PRIVACY & DATA POLICY

Last updated: 1 June, 2025

1. INTRODUCTION

This Privacy & Data Policy (“Policy”) describes how SYNDICO SAS (“SYNDICO”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal and business data across the esyndico® ecosystem.

This Policy applies to all users and visitors interacting with:

  • Our websites: esyndico.com, mymarina.esyndico.com, supplier.esyndico.com, myboat.esyndico.com
  • Our mobile apps: Syndico Owner App, Syndico Technician App

This Policy complies with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other relevant international data protection laws.

2. DATA CONTROLLER
  • Entity: SYNDICO SAS
  • Legal Form: Société par Actions Simplifiée (SAS)
  • Registration: 984 871 095
  • Address: 38B Boulevard Victor Hugo, 06000, Nice, France
  • Email: contact@esyndico.com
3. TYPES OF DATA COLLECTED

3.1. User-Provided Data

  • Name, email, phone number
  • Account credentials
  • Boat and equipment details
  • Business contact details (Marinas, Suppliers)
  • Uploaded media and documents
  • Feedback, ratings, reviews

3.2. Automatically Collected Data

  • IP address, browser, device info
  • App usage logs, clickstreams
  • Language and region settings
  • Crash reports and error logs

3.3. App-Specific Data

  • GPS location (on consent)
  • Device ID
  • Photo/Media files (for uploads)

3.4. Third-Party Data

  • Stripe: payment metadata (no credit card numbers)
  • Marina operators or suppliers: booking/contract details
  • Analytics & performance tools: pseudonymous usage behavior
4. PURPOSE OF DATA PROCESSING

Your data may be used to:

  • Provide and personalize platform services
  • Authenticate and secure user accounts
  • Process bookings, requests, and payments
  • Monitor and optimize platform usage
  • Support customer service and dispute resolution
  • Comply with legal and regulatory obligations
  • Generate internal business intelligence reports
5. LEGAL BASES UNDER GDPR

Our data processing is based on:

  • Performance of a contract: account, services, transactions
  • Legal obligation: invoicing, audits, law enforcement
  • Legitimate interest: platform improvement, fraud prevention
  • Consent: cookies, marketing, location sharing
6. COOKIE USAGE & TRACKING

We use cookies and trackers on our web portals to:

  • Maintain secure sessions
  • Remember user preferences
  • Measure engagement and performance (Google Analytics, Hotjar)
  • Deliver marketing campaigns (Meta Pixel, LinkedIn Tag)

You may control your cookie settings through the Cookie Preferences Manager on esyndico.com.

See our [Cookie Policy] for full details.

7. SHARING & DISCLOSURE

We do not sell your personal data. We may share it with:

  • Hosting and infrastructure partners
  • Authorized service providers and subcontractors
  • Payment processor (Stripe)
  • Marinas, Suppliers, or Technicians involved in your request
  • Legal/regulatory authorities where legally required

All partners are contractually obligated to adhere to confidentiality and GDPR requirements.

8. INTERNATIONAL DATA TRANSFERS

If data is processed outside the EU/EEA:

  • We use only GDPR-compliant providers
  • EU Standard Contractual Clauses (SCCs) are enforced
  • Data centers are located in secure, regulated regions (e.g., EU, GCC)
9. DATA RETENTION
  • Account data: retained during active use and for 12 months after deletion
  • Payment records: retained for 10 years (EU accounting laws)
  • Cookies & analytics: retained as per consent and browser settings
  • App permissions: stored securely with time of opt-in/opt-out
10. USER RIGHTS UNDER GDPR

You have the right to:

  • Access your personal data
  • Rectify inaccurate information
  • Request deletion (right to be forgotten)
  • Restrict or object to processing
  • Request data portability
  • Withdraw your consent at any time
  • Lodge a complaint with the CNIL (France) or your local data authority

To exercise your rights, contact us at contact@esyndico.com.

11. SECURITY MEASURES

We take appropriate security measures to protect your data:

  • TLS/SSL encryption
  • Strong authentication and role-based access
  • Daily backups and secure server infrastructure
  • Regular penetration testing and code review
12. CHILDREN’S PRIVACY

Our platform is not intended for children under 16. We do not knowingly collect data from minors without verifiable parental consent.

13. CHANGES TO THIS POLICY

We may amend this Policy periodically. You will be notified of significant updates via email, in-app notification, or upon login.

14. CONTACT US
  • Email: contact@esyndico.com
  • Address: 38B Boulevard Victor Hugo, 06000, Nice, France
15. VERSION HISTORY
  • v1.0 – Issued on 1 June, 2025