Privacy Policy
Last updated: 2026-07-25 · Version 1.0
This policy explains what personal data we process when you visit synapse-eu.eu or contact us through this site, why we process it, and the rights you have. We keep it deliberately short and specific — there is not much data to describe.
1. Who is responsible
CAI TECHNOLOGY S.R.L.
Str. Victor Brauner 34-38, bl. 1, sc. 4, ap. 5, Sector 3, 032621 Bucharest, Romania
Company reg.: J2024020380005 · Tax ID: 50512457 · VAT: RO50512457 (EU VAT: RO52732750)
Data protection contact: privacy@caitech.eu
SYNAPSE-EU is a CAI Technology initiative. It is a project brand, not a separate legal entity.
2. What we process, and why
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Name, email, organisation, subject, message (contact form) | To read your enquiry and reply to it | Your consent — Art. 6(1)(a) GDPR | 24 months, then deleted |
| IP address, browser user-agent, referring page, timestamp (recorded with a form submission) | Abuse prevention, spam filtering and security audit trail | Legitimate interest — Art. 6(1)(f) GDPR | 24 months |
| Aggregated page views, referrer, country, device type, browser (analytics) | To understand which pages are useful | Legitimate interest — Art. 6(1)(f) GDPR | Aggregated; no individual profile is built |
We do not use your data for marketing without separate, explicit consent. We do not sell or rent personal data. We do not build advertising profiles.
3. Analytics — self-hosted and cookieless
We use Umami, an open-source analytics tool that we host ourselves on our own infrastructure in the European Union. It is served from our own domain, so no analytics request leaves our systems for a third-party network.
Umami does not use cookies, does not store an identifier on your device, and does not track you across websites. It records page views in aggregate form — page, referrer, approximate country (derived from the IP, which is not stored), device type and browser. Because no identifier is stored and no profile is created, this does not require a cookie banner under the ePrivacy Directive.
4. Bot protection (third party)
The contact form is protected by Cloudflare Turnstile so that automated systems cannot abuse it. To perform that check, Cloudflare receives your IP address and basic browser signals. Cloudflare acts as our processor and is contractually bound by EU Standard Contractual Clauses. Turnstile is a privacy-focused alternative to CAPTCHA and does not profile you for advertising. See Cloudflare's privacy policy.
5. Where your data is stored
Contact submissions, our analytics and the website itself run on infrastructure operated by CAI Technology in the European Union. Email replies are handled on EU-hosted mail infrastructure. The single exception is the bot-protection check described in section 4.
6. Who can see it
Only CAI Technology staff who need it to answer you. We do not share enquiries with third parties. We may disclose data if legally required to do so.
7. Your rights
Under the GDPR you may request access to your data, rectification of inaccurate data, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing relies on consent, you may withdraw it at any time — that does not affect processing already carried out.
Write to privacy@caitech.eu and we will respond within 30 days. You also have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP, or with the authority in your country of residence.
8. Security
The site is served over HTTPS only. Submissions are transmitted encrypted, stored on EU infrastructure with restricted access, and secrets are never written to logs. Security issues can be reported per our security.txt.
9. Changes
If we change how we process data, we update this page and its version number. Material changes will be noted at the top.