Privacy Policy
Last updated July 2026
This policy explains what data Synviora (operated by Synvolve Intellis) processes, why, and the choices you have. It is written to be read, not to hide behind. It is provided for information and is not legal advice.
Who we are
Synviora is a multi-tenant business platform for CRM, finance and e-invoicing across India, the UAE and Saudi Arabia. Each customer organisation is a “tenant”. This policy covers the Synviora product; your own use of Synviora to process your customers’ data makes you the controller of that data and us your processor.
Data we process
Account data (names, work email, role) for the people who use Synviora. Tenant business data you enter or import — contacts, deals, activities, invoices, documents and related records. Operational data such as logs, timestamps and IP addresses used to run and secure the service. Integration credentials you choose to connect (email, messaging, telephony, e-signature), stored encrypted.
How your data is isolated
Each tenant’s data lives in its own database schema — not a shared table filtered by an id. Access is bound to your tenant by authenticated tokens and role-based permissions on every route. Provider credentials are encrypted at rest with AES-256-GCM and only decrypted server-side at the moment of use.
How we use data
To provide and secure the service, to deliver the outbound messages and documents you initiate, to power AI features you invoke, and to meet legal and tax-compliance obligations (for example, e-invoicing clearance). We do not sell your data, and we do not use tenant business data to train external models.
AI features
When you use an AI feature, the relevant record context is sent to our AI gateway, which redacts obvious personal identifiers before calling the model provider, and returns a result stored against your tenant. AI usage is metered per tenant. You choose when to invoke it.
Sharing
We share data only with sub-processors needed to run the service (hosting, model providers, and the messaging/telephony/e-sign providers you connect), and where required by law. Outbound messages honour per-contact consent and do-not-contact settings.
Your rights
Depending on your region (GDPR, India’s DPDP, KSA PDPL and equivalents) you may request access, correction, export or erasure of personal data. Tenant administrators can manage most data directly in the product; for anything else, contact us.
Retention & security
We retain data for as long as your account is active and as required for tax and legal compliance, then delete or anonymise it. We apply encryption in transit and for sensitive fields at rest, scoped access, and rate limiting. No system is perfectly secure, but isolation and least-privilege are built into the architecture rather than added later.
Contact
Questions or requests: reach us through your account or at the contact address published on our site.