Trust Center
Your data. Protected by design.
Sintora is built on an EEA-first architecture: tenant isolation, controlled access, logging of significant actions and managed AI processing. What you need in order to assess security, privacy and data processing is gathered here.
Current status
Every value below is read from the sub-processor list and from the document registry. Where a statement is not yet confirmed it is marked as such rather than shown as a fact.
- Primary data hosting
- Hetzner Online GmbH EEA Awaiting confirmation: the specific region and availability zone
- Sub-processors 3 Active providers on the published list, each with its purpose and its location. Open the list
- International transfers Limited and disclosed — 1 of 3
- Cloudflare, Inc. · US / global edge DPF or the Standard Contractual Clauses, where applicable Awaiting confirmation: whether the DPF certification is current and whether our contract carries the Clauses
- Latest log entry No entries yet Every document is in force — the date each came into force is on its card below. Changelog
What you can check
The areas a security assessment goes through. Each leads to the page or the document where it is written down.
- Security Access control, encryption, tenant isolation, logging and incident response. Open
- Privacy Which personal data we process, on what basis, and for how long we keep it. Open
- AI and your data Four guarantees, the route an AI request takes, the boundary between infrastructure and models, and the roles under Art. 50(1) of the AI Act. Open
- Sub-processors Who processes data to deliver the service, for what, and where. We give advance notice of a replacement, as the current DPA provides. Open
- Data residency Providers engaged for locations within the EEA, Estonian jurisdiction — and what leaves the EEA. Open
- Data Processing Agreement The processor obligations under Art. 28 GDPR: security measures, sub-processors, transfers, incident notification. Open
How data and AI requests move
Every step below is a boundary named in a published document. There is no description here of which context reaches a model for a given feature, because there is none in the documents either.
- Customer (controller)
You load data into the platform. For that data you are the controller and we are the processor, acting on your documented instructions.
- Sintora tenant
Each customer is a separate tenant, and data is segregated so that one tenant cannot read or affect another’s.
- Roles and permissions
Access is determined by roles and permissions that you configure, scoped by network, object or team. Significant actions are recorded in a log inside your tenant on paid plans.
- Synapse and the products
Modules and industry solutions run inside your own tenant on a shared data model — isolation, permissions and audit stay the same across them. On the Advanced tier of Sintora Meetings the compute Meetings runs on is dedicated — inside that same tenant and that same data model.
- Controlled AI processing
Built-in AI features reach the inference provider through our own account. Your input and the output generated for you are not used to train models, and the features themselves can be switched off for your tenant.
- Inference infrastructure
Scaleway SAS
AI inference using agreed models on Scaleway infrastructure
Location: France / EEA Awaiting confirmation: the specific region
Documents
The status and the revision number on each card are read from the document registry, so a card and the document it names cannot disagree.
Legal
- Terms of Use In force Rights of use, your content, AI features, liability, termination and governing law. Revision 1.0 · In force from: 8 September 2026 View
- Privacy Policy In force Which personal data we process, on what basis, how long we keep it and what rights a data subject has. Revision 1.0 · In force from: 8 September 2026 View
- Data Processing Agreement In force The processor's obligations under GDPR: subject matter and duration of processing, security measures, subprocessors, international transfers, incident notification. Revision 1.0 · In force from: 8 September 2026 View
- Cookies Policy In force Which cookies the site sets, why, for how long, and how to withdraw consent. Revision 1.0 · In force from: 8 September 2026 View
Security
Transparency
- The sub-processor list Who processes data in order to deliver the service, with the purpose, the categories of data and the location for each. Providers: 3 View
- Changelog Where editions of the terms, the DPA and the policies are recorded — with a date, a list of changed documents and a marker for whether the change is material. Entries: 0 View
Need more information
Anything that needs a signature, your company details or your questionnaire is marked “on request” below — without those it does not exist at all. One mailbox reads all of them, info@sintora.ai.
- A DPA to sign on request The same document in a signable format, with your company's details and, if needed, the SCCs as an annex. Write to us
- Answers to a security questionnaire on request We will fill in your form, or send our own set of answers if you have no template of your own. Write to us
- Privacy request Access, rectification, erasure and the other applicable rights — through the form or by writing to the same address. Open the form
- Anything else A question about security, data processing or procurement — write to us and we answer from the same address. Write to us