About this notice
This notice explains what personal data we collect on this website, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it.
It applies to the Syntech Manufacturing website only. It is written to meet the EU General Data Protection Regulation (GDPR) and the Law of Ukraine "On Protection of Personal Data", because most of our visitors are in Ukraine or the EU. Where the two differ, we follow the stricter rule.
Last updated: the date of the current version is shown at the top of the page and is filled in by the build each time we revise this notice.
Who we are
The controller of your personal data is Syntech Digital, the company that publishes this website and the parent site https://syntech.digital.
- — Email for privacy questions: info@syntech.digital
- — Phone: +380 (63) 673-35-29
- — Company website: https://syntech.digital
If you write to us about privacy, use the subject line "Privacy request" so it reaches the right person quickly.
What this notice covers
This notice covers the website. It does not cover the product.
Syntech Manufacturing runs inside your own Creatio environment, in your own perimeter. We do not receive, host or process your production orders, drawings, batches, serial numbers, contracts or employee records through this website. If we also work with you under a services agreement, the handling of data in that project is governed by that agreement and, where required, by a separate data processing agreement.
What we collect
| What | Where it comes from | Detail |
|---|---|---|
| Contact and demo request form | You fill it in; the page adds technical context | Name, company, phone, work email and your message, together with the campaign parameters carried in the link you arrived on (utm_source, utm_medium, utm_campaign, utm_term, utm_content), the fbclid and gclid advertising identifiers, the page you landed on, the page that referred you, and your browser's user agent |
| Webinar registration form | You fill it in | Name, company, work email, the webinar you chose, whether you attended |
| Correspondence | You write or call us | Email content, call notes, anything you choose to tell us |
| Server logs | Automatic | IP address, date and time, pages requested, referrer, browser and device type |
| Cookies and similar technologies | Automatic, with your consent for non-essential ones | See the [cookie notice](/legal/cookies) |
| Analytics | Automatic, with your consent | Pages viewed, time on page, approximate region derived from IP, device type, referrer. Three systems do this: Google Analytics 4 (measurement ID G-9YN59640S2), Creatio web tracking, and the first-party analytics of Lovable, the platform the site is built and hosted on |
| Video | When you play a film | Playback events. The films are embedded from YouTube through youtube-nocookie.com behind a click-to-load player, so YouTube is contacted only after you press play, and may set its own identifiers from that moment |
The form deserves a plain statement, because it does more than send us an email. When you submit it, the data goes to two places at once: a `leads` table in our Supabase database, and a webhook into our own Creatio CRM. Both receive the same set — what you typed, plus the technical context listed in the first row above. If a Meta Pixel is active on the page, submitting the form also fires a `Lead` event to Meta, which tells Meta that a lead was sent from your browser.
We do not ask for and do not want special categories of data (health, political opinions, biometrics and so on). Please do not send them to us in a form or an email.
We do not buy contact lists. What the tracking described here does build is a picture of how one browser moved through the site; once you send us the form, that picture is attached to your contact record in our CRM.
Why we use it, and on what legal basis
| Purpose | Data used | Lawful basis (GDPR) | How long |
|---|---|---|---|
| Reply to your business enquiry or demo request, prepare and run the demo | Form data, correspondence | Legitimate interest (Art. 6(1)(f)) — answering a business enquiry that you started | 24 months after the last contact |
| Send you marketing: newsletters, webinar invitations, release news | Name, work email, company | Consent (Art. 6(1)(a)) | Until you withdraw consent, plus 12 months to prove the withdrawal |
| Register you for a webinar and deliver it | Registration data, attendance | Consent (Art. 6(1)(a)); steps at your request before a contract (Art. 6(1)(b)) | 12 months |
| Manage a customer, partner or supplier relationship | Contact data, correspondence | Contract (Art. 6(1)(b)) | The contract term plus the statutory limitation period |
| Keep the site available and secure, prevent abuse, investigate faults | Server logs | Legitimate interest (Art. 6(1)(f)) — network and information security | 90 days |
| Understand how the site is used and improve it | Analytics data | Consent (Art. 6(1)(a)) | 14 months |
| Meet legal duties: accounting, tax, answering lawful requests | Whatever the duty requires | Legal obligation (Art. 6(1)(c)) | The period the law sets |
Under Ukrainian law the same processing rests on your consent or on the other grounds in Article 11 of the Law of Ukraine "On Protection of Personal Data", in particular the performance of a contract and our legitimate interest.
You can object to processing based on legitimate interest, and you can withdraw consent at any time. See **your-rights** below.
Transfers outside Ukraine and the EEA
Some of the providers above are established outside Ukraine and outside the European Economic Area, and they may store or process data on servers in other countries. We do not list those countries here: the platforms choose the region themselves and can change it without changing the service.
Where that happens, the transfer relies on the safeguards the recipient itself provides and on the data protection terms we accept when we use its service. For transfers out of Ukraine we follow the conditions for cross-border transfer set by the Law of Ukraine "On Protection of Personal Data".
Write to info@syntech.digital and we will tell you which provider handles a given part of the site and on what terms.
How we protect it
We use encryption in transit (HTTPS) across the whole site, restrict access to enquiry data to the staff who need it, keep our systems patched, and log administrative access.
No website is perfectly secure, and we cannot guarantee that transmission over the internet is risk-free. If a breach is likely to put your rights at risk, we will notify the supervisory authority and, where the law requires it, you.
How long we keep it
The table in **why-we-use-it** gives the period for each purpose, and those are the periods we actually apply.
When a period ends, we delete the data or anonymise it so that it can no longer be linked to you. We may keep a minimal record of an opt-out (your email in a suppression list) so that we do not contact you again by mistake.
Your rights
You have the right to:
- Access — get a copy of the personal data we hold about you, and an explanation of how we use it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where we no longer need it, where you withdraw consent, or where you successfully object.
- Restriction — have us pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection — object to processing based on legitimate interest, and object to direct marketing at any time, with no reason needed.
- Portability — receive the data you gave us in a machine-readable format, or have it sent to another controller.
- Withdraw consent — at any time, by the unsubscribe link in any marketing email, by the cookie settings on this site, or by writing to us. Withdrawal does not affect what was lawful before it.
- Not be subject to automated decisions — we do not make decisions about you by automated means.
To exercise any of them, write to info@syntech.digital with "Privacy request" in the subject line. We answer within one month. If a request is complex we may extend that by two months and will tell you why. We may ask you for enough information to confirm who you are. Exercising your rights is free; we charge only for manifestly unfounded or repetitive requests.
The Law of Ukraine "On Protection of Personal Data" gives you an equivalent set of rights, including the right to know who holds your data and to demand that it be changed or destroyed.
How to complain
Tell us first if you can: info@syntech.digital. Most things are faster to fix directly.
You can also complain to a supervisory authority:
- In Ukraine — the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman), who supervises personal data protection. Contact details and the complaint procedure are on the Commissioner's official website.
- In the EU or EEA — the data protection authority of the country where you live, where you work, or where you believe the infringement happened.
Children
This is a business website for manufacturers. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, write to info@syntech.digital and we will delete it.
Changes to this notice
We update this notice when the site or the way we work changes: a new analytics provider, a new form, a new processor. The date at the top always shows the current version.
If a change materially affects your rights, we will say so on the site before it takes effect, and, where consent is the basis, we will ask you again.
Contact us
Questions about this notice, or about anything we do with your data:
- — Email: info@syntech.digital
- — Phone: +380 (63) 673-35-29
- — Company website: https://syntech.digital
Open questions for the client
The controller, the processors, the retention periods and the cookie durations are now settled and written into the text above. What is still missing is listed here. The first group blocks publication.
**Blocks publication — registered company details**
- — The full registered name of the legal entity that operates the site and is the controller. The page currently names only the trading name, Syntech Digital.
- — Its registered address. The **contact** section has no postal address until this arrives.
- — Its state registration number (ЄДРПОУ or equivalent), and the VAT number if it is to be shown.
**Still to decide, but the page works without them**
- — **Hosting location.** The notice now describes the hosting arrangement (Lovable for the site, Supabase for the `leads` table) without asserting a country, because the region is a platform setting we have not verified. Confirm the actual storage region for each, and we will name it.
- — **International transfers.** If counsel wants the destination countries and the transfer instrument named rather than described generically, we need the list per provider.
- — **Privacy mailbox.** Everything routes to `info@syntech.digital`. Confirm whether a dedicated address (for example `privacy@syntech.digital`) is to be created, and who monitors it.
- — **Governing law and forum.** Decided on the terms page, and it should be consistent with whatever is agreed there.
- — **Meta Pixel.** The form fires a `Lead` event when a Meta Pixel is present. Confirm whether a pixel is actually deployed; if it is not, the advertising-measurement line can be deleted from **who-we-share-with**.
- — **Webinars.** The webinar registration form and the 12-month retention are described. If webinars are run on a third-party platform, that platform must be named here before the form goes live.
**One build requirement, not a placeholder**
- — Google Analytics 4, Creatio web tracking and the YouTube embeds must not load before consent, and the Creatio scripts in particular must be gated by the banner. If the build loads them on arrival, the consent statements on this page and in the cookie notice are untrue.