PRIVACY POLICY
Last updated: 2026/1/15
This privacy notice for Querier, Inc. (“Synatra,” “we,” “us,” or “our”) describes how and why we might collect, store, use, and/or share (“process”) your information when you use our services (“Services”), such as when you:
- Visit our website at https://synatrahq.com, or any website of ours that links to this privacy notice
- Use our cloud-based AI agent platform to connect data sources and build AI-powered workflows
- Engage with us in other related ways, including sales, marketing, or events
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at privacy@synatrahq.com.
SUMMARY OF KEY POINTS
This summary provides key points from our privacy notice, but you can find out more details about any of these topics in the sections below.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with Synatra and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? We do not intentionally collect or process sensitive personal information. Data source credentials you provide are encrypted and processed solely for the purpose of connecting to your data sources.
Do we receive any information from third parties? We may receive information from third parties, such as authentication providers when you use social login features.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
Do we share information with third parties? We share information with third-party service providers necessary to operate our Services, including payment processors (Stripe) and AI providers (OpenAI, Anthropic, Google) when you use AI features.
How do we keep your information safe? We implement organizational and technical processes and procedures to protect your personal information, including AES-256-GCM encryption for sensitive credentials.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
1. WHAT INFORMATION DO WE COLLECT?
Personal Information You Provide to Us
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information we collect may include:
- Names
- Email addresses
- Phone numbers
- Job titles
- Usernames
- Billing addresses
- Profile images
Sensitive Information. We do not intentionally collect or request sensitive personal information (such as racial or ethnic origin, religious beliefs, health information, or biometric data). Please do not provide sensitive information to us through the Services.
Organization Information. When you create or join an organization:
- Organization name and identifier
- Organization logo (optional)
- Your role within the organization
Payment Information. When you subscribe to a paid plan:
- We may collect data necessary to process your payment, such as your payment instrument number and the security code associated with your payment instrument
- All payment data is stored by Stripe. You may find their privacy notice at: https://stripe.com/privacy
- We store only Stripe customer and subscription identifiers
- We do not store your credit card numbers or payment details directly on our servers
Data Source Credentials. When you connect external data sources:
- Connection credentials (passwords, API keys, certificates)
- These are encrypted using AES-256-GCM before storage
- Credentials are decrypted only in isolated services when establishing connections
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information Automatically Collected
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
Log and Usage Data:
- IP address
- Browser type and version
- Operating system and settings
- Device information
- Referring URLs
- Pages viewed and features used
- Date and time of access
- Error reports and system activity
Device Data:
- Device and application identification numbers
- Hardware model
- Internet service provider and/or mobile carrier
- System configuration information
Location Data:
- We collect location data such as information about your device’s location, which can be either precise or imprecise. How much information we collect depends on the type and settings of the device you use to access the Services.
- For example, we may use GPS and other technologies to collect geolocation data that tells us your current location (based on your IP address).
- You can opt out of allowing us to collect this information either by refusing access to the information or by disabling your Location setting on your device. However, if you choose to opt out, you may not be able to use certain aspects of the Services.
Session Information:
- Session tokens
- Session duration
- User agent string
Like many businesses, we also collect information through cookies and similar technologies.
Information from AI Interactions
When you use AI agents:
- Prompts and messages you send to agents
- Agent responses and outputs
- Tool calls and their results
- Data retrieved from your connected sources during agent execution
This information is processed to provide the AI agent functionality and may be sent to third-party LLM providers as described in Section 4.
2. HOW DO WE PROCESS YOUR INFORMATION?
We process your personal information for a variety of reasons, depending on how you interact with our Services:
To facilitate account creation and authentication. We process your information so you can create and log in to your account, as well as keep your account in working order.
To provide our Services. We process your information to:
- Connect to your external data sources
- Execute AI agent workflows
- Process and display agent outputs
- Manage triggers and automated tasks
To manage subscriptions and billing. We process your information to:
- Create and manage your subscription
- Track usage against plan limits
- Process payments through Stripe
- Send invoices and billing notifications
To communicate with you. We may process your information to:
- Send authentication emails (magic links)
- Send service-related notifications
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
To ensure security and prevent fraud. We process your information to:
- Monitor for suspicious activity
- Prevent unauthorized access
- Maintain audit logs for security purposes
To comply with legal obligations. We may process your information to comply with applicable laws, regulations, and legal requests.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
If you are located in the EU or UK
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on to process your personal information:
Consent. We may process your information if you have given us permission to use your personal information for a specific purpose. You can withdraw your consent at any time.
Performance of a Contract. We process your personal information when necessary to fulfill our contractual obligations to you, including providing our Services.
Legitimate Interests. We may process your information when reasonably necessary to achieve our legitimate business interests, such as:
- Improving and optimizing our Services
- Understanding how users interact with our platform
- Ensuring the security of our Services
Legal Obligations. We may process your information where necessary for compliance with our legal obligations.
If you are located in Japan
We process your personal information in accordance with the Act on the Protection of Personal Information (APPI). We identify a specific purpose for the use of personal information and process data only to the extent necessary for stated purposes.
If you are located in Canada
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If the information is publicly available and is specified by the regulations
If you are located in California
The California Consumer Privacy Act (CCPA) provides California residents with specific rights regarding their personal information. See Section 10 for more details.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We may share your information with the following categories of third parties:
Service Providers
Payment Processing (Stripe)
- We use Stripe to process payments
- Stripe receives your billing information directly
- Stripe’s privacy policy: https://stripe.com/privacy
Email Services (Resend)
- We use Resend to send transactional emails
- Resend receives your email address for delivery purposes
Infrastructure Providers
- We use cloud infrastructure providers to host our Services
- These providers process data on our behalf under data processing agreements
AI/LLM Providers
When you use AI agent features, data may be sent to third-party LLM providers:
Supported Providers:
- OpenAI
- Anthropic
- Google (Gemini)
What data is shared:
- Prompts and messages to agents
- Data retrieved from your connected sources during agent execution
- Context necessary for the AI to respond
Important: We do not use your data, prompts, or outputs to train generalized AI models. LLM providers process data solely to generate responses for your specific requests. You can configure which LLM provider your organization uses.
AI Processing Risks. When using AI agents, please be aware:
- Data sent to LLM providers may be processed in jurisdictions with different privacy standards than your own
- LLM outputs may inadvertently reflect patterns from training data and should not be considered authoritative
- We recommend not inputting highly sensitive personal data (such as government IDs, financial account numbers, or health information) into AI agent prompts unless necessary for your use case
- You are responsible for ensuring your use of AI features complies with applicable data protection laws
Advertising and Analytics Partners
We may share your data with:
- Ad Networks: For targeted advertising purposes
- Data Analytics Services: To help us understand how users interact with our Services
Business Transfers
We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
Affiliates
We may share your information with our affiliates, in which case we will require those affiliates to honor this privacy notice. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.
Legal Requirements
We may disclose your information where required to do so by law or in response to valid requests by public authorities.
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
We may use cookies and similar tracking technologies to access or store information. We use:
Essential Cookies: Required for the Services to function, including authentication and session management.
Analytics Cookies: Help us understand how visitors interact with our Services.
You can set your browser to refuse all or some cookies. If you disable or refuse cookies, some parts of the Services may become inaccessible or not function properly.
6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
Our Services may offer you the ability to register and log in using your third-party social media account details (such as Google). If you choose to do this, we will receive certain profile information from your social media provider, typically including your name, email address, and profile picture.
We will use the information we receive only for the purposes described in this privacy notice or otherwise made clear to you on the Services.
Our application does not retain user data obtained through Google Workspace APIs for the purpose of developing, improving, or training generalized AI and/or ML models. We also do not use Customer Content that you upload to the Services as training input for generalized AI and/or ML models without your consent. We prioritize user privacy and ensure that any data accessed through these APIs is used solely for the intended functionality of our application.
7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by third parties with whom we may share your personal information, in the United States, Japan, and other countries.
If you are a resident in the European Economic Area (EEA) or United Kingdom (UK), we have implemented measures to protect your personal information, including by using the European Commission’s Standard Contractual Clauses for transfers of personal information. These clauses require all recipients to protect personal information in accordance with European data protection laws and regulations.
8. HOW LONG DO WE KEEP YOUR INFORMATION?
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law.
Account Data: Retained while your account is active and for a reasonable period thereafter for legal and business purposes.
Usage Data: Retained for analytics purposes, typically aggregated and anonymized after 12 months.
Agent Interaction Data: Retained according to your organization’s settings and our data retention policies.
Billing Records: Retained as required by applicable tax and accounting laws.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information.
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process:
Encryption:
- Data source credentials are encrypted using AES-256-GCM
- Data in transit is protected using TLS/HTTPS
- Encryption keys are managed securely and separately from encrypted data
Access Controls:
- Role-based access control within organizations
- Authentication via secure methods (magic links, OAuth)
- Session management with expiration
Infrastructure Security:
- Network isolation between services
- Regular security updates and patches
- Monitoring for unauthorized access
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. We cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
10. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at privacy@synatrahq.com.
11. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: In some regions, such as the European Economic Area (EEA), United Kingdom (UK), Canada, and Japan, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
Depending on your location, you may have certain rights regarding your personal information:
For All Users
Access: You may request access to the personal information we hold about you.
Correction: You may request that we correct any inaccurate personal information.
Deletion: You may request that we delete your personal information, subject to certain exceptions.
Account Termination: You may terminate your account at any time by contacting us.
For EEA and UK Residents (GDPR)
In addition to the rights above, you have:
Right to Restriction: You may request that we restrict processing of your personal information.
Right to Data Portability: You may request a copy of your personal information in a structured, commonly used, machine-readable format.
Right to Object: You may object to processing based on legitimate interests.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time. You can withdraw your consent at any time by contacting us using the contact details provided below. However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Right to Lodge a Complaint: If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
For California Residents (CCPA)
California residents have specific rights:
Right to Know: You may request information about the categories and specific pieces of personal information we have collected.
Right to Delete: You may request deletion of your personal information.
Right to Opt-Out: You may opt-out of the sale of your personal information. Note: We do not sell personal information.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
“Shine the Light” Law: California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
California Residents Under 18: If you are under 18 years of age, reside in California, and have a registered account with Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).
Opting Out of Marketing Communications
You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us using the details provided below. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account, to respond to service requests, or for other non-marketing purposes.
Cookies and Similar Technologies
Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Services. You may also opt out of interest-based advertising by advertisers on our Services.
To exercise your rights, please contact us at privacy@synatrahq.com. We will consider and act upon any request in accordance with applicable data protection laws.
12. NOTICE TO JAPAN RESIDENTS
If you are located in Japan, we will handle your Personal Information in accordance with the Act on the Protection of Personal Information (APPI).
Security Management Measures. We take necessary and appropriate measures to manage Personal Information, including organizational, human, physical, and technical safeguards, to address risks such as loss, destruction, alteration, and leakage of Personal Information. We will provide information about the outline of our security management measures without delay upon request.
Disclosure. If you request disclosure of your Personal Data under APPI, we will confirm that the request is made by you and disclose it without delay, unless APPI or other applicable laws permit us not to disclose it.
Correction, Addition, or Deletion. If you request correction, addition, or deletion of your Personal Data on the grounds that it is inaccurate, we will conduct necessary investigation without delay and, based on the results, make the requested changes and notify you.
Cessation of Use or Provision. If you request cessation of use, erasure, or cessation of provision to third parties of your Personal Data under APPI and we determine that your request has grounds, we will take such measures without delay and notify you.
To make requests under APPI, please contact us at privacy@synatrahq.com. We may ask you to verify your identity.
13. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.
14. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated “Last updated” date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email us at privacy@synatrahq.com or contact us by post at:
Querier, Inc. (Representative: Akatsuki Yoshida) Hamamatsu-Cho-Daiya-Building 2F, Hamamatsu-Cho 2-2-15, Minato-ku, Tokyo
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please contact us at privacy@synatrahq.com.