Legal
Privacy Notice
Last updated 1 August 2026
This notice explains how Ossyntra, trading as Ossyntra, collects and uses personal data when you visit our site, create an account, or use the Ossyntra platform. It is maintained by Ossyntra and describes our own practices; it is not an independent certification or audit.
1. Who we are and our role
Ossyntra is the data controller for personal data relating to account holders and workspace members — that is, we decide why and how that data is processed.
For business records you upload into your workspace (customers, suppliers, employees, invoices, tickets and similar), you are the controller and we act as a processor on your instructions. You are responsible for having a lawful basis to upload that data and for informing the people it concerns.
2. Personal data we collect
- Account data — name, email address, workspace name, role and authentication credentials, including multi-factor authentication enrolment.
- Support and communications — messages, attachments and correspondence you send us.
- Usage and telemetry — pages visited, features used, timestamps and performance/error diagnostics.
- Security data — audit log entries, sign-in attempts and lockout records, session activity, IP address, device and browser identifiers.
- Customer Data — the business records you and your team enter or import, which may contain personal data about your own contacts and staff.
Payment card details are never collected or stored by us. Checkout and billing are handled by Paddle as merchant of record, under their own privacy notice.
3. Why we use it, and our legal basis
- Creating and administering accounts and workspaces — performance of our contract with you.
- Providing, hosting and supporting the platform — performance of our contract.
- Security, fraud prevention, audit logging and abuse protection — our legitimate interest in keeping the platform and its tenants safe, and our legal obligations.
- Diagnosing faults and improving the product — our legitimate interest in maintaining and developing a reliable service.
- Service and transactional messages — performance of our contract.
- Marketing communications — your consent, which you may withdraw at any time.
- Meeting accounting, tax and other legal duties — compliance with a legal obligation.
4. Who we share data with
- Cloud hosting and database providers — to host the application and store your data.
- Merchant of record — Paddle — for the sale of subscriptions, subscription management, payments, tax compliance, invoicing and billing support.
- AI model providers — where you use AI Copilot or AI Analyst, the content of your request is sent to a model provider to generate a response. It is not used to train third-party models.
- Operational service providers — email delivery, rate limiting, error monitoring and support tooling.
- Professional advisers — legal, accounting and insurance advisers where necessary.
- Authorities — where we are required to disclose by law or valid legal process.
We do not sell personal data.
5. International transfers
Our providers may process data outside the country where you are located, including outside the UK and EEA. Where that happens we rely on appropriate safeguards such as UK/EU Standard Contractual Clauses or an adequacy decision.
6. Retention
Account data is kept for as long as your account is active. After termination, Customer Data remains available for export for 30 days and is then deleted or anonymised, except where we must keep records longer to meet legal, tax or accounting obligations. Security and audit log entries are retained for up to 12 months to support investigations, and backups are cycled out on a rolling schedule.
7. Your rights
Subject to applicable law, you have the right to access the personal data we hold about you, to have inaccurate data corrected, to request erasure, to restrict or object to certain processing, to receive your data in a portable format, and to withdraw consent where processing is based on it.
To exercise any of these rights, email hello@ossyntra.com. We aim to respond within one month. If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority. If your request concerns data held inside another organisation's workspace, we will direct you to that organisation as the controller.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, tenant isolation enforced at the database level, role-based access control, optional multi-factor authentication, session timeouts, append-only audit logging, rate limiting and least-privilege access for our own staff. No system can be guaranteed completely secure, and responsibility is shared: we secure the platform, you secure your credentials, user roles and the data you choose to upload.
To report a suspected vulnerability or security incident, contact hello@ossyntra.com.
9. Cookies and local storage
We use strictly necessary cookies and browser storage to keep you signed in, maintain your session, and remember interface preferences such as light or dark theme. These are required for the platform to function. We do not use advertising cookies. Where any optional analytics are introduced, we will ask for your consent first and you will be able to change your choice at any time through your browser settings.
10. Changes and contact
We may update this notice as the platform evolves; the date at the top shows the latest revision, and material changes are notified to account administrators. Questions can be sent to hello@ossyntra.com.