Sintora Give Your Company One Brain
Trust Center

Trust Center

Data residency

Sintoralabs OÜ is established in Estonia, and the infrastructure sits within the European Economic Area. Below is what that means concretely, with the document behind every line, and separately what we deliberately do not publish. The providers are named on the sub-processor list; the specific regions are marked there as awaiting confirmation.

What we can prove

Every line leads to the document it is written in.

  • The company and the jurisdiction

    Sintoralabs OÜ is registered in Estonia, registry code 17456201. Our lead supervisory authority is the Estonian Data Protection Inspectorate, Tatari 39, 10134 Tallinn. No representative under Art. 27 GDPR is required, because the company is established in the EU.

    Privacy Policy → Complaints, Contact
  • Infrastructure

    Compute, storage and backups for the website and the platform are with the provider named on the sub-processor list, engaged for locations within the European Economic Area. How well each line is proven — region, zone, configuration — is marked on the list itself, beside the value.

    Security Summary → Infrastructure and data residency
  • Виділений сервер Sintora Meetings

    The same infrastructure as the rest of the platform Awaiting confirmation: the dedicated server’s specification (vCPU, memory, disk), the site it is deployed in, and what happens to the environment once the agreement ends

    Ціни Sintora Meetings
  • Handling enquiries

    The system that receives and routes enquiries from the forms is open-source software we deployed and operate ourselves, on the infrastructure of our hosting provider inside the EEA. It is us processing the data rather than a third party we hand it to, which is why it is not on the sub-processor list — while the provider whose infrastructure it runs on is.

    DPA → Annex 2
  • What leaves the EEA anyway

    Not every sub-processor keeps processing inside the EEA. Where it leaves, the transfer relies on a Chapter V GDPR mechanism — the recipient, the direction and the mechanism are named in the transfers table, together with whatever in each row is still awaiting confirmation.

    Data transfers — provider, direction, mechanism
  • Backups

    Regular encrypted backups are stored separately from production. Frequency, retention, recovery objectives and the date of the last restore test are provided on request rather than published.

    DPA → Annex 3, Backup and recovery

What we do not publish

Each refusal is named outright, with its reason and with how to get the answer another way. What we have not confirmed yet is not here: it is marked on the sub-processor list itself, because “we will not say” and “we do not know yet” are different answers.

  • Exact configuration parameters

    Versions, intervals and thresholds are provided on request under NDA rather than published.
  • Per-customer residency

    Placement outside the EEA at a customer’s choice is not offered today. If it is your requirement, it is settled by a signed agreement rather than by a switch in the settings.
  • A public status page

    There is none. Availability and error monitoring stands in the Security Summary control matrix as to be confirmed, and the row names what is missing.

Everything listed above is provided on request under NDA — write to info@sintora.ai and describe what your security review needs. If a specific region is a hard requirement of your procurement, say so early: we name the providers publicly, and the specific region is not yet confirmed.

“Within the EEA” is not the whole answer

The infrastructure is in the EEA, and for 1 of the 3 sub-processors processing still leaves it. The recipient, the direction and the mechanism are named in the transfers table.

Data transfers