1. Who we are and our roles
Sytance Technologies Limited (序衡科技有限公司) provides and operates Sytance. In this notice, “we”, “us” and “Sytance” refer to that company. “Personal data” means information relating to an identified or identifiable individual, as defined by applicable law.
We act as the data user or controller when deciding the purposes and means of processing for our website, account administration, billing, business contacts, support, security and our legal obligations. The privacy contact for those activities is privacy@sytance.com.
A Customer normally controls personal data it places in a workspace, including information about its personnel, suppliers and product users. Where we process that data on the Customer’s behalf to provide the Service, we act as a processor or service provider. If the Customer itself acts for another controller, it must have authority to appoint us as a further processor. The Data Processing Terms in Appendix A to the Terms of Service govern that processing.
An organisation’s administrator may manage membership, permissions and workspace records. Removing an individual’s account does not necessarily delete records controlled by that organisation. We distinguish the individual’s account rights from the organisation’s authority over its workspace.
2. Scope of this notice
This notice applies to website visitors, account holders and authorised users, customer and supplier contacts, people who contact our sales, support, privacy, legal, or security teams, and others whose personal data we handle in the course of our business.
If an organisation provides or manages your Sytance account, that organisation may also give you a privacy notice. Questions about data controlled by that organisation should normally be directed to it first.
This notice does not govern an external website or service merely because Sytance links to it. The operator's own notice applies once you leave a Sytance-operated service.
3. Information we collect
- Account information, such as name, email address, organisation, role, account identifiers, permissions, and preferences.
- Customer Content, such as product information, architecture and data-flow records, security and compliance records, files, comments, evidence, and generated materials.
- Service data, such as sign-in activity, audit events, request and device information, IP address, timestamps, error records, and security signals.
- AI interaction data, such as instructions, relevant workspace context, generated output, provider and model information, and usage metrics.
- Commercial information, such as plan, subscription, invoice, payment status, and procurement records.
- Correspondence submitted to our sales, support, privacy, legal, or security contacts.
- Public website analytics through Umami Cloud (EU region), including public page paths, referring domains, selected campaign labels, browser and device information, approximate location, and registration or contact events. We do not send account identifiers, email addresses, form contents, verification tokens, or workspace content in analytics payloads. Network requests necessarily disclose an IP address to the analytics service; geographic reports are approximate.
4. How we collect information
We receive information directly from individuals, from organisations that provide or administer accounts, automatically through use of the website and service, from providers that support our operations, and from lawful business or professional sources.
Providing personal data is generally voluntary, but some information is needed to create an account, authenticate a user, deliver a requested service, process a transaction, or answer an enquiry. Without it, we may be unable to complete the request or provide the affected service.
For account creation, the email address and authentication information are required; profile details not marked as required are optional. We record the terms and adult declaration and the separate marketing choice with their relevant versions. Declining marketing does not prevent account creation.
Organisation invitations and workspace records may contain information supplied by an administrator or another authorised user rather than by the individual concerned. We do not require customers to upload unrelated personal data or sensitive material merely to use the platform.
5. Purposes and legal bases
We process information for the activities below. Where a legal basis is required, we identify it by reference to the actual relationship and purpose; an organisation’s contract does not automatically make every processing activity necessary for a contract with each of its users.
Our legitimate interests are operating a reliable service, managing business relationships, resolving problems and preventing fraud or abuse. We assess necessity, reasonable expectations and effects on individuals, and do not rely on that basis where their interests or fundamental rights override ours. Where local law does not recognise that basis, we use a basis permitted by that law.
Customer workspace processing follows the Customer’s lawful instructions and the Data Processing Terms. The Customer is responsible for the legal basis and notices for its own processing. We do not treat accepting these terms as consent to every use of personal data, and service improvement does not authorise model training on Customer Content.
Before using personal data for a materially different purpose, we assess whether that use is lawful and compatible, provide any required additional notice and obtain consent where required.
- Account and access: use email, account identifiers, authentication records and permissions to create and protect accounts, authenticate users and deliver requested functions. The basis is our contract with an individual Customer or, for organisation users, our legitimate interest in administering the Customer relationship, subject to applicable law.
- Purchases and billing: use subscription, payment-status and billing records to provide paid access, reconcile payments and manage renewals. We rely on contractual necessity and on applicable tax, accounting and other legal obligations for required records.
- Support and business enquiries: use contact details and correspondence to answer requests, investigate faults and manage service relationships. The basis is requested pre-contractual steps, contract performance or our legitimate interest in responding to an organisation’s contacts, as appropriate.
- Service security and reliability: use activity logs, device and request information, error details and limited diagnostic content to identify failures, detect abuse and investigate incidents. The basis is our legitimate interest in protecting the Service and affected persons, and legal obligations where applicable.
- Marketing: use email and any supplied name for the communications described in section 7 only after voluntary opt-in. The basis is consent, which may be withdrawn without affecting service access.
- Legal and accountability records: retain relevant transaction records, acceptance and consent history, and request-handling evidence to meet legal obligations or establish and defend legal claims, using only the information necessary for those purposes.
7. Business communications and direct marketing
Only after you voluntarily opt in to marketing emails will we use your email address and name, if provided, to send promotions about Sytance products, cybersecurity and compliance services, events and resources. This choice is separate from the service terms and unchecked by default; declining does not affect registration, purchase or use of the Service.
You can turn off marketing emails in account settings or unsubscribe free of charge by emailing privacy@sytance.com. We record the time and applicable notice version of consent or withdrawal to honour your choice. Opting out does not stop authentication, security, billing or necessary service notifications.
Acceptance of the service terms is not marketing consent. We do not provide your personal data to third parties for their independent marketing.
8. International processing
Sytance’s current application servers are located in Hong Kong. AI, payment, email and other supporting services may process data in other countries or regions; the application-server location does not mean that all processing or backups take place exclusively in Hong Kong.
Where applicable law requires, we use appropriate transfer safeguards, including applicable contractual arrangements, and complete required notice, consent or other statutory procedures. Contact privacy@sytance.com for information about recipients, processing regions and safeguards relevant to the processing.
The Service is hosted online; customer self-hosting and private deployment are not offered. If your data is subject to location restrictions, check the suitability of the Service with us before submitting it.
Where a transfer mechanism is legally required, the relevant safeguards must be in place before the restricted transfer takes place. A reference to contractual safeguards in this notice does not itself execute standard contractual clauses, establish an adequacy decision or replace a required assessment, filing or separate consent. We provide relevant safeguard information or a copy on request, with necessary redactions to protect confidential information.
Where local law requires particular recipient information or a separate transfer notice, we provide that information through the relevant collection, contracting or privacy-request process. The Customer must not treat a general acceptance of this notice as satisfaction of its own transfer obligations.
9. Retention and deletion
Paid-plan expiry does not automatically delete workspace content. Existing content remains available for browsing, while editing and export are unavailable. We retain account and workspace content to provide that continuing service until the Customer deletes it or makes a valid deletion request, subject to legal requirements. Cancelling renewal, disabling an account and requesting deletion are different actions.
To request deletion, email privacy@sytance.com with the account or workspace concerned and the requested scope. We verify identity and authority using proportionate information, clarify whether the request concerns a personal account or organisation-controlled content, and explain material consequences before irreversible deletion where appropriate. We act as soon as practicable and within applicable legal requirements; a paid subscription is not required to submit the request.
Retention is determined separately for the following categories. We do not apply the continuing workspace-content rule to every log, backup or business record, or retain unnecessary personal data indefinitely merely because no deletion request was received.
Where a legal hold or mandatory recordkeeping duty prevents deletion, we retain only the affected records, limit their use to that purpose, and explain the exception where permitted. We delete or irreversibly anonymise records once the relevant need ends. Deletion from our systems cannot remove copies independently exported by the Customer or retained by an independent controller.
- Account and workspace records: retained while needed to provide the requested account and continuing workspace service, until deletion or closure instructions are completed; legal and accountability records are separated where continued retention is required.
- Support and correspondence: retained while the request, complaint or follow-up remains open and afterwards only for necessary service accountability, an applicable claim period or a legal obligation, considering the issue, sensitivity and likelihood of a related dispute.
- Security and operational logs: retained for the period needed to detect, reconstruct and investigate relevant events and verify remediation, considering incident status, security risk and applicable evidence requirements; resolved events do not justify retaining all logs indefinitely.
- Temporary processing records: retained only while needed to complete or retry the requested operation, diagnose a related fault or meet a separate security or legal requirement. AI conversations intentionally saved in the workspace follow the workspace rule instead.
- Billing, legal acceptance and marketing-choice records: retained for applicable accounting and tax requirements, evidence of contractual rights or consent, and relevant claim periods. A minimal opt-out record may remain to prevent unwanted marketing; it is not permission to resume marketing.
- Backups: deleted data may remain in restricted recovery copies until those copies are overwritten or expire through backup rotation. Rotation is determined by recovery requirements and the minimum recoverable history needed for continuity; it is not extended to keep deleted content for ordinary use. On a deletion request, we will explain the applicable remaining backup handling. Restored copies must have the deletion reapplied before normal use.
10. Your choices, requests and complaints
Depending on applicable law and our role, you may request confirmation of processing, access and correction, deletion, restriction, objection, or a copy in a portable format. Portability applies where the legal conditions are met; it does not create a right to every commercial report or another person’s information. Commercial export restrictions do not limit statutory personal-data rights.
Send requests to privacy@sytance.com from your account email where possible. Describe the data and requested action; a particular subject line is not required. An authorised representative may act with evidence of authority. We seek only information reasonably needed to verify the request and do not routinely require identity documents for an ordinary account request.
We respond without undue delay and within the applicable statutory period. Where the EU or UK GDPR applies, we normally respond within one month of receipt; a permitted extension of up to two further months for complexity or number of requests is explained within the initial month. Hong Kong data-access and correction requests are handled within the applicable 40-day period, subject to statutory exceptions. Other applicable time limits remain unaffected.
Requests are handled free of charge unless applicable law permits a reasonable fee or refusal. We explain the basis before charging. If a request affects other people, protected confidential material or records we must retain, we provide the information or action that can lawfully be provided and explain any restriction where permitted.
You may withdraw marketing or other consent at any time; withdrawal does not invalidate lawful processing carried out before it. You may object to processing based on legitimate interests, and we assess whether a lawful reason permits continuation. Direct-marketing objections are honoured without requiring a reason.
If we process the relevant data for your organisation, we promptly refer or communicate the request to its authorised contact and assist it in responding. You may complain to privacy@sytance.com or to the competent supervisory authority, including the authority in your habitual residence, place of work or alleged infringement where the law provides. Contacting us first is not a condition for a complaint or judicial remedy.
11. Security
We use technical and organisational measures designed to protect personal data against unauthorised or accidental access, use, alteration, disclosure, loss, or destruction. Measures are selected with regard to the nature of the information, the processing, and the risks involved.
No online service can eliminate every security risk. If we become aware of a personal-data incident, we will investigate, contain, remediate, and make notifications where required by applicable law or an agreement.
12. Minors
Sytance is not directed to minors, and minors must not register. Registrants must be at least 18 years old and have reached the age of majority under the law where they live. Customers must not submit personal data about minors that is unrelated to the requested service. If we discover a minor’s account, we will restrict access and take appropriate account-closure and data-deletion steps. Contact privacy@sytance.com if you believe a minor has registered or provided personal data.
13. Automated processing and AI
AI features generate analysis and drafts from user instructions and relevant context. They are not offered as a system for making solely automated decisions about individuals with legal or similarly significant effects. Customers must apply the human review described in the AI and Customer Data notice and remain responsible for any decisions they make.
Authentication, security and entitlement controls may automatically permit or restrict requests. If you believe a restriction is wrong, contact support@sytance.com for review. This does not limit any additional rights concerning automated decisions available under applicable law.
14. Contact and changes
Send privacy enquiries, direct-marketing opt-outs, and data-rights requests to privacy@sytance.com. For account or workspace data controlled by your organisation, contact that organisation first where practicable.
We may revise this notice when our services, providers, practices, or legal obligations change. We will post the revised notice and update the date above. Where required, we will provide additional notice or obtain consent before a material change takes effect.