Effective: June 01, 2026
1. Introduction
At Synclo, we understand that business data is sensitive and must be handled responsibly. Synclo is a modular ERP platform that helps organizations manage people, recruitment, payroll, finance, sales, support, projects, learning, supply chain, documents, workflows, analytics, and AI-assisted operations.
This Privacy Policy explains how Synclo collects, uses, processes, stores, shares, protects, retains, and deletes information through our platform, website, modules, integrations, support channels, and related services.
2. Scope of This Policy
This Privacy Policy applies to Synclo’s ERP platform, website, modules, features, integrations, AI-assisted capabilities, support channels, sales and onboarding interactions, and related services.
It covers information processed through Synclo’s current and future modules, including PeopleManager, HireHub, SmartLedger, SalesEnginePro, ProjectHub, Resolve, Academy, SupplySuite, Alci, and any additional tools or services introduced as part of the Synclo platform.
This policy may apply to client companies, authorized platform users, employees, candidates, customers, leads, vendors, suppliers, learners, help desk participants, website visitors, demo requesters, trial users, and any other individual whose information is entered, uploaded, submitted, generated, or processed through Synclo.
Where a client company uses Synclo to manage information, that company remains responsible for informing relevant individuals about how their data is collected, used, retained, and managed within its organization.
3. Our Role in Handling Data
Synclo may handle information in different roles depending on the type of data involved and the purpose for which it is processed.
3.1 Client-Controlled Data
When a client company uses Synclo to manage information about its employees, candidates, customers, vendors, suppliers, learners, projects, finances, support requests, documents, workflows, or business operations, the client company remains the owner and primary controller of that data.
In these cases, Synclo acts as a service provider and data processor. We process client-controlled data on behalf of the client company, according to the client’s instructions, platform configurations, enabled features, and applicable agreements.
3.2 Synclo-Controlled Data
In some cases, Synclo may collect and use information for its own business, operational, security, support, or communication purposes. This may include website inquiries, demo requests, trial signups, sales communication, onboarding interactions, billing or account communication, support requests submitted directly to Synclo, service updates, marketing communication, platform security, performance monitoring, troubleshooting, and internal business administration.
For this type of information, Synclo may act as an independent data controller.
3.3 Client Responsibilities
Client companies are responsible for ensuring that their use of Synclo complies with applicable laws, contracts, internal policies, and notices. This includes informing relevant individuals about how their information is collected and used, obtaining any required permissions or consents, managing user access, configuring workflows and permissions appropriately, and responding to requests from individuals whose data is controlled by the client company.
Where required and reasonably possible, Synclo may assist client companies with data-related requests, security matters, export requests, or compliance obligations related to their use of the platform.
4. Information We Collect
The information Synclo collects depends on how a client company uses the platform, which modules are enabled, which features are configured, and what information is entered, uploaded, imported, generated, or submitted by authorized users.
Most of the information processed through Synclo is provided by client companies and their authorized users. Some information is collected automatically when users interact with the platform, website, integrations, support channels, or AI-assisted features.
4.1 Account, Company, and Contact Data
When a client company creates an account, requests a demo, starts a trial, contacts Synclo, or configures its workspace, we may collect account and company-related information. This may include the company name, business details, industry, address, official contact details, logo, branches or locations, subscription details, billing or account contacts, administrator details, and other information needed to create, manage, support, and configure the client’s Synclo workspace.
4.2 User, Access, and Authentication Data
When individuals are invited to, registered on, or granted access to Synclo, we may collect user and access-related information. This may include names, email addresses, phone numbers, usernames, roles, departments, designations, permissions, reporting relationships, account status, login activity, password reset activity, authentication records, two-factor authentication status where applicable, and related security or access-control information.
4.3 Client Workspace and ERP Data
When a client company uses Synclo, the information entered, uploaded, imported, generated, or managed within its workspace remains client-controlled data. This may include business and operational data across Synclo modules, including human resources, payroll, attendance, recruitment, onboarding, finance, accounting, sales, CRM, projects, tasks, help desk tickets, learning, training, supply chain, procurement, inventory, documents, policies, approvals, reports, dashboards, and related records.
Depending on the modules used, this data may include employee records, candidate records, customer and lead information, vendor and supplier information, financial records, payroll and compensation details, attendance and leave records, performance records, support tickets, project files, learning progress, procurement records, inventory records, uploaded documents, workflow history, approvals, comments, audit logs, and other business information managed by the client company through Synclo.
Synclo processes this information on behalf of the client company and according to the client’s instructions, configurations, permissions, and enabled features.
4.4 Recruitment and Candidate Data
When client companies use HireHub or related recruitment features, Synclo may process candidate and applicant information on behalf of the client company. This may include resumes, CVs, job applications, contact details, education history, work experience, skills, interview records, screening responses, assessment results, AI-assisted candidate evaluations, recruiter notes, hiring stage history, offer details, referral information, talent pool records, and related recruitment activity.
Client companies remain responsible for determining what candidate information is collected, how it is used, how long it is retained, and how candidates are informed about the processing of their information.
4.5 Communication, Document, and Workflow Data
When client companies use Synclo for internal communication, document management, policy management, approvals, surveys, notices, or workflow automation, we may process related communication and workflow information. This may include notices, announcements, gestures, surveys, polls, responses, policy documents, handbooks, templates, acknowledgement records, uploaded files, comments, approvals, reminders, notifications, system-generated messages, and workflow activity.
4.6 AI and Automation Data
When users interact with Synclo’s AI-assisted features, including Alci, we may process prompts, commands, questions, user instructions, generated responses, summaries, suggestions, classifications, draft content, workflow recommendations, automation activity, and related interaction history.
Where AI-assisted features use information from Synclo modules to generate responses or recommendations, such processing is based on the user’s role, permissions, enabled modules, and authorized access within the client’s workspace.
4.7 Technical, Usage, and Security Data
When users access Synclo or visit our website, we may automatically collect technical, usage, and security-related information. This may include IP address, device type, browser type, operating system, login times, session activity, module interactions, feature usage, page activity, error logs, performance data, security logs, audit trails, approximate location where applicable, cookies, analytics identifiers, and similar technical information.
This information helps us operate the platform, authenticate users, maintain security, troubleshoot issues, monitor performance, improve user experience, and protect Synclo from unauthorized access, misuse, or security threats.
4.8 Website, Sales, Marketing, and Support Data
When individuals visit Synclo’s website, submit forms, request demos, start trials, subscribe to communications, interact with campaigns, or contact Synclo for sales, onboarding, support, or account-related matters, we may collect information such as name, email address, phone number, company name, job title, inquiry details, product interest, communication preferences, chat or support messages, meeting notes, campaign interaction data, referral sources, and website analytics data.
This information is used to respond to inquiries, provide demos and trials, manage sales and onboarding communication, deliver support, send relevant product or service updates, improve our website, and understand the effectiveness of our marketing and communication efforts.
5. How We Collect Information
Synclo collects information in different ways depending on how a client company, user, visitor, or authorized representative interacts with the platform, website, modules, integrations, support channels, or related services.
Most information is provided directly by client companies and their authorized users when they create accounts, configure workspaces, enable modules, upload or import records, complete forms, submit requests, manage workflows, or communicate through Synclo.
Information may also be collected from individuals who interact with Synclo-enabled processes, such as employees, candidates, customers, vendors, suppliers, learners, or help desk requesters submitting information through forms, portals, tickets, applications, onboarding flows, learning activities, surveys, feedback forms, or other platform features.
Some information is collected automatically when users access or use Synclo, including platform activity, login records, module interactions, technical logs, cookies, analytics data, and security-related information.
Synclo may also receive information through client-authorized integrations, connected services, support conversations, website forms, demo or trial requests, sales and onboarding interactions, and AI-assisted interactions with Alci or other automation features.
6. How We Use Information
Synclo uses information to provide, operate, secure, support, improve, and develop the Synclo platform and related services. The way information is used depends on the modules enabled by the client company, the features configured, the user’s role and permissions, and the information entered, uploaded, generated, or processed through the platform.
We use information to create and manage accounts, authenticate users, apply role-based permissions, enable ERP modules, process workflows, generate reports, maintain records, manage notifications, support integrations, and deliver the features selected by each client company.
Depending on how Synclo is used, information may support HR and payroll, recruitment and onboarding, finance and accounting, sales and CRM, help desk and support, projects and tasks, learning and training, supply chain and procurement, internal communication, document management, policy management, approvals, analytics, and other business operations.
We may also use information to send system alerts, reminders, emails, in-app notifications, approval requests, policy acknowledgements, workflow updates, service announcements, product updates, and other communications related to the platform or the client company’s use of Synclo.
Information may be used to provide dashboards, reports, analytics, summaries, audit trails, and operational insights. Where AI-assisted features are enabled, information may also be used to generate suggestions, summaries, classifications, drafts, recommendations, workflow assistance, or other Alci-powered outputs based on the user’s authorized access.
We may use information to provide customer support, troubleshoot issues, monitor performance, improve user experience, develop new features, maintain platform reliability, detect misuse, prevent unauthorized access, investigate security concerns, comply with legal obligations, enforce agreements, and protect the rights, safety, and security of Synclo, our clients, users, and others.
7. AI-Assisted Features and Alci
Synclo may offer AI-assisted features through Alci and other automation tools to help users work more efficiently across the platform. These features may assist with tasks such as generating summaries, drafting content, classifying information, recommending workflows, suggesting categories or priorities, creating reports, preparing communications, and supporting other business processes. When users interact with Alci or AI-assisted features, Synclo may process prompts, commands, questions, instructions, user inputs, generated responses, interaction history, and relevant module data needed to produce the requested output. Any use of client-controlled data for AI-assisted features is based on the user’s role, permissions, enabled modules, and authorized access within the client company’s workspace.
AI-generated outputs are intended to assist users and may not always be complete, accurate, or appropriate for every situation. Authorized users should review AI-generated content before relying on it for business, HR, financial, legal, employment, customer, vendor, or operational decisions.
AI-assisted features are designed to support human review and decision-making and are not intended to make final employment, hiring, payroll, financial, legal, or disciplinary decisions without appropriate human oversight.
Synclo does not use client-controlled business data, employee data, candidate data, customer data, vendor data, financial records, uploaded documents, or other workspace data to train public AI models.
Where third-party AI infrastructure or service providers are used to support AI-assisted features, such providers are selected and managed under appropriate confidentiality, security, and data protection obligations.
8. Data Ownership and Client Controls
Client companies retain ownership and control of the information they enter, upload, import, generate, or manage within their Synclo workspace. Synclo does not claim ownership over client-controlled data.
Client companies and their authorized administrators are responsible for managing their workspace settings, including users, roles, permissions, modules, workflows, approvals, documents, exports, integrations, and available retention settings. Access to information within Synclo is controlled through the roles, permissions, and configurations selected by the client company.
Synclo maintains logs of important user, admin, system, workflow, and security-related actions to support traceability, troubleshooting, auditability, compliance, and platform security.
Individuals whose information is managed within a client company’s Synclo workspace, such as employees, candidates, customers, vendors, suppliers, learners, or help desk participants, should generally contact the relevant client company for requests relating to access, correction, deletion, export, or use of their information. Where required and reasonably possible, Synclo may assist the client company in responding to such requests.
9. How We Share Information
Synclo does not sell, rent, or trade client-controlled data for third-party marketing or advertising purposes.
Information within a client company’s Synclo workspace may be accessible to authorized users within that organization based on the roles, permissions, modules, workflows, and configurations selected by the client company.
We may share information with trusted service providers who help us operate, secure, support, and improve Synclo. This may include cloud hosting providers, email or SMS providers, analytics and monitoring tools, customer support tools, payment or billing providers, security providers, and AI infrastructure providers, where applicable. These providers are only permitted to process information for the services they provide to Synclo and are expected to protect it under appropriate confidentiality, security, and data protection obligations.
Information may also be shared with third-party systems or integrations that a client company chooses to connect with Synclo. In such cases, the sharing of information depends on the integration enabled, the permissions granted, and the client company’s configuration.
We may disclose information where required by law, regulation, legal process, court order, government request, or where necessary to protect the rights, safety, security, or integrity of Synclo, our clients, users, or others.
If Synclo is involved in a merger, acquisition, financing, restructuring, sale of business assets, or similar business transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality and data protection safeguards.
10. Security of Your Data
Synclo uses reasonable technical, administrative, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
These safeguards may include access controls, role-based permissions, authentication measures, encryption where applicable, audit logs, activity monitoring, secure hosting practices, backups, internal confidentiality controls, and other security measures appropriate to the nature of the information being processed.
Access to client-controlled data is limited to authorized users and personnel who need such access for legitimate platform, support, security, operational, or legal purposes.
While we take data security seriously, no method of transmission, storage, or processing is completely secure. Therefore, we cannot guarantee absolute security of any information processed through Synclo.
For more information about Synclo’s security practices, please view our detailed Security Policy here: [Security Policy].
11. Data Retention, Export, and Deletion
Synclo retains client-controlled data for as long as the client company’s account or subscription remains active, unless the data is deleted earlier by the client company, its authorized users, or in accordance with applicable settings, agreements, or legal requirements.
Client companies may export supported records, reports, documents, and other information from Synclo, depending on the modules enabled, user permissions, subscription terms, and available export features.
If a client company cancels its subscription or closes its account, Synclo may retain the client’s data for a limited period to allow for backup, export, migration, account recovery, or administrative purposes. Unless otherwise agreed, this post-cancellation retention period is 30 days.
After the applicable retention period, client-controlled data may be deleted, de-identified, or made inaccessible from active systems, subject to backup cycles, technical limitations, legal obligations, dispute resolution, fraud prevention, security requirements, and other legitimate business or compliance needs.
Some records may be retained for longer where required by law, contract, accounting obligations, audit requirements, security investigations, or to protect the rights and interests of Synclo, our clients, users, or others.
12. Individual Privacy Rights
Depending on applicable law and the nature of the information involved, individuals may have certain rights in relation to their personal data. These may include the right to request access to their data, correction of inaccurate or outdated data, deletion of certain data, export or portability of data, restriction or objection to certain processing activities, and withdrawal of consent where processing is based on consent.
Where personal data is managed within a client company’s Synclo workspace, such as employee, candidate, customer, vendor, learner, or help desk-related data, the relevant client company is usually responsible for handling privacy rights requests. Individuals should contact that client company directly for requests relating to access, correction, deletion, export, or use of their information.
Where Synclo controls the relevant information directly, such as website inquiries, demo requests, trial signups, sales communication, support interactions, account communication, or marketing preferences, individuals may contact Synclo to exercise their applicable privacy rights.
Synclo may verify the request, ask for additional information where necessary, and respond in accordance with applicable laws. Where required and reasonably possible, Synclo may also assist client companies in responding to valid privacy rights requests relating to client-controlled data.
13. Cookies and Website Data
Synclo may use cookies and similar technologies on its website and platform to support essential functionality, maintain sessions, improve security, remember preferences, analyze usage, monitor performance, and improve the user experience.
These technologies may include essential cookies, session cookies, analytics cookies, performance cookies, and marketing or advertising cookies where applicable. Cookies may collect information such as device details, browser type, IP address, pages visited, referral sources, session activity, and interaction data.
Users may be able to manage or disable certain cookies through browser settings or available cookie preference tools. However, disabling some cookies may affect website or platform functionality.
For more information about how Synclo uses cookies and similar technologies, please view our Cookie Policy here.
14. Integrations and Third-Party Services
Client companies may choose to connect Synclo with third-party tools, systems, applications, devices, APIs, or services to support their business operations. These may include services for email, SMS, payments, accounting, biometrics, job boards, communication, analytics, reporting, automation, or other integrations enabled by the client company.
When a client company enables an integration or authorizes a third-party service, information may be shared between Synclo and that third party based on the permissions granted, the configuration selected, and the purpose of the integration.
Third-party services are governed by their own terms, privacy policies, security practices, and data handling procedures. Synclo is not responsible for the privacy, security, or data practices of third-party services that are outside Synclo’s control.
Client companies are responsible for ensuring that they have the necessary rights, permissions, consents, and authority to enable integrations and share relevant information with connected third-party services.
15. International Data Transfers
Synclo may process, store, or transfer information in countries where Synclo, its affiliates, service providers, infrastructure providers, or support teams operate.
Where information is transferred across borders, Synclo takes reasonable steps designed to protect such information in accordance with applicable data protection laws, contractual obligations, and appropriate security safeguards.
Client companies are responsible for ensuring that their use of Synclo, including any cross-border transfer of information into or through the platform, complies with the laws and obligations applicable to their organization, users, and operations.
16. Security Incidents
Synclo will take reasonable steps to investigate suspected or confirmed security incidents involving unauthorized access, disclosure, loss, misuse, alteration, or destruction of information processed through the platform.
Where required by applicable law, contract, or relevant obligation, Synclo will notify affected client companies about security incidents involving their client-controlled data and may provide reasonable assistance to support any required investigation, remediation, or notification process.
Users and client companies should promptly report any suspected unauthorized access, account compromise, security weakness, or misuse of Synclo to us through the appropriate support or security contact channel.
17. Compliance With Applicable Laws
Synclo is designed to support privacy, data protection, employment, labor, commercial, technology, and other compliance-related obligations where applicable.
Because compliance requirements may vary by country, industry, organization, module, workflow, and use case, each client company is responsible for ensuring that its use of Synclo complies with the laws, regulations, contracts, internal policies, and notices applicable to its organization and users.
Synclo may provide features, records, workflows, audit trails, exports, reports, access controls, and security measures that help client companies manage compliance-related processes. However, Synclo does not guarantee that use of the platform will make any client company fully compliant with all applicable laws or obligations.
Client companies should seek independent legal, regulatory, tax, employment, or compliance advice where required for their specific business, jurisdiction, and use of Synclo.
18. Changes to This Policy
Synclo may update this Privacy Policy from time to time to reflect changes in our platform, services, business practices, legal requirements, or security and operational processes.
When we update this policy, we will revise the effective date at the top of the policy. Where changes are material, we may notify client companies or account administrators through email, in-app notice, website notice, or other appropriate communication channels.
Continued use of Synclo after an updated Privacy Policy becomes effective means that the updated policy applies to the use of the platform and related services.
19. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or Synclo’s handling of information, you may contact us at:
Email: legal@synclo.com
Phone: +1 (833) 201-7494
Address: Bu Haleeba Gold Building, Office M2, Hor Al Anz East, Dubai
For requests relating to information managed within a client company’s Synclo workspace, individuals should generally contact the relevant client company first. Synclo may assist the client company where required and reasonably possible.
