Legal
Privacy Policy.
Last updated: September 2026
This policy is issued by Synalogic Solutions Pty Ltd (ABN 72 699 931 738). Synalogic Solutions operates this website and the Synalogic Platform, contracts with customers, and holds the personal information described here. In this policy, “Synalogic”, “we”, “us” and “our” mean Synalogic Solutions Pty Ltd.
“Synalogic” is a registered trademark of Synalogic Pty Ltd (ABN 45 691 043 320), a related company that holds our intellectual property. Synalogic Pty Ltd does not collect or hold personal information under this policy and does not contract with customers.
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what we collect, why, where it is held, and how to contact us about it.
We operate the Synalogic Platform, an AI trust platform for professional workflows. Customers use it to apply AI to high-stakes work such as compliance, audit, legal review, contract analysis and evidence review, where the outputs need to be defensible. How we handle personal information depends on your relationship with us. This policy covers both cases.
1. The Two Ways We Handle Personal Information
We handle personal information in two roles. The rest of this policy says which role applies where it matters.
1.1 As a controller — for visitors, prospects, applicants and Platform users
When you use a form on this website, register for a demo, apply to work with us, or use the Platform under a subscription, we decide how and why your information is handled. Section 2 describes what we collect in this role.
1.2 As a processor — for content provided by our customers
Customers use the Platform on their own professional work. The content they upload, generate or store — contracts, evidence documents, audit findings, asset records, risk assessments — may contain personal information about their staff, suppliers, contractors or other people. We process that information only on the customer’s documented instructions, under the data processing agreement (DPA) we hold with them.
If your personal information is in customer content and you want to exercise rights over it, contact that customer first. We will help you find the right contact if you need it (section 11).
2. Information We Collect as a Controller
2.1 Information you give us through website forms
Each form collects only what it needs. All form data is stored in Google Cloud Firestore in the australia-southeast1 (Sydney) region.
| Form | What we collect |
|---|---|
| Demo registration | Name, email, company, role, phone, area of interest, your message, your acceptance of the Demo Access Terms and the version you accepted, a visitor identifier, and the page you registered from |
| AI governance health check | Name, email, company, role, your 12 answers, your maturity score and level, per-domain scores, what prompted the check, where you are deploying AI, and your ISO 42001 status |
| ROI calculators | Name, email, company, role, the financial inputs you enter, and the calculated outputs |
| Contact and workshop enquiries | Name, email, company, role, and your message |
| Careers | Name, email, LinkedIn URL, the role you are applying for, and your note to us |
If you hold a Platform account we also collect your login email and role assignments. We keep records of our communications with you.
2.2 Information we collect automatically
When you visit the site we collect your IP address, browser type, pages visited and referring page.
When you register for a demo we assign you a visitor identifier. We use it to record that you accepted the Access Terms, to show you the demo, and to record how far through it you got during that session.
Every form is protected by Firebase App Check using Google reCAPTCHA Enterprise. When you submit a form, Google evaluates signals from your browser and device to assess whether the request comes from a person. Google processes those signals under its own terms and may do so outside Australia. We use the result only to block automated abuse.
If you are a Platform user, we log usage events (logins, feature use, errors) against your account.
2.3 Sensitive information
We do not ask for sensitive information (as defined in the Privacy Act — health, racial or ethnic origin, sexual orientation, religious beliefs, criminal history and similar) through any of our forms. Free-text fields are for the purpose stated on the form. Please do not put sensitive information in them. If you include sensitive information in a job application, we use it only to assess that application. Sensitive information in customer content is processed only under the customer’s instructions and our DPA.
3. How We Use the Information
We use information collected as a controller to:
- respond to your enquiry and tell you about our products and services
- run the demo you registered for and enforce the Demo Access Terms (section 3.1)
- give you your health check or ROI results
- follow up on your interest in Synalogic, by email or phone (section 3.2)
- assess your application if you apply to work with us, including contacting referees you nominate
- operate, secure and improve the website and the Platform
- tell Platform users about their account and about material changes to our terms or policies
- detect and respond to security events
- meet our legal obligations
3.1 Demo watermark and attribution
The demo is confidential material. When you view it, your first name is shown as a watermark on screen and your viewing is recorded against your registration. This is deliberate. It lets us attribute any unauthorised copy or disclosure to the person who accepted the Access Terms. If you do not want your viewing to be attributable to you, do not register for the demo.
3.2 Our sales records
If you submit the demo, health check, ROI or contact forms, we copy your details into our customer relationship management (CRM) system. The CRM runs in a separate Google Cloud project, also in the Sydney region. There we hold a contact record for you and a history of what you did on our site: forms submitted, demo viewed, results generated. We use this to understand your interest and to follow up with you. You can ask us to delete this record at any time (section 7).
We do not copy job applications into the CRM. Applications are held separately and seen only by the people involved in recruitment.
3.3 AI processing of customer content
Where personal information appears in customer content in the Platform, that content may be processed by AI services inside the Google Cloud region chosen for the customer’s deployment. The region is recorded in the DPA. Our terms with our AI service provider prohibit it from retaining customer content or using it to train models. Before content is sent to an AI service, a sanitisation step in the Platform screens it to reduce the personal information exposed.
3.4 Automated processing
The health check calculates your score and level automatically from your answers. That is information for you, not a decision about you. We do not make recruitment decisions, or any other decision that affects an individual, by automated means alone. In the Platform, AI-generated outputs are presented to human reviewers, who make the resulting decisions.
4. Where Personal Information Is Held and Processed
4.1 Customer content in the Platform
The Platform is deployed in the Google Cloud region each customer selects. Customer content — the documents, data and AI-generated outputs in a customer’s workspace — is processed and stored in that region. It does not leave that region unless the customer changes their deployment. The region is recorded in the DPA.
4.2 Information we collect as a controller
Information you give us through the website, and our CRM records, are stored in Google Cloud in the australia-southeast1 (Sydney) region. We do not use third-party marketing or email-delivery processors for this data. Analytics cookies are set only with your consent (section 6).
Two Google services process some data outside Australia:
- reCAPTCHA Enterprise (section 2.2) processes browser and device signals wherever Google operates that service.
- Email. We send and receive email through Google Workspace (Gmail) from contact@synalogic.com.au and careers@synalogic.com.au. Google Workspace stores email in Google’s data centres, which may be outside Australia.
Google handles this data under the Google Cloud and Google Workspace data processing terms, which commit Google to protections consistent with the Australian Privacy Principles. We do not send personal information overseas for any other purpose.
4.3 Business communications with advisers
In running the business we correspond with professional advisers (lawyers, accountants, auditors), partners and other third parties. Some are outside Australia. Where that correspondence contains personal information, we require the recipient to handle it consistently with our obligations to you, through written agreement, professional confidentiality obligations, or both.
4.4 Legal and corporate disclosures
We may disclose personal information to government authorities if required by law, court order or regulatory direction. If the business is reorganised, merged or sold, personal information may pass to the successor, who will be bound by terms no less protective than this policy.
We have never sold, rented or traded personal information and do not intend to.
5. Data Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Our measures include:
- Encryption in transit (TLS) and at rest, using Google Cloud’s encryption of stored data
- Role-based access control and multi-factor authentication on all Synalogic accounts
- Logging and monitoring of Platform and infrastructure activity
- Vulnerability management and regular security review
- Privacy and security training for everyone who works at Synalogic
- A documented incident response plan
Synalogic Solutions operates an information security management system aligned with ISO/IEC 27001:2022 and is in the process of obtaining certification, and an AI management system aligned with ISO/IEC 42001:2023. We will notify affected individuals and the Office of the Australian Information Commissioner of eligible data breaches under the Notifiable Data Breaches scheme.
6. Cookies and Tracking
We use strictly necessary cookies to run the site and keep it secure, including reCAPTCHA Enterprise on our forms (section 2.2). These are always on because the site does not work without them. We set optional cookies, such as analytics, only with your consent. You can accept, reject or set your preferences in the cookie banner when you first visit, and change your choice at any time through the “Cookie settings” link in the footer. When you register for a demo we also assign the visitor identifier described in section 2.2. Disabling cookies in your browser may stop some parts of the site working, including the demo. We do not use cookies to track you across other sites.
7. Your Rights
Under the Privacy Act you can:
- Access the personal information we hold about you
- Correct it if it is inaccurate, incomplete or out of date
- Ask us to delete it, subject to our legal and contractual obligations
- Opt out of follow-up contact at any time
- Complain if you think we have breached the APPs
To do any of these, email privacy@synalogic.com.au. If it concerns a job application, email careers@synalogic.com.au. We will acknowledge your request promptly and respond within the time the Privacy Act requires.
If your personal information is in customer content held in the Platform, contact that customer first. We will help identify the right contact and will support their response.
7.1 If you are outside Australia
We are an Australian company. Your information is held in Australia and handled under Australian law. We do not direct our services at people in the European Union or the United Kingdom. If you use our forms from those places, the rights above apply to you the same as to anyone else. If the GDPR or UK GDPR does apply to you, you may have additional rights. Contact us and we will deal with your request.
8. How Long We Keep Your Information
8.1 Customer content held in the Platform
Retention and deletion of customer content is governed by each customer’s contract and DPA, and is agreed with that customer. Terms vary between customers. If your personal information is in customer content, that customer’s terms determine how long it is kept.
8.2 Records of our operations
We keep security and infrastructure logs (metadata about activity such as timestamps, identifiers and content hashes, not the underlying content) for the period required by our information security management system and Australian record-keeping obligations. These logs do not contain the content of customer documents.
8.3 Website and CRM records
We keep the information you submit through the website, and the CRM record built from it, until you ask us to delete it or until we no longer need it for the purposes in section 3. We are introducing fixed retention periods for each type of record and will publish them here when they are in place.
If you apply for a role and are not successful, we delete your application within six months of the role closing unless you agree to us keeping it to consider you for future roles. You can ask us to delete it at any time by emailing careers@synalogic.com.au.
9. Children
This website and the Platform are for professionals at work. They are not directed at anyone under 18, and we do not knowingly collect information from minors. If you think a minor has given us personal information, email privacy@synalogic.com.au and we will delete it.
10. Third-Party Links
The website and the Platform may link to other sites. We are not responsible for their privacy practices. Read their policies.
11. Contact Us
For questions about this policy, to access or correct your information, or to complain about how we have handled it:
Synalogic Solutions Pty Ltd
privacy@synalogic.com.au
For job applications: careers@synalogic.com.au
We will acknowledge your message promptly and respond substantively within the time the Privacy Act requires.
12. Complaints
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001
If you are in the EU or UK and the GDPR or UK GDPR applies to you, you may also contact your local supervisory authority.
13. Changes to This Policy
We may update this policy. Material changes will be posted here with a new revision date. If a change is significant, we will email Platform users.
14. Governing Law
This policy is governed by the laws of New South Wales, Australia. Disputes are subject to the exclusive jurisdiction of the courts of New South Wales.