SYNCAS / INFORMATION
Privacy notice
DRAFT — operator and supplier details and launch checks are incomplete. This version is for preparation and local review.
1. Who is responsible
An individual conducting unregistered activity.
Privacy contact: 537.gymtracker@gmail.com. Service contact: 537.gymtracker@gmail.com. Website: https://syncas.ai.
2. What we collect and why
Card enquiries: name, email, optional company, message and submission time, supplied directly by you. We use them to answer and prepare a proposal. Under the GDPR, steps towards a contract requested by you rely on Article 6(1)(b); other enquiries, including company representatives, rely on our legitimate interest in handling correspondence under Article 6(1)(f).
Waitlist: your email, consent wording, language, document versions and time, to send one launch announcement. The GDPR basis is your consent, Article 6(1)(a); the checkbox also records permission for this electronic promotional message. No unrelated newsletter is included.
Privacy requests: email, request type, optional explanation, language and handling record. We use them to fulfil applicable legal duties (Article 6(1)(c)), or our legitimate interest in handling requests where no specific duty applies (Article 6(1)(f)). Do not include ID documents or sensitive information in these forms.
Security and records: a session cookie protects forms and remembers an explicitly selected language. Hosting may process IP addresses, request times and technical logs for security. Minimal notice, consent and withdrawal records use a keyed email digest; this is pseudonymised personal data, not anonymous data. Compliance evidence relies on applicable legal duties; proportionate security and suppression records rely on our legitimate interests (Articles 6(1)(c) and (f), as relevant).
3. Your choices
Providing data is voluntary. Required enquiry fields let us respond; an email and unticked-by-default consent are required only if you choose to join the waitlist. Withdrawal is free and needs only the email address, without an account. It does not affect the lawfulness of earlier consent-based processing. Browsing does not require subscribing.
4. Recipients and international transfers
Authorised staff and necessary hosting and email processors may access data to operate these services. Hosting: ; processing locations: . Email: ; processing locations: . Authorities and professional advisers may receive data where legally required or necessary for claims.
Ask the privacy contact for information about applicable safeguards and how to obtain a copy. Access from another country, including support access, is included in the transfer assessment.
5. Retention
Enquiries: up to 365 days from receipt, unless a resulting contract or a documented legal hold requires a separate retention rule. Waitlist: until withdrawal, the launch announcement, or 365 days from consent, whichever is earlier. Withdrawal removes the active email entry immediately. Minimal evidence and a keyed suppression digest: up to 730 days after the event. Privacy case records: up to 730 days after closure. Justified legal holds last only while necessary and are reviewed.
Operational log limit: 30 days; backup expiry: 30 days. Deleted records in isolated backups expire with backup rotation; if a backup is restored, deletions and withdrawals must be reapplied before use. The session cookie has no persistent expiry and is normally cleared when the browser session ends; browser session restoration can preserve it.
6. Rights in the EU/EEA
Where the GDPR applies, you may request access and a copy, correction, deletion, restriction and portability where its conditions are met; you may object to processing based on legitimate interests and withdraw consent at any time. You can complain to your competent supervisory authority, including the Polish President of the Personal Data Protection Office (uodo.gov.pl). We do not make automated decisions producing legal or similarly significant effects or profile you for marketing.
7. US residents and California disclosures
We collect the identifiers and correspondence described above directly from you; technical data comes from your browser and hosting. We do not sell personal information, share it for cross-context behavioural advertising, use targeted advertising, or permit third-party advertising trackers on these pages. We do not change this practice in response to Do Not Track or Global Privacy Control: there is no sale, sharing or targeted advertising here to opt out of. We do not infer sensitive characteristics or ask for sensitive data.
Depending on your state and whether its law applies to this operator, rights may include access, correction, deletion, portability, opting out of sale/sharing, targeted advertising or certain profiling, limiting certain sensitive-data uses, and appealing a refusal. California rights, when applicable, include knowing categories and specific information, sources, purposes and recipients. We do not discriminate for exercising applicable rights. Authorised agents may submit requests subject to proportionate verification of authority. Contact us or use Privacy requests; to appeal, choose Appeal. Statutory rights and deadlines apply even if this notice does not list each of them.
8. How to make a request; changes
Use Privacy requests or the privacy email above. We may verify control of your email or seek proportionate information before disclosure or deletion; submitting a form does not automatically disclose or erase records. GDPR requests are normally answered within one calendar month; where permitted, up to two additional months with notice and reasons within the first month. Applicable US law may set different deadlines; for covered CCPA requests, receipt is confirmed within 10 business days and a substantive response is normally due within 45 calendar days, with a permitted further 45 days after notice. Unsubscribing works immediately in this application.
This website is intended for adults, including consumers and business customers in the EU and USA, not children. Tell us if a child has submitted data so we can assess and remove it appropriately. Updates are identified by version and effective date. Material changes will be communicated appropriately before new uses; a policy update alone does not authorise new marketing.