Legal
Privacy Policy
Last updated: 1 April 2026
Synelio Labs ("Synelio Labs", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have in relation to it. It applies to our website at syneliolabs.com and all services we provide.
1. Who we are
Synelio Labs is a company registered in Croatia (10000 Zagreb, Croatia). We are the data controller for the personal data we collect through our website and services. You can reach our privacy team at team@syneliolabs.com.
2. Data we collect
We collect the following categories of personal data:
- Contact information: your name and email address when you submit our contact form or sign up for communications.
- Usage data: pages visited, time spent, browser type, operating system, referring URL, and IP address, collected automatically through our server logs and analytics tools.
- Communication data: the content of messages you send us via our contact form or email.
- Technical data: cookies and similar tracking technologies as described in Section 6 below.
We do not intentionally collect sensitive personal data (e.g. health information, religious beliefs, or financial account numbers).
3. How we use your data
We use personal data for the following purposes and legal bases:
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to your enquiries | Legitimate interest / Contract |
| Improving our website and services | Legitimate interest |
| Sending service-related communications | Contract |
| Marketing communications (with opt-in) | Consent |
| Security monitoring and fraud prevention | Legitimate interest |
| Compliance with legal obligations | Legal obligation |
4. Data sharing
We do not sell your personal data. We may share it with:
- Service providers: third parties who help us operate our business (e.g. cloud hosting, email delivery, analytics). These parties act as data processors under contract and may only process your data on our instructions.
- Legal authorities: when required by law, court order, or to protect the rights and safety of Synelio Labs or others.
- Business transfers: in connection with a merger, acquisition, or sale of assets, where personal data may be part of the transferred business assets.
5. International transfers
Our servers are located within the European Economic Area (EEA). Where we transfer data outside the EEA, we ensure appropriate safeguards are in place (e.g. Standard Contractual Clauses approved by the European Commission).
6. Cookies
We use cookies and similar technologies to make our website work and to understand how it is used. Specifically:
- Essential cookies: required for the website to function (e.g. security, session management). These cannot be disabled.
- Analytics cookies: help us understand traffic patterns and improve content. We use Google Analytics 4, a service provided by Google Ireland Ltd., which sets cookies and collects usage data (pages visited, visit duration, device type, anonymized IP address). Data may be transferred to Google under its privacy policy. You can opt out with the Google opt-out add-on or by blocking cookies in your browser.
You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.
7. Data retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Contact form submissions are retained for up to 2 years. Usage and analytics data is retained for up to 13 months. You may request deletion at any time (see Section 8).
8. Your rights
Under GDPR and applicable law, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your personal data ("right to be forgotten").
- Restriction: ask us to restrict processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at team@syneliolabs.com. We will respond within 30 days. You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include encryption in transit (TLS), access controls, and regular security reviews.
10. Children's privacy
Our website and services are not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be communicated via a notice on our website or directly to affected users. Your continued use of our services after any change constitutes acceptance of the updated policy.
12. Contact
For any privacy-related questions or requests, please contact:
Synelio Labs
10000 Zagreb, Croatia
Email: team@syneliolabs.com