1. General Information and Roles of the Parties
This Privacy Policy describes the rules for processing and protecting personal data in the Synomi web service and in the Synomi mobile application provided by Synomi.
Synomi is a service intended for businesses (B2B) and is not directed at persons under 18 years of age; we do not knowingly collect data of minors.
In accordance with Regulation 2016/679 (GDPR), Synomi acts in two different roles depending on the type of data processed:
- As a Data Controller — with regard to the User's Synomi account data (first name, last name, email address, phone number, correspondence address, company data, payment data, technical logs), i.e. data collected directly to provide the Synomi service and operate the account.
- As a Processor within the meaning of Art. 4(8) and Art. 28 GDPR — with regard to the data that the User enters or generates in the Synomi system in the course of their business (client data, invoice content, receipts and accounting documents, voice recordings/transcripts, document photos, GPS routes in the mileage log). The Controller of this data is the Synomi User (Art. 4(7) GDPR), and Synomi processes it solely on the User's documented instructions. The detailed terms of data processing are set out in section 9 of the Synomi Terms and Conditions.
Synomi contact details:
Synomi
's-Gravelandseweg 397, 3125 BJ Schiedam, Netherlands
KvK: 64597237
Email: hello@synomi.ai
2. Scope of Collected Data
As part of our services, we collect the following personal data:
- Identification data: first name, last name, company name
- Contact data: email address, phone number, correspondence address
- Business data: KvK number, VAT number
- Usage data: logs, IP address, browser type
- Payment data: processed by Mollie (we do not store card details)
2a. Data in the Mobile Application (iOS / Android)
The Synomi mobile application accesses selected device features only after the User's explicit consent and solely to perform the feature chosen by the User. Data generated by these features (invoice content, receipts, routes) is processed by Synomi as a Processor on behalf of the User-Controller (see section 1).
- Microphone (Voice-to-Invoice™) — after tapping the “Speak” button, the application runs speech recognition on the device (on-device Speech Recognition on iOS / Android). Only the text (command transcript) is sent to our server — we do not transmit or store audio recordings.
- Location (Mileage) — GPS coordinates are recorded ONLY when the User actively starts the trip tracker. The “background” (Always) mode is used solely to keep the trip log from being interrupted when the application runs in the background while driving. Route data is used to settle business travel costs.
- Camera / Photos (Expenses — receipt OCR) — after taking a photo of a receipt or invoice, the image is sent to the Anthropic AI service for automatic data extraction (OCR, see section 6) or processed by a local OCR engine running on our server. After extraction, the image may be stored in the User's account as an expense attachment.
- Crash reports — iOS and Android by default send Apple / Google diagnostic crash data if the User has consented to this in the system settings. Synomi does not use any third-party analytics or advertising SDKs in the mobile application (no Firebase Analytics, no Google Analytics in the app, no advertising tracker SDKs).
The User may withdraw consent to microphone, location or camera access at any time in their device's operating-system settings (iOS: Settings → Privacy; Android: Settings → Apps → Synomi → Permissions).
3. Purpose of Data Processing
Personal data is processed for the following purposes:
- Providing invoicing and business-management services
- Managing user accounts
- Processing payments and settlements
- Communication with users
- Ensuring service security
- Analysis and improvement of our services
- Fulfilling legal and tax obligations
4. Legal Basis for Processing
Personal data processing is based on:
- User consent (Art. 6(1)(a) GDPR)
- Performance of a contract (Art. 6(1)(b) GDPR)
- Compliance with legal obligations (Art. 6(1)(c) GDPR)
- Legitimate interests of the controller (Art. 6(1)(f) GDPR)
5. Cookies
5.1. What are cookies?
Cookies are small text files stored on your device while browsing websites. They are used to remember your preferences and settings.
The provisions of this section apply to the website. The Synomi mobile app (iOS and Android) does not display a cookie banner and uses only technically necessary session mechanisms (login, security) — no marketing, analytics or tracking cookies.
5.2. Why won't Synomi work without cookies?
Synomi requires technical cookies to function properly for the following reasons:
- User authentication — session cookies enable login and access to your account
- CSRF protection — protection against cross-site request forgery attacks requires tokens in cookies
- Language preferences — remembering selected interface language
- Cart and session — storing application state between HTTP requests
Important: Without accepting necessary cookies, you will not be able to log in or use basic Synomi features. This is not optional — it is a technical necessity.
5.3. What cookies do we use?
Essential cookies (technical)
These cookies are necessary for the service to function and cannot be disabled:
synomi_session — user session identifier
XSRF-TOKEN — security token against CSRF attacks
synomi_cookie_consent — your cookie consent (LocalStorage)
Analytics and advertising cookies
Synomi does not use analytics, advertising or tracking cookies — neither in the web service nor in the mobile application (no Google Analytics, no advertising SDKs, no data brokers).
5.4. How long do we store cookies?
- Session cookies — deleted after closing the browser
- Persistent cookies — stored for up to 30 days (cookie consent)
- “Remember me” cookies — up to 1 year (if you enable this option when logging in)
5.5. How to manage cookies?
You can manage cookies through:
- Browser settings — you can block or delete cookies
- Information banner — on your first visit to the synomi.ai website we display a notice about the use of necessary technical cookies (“I understand” button). Since we use only necessary cookies, the banner is informational and does not require a choice. This banner does not appear in the mobile application
Warning: Blocking technical cookies will cause Synomi to stop working. You will not be able to log in or use any features.
5.6. External cookies (payments)
During payment processing, the user is redirected to the website of payment provider Mollie B.V., who may use their own cookies in accordance with their privacy policy available at mollie.com/privacy. Synomi has no control over cookies set by Mollie.
Payments are not processed in the Synomi mobile app (iOS and Android) — the redirection to Mollie described above and the related cookies occur only on the website.
6. Data Sharing (Sub-processors)
To provide the Synomi service, we use trusted external providers (sub-processors within the meaning of Art. 28 GDPR). Data may be shared with the following parties only to the extent necessary to perform a specific function:
- Mollie B.V. (Netherlands) — online payment provider. See mollie.com/privacy
- Anthropic PBC (USA) — provider of AI models used for automatic data extraction from photos of receipts and invoices (OCR), processing Voice-to-Invoice commands, and powering the Daisy AI assistant. Only data that requires external processing is sent to Anthropic, and queries are not linked to a specific user. Anthropic is bound by a DPA and does not use the transferred data to train models. See anthropic.com/legal/privacy
- Google LLC (USA) — in two independent cases:
- “Sign in with Google” — if the User chooses to log in via Google, Google provides us with the email address and basic profile data within the scope of the consent given.
- Google Calendar synchronization — if the User actively connects their Google Calendar account (OAuth2), Synomi writes events generated in the system to their calendar (invoice payment due dates, scheduled meetings, expense reminders) and reads events from the calendar to display them in the Synomi panel. The User may disconnect the integration and withdraw consent at any time in their Google account settings (myaccount.google.com/permissions).
See policies.google.com/privacy
- Apple Inc. (USA) — in two independent cases:
- “Sign in with Apple” — if the User chooses to log in via Apple, Apple provides us only with an identifier and — at the User's request — an email (optionally in anonymized form, relayed by Apple).
- iCloud Calendar synchronization (CalDAV) — if the User actively connects their iCloud calendar using an App-Specific Password, Synomi communicates with Apple servers (caldav.icloud.com) to write and read events (payment due dates, meetings, reminders). The User may disconnect the integration at any time by revoking the app-specific password at appleid.apple.com.
See apple.com/legal/privacy
- Government authorities — when required by law (e.g. court summons, tax obligations).
Transfers of data to the USA (Anthropic, Google, Apple) take place on the basis of Standard Contractual Clauses (SCC) approved by the European Commission and — for Google and Apple — certification under the EU–US Data Privacy Framework.
We do not sell your personal data to third parties. We do not use advertising networks or data brokers.
7. User Rights
Under the GDPR, you have the right to:
- Access to your personal data
- Rectification (correction) of data
- Erasure of data (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority — in the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl)
To exercise these rights, contact us at: hello@synomi.ai
8. Data Security
We apply appropriate technical and organizational measures to protect your data:
- Encryption of business data (encrypted at rest)
- SSL/TLS connections (HTTPS)
- Regular security updates
- Restricted access to personal data
- Regular backups
- Servers in the Netherlands (GDPR compliant)
9. Data Retention and Account Deletion
We retain your data for:
- The duration of the agreement and service provision
- After the subscription expires — in read-only mode, for no longer than 24 months of uninterrupted inactivity (deletion after prior e-mail notice with a 30-day period)
- Maximum 30 days after account deletion (grace period)
9.1. Account deletion
You can delete your account yourself in the app: Profile → Delete account. You may also request deletion of your account and data by e-mail at support@synomi.ai (also without using the app).
After the request, the account enters a 30-day grace period — during this time you can cancel the deletion by logging in again. After 30 days the data is permanently and irreversibly deleted from our servers.
Before deletion we recommend exporting your data (PDF/XML/Excel exports) — recovery will not be possible after deletion. The obligation to keep your own accounting documents for 7 years rests with the User.
What remains: the sales invoices issued by Synomi (for the subscription) are kept for 7 years in our accounting — this follows from a legal obligation (administratieplicht; Art. 6(1)(c) GDPR), in respect of which Synomi acts as Controller.
10. Changes to the Privacy Policy
We reserve the right to make changes to this Privacy Policy. We will inform you of any changes by publishing a new version on the website and sending an email notification (for significant changes).
11. Contact
If you have questions about personal data processing or this Privacy Policy, please contact us: