Privacy Policy

Last updated: 26 June 2026

This Privacy Policy explains how Synnea handles personal data for the people who hold accounts and use our service. It is written with the EU General Data Protection Regulation (GDPR) and the EEA in mind. It mainly concerns personal data for which Synnea acts as a controller (for example, account holders). The register data our customers store in Synnea is handled separately — see section 4 and our Data Processing Agreement.

1. Introduction & who we are

Synnea is a multi-tenant business-to-business software service for marine and offshore interface management. It lets customer organisations model systems, interfaces and redundancy on vessels and installations and produce supporting analyses (including dynamic positioning and FMEA work). The application is available at app.synnea.no and our marketing website at synnea.no.

The controller responsible for the personal data described in this policy is [Synnea legal entity name], [registered address]. Where we determine the purposes and means of processing your personal data, we are the controller. Where we process data on behalf of a customer organisation, we act as a processor (see section 4).

This policy covers the personal data Synnea controls — principally the data of account holders and other individuals who interact with us directly. It does not, by itself, govern the customer register and other content that organisations upload to the service; that Customer Content is processed under our Data Processing Agreement (available at /legal/dpa).

If you have questions about this policy or how we handle your personal data, you can contact us using the details in section 13.

2. The personal data we collect

We collect and process the following categories of personal data when you create an account and use Synnea. The table below summarises each category, typical examples and where it comes from.

CategoryExamplesSource
Account dataEmail address, full name, profile details, organisation membership. Passwords are handled by our authentication provider and are stored only as salted hashes — we never see your password in plain text.Provided by you, or by an administrator who invites you.
Authentication & session dataLogin records, session tokens, multi-factor settings and similar information used to keep your account secure and signed in.Generated when you sign in and use the service.
Support communicationsThe content of messages you send us, and our correspondence with you, including any information you choose to include.Provided by you when you contact us.
Usage & diagnostic dataTechnical and error information collected by our error-monitoring tool, such as error events, performance traces, browser and device type, and limited context needed to diagnose problems. Session replay is masked and captured only on errors, and our error monitoring is configured to send no personal data by default.Generated automatically as you use the service.

We do not intentionally collect special categories of personal data (such as health, biometric or similar sensitive data) about account holders. Please do not include such data in support messages or your profile.

3. How we use your data and our legal bases

We process your personal data only where we have a lawful basis to do so under the GDPR. The purposes and corresponding legal bases are:

  • Performance of a contract (Article 6(1)(b)): to create and administer your account, authenticate you, provide the service, and respond to your support requests.
  • Legitimate interests (Article 6(1)(f)): to keep the service secure (including detecting and preventing fraud, abuse and security incidents), to maintain, troubleshoot and improve the service, and to communicate with you about service-related matters. Where we rely on legitimate interests, we balance those interests against your rights and freedoms.
  • Consent (Article 6(1)(a)): where consent is required — for example, for certain optional cookies or non-essential communications. You can withdraw consent at any time without affecting processing carried out before withdrawal.
  • Legal obligations (Article 6(1)(c)): to comply with applicable laws, such as tax, accounting and lawful requests from competent authorities.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not engage in profiling for those purposes.

4. Customer Content & our role as processor

The register and related content that customer organisations store in Synnea — including organisations, installations, systems, interfaces, vendors, uploaded documents, comments, activity logs, notifications and API keys (which are stored only as a salted hash) — is Customer Content. For that content, Synnea acts as a processor on behalf of the customer organisation, which is the controller.

Our processing of Customer Content is governed by our Data Processing Agreement (available at /legal/dpa), which sets out the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, and the security and sub-processor commitments that apply. If you are an individual whose data appears in a customer's register, please direct privacy requests to that customer organisation as the controller; we will assist them as required by the Data Processing Agreement.

5. Sharing & sub-processors

We do not sell your personal data, and we do not share it for third-party advertising. We share personal data only with service providers (sub-processors) who help us run the service, and only as needed for them to perform their function under contract. Our current sub-processors are:

Sub-processorPurposeLocation
SupabaseManaged Postgres database, authentication and file storage.European Union (region eu-north-1).
VercelApplication hosting and content delivery network.Global edge network; EU data residency for the database is maintained by Supabase.
SentryError monitoring and performance. Session replay is masked and error-only, and the integration sends no personal data by default.EU-hosted instance.

Our marketing website (synnea.no) is hosted on a separate web/FTP host that handles no customer data. We may also disclose personal data where required by law, to enforce our agreements, or to protect the rights, safety and property of Synnea, our customers or others. If Synnea is involved in a merger, acquisition or asset sale, personal data may be transferred as part of that transaction, subject to this policy.

6. International transfers

We host our database within the EU/EEA. Where a transfer of personal data outside the EEA does take place (for example, through a sub-processor's global infrastructure), we put appropriate safeguards in place as required by Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses [Standard Contractual Clauses reference / mechanism], together with any supplementary measures needed to ensure an adequate level of protection. You can ask us for more information about the safeguards we use.

7. Data retention

We keep account data for the lifetime of your account and for a limited period afterwards, so that we can wind down the account, resolve disputes, and meet our legal, tax and accounting obligations. When that period ends, we delete or anonymise the data.

  • Account, authentication and profile data: retained for the life of the account, then for a limited period after closure before deletion or anonymisation.
  • Support communications: retained for as long as needed to handle your request and for a reasonable period afterwards.
  • Usage & diagnostic data: retained for a limited period for security, troubleshooting and service-improvement purposes, after which it is deleted or aggregated.

Retention of Customer Content is governed by the Data Processing Agreement and the customer organisation's instructions.

8. Security

We take technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or loss. These include:

  • Tenant isolation enforced in the database using Postgres Row-Level Security, so that each organisation's data is segregated from others.
  • Encryption of data in transit using HTTPS.
  • EU data residency for the database.
  • Access controls and authentication, with credentials stored only as salted hashes.
  • Error-monitoring session replay that is masked and captured only on errors, and configured to send no personal data by default.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security; however, we work to maintain appropriate protection and to respond promptly to any incident.

9. Your rights

Subject to the conditions and exceptions in the GDPR, you have the following rights in respect of your personal data:

  • Access — to obtain confirmation of whether we process your data and a copy of it.
  • Rectification — to have inaccurate data corrected and incomplete data completed.
  • Erasure — to have your data deleted in certain circumstances (the “right to be forgotten”).
  • Restriction — to limit how we process your data in certain circumstances.
  • Portability — to receive certain data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Objection — to object to processing based on our legitimate interests, on grounds relating to your particular situation.
  • Withdraw consent — where we rely on consent, you can withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us using the details in section 13. We will respond within the time limits required by law and may need to verify your identity first. There is normally no charge, though we may charge a reasonable fee or decline to act on manifestly unfounded or excessive requests as permitted by law.

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority — in particular the supervisory authority in the EEA country of your habitual residence, place of work or the place of the alleged infringement [supervisory authority — e.g. the Norwegian Data Protection Authority (Datatilsynet)]. We would, however, appreciate the chance to address your concerns first.

10. Cookies

Synnea uses cookies and similar technologies — for example, to keep you signed in and to operate the service. These are described in our separate Cookie Notice (available at /legal/cookies), which also explains how you can manage your preferences.

11. Children

Synnea is a business tool. The service is not directed to children and is not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our service, our practices or the law. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (for example, in the application or by email). We encourage you to review this policy periodically.

13. Contact

If you have questions, requests or complaints about this policy or our handling of your personal data, you can reach us at hello@synnea.no.

  • Controller: [Synnea legal entity name], [registered address].
  • Privacy contact: [Data Protection Officer / privacy contact, if appointed].
  • Email: hello@synnea.no.