Privacy
Last updated on
This policy explains what personal data we process when you use this website, why we process it, and the rights you have over it. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.
Who we are
Synchronicity Labs (“we”, “us”) is a software engineering and consulting studio based in Greece and is the controller of the personal data described in this policy.
Contact for privacy matters: hello@synchronicitylabs.io
What we collect
This website has no user accounts, no contact forms, no advertising, no analytics, and sets no cookies.
Hosting logs. Our hosting provider (Cloudflare, Inc.) processes technical data such as your IP address, browser type, and requested pages in server logs in order to deliver the site and protect it against abuse.
Booking a call. If you book a consultation, scheduling is handled by Cal.com, Inc. You provide your name, email address, and anything you choose to write in the booking notes. We receive this information to prepare for and hold the call, and to follow up on it.
Email. If you email us, we process your email address and the contents of your message to respond to you.
Why we process it, and on what legal basis
- Operating and securing the website: legitimate interest (Article 6(1)(f) GDPR).
- Handling your booking and holding the call: steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).
- Corresponding with you and following up: legitimate interest (Article 6(1)(f) GDPR) or pre-contractual steps, depending on context.
We do not use your data for automated decision-making or profiling, and we do not sell or share it for advertising.
Processors and transfers
We use a small number of service providers who process data on our behalf: Cloudflare (hosting and content delivery) and Cal.com (scheduling). These providers may process data outside the European Economic Area, in particular in the United States. Where that happens, transfers rely on an adequacy decision (such as the EU-U.S. Data Privacy Framework) or on Standard Contractual Clauses.
Retention
Booking details and correspondence are kept for as long as needed to discuss and, where applicable, carry out an engagement, and afterwards only as long as legal obligations (such as tax and accounting rules) require. Hosting logs are retained by our provider for short periods for security purposes.
Your rights
Under the GDPR you have the right to access your personal data, to have it rectified or erased, to restrict or object to its processing, and to receive it in a portable format. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us using the details above. We will respond within one month.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece — www.dpa.gr.
Changes to this policy
If we change how we process personal data, we will update this page and revise the date shown above.