Privacy Policy

Last updated: 4 October 2026

1. Introduction

This Privacy Policy explains how SYFT.AI LIMITED (referred to as "we", "us", "our", or "Syft") collects, uses, stores, and protects your personal data when you use our product data platform ("the Service").

We are committed to protecting your privacy and handling your data in an open and transparent manner. This policy is compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

Data Controller

SYFT.AI LIMITED is the data controller responsible for your personal data. We are registered in England and Wales, and our registered office is at 2 Trinity House, 5 Cliddesden Road, Basingstoke, England, RG21 3DU. If you have any questions about this Privacy Policy or our data practices, please contact us at:

2. Information We Collect

2.1 Personal Information You Provide

We collect information you provide directly to us, including:

  • Account registration information: Name, email address, password
  • Profile information: Preferences, settings, and configuration options
  • Communication data: Support requests, feedback, and correspondence with us

2.2 User Content

We process and store data you upload to our Service, including:

  • Spreadsheet data and files: Product catalogues, pricing data, and inventory information
  • Processing results and exports: Enhanced data and generated files

2.3 Automatically Collected Information

We automatically collect certain information when you use our Service:

  • Usage data: Features used, actions taken, file uploads, processing activity
  • Device information: Browser type, operating system, device identifiers
  • Log data: IP addresses, access times, pages viewed, referring URLs
  • Performance data: Page load times, errors, and system diagnostics

3. How We Use Your Information

3.1 Lawful Basis for Processing

Under UK GDPR, we process your personal data based on the following lawful bases:

Purpose Lawful Basis
Providing and maintaining the Service Contract performance
Processing your data according to your instructions Contract performance
Sending transactional emails and service notifications Contract performance
Providing customer support Contract performance / Legitimate interest
Improving and developing our Service Legitimate interest
Analytics and performance monitoring Legitimate interest
Error tracking and debugging Legitimate interest
Fraud prevention and security Legitimate interest
Legal compliance and regulatory obligations Legal obligation
Marketing communications Consent

4. Section removed

This section is no longer used.

5. Artificial Intelligence and Automated Processing

5.1 AI-Powered Features

Syft has one feature that can use artificial intelligence: matching products to Amazon listings by product name when a product cannot be matched by its barcode. This feature is not currently in use. Column mapping and data structure detection use rule-based methods, not artificial intelligence.

5.2 Third-Party AI Services

When the product-name matching feature is in use, it sends product information to OpenAI: product names, brands, part numbers, pack sizes, candidate Amazon listings and, where a product has no name, its barcode. It never sends your account details. When it is in use:

  • Relevant portions of your data may be processed by OpenAI's systems
  • OpenAI processes this data in accordance with its privacy policy
  • We minimise the data sent to external AI services to only what is necessary for the specific feature
  • AI processing is used to assist your workflows, not to make automated decisions with legal or significant effects

5.3 Your Rights Regarding AI Processing

Under UK GDPR, you have rights regarding automated processing:

  • You can request human review of any AI-assisted decisions
  • You can object to automated processing in certain circumstances
  • You can request information about the logic involved in automated decisions

6. Cookies and Similar Technologies

6.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website. We use cookies and similar technologies to operate our Service effectively.

6.2 Types of Cookies We Use

Essential Cookies (Strictly Necessary)

These cookies are required for the Service to function and cannot be disabled:

  • Session cookies: Maintain your login session and remember your authentication status
  • Security cookies: Protect against cross-site request forgery (CSRF) attacks
  • Preference cookies: Remember your settings and preferences within the application

Analytics Cookies

We use analytics cookies to understand how visitors interact with our Service:

  • PostHog: We use PostHog for product analytics to understand feature usage, identify usability issues, and improve the Service. PostHog may collect information about pages visited, features used, and user interactions. For more information, see PostHog's Privacy Policy.
  • Google Analytics: We use Google Analytics to measure visits and usage on these legal pages, the help centre and the signed-in application (not the home page, nor the sign-in, password-reset or invite pages). Google Analytics may collect information about pages visited and how you interact with them. For more information, see Google's Privacy Policy.

Performance and Error Tracking

  • Sentry: We use Sentry for error tracking and performance monitoring. When errors occur, Sentry collects diagnostic information to help us identify and fix issues. This may include browser information, the action being performed, and relevant technical data. For more information, see Sentry's Privacy Policy.

6.3 Managing Cookies

You can control and manage cookies through your browser settings. However, please note that disabling essential cookies may prevent the Service from functioning correctly.

Most browsers allow you to:

  • View what cookies are stored and delete them individually
  • Block third-party cookies
  • Block cookies from specific sites
  • Block all cookies
  • Delete all cookies when you close your browser

7. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share your information only in the following circumstances:

7.1 Service Providers (Data Processors)

We work with carefully selected third-party service providers who process data on our behalf:

Provider Purpose Location
Hetzner Online GmbH Cloud hosting (application, database and cache) Germany (EU)
Cloudflare (R2) File storage and encrypted backups Western Europe
PostHog Product analytics EU (Frankfurt)
Sentry Error tracking and monitoring EU (Germany)
OpenAI Product-name matching (artificial intelligence), when in use USA (with appropriate safeguards)
Mailgun Email delivery and inbound email routing EU
Google (Google Analytics) Analytics for the legal pages, help centre and signed-in application USA
Google (Google Workspace) Inbox for email sent to Syft addresses USA and other countries

To enrich product data, Syft sends product identifiers (barcodes and product names), never personal data, to product data providers: Keepa, and ScraperAPI when the product-name matching feature is in use.

7.2 Legal Requirements

We may disclose information if required by law or in response to valid legal process, including:

  • Compliance with court orders, subpoenas, or other legal processes
  • Requests from law enforcement or regulatory authorities
  • Protection of our legal rights and property
  • Prevention of fraud, security threats, or illegal activity
  • Protection of the safety of our users or the public

7.3 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and your options regarding your data.

8. International Data Transfers

Some of our service providers are located outside the United Kingdom. When we transfer personal data internationally, we ensure appropriate safeguards are in place:

  • Adequacy decisions: We may transfer data to countries that the UK government has determined provide adequate protection
  • Standard Contractual Clauses (SCCs): We use UK-approved international data transfer agreements where required
  • UK Extension to the EU-US Data Privacy Framework: Where applicable for US-based processors
  • Supplementary measures: Additional technical and organisational safeguards where necessary

You have the right to request information about the safeguards we have in place for international transfers.

9. Data Security

We implement appropriate technical and organisational measures to protect your information:

  • Encryption: Data is encrypted in transit using TLS/SSL and at rest where appropriate
  • Access controls: Strict authentication requirements and role-based access
  • Secure infrastructure: Hosted on secure cloud platforms with industry-standard protections
  • Regular security assessments: Ongoing monitoring and security reviews
  • Employee training: Staff are trained on data protection and security best practices
  • Incident response: Procedures in place to detect, respond to, and report security incidents

While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

10. Data Retention

We retain your information only for as long as necessary to fulfil the purposes outlined in this policy:

  • Account information: Retained until you delete your account, plus a reasonable period for backup and legal compliance
  • Uploaded files and processed data: Retained until you delete them or close your account
  • Usage logs and analytics: Up to 2 years for service improvement and security purposes
  • Error logs: Up to 90 days for debugging purposes
  • Email communication records: Up to 6 years for legal compliance
  • Financial records: Up to 7 years as required by UK law

After the retention period, data is securely deleted or anonymised.

11. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, you have the following rights:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will respond to your request within one month.

Right to Rectification

You can request that we correct any inaccurate or incomplete personal data.

Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You can request that we limit how we use your data in certain circumstances, such as while we verify the accuracy of your data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Object

You can object to processing based on legitimate interests, including profiling. You can also object to processing for direct marketing purposes at any time.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. You can request human intervention in such decisions.

Right to Withdraw Consent

Where we process your data based on consent, you can withdraw that consent at any time. This will not affect the lawfulness of processing before withdrawal.

How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@syft.it. We will respond to your request within one month. In complex cases, we may extend this by a further two months, but we will inform you if this is necessary.

We may ask you to verify your identity before processing your request. There is generally no fee for exercising your rights, but we may charge a reasonable fee for manifestly unfounded or excessive requests.

12. Right to Complain

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:

  • Website: https://ico.org.uk
  • Telephone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first at privacy@syft.it.

13. Children's Privacy

Our Service is intended for business users and is not directed at children under 18 years of age. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us immediately.

14. Email Marketing

When you use Syft to send marketing emails to your customers, you are the data controller for that processing. You are responsible for:

  • Ensuring you have the appropriate legal basis (usually consent) to contact your recipients
  • Complying with the Privacy and Electronic Communications Regulations (PECR)
  • Including accurate sender information and unsubscribe mechanisms
  • Honouring unsubscribe requests promptly

Syft acts as a data processor when sending emails on your behalf and will only process recipient data according to your instructions.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • We will update the "Last updated" date at the top of this policy
  • For significant changes, we will notify you by email or through a prominent notice in the Service
  • We encourage you to review this policy periodically

Your continued use of the Service after any changes indicates your acceptance of the updated policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We aim to respond to all enquiries within 5 working days.

17. Governing Law

This Privacy Policy and any disputes relating to it shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction over any disputes arising from or relating to this policy.