Subprocessors

About this page

This page lists the third parties that process content and personal data on SynC's behalf, what each one does for us, how a request reaches it, and what controls we apply to them. SynC offers the Services to customers in the United States and processes personal data there; the Privacy Policy §7 states what that means if you use the Services from elsewhere. Where more than one provider may perform a function, this page names every one of them, and does not say which is serving at a given time. A provider is named here before any content or personal data is sent to it, and a provider that is named may or may not be serving on the day you read this. A change within the named set needs no change to this page.

Each provider's own documents govern how it handles data. Where a provider processes data, how long it keeps a request, and whether it trains on what it receives are stated in that provider's own terms, data processing addendum, privacy policy or data-handling page, and each row below links them. Those documents are the authority. This page does not restate or summarise them, so that you are never left with two versions of the same fact; for the provider you are asking about, read the document its row links. Where the region in which our own account with a provider runs is ours to choose, §3 and §4 state the region we chose.

This page states no promises. Our commitments about what we and our providers may do with your content are in the Terms of Service §5.3 and the Privacy Policy §4.1A. If this page and either of those ever disagree, they govern. This page records who we use or may use; those documents record what any of them is permitted to do.

Providers change from time to time. Our obligations do not. Where a change would materially reduce the protections described in Terms of Service §5.3.3, we give at least thirty days' notice before it takes effect. A provider added to this page, or removed from it, is recorded under "Changes to this page" with the date.

Where a provider is visible to you, we say so. A payment page shows its operator's name; a booking page's address is its operator's; a link in our email resolves through our email provider's tracking domain. This page names those providers as it names the others.

Which provider received your own data. If you are in the EEA, the UK or Switzerland, an access request under the Privacy Policy §8.1 may ask us to identify the actual recipients of your personal data, including which inference provider served your requests to the AI assistant, rather than the candidates named here.

1. AI inference

The hosts below are the ones we may send content to: one or more of them serves at any given time. Which of them serves a given request depends on the model in use and on how the request is sent, and that can change without this page changing. What does not change is that content goes only to a host on this list, and that a host is listed here before any request is sent to it.

How a request reaches a host. A request is either sent to a host directly, on our own account with that host, or sent through OpenRouter, a routing service that does not run the model itself but selects a host from a set we specify. Where a request is routed, the operative data policy is the selected host's, not the router's, which is why the hosts are listed individually rather than as "the router". The "How reached" column states which path applies to each host.

Controls applied to every request:

  • content is sent only to a host listed below;
  • where a request is sent directly, we rely on the host's standard terms with us, which do not permit it to use submitted content to train its models or to retain it for its own purposes, and on its published data-handling terms, linked below; where the host offers an account setting that shares inputs and outputs with it for model improvement, that setting is off on our account; we do not ask the host to store completions on our behalf;
  • where a request is routed rather than sent directly, the router is instructed to exclude providers it classifies as logging on or training on submitted content (that classification is the router's, reported to us), automatic failover is disabled, so an outage produces a failed request rather than a reroute to a host we have not vetted, and a minimum numeric-precision floor is set; and
  • the request fails rather than proceeding if no host satisfies these constraints.

Our terms with the hosts. We are on each host's standard terms, with no negotiated agreement, and we have no zero-data-retention arrangement with any host.

Our configuration pins the host, not the region. We choose which companies may serve a request, and neither the router nor our own routing offers a country or jurisdiction filter. Where a host processes a request, how long it keeps it, and whether it trains on it are stated in the host's own documents, linked in the last column; those documents govern, and this page does not restate them. The Privacy Policy §5.1 states what a request a host keeps contains.

Host How reached The host's own documents
OpenAI Direct Privacy Policy · API data usage and retention
Anthropic Direct Commercial Terms · Data Processing Addendum · Privacy Policy · Data retention · Subprocessors
xAI (SpaceXAI LLC) Direct Enterprise Terms · Data Processing Addendum · API data handling · Subprocessors
DigitalOcean Routed Privacy Policy
Venice Routed Privacy Policy
Fireworks AI Routed Privacy Notice
CoreWeave Routed Privacy Policy

Companies not listed here are excluded by our configuration, including other companies that serve the same models, and automatic failover is disabled so that none can be selected.

2. Text embedding (semantic search)

To make content searchable by meaning rather than only by keyword, text is converted into numeric vectors by a third-party embedding service. The vectors are stored in our own database. This covers public SynC Standards content, customers' own standards and project specifications, and the search queries users type.

Controls applied to every request: the same set as §1 for the routed path — logging and training excluded at the provider on the router's classification, routing restricted to the hosts below, automatic failover disabled, and fail-closed behaviour, so that search falls back to keyword matching rather than relaxing a constraint. Both hosts are reached through the routing service; one or the other serves at any given time.

Host How reached The host's own documents
DeepInfra Routed Privacy Policy
Nebius Routed Privacy Policy

Search-query caching is first-party. Queries and their vectors are cached in our own database and are not shared with any processor. That cache carries no account identifier; see Privacy Policy §5.1 ("Derived Search Data").

3. Infrastructure, storage, email

The locations in this table are our own. They are the regions in which our accounts, instances and buckets with each provider are placed, or, where a service has no region to choose, the nature of that service; none is taken from a provider's policy.

Function Provider Processing locations
Application hosting and database Amazon Web Services United States (US East, Ohio)
Document and file storage Cloudflare R2 United States (Eastern North America)
Backups Cloudflare R2, Google Drive R2: United States (Eastern North America). Google Drive: Google-managed global infrastructure
Transactional email Amazon SES United States (US East, Ohio)
DNS, CDN, TLS Cloudflare Global edge network
Calendar and video meetings for calls booked with us (§6) Google Workspace (Calendar and Meet) Google-managed global infrastructure

The email we send is tracked by the processor that delivers it. Amazon SES rewrites every link in our mail so that a click resolves first through its tracking domain, awstrack.me, which records the click and then redirects to the destination on our site — this is why a link in one of our emails shows an awstrack.me address when you hover over it rather than a synergyinconstruction.com one. Where open tracking is enabled on our account, an invisible image in the message also records that it was opened. Both records are held by that processor; neither is written to your account or to our own database. The Privacy Policy sets out what is recorded, what we can and cannot say about how long it is kept, and what you can do about it — including that no setting in the Services turns it off. This applies to transactional mail, not only marketing, so a marketing opt-out does not reach it.

4. Analytics and monitoring

What each of these receives, and what is withheld from it, is set out in Privacy Policy §4.1. They are listed here for completeness of the set. The locations are the regions of our own accounts with each provider.

Function Provider Processing locations
Web analytics Cloudflare Web Analytics United States
Product analytics PostHog United States
Error monitoring Sentry United States
Search telemetry First-party — our own database —

5. Payments

Seats and AI credits are bought on a payment page the processor below hosts, a company's subscription is changed or cancelled on a billing portal it hosts, and any invoice we raise against a written agreement is paid on a page it hosts. The Services are connected to the processor. The application sends it the company's name and contact email, an identifier for the company and for the purchase, and the item and quantity being bought; it receives back the status of the company's subscription, the amounts charged and whether they were paid, and the billing name, email and address the purchaser entered on the processor's page — and it stores those records. The card details a customer enters on the processor's pages go to the processor directly and never to us, and no content, conversations, credentials or usage data go to the processor. The Privacy Policy §4.1 states what passes in each direction.

Function Provider The provider's own documents
Purchases, subscriptions, invoicing and payment collection Stripe (Stripe, LLC) Privacy Policy · Data Processing Agreement

Where the processor processes is stated in its Data Processing Agreement, linked above, which governs the data we hand to it; this page does not restate it. Where the payment itself is routed depends on the payment method the customer uses, which is the customer's choice on the hosted page and is not something we control or can state here.

6. Scheduling

Where our website offers a booking page, a visitor who books a call with us does so on a page the processor below hosts; the link on our site takes them to it, and its address is shown in the browser when it opens. Until our website offers that page, nothing is sent to this processor; it is named here first so that the name precedes the data. The processor receives the name, work email, company name, optional note and chosen time the visitor enters, and places the booking in our calendar (§3). It receives nothing else: no account credentials, content, conversations or usage data, and a booking is not linked to a SynC account. The Privacy Policy §4.1 states what passes in each direction.

Function Provider The provider's own documents
Booking a call with us Cal.com (Cal.com, Inc.) Privacy Policy · Subprocessors

Where the processor processes is stated in its privacy policy and its subprocessor list, linked above; this page does not restate them.

Changes to this page

This page was first published together with Terms of Service v1.7 and Privacy Policy v1.8; those documents carry the effective date. Changes made after that are recorded here.

2026-08-27 — what our email processor does to the mail it sends. Amazon SES was already listed in §3 as our transactional-email provider, but the page did not say that it rewrites the links in our mail through awstrack.me and can record when a message is opened. §3 now states both. The provider, its function, and its processing location are unchanged; what is new is the description of the tracking it applies.

2026-09-07 — a payment processor is engaged. §5 previously said that no payment processor was engaged and that this page would be updated before one was. It now lists Stripe, which we use to raise invoices and collect payment of them. The entry says what the processor is used for and — because a reader will reasonably assume more — what it is not: it is not connected to the Services, nothing in the application sends it data or receives data from it, and the card or bank details a customer enters on its hosted page go to it directly and never to us. The Privacy Policy §4.1 carries the full disclosure. No other provider on this page changed.

2026-09-14 — the Services are now connected to the payment processor. The 2026-09-07 entry said the processor was not connected to the Services and that nothing in the application sent it data or received data from it. That is no longer so. Companies now buy seats and AI credits on a payment page the processor hosts, opened from the Services, and change or cancel their subscription on a billing portal it hosts; the application sends the processor the company's name, contact email, identifiers, and the item and quantity bought, receives back the purchase, payment and subscription status together with the billing details the purchaser entered, and stores those records. §5 now says so. What has not changed: card details are entered on the processor's pages and never reach us, and no content, conversations, credentials or usage data go to the processor. The provider, its processing locations, and its privacy terms are unchanged. The Privacy Policy §4.1 states what passes in each direction, and the Terms of Service §10 state how purchases and renewals are charged.

2026-09-16 — OpenAI added to §1, and requests to it are no longer routed. OpenAI now serves requests from the AI assistant, and §1 lists it. Two things changed together. The host changed: the four hosts already listed — DigitalOcean, Venice, Fireworks AI and CoreWeave — remain vetted and permitted and stay on the list, but they serve a different model from the one the assistant runs on now. And the path changed: requests to OpenAI are sent to it directly, on our own account, rather than through the routing service, so for those requests there is no router in the path and no host selection to make. §1 is rewritten to describe both ways a request can reach a host, and the controls are stated against the routed path, which is the one they apply to. What has not changed: the set of hosts content may be sent to is still a closed list, companies not on it are still excluded, and our obligations under Terms of Service §5.3.3 are unaffected by a change of host or of path. §2 (text embedding) is unchanged and still routed.

2026-09-29 — this page now names every provider we use or may use, defers to each provider's own documents, and adds Anthropic, xAI and Cal.com. Until this date the page described the AI inference hosts as the ones content may be sent to; it now says the same of every function on the page: where more than one provider may perform a function, all of them are named, none is marked as serving, and a provider is named before any content or personal data is sent to it. Three providers are added. Anthropic and xAI are added to §1 as hosts reached directly, on our own account, alongside OpenAI, and §1 gains a "How reached" column. Cal.com is added in a new §6 as the processor that will host the page on which a visitor books a call with us, where our website offers that page, and §3 lists the calendar and video-meeting purpose our workspace provider serves for those calls; both are named before any booking is taken. §2 gains the "How reached" column. This page also stops restating what a provider's own documents say. Until this date the tables in §1, §2 and §5 gave each provider's processing locations as summarised from its own policy; from this date each row links the provider's own terms, data processing addendum, privacy policy, data-handling page or subprocessor list, and the page does not summarise them, so that a reader is never left with two versions of a fact that the provider's document governs. Where a region is ours to choose, §3 and §4 still state it. The controls for the direct path now also say that where a host offers an account setting to share inputs and outputs with it for model improvement, that setting is off on our account, and §1 now says that we are on each host's standard terms and have no zero-data-retention arrangement with any host; both describe arrangements already in place. No provider was removed on this date, no control changed, and our obligations under Terms of Service §5.3.3 are unaffected. "About this page" now says that SynC offers the Services to customers in the United States and processes personal data there, and points to the Privacy Policy §7 for what that means elsewhere; that is a statement of where we operate. The Privacy Policy v1.14 describes the list the same way, defers to the same documents, and says how to ask which provider received your own data.

Questions

privacy@synergyinconstruction.com — including if your engagement requires zero-data-retention processing or a restricted set of processing jurisdictions, or if you want to know which named provider served your own requests (Privacy Policy §8.1).