if so, their contact details; and whether an EU representative is required for any group entity established outside the EEA.