Privacy Policy
At Synapse Soft Software Technologies (“Synapse Soft”, “we”, or “Company”), we adhere to the highest standards of confidentiality, data integrity, and cybersecurity regarding visitors to our website (synapsesoft.studio), enterprise business partners, and organizations evaluating or deploying our flagship DigiVal® Validation Management System (VMS). This Privacy Policy delineates how personal data is collected, processed, protected, and the legal mechanisms safeguarding data subject rights.
1. Data Controller & Scope
This Privacy Policy governs data processing activities across synapsesoft.studio, our inquiry and demo request forms, direct communications, and software services delivered by Synapse Soft. Synapse Soft acts as a Data Controller under Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR) for data gathered directly via our web platform. For enterprise B2B customers utilizing our SaaS or On-Premise software deployments, Synapse Soft operates strictly as a "Data Processor", handling operational, clinical, and validation records solely pursuant to the Master Services Agreement and Data Processing Addendum (DPA) executed with the customer.
2. Categories of Personal Data Processed
Synapse Soft collects and processes only the minimum data necessary for legitimate business operations, proposal generation, service delivery, and statutory compliance:
- Identity & Corporate Contact Data: Full name, job title, corporate email address, telephone number, and represented company/institution name.
- Inquiry & Scoping Content: Information submitted through demo request forms, including intended deployment architecture (Cloud/On-Premise/Hybrid), scope of validation, and architectural requirements.
- Technical Transaction & Security Data: Internet Protocol (IP) addresses, browser type and version, operating system, referrer URL, UTC access timestamps, and system security telemetry logs.
- DigiVal In-App Audit Data: Operational entries, electronic signatures, approvals, Out-Of-Specification (OOS) exception logs, and protocol revisions recorded in accordance with regulatory mandates, sealed via immutable SHA-256 hash chains.
3. Customer Data Ownership & Absolute Isolation
Synapse Soft explicitly acknowledges that all protocols, FMEA risk assessments, document templates, and proprietary scientific data uploaded by enterprise customers remain the exclusive intellectual property of the customer. Synapse Soft:
- Never sells, rents, leases, or monetizes customer data to any third party under any circumstances.
- Never ingests, parses, or exposes customer proprietary data for training public or foundational artificial intelligence models.
- Ensures that in On-Premise and Air-Gapped deployments, all data stores and compute resources reside strictly within customer infrastructure behind enterprise firewalls, with zero telemetry or data transmission to Synapse Soft servers.
4. Purposes of Processing & Legal Grounds
Personal data is processed pursuant to valid legal grounds under KVKK Article 5 and GDPR Article 6: (a) Performance of a contract or steps prior to entering into a contract (KVKK Art. 5/2-c, GDPR Art. 6/1-b) for managing corporate proposals, demo sessions, and commercial agreements; (b) Compliance with legal obligations (KVKK Art. 5/2-ç, GDPR Art. 6/1-c) including cybersecurity log retention under Law No. 5651; and (c) Legitimate interests (KVKK Art. 5/2-f, GDPR Art. 6/1-f) in safeguarding system integrity, preventing cyber threats, and optimizing enterprise service availability.
5. Cryptographic Security & Technical Controls
Synapse Soft enforces state-of-the-art administrative, physical, and technical safeguards to ensure data confidentiality and tamper-resistance:
- Mandatory TLS 1.3 encryption with strong cipher suites and HTTP Strict Transport Security (HSTS) across all web endpoints and API gateways.
- Cryptographic Audit Trail sealing adhering to FDA 21 CFR Part 11.10(e) using SHA-256 hash chains and synchronized UTC timestamps.
- AES-256 encryption for data at rest across all database partitions and cloud storage buckets.
- Enforcement of Role-Based Access Control (RBAC), the principle of least privilege, and mandatory Multi-Factor Authentication (MFA) across internal operations.
6. Third-Party Disclosures & International Transfers
Data is disclosed to third parties strictly on a need-to-know basis and exclusively to ISO 27001 and SOC 2 Type II certified cloud infrastructure providers (European Union / GCP Frankfurt region and locally compliant data centers). Synapse Soft does not transfer personal data internationally except under recognized adequacy decisions or standard contractual clauses (SCCs), or when legally compelled by competent judicial authorities pursuant to valid court orders.
7. Retention & Disposal Schedule
Personal data is retained only for the duration necessary to fulfill the stated processing purposes and throughout applicable statutory limitation periods under the Turkish Commercial Code, Code of Obligations, and Tax Procedure Law (up to 10 years). Upon expiration of the retention window or cessation of the processing ground, data is irreversibly erased, destroyed, or anonymized in compliance with KVKK regulations.
8. Data Subject Rights & Contact Channels
Under KVKK Article 11 and GDPR Articles 15–22, you possess the right to access your personal data, demand rectification, request erasure, restrict processing, and seek compensation for unlawful processing. To exercise your statutory rights, direct your verified application to privacy@synapsesoft.studio. Formal requests are processed and concluded free of charge within a statutory maximum of thirty (30) days.