Last updated: 28 August 2026
Nextsense Solutions LLC FZC, trading as Syntrum ("Syntrum," "we," "our," or "us"), values the privacy of the people who use our website and services (together, the "Services"). This Privacy Policy explains how we collect, use, and share personal data when providing the Services.
Syntrum provides autonomous AI agents that operate inside a customer's existing tools such as chat, email, file storage, code hosting, calendars, and record systems. This means that, in addition to data we collect about our own users, our Services process data belonging to our customers and to people our customers interact with. Section 6 explains that distinction and which rules apply to each.
Your use of the Services is also subject to our Terms of Service.
1. Personal Data We Collect
Registration and profile data. Name, username, email address, and company or role information associated with your account. If you sign up through a third-party account such as Google, we receive the data associated with that account consistent with your settings on that service.
Workspace and collaboration data. Data about the workspaces, teams, and members using the Services, including roles, permissions, agent configurations, approvals, and interactions with agents and their output.
Connected service data. Where you connect a third-party system to the Services, for example email, chat, file storage, calendar, code hosting, or a customer relationship management system, we access and process data from that system in order to run the agents you configure. Depending on the systems you connect and the permissions you grant, this may include the content of messages and documents, contact and calendar information, and records held in those systems. You control which systems are connected and can disconnect them at any time.
Agent activity and output. Records of what agents do on your behalf: tasks created and completed, tool calls made, documents and records produced, approvals requested and granted, and the audit trail we maintain so that agent activity can be reviewed after the fact.
Usage and interaction data. Data about how you interact with the Services, including pages viewed, features used, actions taken, and the dates and times of your visits.
Communications. Data contained in communications with us, including your name, email address, message content, and any attachments you send.
Payment and transaction data. Billing details, subscription type, and transaction amounts. Payment card data is collected and processed by our payment provider; we receive only limited data such as the last four digits of a card and the payment method.
Device data. IP address, browser type, operating system, device type and identifiers, and similar technical data.
Location data. We may infer your general region from your IP address. We do not collect precise location data.
2. How We Collect Personal Data
From your use of the Services. When you register, configure agents, connect systems, review approvals, and otherwise interact with the platform.
Automatically. Through system-generated logs, events, cookies, and similar technologies.
From systems you connect. When you authorise a connection to a third-party system, we receive data from that system according to the permissions granted. Connections are established and maintained through our integration and authentication provider, which stores the authorisation credentials on our behalf.
From your organisation. Where an employer or workspace administrator manages your access to the Services, we may receive data from them in order to provision and manage your account.
From third parties. Including authentication providers, integration partners, and data or marketing partners.
In connection with legal matters. Including from law enforcement, government agencies, or parties to a claim or dispute.
3. How We Use Personal Data
- To provide the Services: creating and managing accounts and workspaces, running agents, executing the actions you approve, maintaining memory and context so agents can do their work, and producing output in your connected systems.
- To communicate with you: service updates, responses to requests, and customer support.
- To operate and improve the Services: troubleshooting, monitoring, security, understanding how features are used, and product development.
- For safety and abuse prevention: detecting, preventing, and investigating fraud, abuse, and security incidents.
- For marketing: where permitted, sending promotional communications and measuring their effectiveness. You can opt out at any time.
- For legal and compliance purposes: meeting our legal obligations and enforcing our agreements.
4. AI Models and Training
Our Services use large language models provided by third-party model providers. To generate agent output, relevant data, which may include content from the systems you connect, is sent to those providers for processing.
We do not use customer content to train AI models, and our model providers are contractually prohibited from using it to train their models.
The current list of model providers we use is available on our Subprocessors page.
5. Google User Data
Where you connect a Google service (Gmail, Google Drive, or Google Calendar), Syntrum accesses that data only to operate the agents you have configured, and only within the permissions you grant when authorising the connection.
Limited Use. Syntrum's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the features you have connected it to.
- We do not use Google user data for advertising, and we do not sell it.
- We do not transfer Google user data to third parties except as necessary to provide the Services (for example our hosting, integration, and AI model providers), to comply with applicable law, or in connection with a merger or acquisition following notice to you.
- We do not allow humans to read Google user data unless we have your explicit consent for specific messages or files, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and de-identified.
- Google user data is not used to train AI models.
You can review and revoke Syntrum's access at any time through your Google Account permissions, and disconnect the integration from within your Syntrum workspace.
6. How We Share and Disclose Personal Data
Service providers. Vendors that process data on our behalf, including hosting and cloud infrastructure, integration and authentication infrastructure, AI model providers, analytics, payment processing, customer support, security, and professional advisers. A current list is available on our Subprocessors page, where you can also subscribe to notifications of changes.
Within your organisation. Where your employer or organisation uses the Services, data about your activity and agent output may be available to workspace administrators and other members according to the permissions configured.
Third-party systems you connect. When you configure an agent to act in a connected system, we send data to that system to carry out the action, for example writing a document, updating a record, or sending a message you have approved.
As required by law. Where we believe in good faith that disclosure is required or appropriate to respond to legal process or to protect the rights, property, or safety of any person.
Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets.
With your consent. Or otherwise at your direction.
We do not sell personal data.
We use Google Ads to measure whether our advertising brings people to our website, and to show our own ads to people who have visited it. Where you have accepted advertising cookies, some US state privacy laws — including California's — may treat that as sharing personal information for cross-context behavioural advertising. We say so plainly rather than rely on the narrowest reading of those terms.
This applies only to visitors to our public website who accept advertising cookies. It never applies to data we process on behalf of a customer, and it never involves the content of your connected tools or agent activity. You can stop it at any time — see Cookies and Similar Technologies.
7. Data We Process on Behalf of Customers
Much of the data flowing through the Services does not belong to us or to the individual user. It belongs to our customers.
Where Syntrum is a processor. When a customer connects their systems and deploys agents, the customer decides what data is processed and for what purpose. Syntrum acts as a processor (or service provider) and handles that data only on the customer's documented instructions, under our Data Processing Addendum. This includes data about the customer's own employees, and data about third parties such as prospects, candidates, suppliers, or customers of our customer, that enters the Services through a connected system or an agent's activity.
If your data is in a customer's workspace. If you believe an organisation using Syntrum holds your personal data, that organisation is responsible for it and you should direct your request to them. If you contact us, we will refer you to the relevant customer or assist them in responding, as our agreement with them requires.
Where Syntrum is a controller. We are the controller for data described in Section 1 that relates to our own users, our website visitors, and our business operations. This Privacy Policy governs that data.
8. Your Privacy Rights and Choices
Depending on where you live, and subject to limits under applicable law, you may have the right to:
- Access and portability: obtain a copy of the personal data we hold about you and details of how we use it.
- Deletion: request that we delete your personal data. We may retain certain data where law permits or requires it.
- Correction: have inaccurate data corrected.
- Objection and restriction: object to or restrict certain processing.
- Withdraw consent: where processing is based on consent.
- Appeal: challenge a decision we make about a privacy request.
- Opt out of sale or sharing: we do not sell personal data. Our advertising cookies may amount to sharing for cross-context behavioural advertising, and you can opt out at any time by selecting Reject in the cookie banner, or by clearing Syntrum site data so the banner appears again. We also honour the Global Privacy Control signal: if your browser sends one, we treat it as a rejection and never ask.
To exercise any of these rights, email contact@syntrum.io. We may need to verify your identity before responding. An authorised agent may submit a request on your behalf with written authorisation. We will not discriminate against you for exercising your rights.
If you have a concern about how we handle your personal data, please contact us first so that we can try to resolve it. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority.
Marketing. You can unsubscribe from marketing emails using the link in any such email. You will still receive transactional messages relating to your account.
9. Legal Bases for Processing
Where the GDPR or similar law applies, we rely on the following legal bases:
- Contractual necessity: to provide the Services you have signed up for.
- Legitimate interests: to operate, secure, analyse, and improve the Services, and to market to business contacts, where those interests are not overridden by your rights.
- Consent: where required, for example for certain cookies and marketing communications.
- Legal obligation: to comply with applicable law, including tax and accounting requirements.
10. International Transfers
Syntrum is established in the United Arab Emirates. The servers used to deliver the Services are located in the United Kingdom. Personal data may also be processed by our service providers in other countries, as set out on our Subprocessors page.
Transfers of personal data from the European Economic Area to the United Kingdom are covered by the European Commission's adequacy decision for the United Kingdom, and require no additional safeguard.
Where personal data is transferred from the European Economic Area or the United Kingdom to a country without an adequacy decision, including access by our personnel in the United Arab Emirates, we rely on appropriate safeguards. These include the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and, where relevant, the Swiss addendum. Copies of the relevant safeguards are available on request, and the clauses are annexed to our Data Processing Addendum.
11. Cookies
We use cookies and similar technologies, including browser local storage and session storage, on our website and in the Services. These technologies currently fall into the following categories:
- Strictly necessary: required to provide requested features, maintain account sessions, secure authentication flows, and remember your cookie choice. These cannot be switched off through the consent banner.
- Functional: remember settings you request, such as theme and sidebar preferences.
- Analytics: help us understand how the Services are used, diagnose errors, and improve the product. We use these only after you select Accept in the consent banner where consent is required.
- Advertising: measure whether a visit that began with one of our ads led to a sign-up, and allow us to show our own ads to people who have visited the site. Advertising cookies are set only after you select Accept in the consent banner. Before you accept, the Google Ads tag runs in a restricted mode described below, in which it sets no cookies.
Technologies currently in use
| Technology | Category | Purpose | Typical duration |
|---|---|---|---|
syntrum-cookie-consent browser storage |
Strictly necessary | Records whether you accepted or rejected optional analytics and advertising cookies so we can respect your choice. | Until you clear site data |
| Authentication tokens in local or session storage | Strictly necessary | Keeps you signed in and authorises requests to the Services. | Until sign-out, token expiry, or the browser session ends, depending on your sign-in choice |
| OAuth and CSRF security cookies | Strictly necessary | Protects sign-in and connected-service authorisation flows against request forgery. | Short-lived or for the browser session |
syntrum-theme browser storage |
Functional | Remembers your selected light or dark appearance. | Until you clear site data |
sidebar_state cookie |
Functional | Remembers whether the application sidebar is open. | 7 days |
PostHog browser storage, including ph_<project-token>_posthog |
Analytics | Measures visits and product interactions and helps us diagnose errors. | Up to 12 months |
Google Ads tag (gtag.js), including the _gcl_* cookies it sets |
Advertising | Measures conversions from our advertising and supports remarketing to previous visitors. Cookies are set only after you accept. | Up to 90 days |
Google Consent Mode
The Google Ads tag loads on every visit to our public website, but it starts with Google Consent Mode set to deny advertising and analytics storage. While that is the case, the tag does not write cookies to your browser and does not store an advertising identifier. It sends Google a measurement signal that carries no identifier and that Google uses to estimate, in aggregate, how many visits our advertising produced. We also enable Google's data redaction setting, which removes advertising click identifiers from those signals.
If you select Accept, the tag is permitted to set the advertising cookies listed above and to measure your visit directly. If you select Reject, or leave the banner unanswered, it stays in the restricted mode described here for as long as you use the site, and no advertising cookies are set.
These cookies serve our own advertising only. We do not use them to build profiles for anyone else, and we do not allow other advertisers to target you through them.
If your browser sends a Global Privacy Control signal, we treat it as a rejection: the tag stays in the restricted mode described above, no advertising cookies are set, and the banner does not appear.
When the banner appears, selecting Reject prevents optional analytics from being initialised and keeps the advertising tag in the cookieless mode described above. Selecting Accept enables them and stores your choice on that browser. You can withdraw or reset your choice by clearing Syntrum site data in your browser; the banner will appear again on your next visit. You can also block or delete cookies through your browser settings, though some features may stop working.
12. Data Retention
We keep personal data for as long as needed to provide the Services and for the purposes described in this Policy, after which we delete it or keep it in de-identified form. Retention periods depend on the type of data and the reason we hold it, including any legal, tax, or accounting obligations.
Data processed on behalf of a customer is retained according to that customer's configuration and our agreement with them, and is deleted following termination as set out in the Data Processing Addendum. Data may persist in encrypted backups for a limited period after deletion.
13. Security
We use technical, organisational, and physical measures designed to protect personal data, including encryption in transit and at rest, access controls, workspace isolation, credentials scoped to each agent, and logging of agent activity. No system can be guaranteed completely secure, but we work continuously to protect the data in our care.
14. Children
The Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Third-Party Sites and Services
The Services may link to or connect with websites and services we do not operate. This Policy does not apply to them, and we are not responsible for their practices. We encourage you to read their privacy policies.
16. Changes to This Policy
We will post any changes to this page and update the date above. If the changes are material, we will provide notice as required by law.
17. Contact Us
Questions about this Policy or how we handle personal data:
Email: contact@syntrum.io Post: Nextsense Solutions LLC FZC, CWS-2V-195841, 26th Floor, Amber Gem Tower, Sheikh Khalifa Bin Zayed Street, Al Rashidiya 3, Ajman, United Arab Emirates

