Table of contents
- 1. What this policy covers
- 2. Personal data we collect
- 3. Why we collect personal data
- 4. Legal basis for processing
- 5. Who we share personal data with
- 6. International transfers
- 7. Cookies and similar technologies
- 8. How long we keep personal data
- 9. Your rights under GDPR
- 10. Security
- 11. Changes to this policy
- 12. Contact
Effective date: 10 June 2026
Controller: SynlogIQ d.o.o., Gospodar Jevremova 42, 11000 Belgrade, Serbia. Registered in the Republic of Serbia. Contact: hello@synlogiq.dev.
1. What this policy covers
This privacy policy explains how SynlogIQ d.o.o. (“SynlogIQ”, “we”, “us”) collects, uses, and protects personal data when you:
- Visit synlogiq.dev or any related subdomain.
- Submit a form on this website (contact form, careers application, general application).
- Communicate with us by email, phone, or other channel.
- Engage SynlogIQ for commercial services under a separate Master Services Agreement or Statement of Work.
This policy applies to personal data only — not to anonymous aggregate data or to information about legal entities that isn’t tied to an identified individual.
2. Personal data we collect
We collect personal data in three ways:
2.1 Data you provide directly.
When you fill in a form on the website, you give us information you choose to share. The exact fields vary by form (see the form on each page for what is asked), but commonly include:
- Your name.
- Your email address.
- Your phone number (optional).
- Your company and role (optional).
- A free-text message describing your enquiry or application.
- For careers applications: your CV, LinkedIn URL, country of residence, primary skill area, and seniority.
2.2 Data collected automatically.
When you visit the website, we automatically collect:
- Technical data: IP address, browser type, device type, operating system, referring URL.
- Usage data: pages visited, time on page, navigation patterns.
- Cookie data: see Section 7 for details.
2.3 Data we receive from third parties.
In limited cases, we may receive personal data from third parties such as professional networks (e.g. LinkedIn for prospect research) or referrers (e.g. a contact who introduces you to SynlogIQ). When this happens, we only use such data for the specific purpose for which it was provided, and we will inform you at the next reasonable opportunity.
3. Why we collect personal data
We collect personal data for the following purposes:
3.1 To respond to your enquiry.
If you contact us via a form, email, or phone, we use your data to reply to you, follow up, and (with your continued consent) develop a commercial conversation.
3.2 To process careers applications.
If you apply for a role or submit a general application, we use your data to evaluate your application, contact you about it, and — with your consent — keep your details in our talent pool for up to 12 months.
3.3 To deliver contracted services.
If you or your organisation engages SynlogIQ under a commercial agreement, we process personal data necessary to deliver the services. The specific data and processing are governed by the engagement contract and any applicable Data Processing Agreement (DPA).
3.4 To operate and improve the website.
Technical and usage data helps us keep the website running, secure it against abuse, and understand which content is useful.
3.5 To comply with legal obligations.
We may process personal data to comply with applicable laws, respond to lawful requests from authorities, and protect our legal rights.
4. Legal basis for processing (GDPR Article 6)
We process personal data on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry | Legitimate interest (your request) and your consent (by submitting the form) |
| Processing your careers application | Your consent + legitimate interest in evaluating talent |
| Keeping you in the talent pool | Your explicit consent (with the option to withdraw at any time) |
| Delivering contracted services | Performance of a contract (Article 6(1)(b)) |
| Compliance with law | Legal obligation (Article 6(1)(c)) |
| Website analytics (where used) | Consent (via cookie banner) |
| Security and abuse prevention | Legitimate interest |
5. Who we share personal data with
We share personal data only where necessary and only with parties who provide adequate protection. Categories include:
- Sub-processors and service providers — for example, our email provider, our CRM provider, our website analytics provider. Each is bound by a DPA where applicable.
- Cloud infrastructure providers — Microsoft Azure, AWS, or comparable, where personal data is stored or processed in the course of website operation or service delivery.
- Professional advisors — legal, accounting, tax — where necessary for SynlogIQ’s legitimate business operation.
- Competent authorities — where legally required (e.g. court order).
We do not sell personal data. We do not share personal data for third-party advertising. We do not use personal data to train AI models without your explicit consent.
6. International transfers
SynlogIQ is based in Serbia. Some of our service providers and cloud infrastructure may be located in the EU/EEA, the United Kingdom, the United States, or other jurisdictions. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards including:
- Standard Contractual Clauses (EU SCCs) where applicable.
- UK International Data Transfer Agreement or Addendum where applicable.
- Adequacy decisions where they exist.
You may request a copy of the safeguards in place for a specific transfer by writing to hello@synlogiq.dev.
7. Cookies and similar technologies
The website uses cookies for the following purposes:
- Essential cookies — required for the website to function (e.g. preferences for the cookie banner itself). Cannot be disabled.
- Analytics cookies — to understand which content is useful. Used only with your consent (set via the cookie banner). We use Google Analytics 4 with anonymisation.
- Marketing cookies — we do not currently use marketing cookies. If this changes, the cookie banner and this policy will be updated.
You can change your cookie preferences at any time by clicking the “Manage cookies” link in the footer.
8. How long we keep personal data
| Data category | Retention period |
|---|---|
| Contact form submissions | 24 months from submission or last meaningful contact, whichever is later |
| Careers applications (specific role) | 12 months from application |
| Careers applications (general / talent pool) | 12 months from last refresh, with reminder to refresh |
| Engagement-related personal data | For the duration of the engagement + 7 years (Serbian record-keeping requirement) |
| Website analytics | Anonymised after 14 months |
| Email correspondence | 24 months from last reply, unless tied to an active engagement |
At the end of the retention period, personal data is deleted or anonymised. Where deletion is not technically possible (e.g. encrypted backups), data is securely isolated and protected until automatic deletion.
9. Your rights under GDPR
You have the following rights with respect to your personal data:
- Right of access — to know what personal data we hold about you.
- Right to rectification — to correct inaccurate data.
- Right to erasure (“right to be forgotten”) — to ask us to delete your data, subject to legal limits.
- Right to restriction — to limit how we process your data.
- Right to portability — to receive your data in a portable format.
- Right to object — to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint — with a supervisory authority. The lead authority for SynlogIQ is the Serbian Commissioner for Information of Public Importance and Personal Data Protection (www.poverenik.rs). EU residents may also lodge a complaint with their local supervisory authority.
To exercise any of these rights, write to hello@synlogiq.dev. We respond within 30 days. If we need to extend, we will tell you why.
10. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, audit logging, and regular review of our security posture. No system is perfectly secure, but we take this seriously.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the appropriate supervisory authority within 72 hours and inform affected individuals where required.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced on the website and, where appropriate, communicated directly to individuals whose data we hold. The “Effective date” at the top of this policy will always show the latest revision.
12. Contact
Questions about this policy, or about how we handle your personal data:
Email: hello@synlogiq.dev
Postal address: SynlogIQ d.o.o., Gospodar Jevremova 42, 11000 Belgrade, Serbia.