Last updated: August 2026 · Version 1.4 · Applies to synopticom.com and all Synopticom CX platform services
1. Who we are
Synopticom, UAB (company code 300650435, VAT LT100003433213) is an experience management platform provider operating the Synopticom CX platform. Address: Savanorių pr. 1, LT-03116 Vilnius, Lithuania. Website: synopticom.com.
For GDPR purposes, Synopticom acts as the data controller for personal data collected via our website and as a data processor for personal data collected on behalf of our clients through the platform. For privacy enquiries, contact us at info@synopticom.com.
2. What data we collect
2.1 Data you give us directly
- Contact information (name, email, company name, job title) when you book a demo or complete a contact form
- Account credentials when you register for the platform
- Communication content when you contact us by email or via our website
- Your email address, the consent wording you agreed to, and the date, when you subscribe to our research newsletter
- Payment and billing information processed securely through our payment provider
2.2 Data collected automatically
- Technical data: IP address, browser type, device type, operating system
- Usage data: pages visited, time spent, features used, clicks, and navigation paths
- Cookie data: session identifiers, preference cookies, and analytics cookies
2.3 Survey and feedback data (Platform clients)
When our clients use the platform to run feedback programmes, survey responses may include personal data about respondents. We process this data strictly as a data processor on behalf of our clients, who act as data controllers.
3. How we use your data
- To provide, operate, and improve the Synopticom CX platform and our services
- To respond to enquiries, demo requests, and support tickets
- To process payments and manage your account
- To send service communications, updates, and security notices
- To send marketing communications (only with explicit consent, which you can withdraw at any time)
- To send our research newsletter to subscribers who confirmed their address, until they unsubscribe
- To analyse usage and improve our platform features
- To comply with legal obligations
- To prevent fraud, abuse, and unauthorised access
4. Legal basis for processing
We process personal data on the following legal bases under the GDPR:
- Contract performance — to provide the platform, manage your account, and deliver services you have requested
- Legitimate interests — to improve our services, ensure security, prevent fraud, and respond to enquiries, where these interests are not overridden by your rights
- Consent — for marketing communications and non-essential cookies; you may withdraw consent at any time
- Legal obligation — to comply with applicable laws, tax requirements, and regulatory requests
When we process data on behalf of platform clients, the client (as data controller) determines the legal basis for collecting respondent data.
5. Who we share data with
We do not sell your personal data. We may share data with:
- Service providers (sub-processors) — hosting, cloud infrastructure, analytics, email delivery, and payment processing providers that support our operations, bound by data processing agreements
- Platform clients — when you respond to a survey or feedback programme run by a client, your data is shared with that client as the data controller
- Legal and regulatory authorities — when required by law or to protect our legal rights
- Professional advisers — lawyers, auditors, or insurers where necessary and subject to confidentiality obligations
Where data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.
6. How long we keep data
- Account data — for the duration of your account plus up to 3 years after closure, unless a longer period is required by law
- Enquiry and demo request data — up to 2 years from last contact, or until you request deletion
- Marketing consent records — until consent is withdrawn, plus a reasonable period to record the withdrawal
- Technical logs — typically up to 12 months
- Survey and feedback data (processor) — retained according to each client's instructions and our data processing agreement; clients define retention periods for respondent data
When data is no longer needed, we securely delete or anonymise it.
7. Your rights
Under GDPR you have the right of access, rectification, erasure, restriction, data portability, to object to processing, to withdraw consent, and to lodge a complaint with your supervisory authority. Contact us at info@synopticom.com. We will respond within 30 days.
If your data was collected through a client's feedback programme, you may also contact that client directly as the data controller.
8. Cookies
Our website uses cookies and similar technologies. We ask for your consent before placing anything that is not strictly necessary:
- Functional cookies — required for the website to work (session management, security, and remembering your cookie choice); these do not require consent
- Preference cookies — remember settings and choices you make on the site
- Statistics cookies — Google Analytics, which helps us understand how visitors use the site; these are placed only after you consent
- Marketing cookies — used for advertising measurement and personalisation; these are placed only after you consent
We use Google Consent Mode. Until you consent, the Google tag stores nothing on your device and sends no identifiers, but it does load and send a cookieless signal that includes your IP address and browser type. Consenting to statistics turns on measurement cookies; consenting to marketing additionally allows advertising and personalisation signals. Refusing either keeps both switched off.
You choose which categories to allow when you first visit the site. You can change or withdraw that choice at any time through the Cookie settings link in the footer of every page — withdrawing consent is as easy as giving it. Refusing statistics cookies does not affect how the website works.
Browser settings can also block cookies, but they are a blunt instrument and may break parts of the site. The Cookie settings link is the reliable way to manage your choice here. For anything else, contact info@synopticom.com.
9. Security
We implement end-to-end encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, regular security audits, and staff training on data protection. In the event of a data breach posing risk to your rights, we will notify the relevant supervisory authority within 72 hours.
Synopticom, UAB
Savanorių pr. 1, LT-03116 Vilnius, Lithuania
Company code: 300650435
VAT: LT100003433213
Email: info@synopticom.com
Website: synopticom.com
Lithuanian supervisory authority: VDAI (vdai.lrv.lt)