Sintora Give Your Company One Brain

Legal

Privacy Policy

What personal data we handle, why we are allowed to, how long we keep it and the rights you can exercise at any time.

Status
In force
Version
1.0
In force from
8 September 2026

Sintoralabs OÜ · Registry code 17456201

This English text is the authentic version of this document. Translations into other languages are provided for convenience only; in the event of any discrepancy between a translation and this English version, the English version prevails.

1. Who we are

Sintoralabs OÜ ("Sintora", "we", "us") is a company registered in Estonia under registry code 17456201, with its registered office at Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.

We build Sintora, an AI business platform covering operations, marketing and product delivery, together with industry solutions for real estate and service businesses.

This policy explains how we handle personal data. It applies to the sintora.ai website, to enquiries and demo requests, and to the accounts of people who administer or use the Sintora platform.

2. When we are a controller and when we are a processor

This distinction matters, because it determines who decides what happens to your data and who you should contact about it.

We act as a controller for the personal data we decide about ourselves: website visitors, people who contact us or request a demo, our customers’ administrative contacts, applicants and suppliers. This policy governs that processing. We do not approach people who have not approached us — see “What we do not do”.

We act as a processor when our customers use the platform and load their own data into it — their clients, tenants, guests, bookings, invoices, conversations. In that case the customer is the controller, decides the purposes, and its own privacy notice applies. We process such data only on the customer’s documented instructions under a data processing agreement. If you are a customer’s client and want to exercise your rights, contact that customer; we will support them in responding.

3. Personal data we collect

As a controller, we collect the following categories of personal data.

CategoryExamplesWhere it comes from
Contact and enquiry dataName, business email, phone, company, role, a LinkedIn profile address if you choose to add one, and the content of your message or demo requestYou, when you fill in a form or write to us
Account dataAccount identifiers, authentication data, role and permissions, product settingsYou or your organisation, when an account is created. Where it is your organisation, “When we did not get your data from you” below sets out what Art. 14 asks for
Usage and technical dataIP address and, where Cloudflare supplies them, the approximate location Cloudflare derives from it — country, region, city and time zone; device and browser type; the language your browser asks for; pages viewed, and the page a form was submitted from; the verdict of our automated abuse checks on a submission and which check produced it; timestamps; security and error logsAutomatically, when you use the website or the platform, and from Cloudflare where a request reaches us through it
Commercial relationship dataContract and billing details, correspondence, support ticketsYou, your organisation, and our records of the relationship
Change-notification dataAn email address you give us so that we can tell you in advance when these documents, or the sub-processors behind the platform, are about to changeYou, when you ask us to tell you — there is no form for it and no box to tick, only an email to info@sintora.ai
Interaction and attribution dataA session identifier, how long you spent on the page and how far you scrolled, counts of clicks, keystrokes and mouse movements, which form fields were interacted with, the page title and address, the page that referred you, and utm_source, utm_medium, utm_campaign, utm_term and utm_content from the link you arrived byAutomatically, and only if you allow the analytics category in the cookie banner. The counters are counts and nothing more — we record that you typed, never what you typed. The data-subject request form does not collect any of this
Product advisor dataYour answers to the advisor’s questions, anything you type into its free-text field, and — if you ask us to continue the conversation — a LinkedIn profile address, an optional work email and the channel you preferYou, when you use the advisor on our website

We do not ask for special categories of personal data (such as health or biometric data) for our own purposes, and we ask you not to include them in free-text fields.

4. Why we use it, and on what legal basis

Under the GDPR every use of personal data needs a legal basis. Ours are set out below.

PurposeLegal basis
Responding to enquiries, arranging and running demosSteps taken at your request before entering a contract (Art. 6(1)(b)), or our legitimate interest in answering business enquiries (Art. 6(1)(f))
Providing the platform, managing accounts, support and billingPerformance of a contract (Art. 6(1)(b)); where you act for an organisation, our legitimate interest in serving that customer (Art. 6(1)(f))
Keeping the service secure — abuse prevention, bot protection, logging, incident investigationLegitimate interest in the security and integrity of our service (Art. 6(1)(f)); legal obligation where security incidents must be reported (Art. 6(1)(c))
Improving the product and understanding how the service is usedConsent, where the measurement stores or reads anything on your device (Art. 6(1)(a)) — the analytics category in the cookie banner, which you can withdraw at any time; our legitimate interest in developing our service (Art. 6(1)(f)) where no such reading is involved
Running the product advisor and following up when you ask us to continueSteps taken at your request before entering a contract (Art. 6(1)(b)); our legitimate interest in knowing who we are speaking to before we reply (Art. 6(1)(f)). We read a LinkedIn address you give us to see who is asking — we do not fetch the profile automatically and we do not enrich what you told us from outside sources
Attributing an enquiry to the campaign or the link it arrived fromConsent (Art. 6(1)(a)) — the analytics category in the cookie banner. Decline it and none of this is recorded; the data-subject request form never collects it at all
Telling you in advance when these documents or our sub-processors changePerformance of our contract with customers and the prior notice Art. 28(2) GDPR requires for a change of sub-processor (Art. 6(1)(b)); for everyone else who asked to be told, our legitimate interest in telling them (Art. 6(1)(f)). It carries nothing but the notice
Complying with accounting, tax and other legal dutiesLegal obligation (Art. 6(1)(c))
Establishing, exercising or defending legal claimsLegitimate interest in protecting our rights (Art. 6(1)(f))

Where we rely on legitimate interests, we weigh those interests against your rights and freedoms, and we can share the outcome of that assessment on request.

5. Whether you have to give us this data

This depends on which of the situations below you are in, so we set each one out rather than give a general assurance.

  • Contacting us through the website — no obligation of any kind, and neither a statutory nor a contractual requirement. What each form insists on differs, so we say it per form rather than in general, because a general answer is one you cannot check against the form in front of you.
  • The demo request will not send without your name and a business email address. The message is genuinely optional: leave it empty and a standard one is sent in its place. Everything else on it can be left blank.
  • The access wizard will not let you past its steps without the areas you are interested in, your company size, a channel to reply on, your name and an email address. Those are not optional and there is no way to submit without them — they are how we prepare for the conversation rather than open it with the same questions. If you would rather not answer them, write to info@sintora.ai instead: nothing on this site is behind a form, and the whole of it can be read without filling one in.
  • The data-subject request form asks for what a request needs and nothing beyond it.
  • The product advisor — voluntary throughout, and it runs in your browser: nothing you answer reaches us unless you send it with a request. We ask for contact details only if you tell us to continue the conversation, and if you do not, there is simply nothing for us to reply to.
  • Creating an account — a contractual requirement in substance. An account cannot exist without an identifier and a means of authenticating you, and we cannot provide the platform to someone we cannot let in. Your organisation decides what role and permissions to give you.
  • Entering into and performing a contract — a contractual requirement. To conclude an agreement, provide the platform and invoice for it, we need the contracting party’s identification, contact and billing details, and we cannot conclude or perform the contract without them.
  • Accounting records — a statutory requirement. Estonian accounting and tax law obliges us to record the details of a transaction and to keep them, which is why that one period under “How long we keep it” is the period we cannot shorten at your request.
  • The technical data of a request — not something you supply, so there is nothing here to withhold: it is produced by the request itself. Submissions are checked automatically before they reach us — a hidden field no human fills in, how long the form took to complete, a limit on how many requests one address may send, a scan for injection-like content, and Cloudflare Turnstile — and a submission Turnstile cannot verify is refused. What each check concluded travels with the submission, so that a real enquiry can be told from an attack.

We never need special categories of personal data for our own purposes, so you are never obliged to provide them. Free-text fields are where people supply more than a request needs — sometimes about other people — and we ask you to write only what your enquiry actually requires.

6. When we did not get your data from you

Almost everything in this policy, you gave us yourself. Article 14 of the GDPR covers the rest, and rather than leave it in a table cell we set out where it applies.

The main case is an administrative contact. When an organisation contracts with us, it tells us who administers the account and who handles billing — a name, a work email address, sometimes a phone number and the role that person holds. We are the controller for that, because we decide to keep it in order to run the contract, and the person concerned is usually not the one who sent it.

The source is the organisation, and it is not a publicly accessible one. The legal basis is our legitimate interest in administering a customer relationship with the people the customer nominated for it (Art. 6(1)(f)) — not the contract itself, because an administrative contact is not a party to it. Where the same person did sign, performance of that contract applies as well (Art. 6(1)(b)). The recipients and the transfers are the ones under “Who we share personal data with” and “International transfers”, since an account adds neither, and the retention period is the one for account and contract data under “How long we keep it”.

Article 14(3) sets the deadline: at the latest when we first communicate with you, and in any event within one month of receiving your details. This policy is linked from the product and from every page of this site, and it is what we point to.

Three smaller cases exist and we would rather name them than let you find them. Your organisation may give us the details of other people it wants us to deal with, in which case the same paragraph applies to them. Someone writing to us may mention you in a free-text field — we ask people not to, and we keep only what the enquiry needs. And the approximate location recorded with a form submission is derived by Cloudflare from your IP address rather than supplied by you, which the table under “Personal data we collect” sets out field by field.

One case is deliberately not here. Where an organisation uses the platform and puts its own people into it — staff accounts, contractors, the guests and clients of its business — we are the processor and it is the controller, so the Article 14 notice is its notice to give, not ours. The Data Processing Agreement names those categories, and “When we are a controller and when we are a processor” above draws the line.

If you want to know exactly what your organisation told us about you, ask us at info@sintora.ai. We will tell you, and we will tell them we were asked only where we have to.

7. What we do not do

A privacy notice is mostly a list of things that happen. This section is the other list, because these are the questions people actually arrive with, and an answer that leaves them open is one you will close yourself, in our disfavour.

  • We do not buy contact data. No list, no data broker, no enrichment service. Everything we hold that identifies you by name came from you or from your organisation — the rest is the technical data your own request produces, which “Personal data we collect” sets out field by field.
  • We do not enrich what you gave us from outside sources. If you give us a LinkedIn address we read it to see who is asking; we do not fetch the profile automatically and we do not add anything to your record from outside.
  • We do not approach people who have not approached us. There is no cold outreach and no prospecting list, and nothing on this site puts you on a list without you asking for it in writing. We do write to an administrative contact a customer nominated, and we do send service, security and legal notices — none of that is marketing, and none of it can be switched off without ending the account it belongs to.
  • We do not send marketing email: no newsletter, no product-update campaign, no email delivery provider — the published sub-processor list names none, and that is the check on this sentence rather than the sentence itself. There is one thing we send unprompted, and it is not marketing: advance notice that these documents or our sub-processors are about to change, to the address you asked us to use for it. Ask at the same address and it is removed.
  • We run no advertising or social-media tracking. The marketing category in our cookie banner is empty and says so, our Cookies Policy states it in the same words, and our content security policy allows no advertising domain at all.
  • We do not fingerprint your device. Our forms used to attach twenty-two attributes read from your browser — platform, screen colour depth, device pixel ratio, touch points, hardware concurrency, device memory, connection speed and the rest — which together are the surface a tracking vendor reads to recognise a device without a cookie. That collection was removed in August 2026 and nothing sends it now. Device and browser type are still recorded with a request, and they are listed as such under “Personal data we collect”; the difference is between what a request produces and what a device is.
  • We do not sell personal data and we do not share it for anyone else’s advertising. The one transfer that is not a sale but can look like one is a merger, acquisition or restructuring, which is listed openly under “Who we share personal data with”.
  • We do not use content to train, fine-tune or improve any generative model, ours or a third party’s, and any sub-processor performing inference is bound by the same restriction. For customer content that is a contractual commitment in the Data Processing Agreement rather than only a statement here; for everything you send us through this website it is a statement here, and there is no model on the other side of these forms. The one thing we do use is aggregated, de-identified statistics — counts, latencies, error rates — that cannot be attributed to you or to any data subject, and we name that exception because the sentence without it would not be true.

If any of this changes, it changes here first, with a dated entry in the legal change log — and where it affects you materially, we tell you before it takes effect rather than after.

8. Cookies and similar technologies

Our website uses strictly necessary cookies for security, delivery and protecting our forms from automated abuse. These do not require consent and cannot be switched off.

Beyond those, the site can remember interface preferences — contrast and text size, currency and billing period, a set you have assembled on the pricing page, and the answers about your company you have already given in a demo or access form. These are stored in your browser and never sent to us, and they are written only if you allow the functional category in the cookie banner. If you decline, nothing is stored beyond the strictly necessary technologies above and the record of your choice; the site works the same, it simply forgets those things between visits and asks a part-finished form again if you reload it.

Measurement of how the page is used is off unless you allow the analytics category. The full inventory, the categories and how to change your choice at any time are in our Cookies Policy.

9. Who we share personal data with

We do not sell personal data. We share it only where necessary, with the following types of recipient.

  • Cloudflare, Inc. — engaged for DNS, content delivery, WAF, DDoS mitigation and bot protection (Cloudflare Turnstile). Which of those are enabled in front of a given property is to be confirmed and is marked as such on our published sub-processor list; the one we can point at today is the Turnstile check on our forms. Where a request does reach us through Cloudflare, it arrives with the approximate location Cloudflare derives from your IP address attached — country, region, city and time zone — and that is recorded with a form submission. Separately, when bot protection runs on a form, your IP address and a challenge token are sent to Cloudflare so it can confirm the submission is not automated; that check answers yes or no and returns nothing else about you.
  • Our hosting provider — the infrastructure the website and our own systems run on, which necessarily processes request data and server logs.
  • Professional advisers such as lawyers, auditors and accountants, where they need the data to advise us.
  • Public authorities and courts, where we are legally required to disclose data or need to defend a legal claim.
  • An acquirer or investor, in the context of a merger, acquisition or restructuring, subject to appropriate confidentiality safeguards.

Each provider acting as our processor is bound by a data processing agreement that permits them to process personal data only on our instructions. The current list of sub-processors used to deliver the platform is in Annex 2 of our Data Processing Agreement; customers on a paid plan are notified in advance of a new sub-processor starting processing, and may object. The length of that notice is to be confirmed and will be stated in that agreement — this policy does not name a figure the agreement does not carry.

10. International transfers

We are established in Estonia and keep personal data within the European Economic Area wherever we can. For the processing described in this policy — the data we hold as controller — one transfer is unavoidable, and we would rather name it than describe it in the abstract.

Cloudflare, Inc. is established in the United States. It is engaged for DNS, content delivery, WAF, DDoS mitigation and bot protection; which of those are enabled in front of a given property is to be confirmed and is marked as such on our published sub-processor list. What we can point at today is bot protection: when it runs on one of our forms, your IP address and the challenge token are transmitted to Cloudflare for verification. The transfer relies on a mechanism recognised under Chapter V GDPR — the EU–US Data Privacy Framework adequacy decision of 10 July 2023 where Cloudflare’s certification under it is current, or the European Commission’s Standard Contractual Clauses. Which of the two applies to our agreement is to be confirmed, and it is marked as such on the sub-processor list rather than stated here as settled; we would rather say that than name an adequacy decision we have not checked is still in force for this recipient.

For the processing in this policy that is the only transfer outside the EEA. The system that receives and routes your enquiry is open-source software we deployed and operate ourselves — it is not a third party we pass your message to. It runs on the infrastructure of our hosting provider, and that provider is named on our sub-processor list; our hosting infrastructure is in the EEA.

Where we act as processor for a customer, the platform’s AI features additionally involve the inference provider engaged for them. That is the customer’s transfer position under that agreement rather than ours under this policy, and it is Annex 2 of the Data Processing Agreement that names the provider, states where its processing sits, and — where processing leaves the EEA — the mechanism it relies on. Annex 2 and the transfer table we publish in the Trust Center are built from the same register, so the two cannot be read as disagreeing.

You may ask us for a copy of the safeguards that apply to any transfer by writing to info@sintora.ai.

11. How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, and then delete or anonymise it. In practice that means:

  • Enquiries and demo requests that do not lead to a contract — 12 months from our last exchange with you, then deleted.
  • Product advisor answers — only what arrives with a request. The advisor runs in your browser and its draft is held there, not by us; if you send it, what you sent becomes an enquiry and follows the first period above, and if you do not, we never receive it and there is nothing here for us to keep.
  • Change-notification addresses — until you ask us to stop, then deleted. We hold nothing else alongside the address.
  • Interaction and attribution data — with the enquiry it arrived on, and for the same period. It is not kept separately, because we run no analytics store of our own.
  • Customer account and contract data — for the life of the contract and 3 years after it ends, which is the general limitation period for contractual claims under Estonian law.
  • Accounting records — 7 years, as required by § 12 of the Estonian Accounting Act. This period is set by law and we cannot shorten it on request.
  • Website and server logs — 30 days, then deleted. They exist to investigate abuse and technical faults, and stop being useful after that.
  • Rate-limiting records — a few minutes. They are held in memory only and are lost when the service restarts.
  • The record that you gave consent — kept for as long as we rely on it and 3 years after it ends, because Art. 7(1) requires us to be able to demonstrate the consent for as long as a claim about it can still be brought. That is the same limitation period as for contract data above.
  • Your cookie choice — 12 months, after which we ask again. You can change or withdraw it at any time from “Cookie settings” in the footer.
  • Records of data protection incidents — 5 years, because we are required to be able to demonstrate how we handled them.

Where a period above has passed but we are required to keep the data for a legal claim that has already been raised, we keep only what that claim needs, and only until it is resolved.

12. How we protect it

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege administration, logging and monitoring, secure development practices and supplier due diligence. Our Security Summary sets these measures out as a control matrix, and states for each one how far it is supported by evidence you can check rather than take on trust.

13. Our records and how changes are tracked

Article 30 GDPR requires a record of processing activities, and there are two of them because we hold two roles.

As a processor, the record of the processing we carry out on a customer’s behalf is set out in our Data Processing Agreement, and we provide the relevant extract on request. As a controller — the processing this policy describes — we keep our own record; it currently covers this website and is a working draft rather than a completed register. We would rather say which of the two is finished than write a sentence that covers both.

Changes to this policy and to the documents around it will be recorded in the legal change log with a date, the documents each one touches and whether the change is material. The revision number at the top of this page identifies the text you are reading, and it will be raised together with any change to that text.

14. AI features and automated decisions

Sintora includes AI features that summarise conversations, draft content, suggest tasks and highlight risks. These produce suggestions for people to act on; they are assistive and remain under human control.

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you: no decision of that kind is taken about you by automated means alone, and we do not score, rank or categorise you in order to take one. If that ever changes, we will tell you and explain the logic involved, the significance and the consequences, and provide the safeguards Articles 13(2)(f) and 22 require.

We do not use customer content, prompts or generated output to train, fine-tune or improve any generative model, whether ours or a third party’s. The same restriction binds any sub-processor performing model inference, through the terms of our agreement with them. The Data Processing Agreement states this as a contractual commitment; the terms behind it are provided on request, since a promise of this kind is worth what the contract under it is worth.

For AI features built into the platform, inference runs on our own account with an inference provider, under terms that do not train on submitted content. That provider is listed as a sub-processor in Annex 2 of the Data Processing Agreement, with its transfer mechanism. The developer of the model it runs is not our sub-processor, because no content of yours reaches them; Annex 2 sets out why, and the model families in use are published in our Trust Center.

Where you connect an AI provider through your own account, inference runs on your account with that provider. The nature of the processing relationship there depends on your configuration and your agreement with that provider; we do not use an account of our own for that inference route, and the terms governing the model are that provider’s, accepted by you directly.

AI features can be switched off for your organisation. Where an AI feature interacts with a person directly, Article 50 of the EU AI Act puts it on us, as the provider of that feature, to design it so the person knows they are interacting with an AI system, and we undertake to do so. That is an undertaking about how we build, not a statement that every interface already carries the disclosure: we keep an internal record of which of our AI systems carry the duty and how far each one is carried, and where the interface that would show it is not yet in place, the record says so.

15. Your rights

Where we are the controller, you have the following rights under the GDPR.

  • Access — obtain confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where one of the grounds in Art. 17 applies.
  • Restriction — have processing limited while a dispute about accuracy or legitimate interests is resolved.
  • Portability — receive data you provided to us in a structured, commonly used, machine-readable format, or have it sent to another controller.
  • Objection — object at any time to processing based on our legitimate interests, by writing to info@sintora.ai or using the form at sintora.ai/privacy/request. We then stop, unless we can show compelling legitimate grounds that override your interests, or the processing is needed for a legal claim; if we stop, the record is deleted. Against direct marketing the right is absolute and there is nothing here to exercise it against — we send none, as “What we do not do” sets out.
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting processing already carried out.

If we correct or delete your data, or restrict its processing, Article 19 requires us to tell every recipient it was disclosed to, unless that proves impossible or would take a disproportionate effort — and to tell you who those recipients are if you ask. The list under “Who we share personal data with” is specific for that reason: a notice that says “various partners” is one you cannot act on.

To exercise a right, write to info@sintora.ai, or use the request form at sintora.ai/privacy/request — it reaches the same mailbox and asks for the same things in a structured way. We respond within one month, which can be extended by two further months for complex requests — we will tell you if that happens. We may need to verify your identity first. There is no reference number: we say so on the form rather than issue one nobody can look up.

16. Complaints

If you believe we have handled your personal data unlawfully, please raise it with us first — we would rather fix it directly. You also have the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work.

Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia.

17. Children

Sintora is a business product and is not directed at children. We do not knowingly collect personal data from children for our own purposes. If you believe a child has provided us with personal data, contact us and we will remove it.

18. Changes to this policy

We review this policy regularly and update it when our processing changes. The revision number at the top identifies the version you are reading, and any change will be listed in the document history. Where a change materially affects you, we will notify you — by email or a notice in the product — before it takes effect.

19. Contact

For any privacy question, or to exercise your rights, contact us at info@sintora.ai, or by post at Sintoralabs OÜ, Narva mnt 7-636, Kesklinna linnaosa, Tallinn, Harju maakond, 10117, Estonia.

We have assessed whether we are required to appoint a Data Protection Officer under Article 37 GDPR and concluded that we are not: we are not a public authority, our core activities do not consist of regular and systematic monitoring of people on a large scale, and we do not process special categories of data on a large scale. We keep that assessment under review and will appoint one, and publish the contact details here, if the position changes.

Sintoralabs OÜ is established in Estonia, so no representative under Article 27 GDPR is required.