Back to app
Last updated: February 2026
GDPR — Regulation (EU) 2016/679

Privacy Policy

Synergy Axella respects your privacy. This policy explains what personal data we collect via the Synergy Axella Operations Excellence Platform (the "Platform"), how we use it, and your rights under the EU General Data Protection Regulation (GDPR).

1. Data controller

Synergy Axella, [Registered address, Belgium — replace with legal entity's official seat], VAT [VAT / BCE-KBO number — replace], is the data controller for personal data processed through this Platform. Contact: privacy@synergyaxella.com.

2. What we collect

  • Account data: email, name, role, preferred language, hashed password.
  • Security data: IP address, timestamps and outcomes of login attempts, session tokens.
  • Operational content you create: shift notes (with optional photos), downtime entries, quality reports, kaizens, work orders.
  • Copilot interactions: questions you send to the AI assistant. These are transmitted to sub-processors (see Sub-processors page).

3. Legal basis

  • Contract (Art. 6(1)(b)): providing you access to the Platform.
  • Legitimate interest (Art. 6(1)(f)): security, brute-force protection, audit logs.
  • Legal obligation (Art. 6(1)(c)): record-keeping duties under Belgian and EU law.

4. Retention

Account data is retained while your account is active. Failed login logs are kept for 30 days. Operational content is retained for as long as your organisation subscribes, or up to 7 years thereafter as required by manufacturing traceability regulations.

5. Your rights

Under GDPR you have the right to access, rectify, erase, restrict or object to processing, and data portability. You can exercise these directly:

  • Data export → Account > Security & Privacy > Download my data (Art. 20).
  • Erasure → Account > Security & Privacy > Delete account (Art. 17).
  • Other rights → email privacy@synergyaxella.com.

You may also lodge a complaint with the Belgian Data Protection Authority (APD-GBA) at autoriteprotectiondonnees.be.

6. Transfers outside the EU

Some sub-processors (e.g. our LLM providers) may process data outside the EEA. Where this is the case, we rely on Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework. See the Sub-processors page for details.

7. Security

Passwords are hashed with bcrypt. Sessions are cookie-based, HttpOnly, Secure, SameSite=Lax, with a 30-minute inactivity timeout. Admin accounts are eligible for TOTP two-factor authentication. Traffic is encrypted with TLS.

Synergy Axella · [Registered address, Belgium — replace with legal entity's official seat] · VAT: [VAT / BCE-KBO number — replace]

Questions? Contact privacy@synergyaxella.com (DPO: dpo@synergyaxella.com).

Placeholder text — please review with your legal counsel before publication.