Sintora Give Your Company One Brain

Your rights

A request about your data

Access, rectification, erasure, restriction, portability, objection or withdrawal of consent. The form sends your request to info@sintora.ai — the same address named in the privacy policy, and it is that address receiving it that starts the one-month clock.

What happens to the request

Every step, with the period the regulation sets, the channel, who acts, and the state it is in: in place, carried out by a person, or non-existent.

9 steps: 6 in place, 2 carried out by a person with nothing recording it, 1 that does not exist.

In place
The step happens, and the row names the document or file where that is written down. Beside it is what the step does not cover.
By hand
A person carries the step out, and no system on this site records that it was. The row names where the evidence stops.
Does not exist
This does not exist. The row names what is missing and what stands in its place.
Data-subject request register: the step, its state, the statutory period and what it rests on
You send the request The form on this page · You In placeArt. 12(2) GDPR sets no period
  • The request form the form that collects the request type, your relationship to the data and the request itself
  • Privacy Policy → Your rights the right is exercised by writing to info@sintora.ai or through this form — the policy names both routes
What this does not cover: The form is a convenience rather than the only channel: an e-mail to the same address carries the same weight and starts the same clock. Art. 12 prescribes no mandatory form of request.
The request reaches the mailbox The info@sintora.ai mailbox · Sintoralabs OÜ By hand— no provision governs this step
  • the only route by which the site sends anything anywhere: form → checks → the n8n webhook, and no store in between
  • the message opens with a [GDPR DSAR] marker so the request can be told apart in a shared mailbox
What is missing: What n8n does with the message next is outside this website: the webhook address comes from an environment setting, and the route behind it is not visible from the site’s side. That the request reaches a person who will handle it is confirmed by the owner rather than by the site’s code.
Logging the request, and a reference number No channel · You Does not exist— no provision governs this step What is missing: There is no case-tracking system: the site has no database, no file store and nowhere else it could write anything down, so no identifier is generated, no state is kept and there is nowhere to check a status. The record of sending is the one you keep — the Art. 12(3) period runs from the date we received the request.
We check that it is you The info@sintora.ai mailbox · Sintoralabs OÜ In placeArt. 12(6) GDPR sets no period
  • Privacy Policy → Your rights the policy states plainly that identity may need to be confirmed before we answer
  • the form asks you not to send identity documents: if they are needed we will ask separately
What this does not cover: No procedure is written down — which details we ask for, and when; the scope is set per request. Art. 12(6) permits asking for further information but sets no period of its own, and we make no claim that an identity check suspends the one-month clock.
We answer on the merits The info@sintora.ai mailbox · Sintoralabs OÜ In placeArt. 12(3) GDPR one month from receipt; extendable by two further months for complex requests, with notice of the reason What this does not cover: The period is an obligation rather than a measurement: we publish no actual response times, keep no statistics of requests and state no service level on top of Art. 12(3).
If the controller is our customer rather than us The company that controls the data · The customer, as controller In placeArt. 28(3)(e) GDPR sets no period What this does not cover: Without the controller’s documented instructions we do not answer on the merits — we pass your request on to them. The Art. 12(3) period is theirs to keep in that case, and going to them directly is faster.
We tell recipients about a correction or a deletion The info@sintora.ai mailbox · Sintoralabs OÜ By handArt. 19 GDPR sets no period
  • Privacy Policy → Your rights the obligation to tell every recipient about a correction, deletion or restriction — and to name the recipients if you ask
  • The sub-processor list the list of recipients is published by name, so who would have to be told can be checked without us
What is missing: The website keeps no log of Art. 19 notices: it is an action taken off the site and it leaves no trace here.
Cookie preferences — without a request Your browser · You In placeArt. 7(3) GDPR sets no period
  • the “Cookie settings” button in the footer opens the current choice and allows it to be changed
  • Cookies Policy the categories, the lifetimes and how consent is withdrawn
What this does not cover: The demo and access request pages carry no footer, so the settings open from any other page on the site. The record of the consent itself lives in a cookie under your control: clearing browser storage removes it along with the choice.
A complaint to the supervisory authority The supervisory authority · You In placeArt. 77 GDPR sets no period What this does not cover: A step outside our process: neither the time it takes nor the outcome depends on us. A complaint can also be lodged with the authority where you live or work.

Every row was checked against this website’s own code and the published documents on 3 September 2026.

Send the request

Whose data is it required

What exactly you need and, if you know it, which form or address you contacted us through. Do not send identity documents — if they are needed, we will ask separately. Characters remaining: 4500

Along with what you entered above, the server records the technical data of the request: IP address, browser, language, the page the form was sent from, and an approximate country, region, city and time zone from Cloudflare — the same as for any other form on the site. What this form does not collect, unlike the rest, is campaign and referral data: we have no need to attribute a privacy request.

Which rights this covers

Eight rights under the GDPR over the data where we are the controller. The last one is exercised through the supervisory authority rather than through us.

  • Access Get a copy of your personal data.
  • Rectification Correct inaccurate data.
  • Erasure Request deletion where it applies.
  • Restrictions Restrict certain processing.
  • Portability Receive your data in a portable format.
  • Objection Object to processing based on legitimate interests — we stop, unless we can show compelling legitimate grounds. Against direct marketing the right is absolute, but there is nothing to object to: we do none.
  • Withdraw consent Where processing relies on consent. Cookie preferences sit in the page footer.
  • Complaint To the Estonian Data Protection Inspectorate, or to the authority where you live or work.

The full text is in the privacy policy: the “Your rights” section.