Privacy Policy for Sincra.cloud
Last Updated: September 1, 2026
At Sincra.cloud, we are committed to protecting the privacy and personal data of our customers (Tenants) and their end-users. This Privacy Policy describes how we collect, use, store, and share personal data in accordance with the General Data Protection Regulation (GDPR), the Spanish Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD), and California Consumer Privacy Act (CCPA/CPRA).
1. Data Controller Identification
- Entity: Ernesto Alonso Céspedes Cáceres (The Operator)
- NIF: Z1362749G
- Address: Calle Horno 4 2B, CP 30003, Murcia, Spain
- Email: support@sincra.cloud
2. Categories of Personal Data Collected
Sincra.cloud collects and processes different types of personal data depending on how you interact with our Platform:
A. For Tenants (Customers of Sincra.cloud):
- Account Information: Name, email address, corporate phone number, password (hashed), and business details.
- Billing Data: Tax registration numbers, corporate address, and transaction metadata. Note: Sincra does not collect or store debit/credit card details.
- Configuration Metadata: API keys, calendar configurations (Cal.com), and custom styling preferences.
B. For End-Users (Visitors interacting with the Sincra Web Widget on Tenant sites):
- Conversation Logs: Chat history, text inputs, and variables collected under the BANT lead qualification protocol (budget, authority, need, timeline).
- Contact Information: Name, email address, and phone numbers captured dynamically during the conversation to log leads.
- System Telemetry: IP address, Browser User-Agent, Session ID, Timezone, and Locale (used for secure dual rate limiting and regional server-side rendering).
3. Purposes of Data Processing and Legal Basis
We process your personal data under the following legal bases:
| Category of Processing | Purpose of Processing | Legal Basis (GDPR) | | ------ | ------ | ------ | | Account Management | Provisioning the SaaS, enabling access to the Dashboard, and managing user profiles. | Contractual Necessity (Art. 6.1.b GDPR) | | Transaction Processing | Executing subscription checkouts and billing via our reseller, Paddle. | Contractual Necessity (Art. 6.1.b GDPR) | | Cognitive Inference (AI Chat) | Answering end-user queries, performing semantic searches (RAG), and qualifying leads. | Consent / Legitimate Interest of Tenant (Art. 6.1.a & f GDPR) | | System Security | Executing Dual Rate Limiting (IP + Fingerprint) and Cloudflare Turnstile token validation to block malicious bots and DDoS attacks. | Legitimate Interest (Art. 6.1.f GDPR) | | Compliance & Logs | Retaining conversations and operation logs to verify transactions and system health. | Legal Obligation (Art. 6.1.c GDPR) |
4. Subprocessors and Data Sharing
To deliver our high-throughput, resilient infrastructure, Sincra.cloud shares specific personal data with verified third-party subprocessors in accordance with Article 28 of the GDPR:
- Paddle.com: Acting as our online reseller and Merchant of Record (MoR). They process payment card data, calculate localized sales taxes, and handle transaction-related fraud detection.
- Google Cloud Platform (GCP): Next.js server components and databases are hosted on Cloud Run in the europe-southwest1 (Madrid) region. Vertex AI manages cognitive and embedding services.
- Upstash: Manages our fast serverless vector index (Upstash Vector) and caching layer (Upstash Redis) under strict multi-tenant logical partitioning (using isolated cryptographic namespaces).
- Sentry: Provides real-time error logging. Sentry is configured with an active client-side and server-side beforeSend interceptor that sanitizes, masks, and strips out personal identifiers (PII), ensuring that names, emails, and phone numbers never leave the local environment.
- Cal.com: Manages headless scheduling integration for B2B appointment booking.
5. Security Measures and Tenant Isolation
Sincra.cloud is designed under a Zero-Trust security architecture:
- Tenant Isolation: Every vector is stored under a namespace tied to the specific Tenant ID, and access is validated against that tenant identifier on every read and write operation.
- Input Validation: All incoming payloads are validated against Zod schemas at the edge, and Cloudflare Turnstile tokens are collected and verified on widget traffic.
- Encryption: Data is encrypted in transit using TLS 1.3 and at rest via Google Cloud KMS and native Firestore encryption.
6. Retention and the Right to be Forgotten (GDPR Cascading Deletion)
In compliance with Article 17 of the GDPR (Right to Erasure):
- Tenants may request the complete deletion of their account at any time.
- When a tenant or user triggers a deletion request, Sincra.cloud initiates a cascading deterministic deletion pipeline:
- Firestore: Recursively deletes the tenant document and all nested subcollections (conversations, leads, configuration).
- Upstash Redis: Scans and purges all active session tokens and cached keys associated with the tenant.
- Upstash Vector: Accesses both dense and sparse indexes to purge all vectorized knowledge chunks tied to the tenant's namespace.
- The deletion pipeline is initiated within 24 hours of the request. Any phase that cannot complete is retried and logged until it does.
7. User Rights (GDPR / CCPA)
Under global privacy regulations, you have the right to access, rectify, restrict, object to, export (portability), or erase your personal data.
To exercise any of these rights, please contact our data protection team at: support@sincra.cloud. If you believe your data has been handled unlawfully, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.