Syntax Agents

Privacy policy

What data moves through the managed service.

This notice maps the current implementation: what is collected, why it is used, who can receive it, where it remains, and what deletion actually does.

Controller

Syntax Studios, Dennis Spannagel, c/o Postflex #10315, Emsdettener Str. 10, 48268 Greven, Germany
kontakt@syntax-studios.org

Version

3 August 2026

01 / Data journey

From collection to deletion

  1. 01

    You provide data

    Account details, orders, prompts, files, integration settings, and requests.

  2. 02

    The portal records it

    Production account, billing, legal-request, and platform state is stored in PostgreSQL.

  3. 03

    The instance uses it

    Runtime content, customer files, credentials, and backups live on the assigned managed node.

  4. 04

    Selected providers receive it

    Only the data needed for payment, email, inference, hosting, or a chosen integration.

  5. 05

    It is deleted or retained

    Operational deletion follows lifecycle jobs. Some records can remain while a legally approved retention schedule is still pending.

The application repository contains no advertising tracker or behavioural analytics integration. Server, reverse-proxy, payment, email, inference, hosting, and integration providers can still process request or service metadata as described below.

02 / Data categories

Concrete records, sources, and storage

CategoryExamplesSourcePrimary location
Account and authenticationEmail address, display name, salted password hash, verification status, roles, TOTP configuration, hashed recovery codes, session identifier and version, and authentication events.You, your browser, and security events generated by the portal.PostgreSQL in production; a signed session cookie is held in your browser.
Subscription and paymentSelected plan and runtime, instance name, PayPal customer, plan, subscription, transaction and webhook identifiers, amount, status, paid-through date, cancellation, refund, reversal, and dispute events.You and verified PayPal API or webhook events.Portal billing records in PostgreSQL and corresponding records at PayPal. The application does not receive card or PayPal login credentials.
Managed service and operationsInstance and node identifiers, runtime choice, provisioning and health state, resource measurements, AI budget usage, backup and patch metadata, audit events, errors, and correlation IDs.The portal, Manager, assigned node, runtime, and infrastructure.PostgreSQL for portal state; restricted Manager and node databases, files, and logs for operations.
Agent content and customer configurationChat messages, sessions, jobs, uploaded files, installed skills, integration settings, and customer-owned credentials. If configured for OpenClaw, a Telegram bot token is stored encrypted by the portal, delivered to the runtime, and may appear in node backups as customer configuration.You, people who communicate with your agent, and the selected runtime or integration.Primarily the assigned node and runtime volume; inference content is transmitted to OpenRouter when the managed model route is used.
Support and legal declarationsName, email, contract or PayPal reference, requested date, optional reason, receipt and delivery state, and timestamps. The implemented refund workflow additionally records staff actor, note, status, and decision history; cancellation and withdrawal currently do not have that operator workflow.You through support or the cancellation, withdrawal, and refund forms; staff adds review data only in the implemented refund workflow.PostgreSQL in production and the configured email provider for receipts and operator notices.
Request and security metadataRequest time, route, method, correlation ID, authentication result, the raw trusted IP string used for rate limiting, and redacted security or error events. If no trusted proxy header is configured, the rate limiter uses the value "unknown". Hosting and proxy providers may also create access logs containing IP address and user-agent data.Your device, network, portal, reverse proxy, and hosting infrastructure.Process memory for the legal-form rate-limit bucket for up to one hour; restricted application or infrastructure logs for other events.

03 / Purposes and bases

Why processing is intended to be lawful

These are intended bases, not a claim that the production legal assessment is complete. The deployed processing inventory, necessity test, legitimate-interest balancing, consent design, and statutory retention duties require counsel approval before launch.

Deliver the contract

Create and secure the account, process checkout, provision and operate the selected instance, route inference, maintain backups, provide support, and handle billing or termination.

GDPR Art. 6(1)(b), where necessary to take requested steps or perform the contract.

Meet legal duties

Keep and answer consumer declarations and retain records where accounting, tax, commercial, or other law requires it.

GDPR Art. 6(1)(c), once the applicable duty and retention period have been confirmed.

Protect and operate the service

Prevent abuse, rate-limit requests, investigate incidents, maintain security audit trails, recover service, and establish or defend legal claims.

GDPR Art. 6(1)(f), after documenting the purpose, necessity, and balancing of interests.

Optional consent-based processing

Only a separate optional activity that genuinely relies on consent. A selected integration may instead be necessary to deliver the feature you requested.

GDPR Art. 6(1)(a) only where the production flow obtains valid consent and offers withdrawal.

Official source: General Data Protection Regulation, including Articles 6 and 13.

04 / Recipients

Who can receive which data

Syntax Studios operations

Authorized staff can access account, billing, support, legal-request, and operational records when needed to provide, secure, or review the service. The implemented refund workflow attributes and timestamps staff decisions; cancellation and withdrawal currently only create an intake record and email attempts.

PayPal

Receives order and subscription instructions and supplies payment, subscription, refund, dispute, and webhook identifiers and status. Payment credentials stay with PayPal.

OpenRouter

Receives model requests, including prompt or conversation content and technical metadata, when your instance uses the managed inference route. The runtime receives a scoped proxy token rather than the per-instance provider key.

Email delivery provider

Receives the destination address and message contents for verification, password reset, legal-request receipts, and operator notifications. Legal-request emails contain the submitted request details.

Hosting and managed nodes

Store and process portal state, runtime content, customer files, secrets, logs, and backups needed to operate the service.

Telegram and chosen integrations

Telegram processes bot messages and metadata only if you configure that channel. A separately configured operator alert bot can receive operational event details; agent conversations are not intended to be included in those alerts.

Authorities or professional advisers

Data may be disclosed where legally required or necessary to establish, exercise, or defend legal claims. No routine sale of personal data is intended.

International transfers are not yet production-resolved. Provider legal entities, processing regions, controller/processor roles, data-processing agreements, and any adequacy decision or standard contractual clauses must be verified and published before launch. No EU-only hosting claim is made here. See the European Commission transfer guidance.

05 / Access and security

Controls implemented, and their limits

Account controls

Passwords use salted scrypt hashes. Recovery codes are hashed. Sessions are signed and sent in HttpOnly cookies that are Secure in production and SameSite=Lax.

Managed secrets

The customer Telegram token is encrypted with AES-256-GCM in portal state. Per-instance OpenRouter keys remain encrypted on the node; runtimes use scoped proxy tokens.

Operational access

Access is limited to authorized operations and support work. The implemented refund workflow records the staff actor and decision history; cancellation and withdrawal do not yet have that workflow. Security logs are designed to redact secrets.

Backup limits

Node archives are permission-restricted and validated, but built-in at-rest archive encryption, off-host replication, legal holds, and independent expiry paging are not yet implemented.

The final archive is created with file mode 0600 and managed platform secrets are replaced. “Sanitized” does not mean customer content is removed: customer files, configuration, and a configured Telegram token can remain in that archive. No system can promise absolute security.

06 / Retention and deletion

What disappears when

Verification and reset

Email verification codes expire after 15 minutes. Password-reset codes expire after 10 minutes.

Portal session

The signed session can remain valid for up to 30 days, but logout, password or security changes, deletion, and administrative revocation can invalidate it earlier.

Active service

Account, subscription, instance, agent content, configuration, and operational data remain while needed to deliver and secure the subscribed service.

Active backups

Pro automatic snapshots default to one every 24 hours with 14 automatic snapshots retained. Manual, pre-patch, and pre-restore archives can also exist; their complete production rotation and legal-hold rules are not yet finalized.

Account deletion and paid access

After a verified deletion request, sessions are revoked and the account enters pending deletion. An already paid runtime remains available until the confirmed paid-through time, even though portal login is unavailable.

Final 30-day recovery window

At paid-through, the runtime is stopped, managed inference is disabled, and one validated final archive is created. Its expiry is exactly 30 days after paid-through, not 30 days after the request.

Final purge

At expiry, the data becomes due for deletion and the system attempts to remove the provider key, runtime project, managed-secret envelope, customer files, and entire node backup directory. A failed purge is marked as failed and retried, so completion can occur later than the exact expiry time. On successful purge, portal environment references and the encrypted Telegram token are cleared. Authentication data is anonymized only after all subscriptions are terminal.

Records without a finalized schedule

Billing, tax, audit, security, support, and legal-request records can remain after runtime deletion. Exact category-by-category periods and automated deletion jobs are not yet implemented and are a production launch blocker.

Important distinction

Deleting an account is not the same as immediately erasing every record. Runtime data follows the paid-through and 30-day final-backup sequence. Billing, consumer-declaration, audit, and claim records need separate, legally approved retention rules. A data-subject erasure request is assessed against those obligations.

07 / Your rights

Request access, correction, deletion, or restriction

Information and access

Correction

Deletion where applicable

Restriction

Data portability where applicable

Objection

Withdraw consent

Complain to an authority

Send a privacy request

Email kontakt@syntax-studios.org. Describe the right you want to exercise and the account email involved. We may request proportionate information to verify identity. Do not send passwords, payment credentials, recovery codes, or a Telegram token.

Account deletion

Authenticated customers can start account deletion in the portal. Password and a second factor are verified where enabled, PayPal subscriptions must be cancelled successfully, sessions are revoked, and the lifecycle above begins. For a GDPR request independent of account closure, use email.

For the controller address stated in North Rhine-Westphalia, the competent state authority is expected to be the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW); jurisdiction can differ in an individual case. You may also contact another supervisory authority where the GDPR permits. Refund decisions require staff review. The public cancellation and withdrawal forms do not make decisions and currently are not connected to an operator decision queue.

Production launch blocker

Before live processing, Syntax Studios must complete and approve the record of processing activities, named processor and subprocessor list, hosting locations, transfer safeguards, data-processing agreements, exact category retention schedule and deletion jobs, supervisory authority, incident and rights-request procedures, archive security decision, cookie inventory, and formal GDPR review against the deployed configuration. This page deliberately does not claim those open items are complete.