Privacy Policy
Last updated: February 2026
Synergy Axella respects your privacy. This policy explains what personal data we collect via the Synergy Axella Operations Excellence Platform, how we use it, and your rights under the EU General Data Protection Regulation (GDPR).
1. Data controller
Synergy Axella, Egelstraat 22, 3512 Hasselt, Belgium, VAT BE 0944.578.721, is the data controller. Contact, privacy@synergyaxella.com.
2. What we collect
- Account data, email, name, role, preferred language, hashed password.
- Security data, IP address, timestamps and outcomes of login attempts, session tokens.
- Operational content you create, shift notes, downtime entries, quality reports, kaizens, work orders.
- Copilot interactions, questions you send to the AI assistant.
- Website contact forms, name, work email, company, role, plant location, preferred window, message.
3. Legal basis
- Contract (Art. 6(1)(b)), providing access to the Platform.
- Legitimate interest (Art. 6(1)(f)), security, audit logs, responding to enquiries.
- Legal obligation (Art. 6(1)(c)), record-keeping duties under Belgian and EU law.
4. Retention
Account data is retained while your account is active. Failed login logs are kept for 30 days. Operational content is retained while your organisation subscribes, or up to 7 years thereafter as required by manufacturing traceability regulations. Contact form submissions are retained for 24 months, then deleted.
5. Your rights
Under GDPR you have the right to access, rectify, erase, restrict, object, and portability.
- Data export โ Account, Security and Privacy, Download my data (Art. 20).
- Erasure โ Account, Security and Privacy, Delete account (Art. 17).
- Other rights โ email privacy@synergyaxella.com.
You may also lodge a complaint with the Belgian Data Protection Authority at autoriteprotectiondonnees.be.
6. Transfers outside the EU
Some sub-processors may process data outside the EEA. We rely on Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework. See the Sub-processors page.
7. Security
Passwords are hashed with bcrypt. Sessions are cookie-based, HttpOnly, Secure, SameSite Lax, with a 30-minute inactivity timeout. Admin accounts are eligible for TOTP two-factor authentication. Traffic is encrypted with TLS.