Privacy Policy for Sincra.cloud
Last Updated: September 25, 2026
At Sincra.cloud, we are committed to protecting the privacy and personal data of our customers (Tenants) and their end-users. This Privacy Policy describes how we collect, use, store, and share personal data in accordance with the General Data Protection Regulation (GDPR), the Spanish Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD), and California Consumer Privacy Act (CCPA/CPRA).
1. Data Controller Identification
- Entity: Ernesto Alonso Céspedes Cáceres (The Operator)
- NIF: Z1362749G
- Address: Calle Horno 4 2B, CP 30003, Murcia, Spain
- Email: support@sincra.cloud
2. Categories of Personal Data Collected
Sincra.cloud collects and processes different types of personal data depending on how you interact with our Platform:
A. For Tenants (Customers of Sincra.cloud):
- Account Information: Name, email address, corporate phone number, password (hashed), and business details.
- Billing Data: Tax registration numbers, corporate address, and transaction metadata. Note: Sincra does not collect or store debit/credit card details.
- Configuration Metadata: API keys, calendar configurations (Cal.com), and custom styling preferences.
B. For End-Users (Visitors interacting with the Sincra Web Widget on Tenant sites):
- Conversation Logs: Chat history and text inputs. Qualification details the visitor chooses to share in the conversation, such as what they need, their timeline or their budget.
- Contact Information: Name, email address, and phone numbers captured dynamically during the conversation to log leads.
- System Telemetry: IP address, Browser User-Agent, Session ID, Timezone, and Locale (used for secure dual rate limiting and regional server-side rendering).
3. Purposes of Data Processing and Legal Basis
We process your personal data under the following legal bases:
| Category of Processing | Purpose of Processing | Legal Basis (GDPR) | | ------ | ------ | ------ | | Account Management | Provisioning the SaaS, enabling access to the Dashboard, and managing user profiles. | Contractual Necessity (Art. 6.1.b GDPR) | | Transaction Processing | Executing subscription checkouts and billing via our reseller, Paddle. | Contractual Necessity (Art. 6.1.b GDPR) | | Cognitive Inference (AI Chat) | Answering end-user queries, performing semantic searches (RAG), and qualifying leads. | Consent / Legitimate Interest of Tenant (Art. 6.1.a & f GDPR) | | System Security | Executing Dual Rate Limiting (IP + Fingerprint) and Cloudflare Turnstile token validation to block malicious bots and DDoS attacks. | Legitimate Interest (Art. 6.1.f GDPR) | | Compliance & Logs | Retaining conversations and operation logs to verify transactions and system health. | Performance of a contract (Art. 6.1.b GDPR) |
4. Subprocessors and Data Sharing
To deliver our high-throughput, resilient infrastructure, Sincra.cloud shares specific personal data with verified third-party subprocessors in accordance with Article 28 of the GDPR:
- Paddle.com: Acting as our online reseller and Merchant of Record (MoR). They process payment card data, calculate localized sales taxes, and handle transaction-related fraud detection.
- Google Cloud Platform (GCP): Next.js server components and databases are hosted on Cloud Run in the europe-southwest1 (Madrid) region. Vertex AI manages cognitive and embedding services.
- Upstash: Manages our fast serverless vector index (Upstash Vector) and caching layer (Upstash Redis) under strict multi-tenant logical partitioning (using isolated cryptographic namespaces).
- Sentry: Provides real-time error logging. Sentry is configured with an active server-side beforeSend interceptor that sanitizes, masks, and strips out personal identifiers (PII), ensuring that names, emails, and phone numbers never leave the local environment.
- Cal.com: Manages headless scheduling integration for B2B appointment booking.
- Cloudflare (Turnstile), to protect the chat from automated abuse.
5. Security Measures and Tenant Isolation
Sincra.cloud is designed under a Zero-Trust security architecture:
- Tenant Isolation: Every vector is stored under a namespace tied to the specific Tenant ID, and access is validated against that tenant identifier on every read and write operation.
- Input Validation: All incoming payloads are validated against Zod schemas at the edge, and Cloudflare Turnstile tokens are collected and verified on widget traffic.
- Encryption: Data is encrypted in transit using TLS 1.3 and at rest via Google Cloud KMS and native Firestore encryption.
6. Data retention and deletion
Data retention. We keep your account data, knowledge sources, conversations and leads for as long as your account is active. You can delete individual leads and conversations from your dashboard at any time. When you delete your account, we remove your data from our systems within 30 days.
Visitor data. For the conversations and contact details that visitors share through your widget, you are the controller and Sincra processes them on your behalf. If a visitor asks you to delete their data, you can delete their lead and conversation from your dashboard. When a visitor shares their contact details, the lead also records the address of the page where the conversation started, without query parameters.
Browser storage in the widget. The chat widget stores no identifier in the visitor's browser until the visitor sends a message. From then on, it keeps a single conversation identifier in the browser's local storage (or, if local storage is blocked, in session storage, which is cleared when the tab is closed), so the conversation continues across pages and tabs. It expires 24 hours after the last message. Separately, when the widget shows its welcome message next to the chat button, it stores a single flag with no identifier in session storage so that the message appears only once per browsing session; the flag is cleared when the tab is closed. Sincra's widget code sets no cookies. To protect the chat from automated abuse, the widget loads Cloudflare Turnstile when the visitor opens the chat; Cloudflare may process technical data about the browser for that check.
7. User Rights (GDPR / CCPA)
Under global privacy regulations, you have the right to access, rectify, restrict, object to, export (portability), or erase your personal data.
To exercise any of these rights, please contact our data protection team at: support@sincra.cloud. If you believe your data has been handled unlawfully, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.