Section 1
Overview
This Privacy Policy describes how Syncora ("Syncora", "we", "us", "our") collects, uses, discloses, and protects personal information when you visit our public website, evaluate the product, or use the Syncora workforce management Services (the "Services"). Capitalized terms not defined here have the meanings assigned in our Data Processing Addendum ("DPA").
Where Syncora processes personal data on behalf of a customer (the "Controller") as part of the Services, we act as a Processor and the Controller's privacy notice governs that processing. This Privacy Policy governs (a) Syncora's own collection of personal data from public-website visitors, evaluators, and contacts, and (b) the limited personal data Syncora collects directly as a Controller in connection with account administration, billing, and security.
Section 2
Information we collect
We collect the following categories of personal information:
- Identifiers — name, email, employer, job title, when submitted via signup, contact, or pilot-application forms.
- Account data — authentication identifiers, role, organization, MFA enrollment, sign-in events.
- Billing data — billing contact, address, and payment-method metadata. Card numbers are tokenized by Stripe; Syncora does not store full card numbers.
- Customer-submitted Personal Data — when an authorized customer uploads employee, contractor, or applicant records into the Services. Syncora processes this data as a Processor on the Controller's behalf, in the categories listed in DPA §5.
- Biometric authentication events — captured only where the Data Subject has provided written, informed, BIPA-compliant consent. See "Retention and destruction" below.
- Location data — captured only where geofence-based clock-in is configured by the Controller and the Data Subject has been notified.
- Usage and device data — IP address, browser metadata, audit-log events of actions taken in the Services.
- Cookies and similar technologies — strictly-necessary cookies for authentication and security, plus opt-in analytics cookies governed by our cookie banner.
Section 3
How we use it
- To provide, secure, and improve the Services consistent with the DPA.
- To authenticate users, prevent fraud, and detect security incidents.
- To bill, collect payment, and administer subscriptions.
- To respond to inquiries, support requests, sales conversations, and Data Subject requests.
- To produce aggregated, de-identified analytics and product-improvement signals (no re-identification).
- To meet legal, regulatory, and audit obligations — including, where applicable, GDPR, CCPA/CPRA, state CDPAs, BIPA, NYC Local Law 144, Colorado SB 26-189 (ADMT), and the EU AI Act.
Section 4
AI governance and automated decisions
Syncora is an AI-Native workforce platform. Any automated decision affecting an employee record passes through a governed pipeline that enforces the four Building Constitution pillars: Explainability, Bias Mitigation, Human-in-the-Loop, and Transparency. This means:
- Every AI decision produces a structured reasoning trace (inputs, model version, confidence, plain-language rationale).
- Disparate-impact monitoring against the four-fifths rule runs continuously; decisions that fail are blocked at the gate.
- A human reviewer approves every load-bearing decision before it reaches an employee record.
- Employees can read the rationale, request a human review, or override the decision per GDPR Art. 22 and analogous state AI bias laws.
Accommodation requests and other sensitive workflows are firewalled from AI pipelines per Building Constitution Pillar 4 and applicable disability law.
Section 6
Retention and destruction
We retain personal data only as long as needed for the purpose collected, or longer where required by law. Specifically:
- Customer-submitted Personal Data — retained for the term of the Services Agreement; returned or deleted within thirty (30) days of termination per DPA §12.
- Biometric authentication events — retained per the customer's documented BIPA destruction policy (default: destruction within three (3) years of the last interaction, per BIPA §15(a)). Destruction jobs are logged and auditable.
- Audit logs — retained seven (7) years to meet GDPR Art. 22, NYC Local Law 144, and AI Act Art. 12 expectations.
- Backups — expire on a standard ninety (90) day rotation.
Section 7
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent or opt out of profiling and automated decisions.
Employees whose data is processed in the Services should direct requests to their employer (the Controller). Syncora provides the Controller with reasonable assistance to respond within the statutory window applicable to that request (CCPA 45 days, VCDPA 45 days, GDPR 30 days, etc.). For direct requests to Syncora as a Controller (e.g., website inquiries), email james.waddell@cognitivewx.info or visit /data-subject-rights.
Section 8
State-specific disclosures
For California residents (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and the 13+ other state CDPAs: you have the rights listed in §7 above. We do not sell or share personal information for cross-context behavioral advertising. We do not knowingly process personal information of consumers under 16 without affirmative consent.
For Illinois residents — biometric authentication is processed only with written, informed BIPA-compliant consent, with a published retention and destruction schedule, and is not disclosed to third parties without consent.
For New York City — where Syncora processes automated employment-decision tools on a Controller's behalf, we support the Controller's compliance with NYC Local Law 144, including bias-audit publication.
Section 9
EU Data Subject rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights set out in GDPR Articles 15–22, including the right to a meaningful human review of any decision based solely on automated processing under GDPR Art. 22. Where Personal Data is transferred outside the EEA/UK/Switzerland to a jurisdiction not subject to an adequacy decision, we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum, or another lawful transfer mechanism. See DPA §8.
Section 10
Security
We maintain technical and organizational measures consistent with industry standards, including:
- AES-256 encryption at rest, TLS 1.3 in transit.
- Zero-trust access controls with least-privilege role enforcement.
- Continuous monitoring of access logs and audit trails.
- SOC 2 is scoped but not yet audited — no auditor is engaged and no report exists. ISO/IEC 42001 (AI Management System) work has not started. We hold no certificate for either.
- Personal Data Breach notification to the Controller without undue delay, and in any event within 24 hours per DPA §10.
Live posture is published at /security.
Section 11
Children's data
The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16 without verifiable parental consent. If you believe a child has provided personal information, contact us so we can delete it.
Section 12
Changes to this Policy
We may update this Privacy Policy. Material changes will be announced via the public website and, where Syncora is a Processor, via direct notice to the Controller. The "Last updated" date at the top reflects the most recent revision.
Section 13
Contact us
Privacy inquiries: james.waddell@cognitivewx.info. For Data Subject requests, visit /data-subject-rights. For the binding DPA, see /dpa.