Privacy Policy
Syntheticaire – CoreCheck Service
PRIVACY POLICY
Syntheticaire – CoreCheck Service
Effective as of: June 24, 2026
Syntheticaire OÜ (hereinafter referred to as the “Service Provider” or “Data Controller”) considers the protection of the personal data of clients and interested parties to be of paramount importance. The purpose of this policy is to present in a clear and transparent manner what data the Service Provider collects through the contact and inquiry form located on the website, the purposes for which such data is used, and how its protection is ensured.
1. Details of the Data Controller
- Company Name: Syntheticaire OÜ
- Registered Office: Harju maakond, Tallinn, Kristiine linnaosa, Seebi tn 1-1501, 11316
- Commercial Registry Number: 17030330
- E-mail address: info@syntheticaire.com
- Website: www.syntheticaire.com
2. Scope, Purpose, and Legal Basis of Data Processing
During the filling out of the form on the CoreCheck subpage, the following data shall be processed:
- Name / Company Name: For the purpose of identification and official communication during contact.
- E-mail address: For the purpose of maintaining contact, professional consultation, and transmitting the contract and the Report.
- Technical Data (Programming language, Codebase size, Project description): Information necessary for providing the service, preparing the analysis, and compiling the customized quotation/contract.
Legal basis for data processing: Article 6(1)(b) of the GDPR – processing is necessary for the performance of a contract to which the Data Subject (Client) is party or in order to take steps at the request of the Data Subject prior to entering into a contract.
3. Duration of Data Processing
- If, following the initial contact, an agreement is concluded (the service is ordered), the Service Provider shall retain the Client’s data and the issued invoice for the mandatory period prescribed by Estonian accounting and tax legislation (7 years from the date of issuance of the invoice).
- If, following the initial contact, no order is placed, the Service Provider shall permanently delete the data provided in the form from its data recording system within 6 months from the date of contact. E-mail correspondence generated during the consultation shall be retained by the Service Provider for business continuity and legal enforcement purposes.
- The destruction of the Source Code transmitted for analysis is not affected by this privacy policy; it is governed by the T&C and the individual Service Agreement, according to which it shall be permanently deleted on the 7th day following the delivery of the Report.
4. Data Transfer and Data Processors
The Service Provider does not sell or transfer the Clients’ data to third parties for marketing or any other purposes. For the secure operation of the service and administration, the Service Provider engages technological partners (data processors) that apply high-level data security measures and comply with GDPR regulations:
- Hosting and Cloud Provider: Rackforest Zrt.
- Database Provider: Neon.tech (Neon Labs, Inc. – strictly utilizing servers located within the European Union)
- ERP, Invoicing, and Digital Signature System: Odoo S.A.
5. Cookies and Tracking
The CoreCheck website uses cookies and similar tracking technologies (e.g. pixels, SDKs, local storage). The cookies used fall into the following categories:
a) Strictly necessary cookies
These are essential for the operation of the website (e.g. security features, form handling, remembering cookie preferences). No consent is required for their use.
b) Analytics/statistics cookies
These are used to measure visitor behaviour and to improve the performance and content of the website. They are only placed with the visitor’s prior consent.
c) Marketing and remarketing cookies
The Service Provider uses third-party marketing and tracking codes for the purpose of ad targeting, measuring the effectiveness of advertising campaigns, and remarketing (retargeting). These may include in particular:
- Meta Pixel (Facebook, Instagram) – Meta Platforms Ireland Ltd.
- LinkedIn Insight Tag – LinkedIn Ireland Unlimited Company
- TikTok Pixel – TikTok Technology Limited
- Google Ads / Google Analytics – Google Ireland Ltd.
- Tracking codes of other social media and advertising platforms
These providers may process data relating to the use of the website (e.g. IP address, device and browser data, pages viewed, interactions) as independent controllers or joint controllers, in accordance with their own privacy policies. Data transfers outside the European Economic Area (e.g. to the United States) may also occur, in which case the legal basis for the transfer is an adequacy decision of the European Commission or Standard Contractual Clauses (SCCs).
Legal basis and consent
Analytics, marketing and remarketing cookies are placed solely on the basis of the visitor’s prior, voluntary and explicit consent (Article 6(1)(a) GDPR). Consent may be given via the cookie management interface (cookie banner) displayed on the website, and may be withdrawn or modified at any time, free of charge. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
Managing cookies
Visitors may also delete cookies already placed, or block the placement of cookies, at any time via their browser settings. Please note that if strictly necessary cookies are disabled, some functions of the website may not work, or may work only in a limited manner.
6. Rights of the Client
Under the GDPR, the Client is entitled at any time to:
- Request information and access to their personal data processed by the Service Provider.
- Request the rectification of inaccurate data.
- Request the erasure of their data (provided that it does not conflict with statutory obligations, e.g. accounting obligations).
- Object to the processing of data or request the restriction of processing.
These rights may be exercised at any time via a simple electronic letter sent to the Service Provider’s e-mail address, to which the Service Provider shall provide a substantive response within a maximum of 30 days.
For legal remedies, data subjects may turn to the Estonian Data Protection Authority (Andmekaitse Inspektsioon, Tallinn) or to the competent national court according to the Client’s place of residence.