
Privacy Notice
This notice explains how Synvero (“we”, “us”) collects, uses, shares and protects personal data, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR and the Cyprus Law 125(I)/2018. Last updated: 27 July 2026.
1. Who is responsible for your data (controller & processor)
Synvero plays two different roles depending on the data:
- Your building's content (issues, offers, works, the financial ledger, charges, votes, decisions, chat, documents, meeting attendance and recordings) belongs to your building. Your building — through its management committee — is the data controllerfor that content, and Synvero acts as its processor, handling the data only to provide the service.
- For your account and platform data (your login, profile, security settings, subscription/billing and how you use the app), Synvero is the controller.
Contact for privacy matters: privacy@synvero.cy. (Operating legal entity and registered address to be completed by the operator.)
2. What we collect
- Account & profile: name, email, phone (optional), password (hashed), language, and two-factor / passkey security settings.
- Membership: the building(s) you belong to, your role, apartment/unit details and dues coefficient.
- Content you take part in: issues, comments, offers, works, ledger entries, charges, votes, decisions, chat messages, documents, meeting attendance and — where applicable — meeting audio recordings.
- Payments: subscription status and invoices. Card payments are handled by Stripe; we do not store your card number.
- Technical & security: IP address, device/browser (user-agent), approximate location, sign-in and security events, and the devices where you are signed in.
Chat messages and payment receipts are encrypted at rest.
3. Why we use it, and our legal bases
- To provide the service (run your building, your account, billing) — performance of a contract.
- Security & fraud prevention (sign-in logs, device management, account locking) — legitimate interests and legal obligation.
- Bookkeeping & governance records (ledger, invoices, decisions, minutes) — legal obligation and legitimate interests of the building.
- Meeting audio recording — your consent, shown and logged before you enter a recorded room, withdrawable at any time.
- Product notices you can't opt out of (e.g. security or billing emails) — legitimate interests. We do not send marketing without consent.
4. Who can see it, and who we share it with
Your building's data is visible only to members of thatbuilding, according to their role. Buildings are fully isolated — one building can never see another's data. The Synvero platform operator cannot accessyour building's chat, finances, documents, votes or recordings; the operator only manages subscriptions, billing and the technical running of the platform.
We use a small number of trusted sub-processors, under data-processing agreements:
- Hosting & infrastructure — to run the application and store data.
- Stripe — to process card payments and subscriptions.
- Email delivery — to send security, billing and account emails.
We do not sell your personal data or share it for third-party advertising.
5. International transfers
We aim to keep data within the European Economic Area. Where a sub-processor (such as Stripe) processes data outside the EEA, that transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
Account and profile data is kept while your account is active. Building financial and governance records (ledger, invoices, decisions, votes) are retained for as long as the building uses Synvero, and archived rather than deleted, so the community keeps a complete, auditable history — and to meet accounting and legal obligations. When you ask us to delete your data we anonymise these shared records rather than erase them (see “Your rights”).
7. How we protect it
We use encryption in transit (HTTPS/HSTS) and encrypt chat and receipts at rest. We support two-factor authentication and passkeys, log security events, let you review and sign out your devices, and can lock a compromised account. Access to production data is restricted.
8. Your rights
Under the GDPR you can ask to:
- Access & port your data (download it from Profile → Download my data).
- Rectify inaccurate data (edit your profile; ask your manager for building records).
- Erase your personal data (Profile → Request data deletion, or the public form). Some records that form part of the building's financial/governance history are retained but anonymised (“Deleted user”), as the building has a legal basis to keep them.
- Restrict or object to certain processing.
- Withdraw consent (e.g. for meeting recording) at any time.
Full instructions are on our Manage & delete your data page. You can also email privacy@synvero.cy. We respond within 30 days.
9. Cookies
We use only strictly-necessary cookies: your sign-in session, your language preference and your light/dark theme. We do not use advertising or third-party tracking cookies.
10. Children
Synvero is intended for property owners, residents and managers, and is not directed at children.
11. Changes to this notice
We may update this notice; we'll change the “last updated” date and, for material changes, notify you in-app.
12. Complaints
You can complain to the Cyprus supervisory authority, the Office of the Commissioner for Personal Data Protection, or the authority in your country of residence.
This notice is provided in good faith to describe our data practices. It is not legal advice; the operator should have it reviewed by a qualified professional and complete the controller details above. A building operating Synvero is the controller for its residents' data and should appoint a contact for requests.
