Pre-Sale Launching 15 April —
🔒 GDPR Compliant 🔐 AES-256 Encrypted 🇬🇧 UK Data Centre 99.9% Uptime

Your data, protected.

Enterprise-grade security and privacy built into every layer of Syndrix AI.

🔒

GDPR Compliant

UK & EU data protection

🔐

Encrypted

End-to-end, AES-256

🇬🇧

UK-Hosted

Secure cloud infrastructure

99.9% Uptime

Enterprise reliability

📜

UK DPA 2018

Data Protection Act compliant

Four pillars of protection

Security isn't an afterthought — it's built into the foundation of Syndrix.

🔐

Encryption

TLS 1.3 in transit, AES-256 at rest. OAuth tokens stored in encrypted vaults. No plaintext secrets anywhere in the system. API communications use authenticated, encrypted endpoints with certificate pinning.

👥

Access Control

Role-based access control with API key scoping and granular permissions. Full audit logging of every action. Session management with automatic timeouts. Support access requires your explicit permission.

📜

Compliance

GDPR Article 17 (right to erasure) compliant. UK Data Protection Act 2018 compliant. Data processing agreements available on request. Regular internal audits with documented retention and deletion policies.

Infrastructure

Cloud-hosted on AWS with redundant backups, automated failover, and real-time monitoring. 24/7 alerting for anomalies. Designed for 99.9% uptime with monthly SLA measurement and outage credits.

How we handle your data

We believe in complete transparency about data collection, usage, and retention.

What We Collect

Account information (name, email, company), business data you connect (emails, calendar, CRM), usage analytics to improve the service, and support communications.

How We Use It

Exclusively to provide and improve Syndrix services for your business. Your data powers the autonomous agent's actions — it's never used for advertising, profiling, or any purpose beyond serving you.

How Long We Keep It

Active account data is retained while your account is active. If you choose to stop using Syndrix, data is retained for 30 days, then permanently deleted. You can request immediate deletion at any time.

Your Rights

You have full rights to access, correct, export, and delete your data at any time. You can request a complete data export in a machine-readable format. Deletion requests are processed within 30 days.

How your data flows

A step-by-step look at how Syndrix handles your information — from connection to delivery.

1

You connect your tools via OAuth or API key

Grant permission through secure OAuth 2.0 flows (Google, Microsoft, CRM) or provide scoped API keys. We never see or store your passwords.

2

Syndrix accesses data through encrypted channels

All API calls use TLS 1.3 encryption. Data is fetched on-demand from your connected platforms — nothing is bulk-copied or cached unnecessarily.

3

Data is processed in isolated sessions

Your data is processed in a sandboxed environment. No cross-client data access — your business data is never mixed with any other customer's data.

4

Results are delivered via Telegram or email

Reports, responses, and alerts are sent through encrypted Telegram Bot API or your connected email. You control what gets delivered and when.

5

Data at rest is encrypted (AES-256)

Any data stored on our servers — OAuth tokens, session logs, preferences — is encrypted at rest using AES-256. Encryption keys are managed separately from data.

We never

These are promises we make to every customer, without exception.

Sell your data to third parties
Use your data to train AI models
Share your data with advertisers
Store your payment card details
Access your accounts without your OAuth consent
Store your email passwords — we use OAuth tokens only

Anti-prompt injection

Syndrix is built with safeguards to prevent AI manipulation and unauthorised actions.

🛡

Input Sanitisation

All AI inputs are sanitised and validated before processing. Malicious prompts, injection attempts, and adversarial inputs are detected and blocked.

🛠

Instruction Isolation

System instructions are isolated from user content. External data (emails, web pages) cannot override Syndrix's core safety rules or business logic.

🔒

Role-Based Tool Access

Tools are scoped by permission level. Syndrix cannot access tools or data beyond what you've explicitly authorised. Sensitive actions require confirmation.

Common security questions

In the unlikely event of a breach, we follow a strict 72-hour notification protocol as required by GDPR. All affected users are contacted directly, the ICO is notified, and our incident response team works to contain and remediate the issue immediately. We maintain a documented incident response plan that is regularly tested.
Yes. Data Processing Agreements are available on request for all plans. Enterprise customers receive a DPA as standard during onboarding. Contact us at info@pulsecode.co.uk to request your copy.
Never. Your business data is used exclusively to provide Syndrix AI services to you. It is never used to train, fine-tune, or improve any AI models — including our own. Your data stays yours, full stop.
Data is stored on AWS cloud infrastructure with servers in secure data centres. All storage is encrypted at rest (AES-256) with redundant backups across multiple availability zones. Our infrastructure is monitored 24/7 with automated failover.

Security questions?

Our team is happy to discuss our security practices in detail.