These pages are beta legal notices for Synago. They are not counsel-approved company terms.
Privacy Notice
- Effective date
- 1 September 2026
- Version
2026-09-01-beta-1- Controller for account/website data
- Liad Berko, operating Synago as a natural person pending incorporation. No company name, registration number, or VAT number exists yet. In this Notice, “Synago” means that operator.
- Address
- Contact via the Synago product.
- Privacy contact
- Privacy and support requests are made through the signed-in Synago account (Settings) until an entity mailbox exists.
This Notice explains how Synago handles personal data when a business representative creates an account, connects Google, and uses the invoice collection, review, and accountant-output service.
1. Our roles
For account registration, service security, support, product administration, and our own legal obligations, Synago determines the purposes and means of processing and acts as controller.
For personal data contained in a customer's Gmail messages, invoice PDFs, extracted invoice details, review history, and accountant output, the business customer generally determines why that data is processed and acts as controller. Synago acts as processor on the customer's documented instructions. The customer is responsible for providing notices and identifying a lawful basis for people whose data appears in its business records.
2. Data we process
Account and business data
- work email address;
- business legal name and account identifiers;
- password hash, account status, and session information;
- acceptance records for Terms, this Notice, and Google-data authorization;
- support communications and security events.
Google Workspace data
When an authorized owner connects Google, Synago may access:
- the connected Google account identifier and email address;
- Gmail message identifiers, dates, headers, sender details, subject, snippet, and—only where the eligibility check needs it—message body content;
- PDF attachment identifiers, filenames, metadata, and eligible PDF contents;
- Google Drive and Sheets identifiers and files created for Synago's accountant output.
Synago requests OpenID identity scopes plus gmail.readonly and drive.file. The gmail.readonly permission technically permits reading Gmail messages and settings, although Synago limits its use to the invoice-collection behavior described here. Synago does not modify or delete Gmail messages. drive.file is used for files created or opened for Synago rather than broad access to all Drive files.
For messages checked by the eligibility filter, body text is processed in memory only when metadata is inconclusive and is not persisted. For invoice-like or skipped attachments, Synago may retain message/attachment identifiers for deduplication. Stored source metadata includes received time and sender details; subjects are redacted before persistence. Attachments that do not match the eligibility rules are not downloaded or stored in GCS.
Invoice and operational data
- original eligible PDF attachments;
- supplier and invoice details, including identifiers, dates, monetary values, currency, and document type;
- extracted values, confidence/evidence, deterministic validation results, corrections, revisions, approvals, exclusions, and duplicate decisions;
- collection, extraction, delivery, and audit status;
- technical request IDs, timestamps, provider status, token counts, latency, and redacted error codes.
Vercel runtime logs are designed not to contain invoice values, emails, filenames, PDF content, OAuth tokens, or secrets.
3. Why we process data and legal basis
Create and operate the business account
- Data
- Account and business data
- Role / legal basis
- Controller; necessary to enter into and perform the service contract
Authenticate and secure the service
- Data
- Account, session, request, and security data
- Role / legal basis
- Controller; contract and legitimate interests in preventing abuse and protecting the service
Collect likely invoice PDFs from Gmail
- Data
- Google Workspace and source metadata
- Role / legal basis
- Processor on Customer's instructions; Google authorization is obtained before access
Store, extract, validate, review, and deliver invoices
- Data
- PDFs, extracted details, review and delivery state
- Role / legal basis
- Processor on Customer's instructions; necessary to provide the requested service
Create customer-controlled Drive/Sheet output
- Data
- Approved records and Google file IDs
- Role / legal basis
- Processor on Customer's instructions
Troubleshoot customer-requested issues
- Data
- Limited relevant Customer Data
- Role / legal basis
- Processor; only with Customer authorization for specific data, or where necessary for security/legal compliance
Maintain redacted audit history
- Data
- Redacted action metadata
- Role / legal basis
- Controller or processor depending on context; legitimate interests in security, accountability, and legal claims
Meet legal obligations
- Data
- Minimum necessary records
- Role / legal basis
- Controller; applicable legal obligation
We do not rely on a bundled marketing consent. If optional marketing is introduced, it will require a separate choice.
4. How Google data is used
Synago uses Google Workspace data only to provide and improve the user-facing invoice collection, review, and delivery features described in the service.
Specifically, Synago:
- scans the authorized Gmail period for messages with PDF attachments;
- evaluates limited message and attachment metadata to identify likely invoices;
- stores eligible PDFs in private application storage;
- sends eligible PDFs to Google Cloud Vertex AI in the configured EU location to extract structured invoice details;
- presents the original and extracted details to the authorized owner;
- creates or updates approved output in the customer's Google Drive and Sheet; and
- uses identifiers and hashes to prevent duplicate collection or delivery.
Synago does not:
- sell Google Workspace data;
- use it for advertising, retargeting, lending, or creditworthiness;
- use it to train or improve a generalized AI or ML model;
- permit routine human reading of messages or invoice content;
- modify, send, label, trash, or delete Gmail messages; or
- transfer it for unrelated purposes.
Human access is limited to explicit customer-authorized support for specific data, necessary security investigation, or legal requirements.
Synago's use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
5. Recipients and subprocessors
Synago uses the following categories of providers:
Google Workspace APIs
- Purpose
- Authorized Gmail discovery and customer-owned Drive/Sheet output
- Primary configuration / transfer note
- Data comes from and returns to the customer's Google account; Google terms apply
Google Cloud Platform
- Purpose
- Private GCS original storage, Workload Identity Federation, and Vertex AI extraction
- Primary configuration / transfer note
- GCS and Vertex are configured for EU locations; Google affiliates/subprocessors may perform support or service operations under Google's DPA
Vercel
- Purpose
- Hosts the Next.js application, functions, deployments, and runtime logs
- Primary configuration / transfer note
- Current Synago project is on Hobby (1-hour runtime-log retention); Vercel and subprocessors may process data outside the EEA using applicable safeguards
Neon serverless Postgres, provisioned through the Vercel Marketplace
- Purpose
- Tenant-isolated application database, point-in-time history, snapshots, and provider backups
- Primary configuration / transfer note
- External-beta baseline: Launch or higher, EU (Neon via Vercel Marketplace); exact primary region recorded in the operator runbook, 7-day history, daily snapshots retained 35 days; Neon states infrastructure backups are retained 30 days; applicable DPA uses DPF/SCC safeguards
Make.com (temporary)
- Purpose
- Calls the collection dispatcher every ten minutes while Vercel Hobby scheduling is insufficient
- Primary configuration / transfer note
- The request contains a bearer key and no tenant/document payload. Make.com is a named subprocessor. The contractual entity will be confirmed before paid customers.
Current provider lists and contractual safeguards:
- Google Cloud DPA and subprocessors: https://cloud.google.com/terms/data-processing-addendum and https://cloud.google.com/terms/subprocessors
- Vercel DPA and subprocessors: https://vercel.com/legal/dpa and https://vercel.com/legal/sub-processors
- Neon DPA/product terms and subprocessors: https://neon.com/pdf/DPA.pdf, https://neon.com/msa, and https://neon.com/subprocessors
- Make.com is a named subprocessor. The contractual entity will be confirmed before paid customers.
Customer generally authorizes these subprocessors under the Data Processing Addendum. Synago will provide notice of material additions and a reasonable opportunity to object as specified there.
If the Postgres provider, Neon plan, region, recovery configuration, contracting entity, DPA, subprocessors, or transfer safeguards change, Synago must update this Notice and the internal processor register before the changed configuration processes customer data.
6. International transfers and regions
Synago does not promise legal “EU-only sovereignty” in beta.
Application invoice originals are configured in an EU GCS location, and extraction is configured for a Google Vertex EU location. Some providers or their subprocessors may process account, support, security, or service data outside the EEA.
Where required, transfers rely on an adequacy decision, an applicable Data Privacy Framework certification, Standard Contractual Clauses, or another lawful safeguard. Current details are available through the signed-in Synago account (Settings) until an entity mailbox exists.
7. Retention
Active account: originals, source metadata, extracted details, revisions, and operational state are retained while needed to provide the service, unless the Customer submits a verified deletion request.
Verified deletion request: Customer content is deleted from primary GCS and Postgres within 30 days.
Termination/churn: Google access is revoked and new collection stops immediately. Customer content is kept for a 60-day recovery/export period and deleted from primary GCS and Postgres by day 60.
Neon recovery data: for external beta, Synago requires a 7-day point-in-time history window and daily scheduled snapshots retained for 35 days on Neon Launch or higher. Customer data therefore ages out of customer-configured Neon history/snapshots within 35 days after primary deletion. Neon separately states that its infrastructure backups are retained for 30 days. If any recovery copy is restored, the deletion is reapplied before service resumes.
Cloud-provider residual copies: deletion from Synago's active GCS bucket and database does not necessarily remove every provider backup or security copy immediately. Those copies are isolated from ordinary use and expire under the applicable provider DPA. Google Cloud's current DPA may allow up to 180 days to complete deletion from its systems.
Vertex AI service data: Synago does not use invoice data to train a generalized model. Depending on model, feature, and configuration, Vertex abuse monitoring can retain certain prompts for up to 90 days or prompts/responses for up to 30 days. The production configuration and applicable maximum must be verified before beta; Synago must not claim zero provider retention without that verification.
Redacted audit events: retained for up to 12 months after termination/deletion for security, accountability, and legal claims, then deleted or irreversibly anonymized. The founder approved this beta period on 1 September 2026; legal counsel may require revision.
Vercel runtime logs: the current Synago project is on Hobby and Vercel retains runtime logs for 1 hour. If the plan changes, documented retention may range up to 30 days with Observability Plus. Synago will not configure longer retention without updating this Notice.
Legally required records: minimal billing, contractual, tax, or claim records may be retained for the period required by law. They do not include invoice PDFs merely because the Customer has its own accounting-record obligations.
Customer-owned Gmail messages, Drive files/folders, and Sheets remain until the Customer deletes them.
8. Security
Measures include:
- server-derived tenant context and Postgres row-level security;
- private GCS storage and short-lived review URLs;
- encrypted HTTPS transport;
- encrypted Google refresh tokens;
- narrow Google scopes;
- authorization checks at command boundaries;
- structured logs and audit redaction; and
- idempotency and persisted delivery state.
No system is completely secure. Synago will handle qualifying incidents and notify affected controllers/data subjects as required by law and contract.
9. Automated processing
Vertex AI extracts proposed invoice fields, and deterministic rules identify validation issues or possible duplicates. During beta, these outputs do not make legal or similarly significant decisions. An authorized user reviews and approves or excludes records. Automatic acceptance and delivery remain disabled unless separately validated and agreed.
10. Rights and requests
Depending on the context and applicable law, individuals may have rights to access, rectify, erase, restrict, object, or receive portable copies of personal data.
For account data controlled by Synago, make the request through the signed-in Synago account (Settings) until an entity mailbox exists. We may verify identity and authority before acting.
For data contained in a Customer's mailbox or invoice records, contact that Customer first because it is generally the controller. Synago will assist the Customer in responding as required by the Data Processing Addendum.
You may lodge a complaint with the Hellenic Data Protection Authority (https://www.dpa.gr/) or another competent supervisory authority.
11. Cookies
Synago uses the strictly necessary synago_session cookie to keep an authenticated user signed in. It is HTTP-only, Secure in production, SameSite=Lax, and expires after seven days.
No advertising, cross-site tracking, or optional analytics cookies are used in the beta product. A consent banner is therefore not used for the essential session cookie. If optional cookies are introduced, Synago will update this Notice and request any consent required before setting them.
12. Changes
Synago may update this Notice as the product or law changes. Material changes will be communicated before they take effect where practicable.
If Synago materially changes how Google Workspace data is accessed, used, stored, or shared, it will update the disclosure and obtain renewed affirmative authorization before beginning the new use.
13. Contact and required publication details
- Controller
- Liad Berko, operating Synago as a natural person pending incorporation. No company name, registration number, or VAT number exists yet.
- Registration / VAT number
- No company name, registration number, or VAT number exists yet.
- Address
- Contact via the Synago product.
- Privacy contact
- Privacy and support requests are made through the signed-in Synago account (Settings) until an entity mailbox exists.
- Support contact
- Privacy and support requests are made through the signed-in Synago account (Settings) until an entity mailbox exists.
- Data protection officer
- A data protection officer has not been appointed.